US2011179488A1PendingUtilityA1

Kernal-based intrusion detection using bloom filters

Individually held — no corporate assignee on recordPriority: Mar 25, 2004Filed: Feb 11, 2011Published: Jul 21, 2011
Est. expiryMar 25, 2024(expired)· nominal 20-yr term from priority
G06F 21/566G06F 21/552G06F 21/554
46
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Kernel-based intrusion detection using Bloom filters is disclosed. In one of many possible embodiments for detecting an intrusion attack, a Bloom filter is provided and used to generate a Bloom filter data object. The Bloom filter data object contains data representative of expected system-call behavior associated with a computer program. The Bloom filter data object is embedded in an operating system (“OS”) kernel upon an invocation of the computer program. Actual system-call behavior is compared with the data in the Bloom filter data object.

Claims

exact text as granted — not AI-modified
1 . A method comprising:
 receiving a Bloom filter data object containing data representative of expected system-call behavior associated with a computer program;   embedding said Bloom filter data object in an operating system (“OS”) kernel upon an invocation of the computer program; and   comparing actual system-call behavior with said data in said Bloom filter data object.   
     
     
         2 - 28 . (canceled) 
     
     
         29 . The method of  claim 1 , further comprising generating said Bloom filter data object using a Bloom filter, said Bloom filter including a set of hash functions. 
     
     
         30 . The method of  claim 1 , further comprising:
 monitoring system calls of the computer program, said monitoring step being performed in said OS kernel of the computer; and   using said monitored system calls to define said expected system-call behavior of the computer program.   
     
     
         31 . The method of  claim 1 , further comprising appending said Bloom filter data object to an executable image of the computer program. 
     
     
         32 . The method of  claim 1 , further comprising performing said comparing step in said OS kernel in real time. 
     
     
         33 . The method of  claim 1 , wherein said data of said Bloom filter data object is representative of predetermined sequences of system calls. 
     
     
         34 . The method of  claim 1 , further comprising issuing an alert in response to a determination that said actual system-call behavior deviates from said data of said Bloom filter data object. 
     
     
         35 . The method of  claim 1 , wherein said expected system-call behavior is defined automatically, without user intervention. 
     
     
         36 . The method of  claim 1 , further comprising:
 identifying a sequence of system calls generated by the computer program, and   comparing said identified sequence of system calls with said data in said Bloom filter data object to determine if said identified sequence of system calls is a normal sequence of system calls for the computer program.   
     
     
         37 . A system, comprising:
 a computer having a processor and a memory configured to:   receive a Bloom filter data object containing data representative of expected system-call behavior associated with a computer program;   embed said Bloom filter data object in an operating system (“OS”) kernel upon an invocation of the computer program; and   compare actual system-call behavior with said data in said Bloom filter data object.   
     
     
         38 . The system of  claim 37 , wherein said Bloom filter data object is generated using a Bloom filter, said Bloom filter including a set of hash functions. 
     
     
         39 . The system of  claim 37 , wherein the computer is further configured to:
 monitor system calls of the computer program, said monitoring step being performed in said OS kernel of the computer; and   use said monitored system calls to define said expected system-call behavior of the computer program.   
     
     
         40 . The system of  claim 37 , wherein the computer is further configured to append said Bloom filter data object to an executable image of the computer program. 
     
     
         41 . The system of  claim 37 , wherein the computer is further configured to:
 identify a sequence of system calls generated by the computer program, and   compare said identified sequence of system calls with said data in said Bloom filter data object to determine if said identified sequence of system calls is a normal sequence of system calls for the computer program.   
     
     
         42 . A non-transitory computer-readable medium comprising a set of computer-executable instructions tangibly embodied thereon, the instructions including instructions for:
 receiving a Bloom filter data object containing data representative of expected system-call behavior associated with a computer program;   embedding said Bloom filter data object in an operating system (“OS”) kernel upon an invocation of the computer program; and   comparing actual system-call behavior with said data in said Bloom filter data object.   
     
     
         43 . The medium of  claim 42 , wherein said Bloom filter data object is generated using a Bloom filter, said Bloom filter including a set of hash functions. 
     
     
         44 . The medium of  claim 42 , further comprising instructions for:
 identifying a sequence of system calls generated by the computer program, and   comparing said identified sequence of system calls with said data in said Bloom filter data object to determine if said identified sequence of system calls is a normal sequence of system calls for the computer program.   
     
     
         45 . The medium of  claim 42 , further comprising instructions for:
 monitoring system calls of the computer program, said monitoring step being performed in said OS kernel of the computer; and   using said monitored system calls to define said expected system-call behavior of the computer program.   
     
     
         46 . The medium of  claim 42 , further comprising instructions for appending said Bloom filter data object to an executable image of the computer program. 
     
     
         47 . The medium of  claim 42 , wherein said expected system-call behavior is defined automatically, without user intervention.

Join the waitlist — get patent alerts

Track US2011179488A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.