Invention Grant
US09323929B2 Pre-identifying probable malicious rootkit behavior using behavioral contracts
有权
使用行为契约预先识别可能的恶意rootkit行为
- Patent Title: Pre-identifying probable malicious rootkit behavior using behavioral contracts
- Patent Title (中): 使用行为契约预先识别可能的恶意rootkit行为
-
Application No.: US14090200Application Date: 2013-11-26
-
Publication No.: US09323929B2Publication Date: 2016-04-26
- Inventor: David Fiala , Mihai Christodorescu , Vinay Sridhara , Rajarshi Gupta , Kassem Fawaz
- Applicant: QUALCOMM Incorporated
- Applicant Address: US CA San Diego
- Assignee: QUALCOMM Incorporated
- Current Assignee: QUALCOMM Incorporated
- Current Assignee Address: US CA San Diego
- Agency: The Marbury Law Group, PLLC
- Main IPC: G06F21/56
- IPC: G06F21/56

Abstract:
The various aspects provide for a computing device and methods implemented by the device to ensure that an application executing on the device and seeking root access will not cause malicious behavior while after receiving root access. Before giving the application root access, the computing device may identify operations the application intends to execute while having root access, determine whether executing the operations will cause malicious behavior by simulating execution of the operations, and pre-approve those operations after determining that executing those operations will not result in malicious behavior. Further, after giving the application root access, the computing device may only allow the application to perform pre-approved operations by quickly checking the application's pending operations against the pre-approved operations before allowing the application to perform those operations. Thus, the various aspects may ensure that an application receives root access without compromising the performance or security integrity of the computing device.
Public/Granted literature
- US20150150130A1 Pre-identifying Probable Malicious Rootkit Behavior Using Behavioral Contracts Public/Granted day:2015-05-28
Information query