US2020218832A1PendingUtilityA1

Automatic Initiation of Execution Analysis

Assignee: HEWLETT PACKARD DEVELOPMENT COPriority: Jan 31, 2014Filed: Sep 18, 2019Published: Jul 9, 2020
Est. expiryJan 31, 2034(~7.5 yrs left)· nominal 20-yr term from priority
G06F 21/53G06F 21/566H04L 63/1441G06F 21/71H04L 63/1425G06F 21/564
59
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Approaches for transferring control to a bit set. Execution of a bit set upon a host operating system is monitored. A determination is made that the execution of the bit set exhibits a suspicious characteristic. In response, the execution of the bit set on the host operating system is ceased. Then, the bit set is copied into an isolated environment and control to the bit set is transferred within the isolated environment. Thereafter, execution analysis upon the bit set is initiated in the isolated environment. The isolated environment may, but need not, reside on a different physical device than upon which executes the host operating system.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . One or more non-transitory machine-readable storage mediums storing one or more sequences of instructions for initiating execution analysis upon a bit set, which when executed by one or more processors, causes:
 monitoring execution of the bit set in a host operating system execution environment; and   upon determining that the execution of the bit set exhibits a suspicious characteristic, then (a) ceasing the execution of the bit set in the host operating system execution environment, (b) copying the bit set into an isolated environment and transferring control to the bit set within the isolated environment, and (c) initiating execution analysis upon the bit set in the isolated environment.   
     
     
         2 . The one or more non-transitory machine-readable storage mediums of  claim 1 , wherein said suspicious characteristic is creating a new executable bit set or modifying an existing executable bit set in the host operating system execution environment. 
     
     
         3 . The one or more non-transitory machine-readable storage mediums of  claim 1 , wherein said suspicious characteristic is loading a new dynamic link library (DLL) file. 
     
     
         4 . The one or more non-transitory machine-readable storage mediums of  claim 1 , wherein said monitoring execution of the bit set is only performed upon determining that said bit set is not in either (a) a set of universally known malicious bit sets or (b) a set of locally known virtuous bit sets. 
     
     
         5 . The one or more non-transitory machine-readable storage mediums of  claim 1 , wherein said isolated environment resides on a different physical machine than said host operating system execution environment. 
     
     
         6 . The one or more non-transitory machine-readable storage mediums of  claim 1 , wherein said host operating system execution environment executes on a device, and wherein execution of the one or more sequences of instructions further cause:
 sending information, from said device to a remote location across a network, which describes attributes of said host operating system execution environment; and   at said remote location, creating said isolated environment to possess said attributes of said host operating system execution environment.   
     
     
         7 . The one or more non-transitory machine-readable storage mediums of  claim 1 , after performing said execution analysis upon the bit set in the isolated environment, updating either a set of universally known malicious bit sets or a set of locally known virtuous bit sets to include said bit set. 
     
     
         8 . The one or more non-transitory machine-readable storage mediums of  claim 1 , wherein execution of the one or more sequences of instructions further cause:
 updating metadata to prevent the execution analysis to be performed upon the bit set more than once.   
     
     
         9 . An apparatus for initiating execution analysis upon a bit set, comprising:
 one or more processors; and   one or more non-transitory computer-readable storage mediums storing one or more sequences of instructions, which when executed, cause:
 monitoring execution of the bit set in a host operating system execution environment; and 
 upon determining that the execution of the bit set exhibits a suspicious characteristic, then (a) ceasing the execution of the bit set in the host operating system execution environment, (b) copying the bit set into an isolated environment and transferring control to the bit set within the isolated environment, and (c) initiating execution analysis upon the bit set in the isolated environment. 
   
     
     
         10 . The apparatus of  claim 9 , wherein said suspicious characteristic is creating a new executable bit set or modifying an existing executable bit set in the host operating system execution environment. 
     
     
         11 . The apparatus of  claim 9 , wherein said suspicious characteristic is loading a new dynamic link library (DLL) file. 
     
     
         12 . The apparatus of  claim 9 , wherein said monitoring execution of the bit set is only performed upon determining that said bit set is not in either (a) a set of universally known malicious bit sets or (b) a set of locally known virtuous bit sets. 
     
     
         13 . The apparatus of  claim 9 , wherein said isolated environment resides on a different physical machine than said host operating system execution environment. 
     
     
         14 . The apparatus of  claim 9 , wherein said host operating system execution environment executes on a device, and wherein execution of the one or more sequences of instructions further cause:
 sending information, from said device to a remote location across a network, which describes attributes of said host operating system execution environment; and   at said remote location, creating said isolated environment to possess said attributes of said host operating system execution environment.   
     
     
         15 . The apparatus of  claim 9 , after performing said execution analysis upon the bit set in the isolated environment, updating either a set of universally known malicious bit sets or a set of locally known virtuous bit sets to include said bit set. 
     
     
         16 . The apparatus of  claim 9 , wherein execution of the one or more sequences of instructions further cause:
 updating metadata to prevent the execution analysis to be performed upon the bit set more than once.   
     
     
         17 . A method for initiating execution analysis upon a bit set, comprising:
 monitoring execution of the bit set in a host operating system execution environment; and   upon determining that the execution of the bit set exhibits a suspicious characteristic, then (a) ceasing the execution of the bit set in the host operating system execution environment, (b) copying the bit set into an isolated environment and transferring control to the bit set within the isolated environment, and (c) initiating execution analysis upon the bit set in the isolated environment.   
     
     
         18 . The method of  claim 17 , wherein said monitoring execution of the bit set is only performed upon determining that said bit set is not in either (a) a set of universally known malicious bit sets or (b) a set of locally known virtuous bit sets. 
     
     
         19 . The method of  claim 17 , wherein said isolated environment resides on a different physical machine than said host operating system execution environment. 
     
     
         20 . The method of  claim 17 , wherein execution of the one or more sequences of instructions further cause:
 updating metadata to prevent the execution analysis to be performed upon the bit set more than once.

Join the waitlist — get patent alerts

Track US2020218832A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.