- 专利标题: Rootkit detection based on system dump sequence analysis
-
申请号: US17656971申请日: 2022-03-29
-
公开(公告)号: US12013942B2公开(公告)日: 2024-06-18
- 发明人: Vladimir Strogov , Sergey Ulasen , Serguei Beloussov , Stanislav Protasov
- 申请人: Acronis International GmbH
- 申请人地址: CH Schaffhausen
- 专利权人: Acronis International GmbH
- 当前专利权人: Acronis International GmbH
- 当前专利权人地址: CH Schaffhausen
- 代理机构: ESPE Legal Consultancy FZ-LLC
- 主分类号: G06F21/56
- IPC分类号: G06F21/56 ; G06F21/00
摘要:
The present disclosure relates to a system and method for rootkit detection based on a system dump sequence analysis. The system includes a security system in communication with one or more applications of a computing system. The security system includes a system event monitor to monitor events occurring at the applications, a system dump capture driver to capture differential system dumps corresponding to each event, and a rootkit detection engine to determine if a system state is infected. The rootkit detection engine is based on a machine learning model, where the machine learning model is trained on collection of clean system dumps and infectious system dumps. Based on analysis carried out by the machine learning model, the rootkit detection engine can classify the system state as suspicious, infectious, or clean state.
公开/授权文献
- US20230315850A1 Rootkit detection based on system dump sequence analysis 公开/授权日:2023-10-05
信息查询