IP Library Granted Patent US 11,042,638
Granted Patent B2
US 11,042,638 · App. 15/812,663 · Granted Jun 22, 2021

Detecting malicious software using sensors

Inventors: Mitchell Thornton (Dallas, TX); Michael Taylor (Dallas, TX); Kaitlin Smith (Dallas, TX)
Assignee: Southern Methodist University
G06F21/568G06F21/50G06F21/53G06F21/56G06F21/566G06F21/567G06F21/57G06N5/022G06N20/00G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,042,638
App. No.
15/812,663
Granted
Jun 22, 2021
Kind
B2
Abstract

In some implementations, a method includes retrieving data from multiple sensors in a computing device, and the multiple sensors comprise different types of sensors. The sensor data is analyzed based on a predictive model, and the predictive model is trained to detect malware. Initiation of malware is determined based on the analysis. In response to the determination, the malware is terminated.

Claims (11)

1. A non-transitory computer readable medium storing instructions to cause a processor of a computing device to perform operations comprising:

simulating initiation of a ransomware encryption in the computing device;

while the ransomware encryption is executed by the computing device, obtaining sensor data from multiple sensors in the computing device, wherein the multiple sensors comprise different types of sensors to monitor an operating condition of internal hardware components of the computing device, the multiple sensors residing in a side channel separate from the processor of the computing device, and the obtained sensor data reflective of the operating condition of the internal hardware components while the ransomware encryption is executed by the computing device, wherein the obtained sensor data obtained while the ransomware encryption is executed by the computing device is different from sensor data obtained while the computing device is not executing the ransomware encryption;

training a predictive model to detect malware using the obtained sensor data to detect execution of ransomware by the computing device;

after training the predictive model, obtaining sensor data from multiple sensors in the computing device during a normal operation of the computing device;

analyzing the obtained sensor data retrieved during the normal operation based on the predictive model;

determining initiation of malware in response to analyzing the obtained sensor data retrieved during the normal operation based on the predictive model; and

in response to the determination, terminating the malware.

2. The non-transitory computer readable medium of claim 1 , wherein the malware comprises ransomware, and initiation of ransomware encryption is detected.

3. The non-transitory computer readable medium of claim 1 , wherein the predictive model comprises a feature vector determined using machine learning.

4. The non-transitory computer readable medium of claim 1 , wherein the multiple sensors comprise a sensor for at least one of a main memory power, voltage, current, or temperature.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 15, 2021
From: THORNTON, MITCHELL
To: IRONWOOD CYBER INC.
Reel/Frame 057806/0684 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 13, 2021
From: SOUTHERN METHODIST UNIVERSITY
To: THORNTON, MITCHELL A.
Reel/Frame 057170/0820 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 13, 2018
From: THORNTON, MITCHELL; TAYLOR, MICHAEL; SMITH, KAITLIN
To: SOUTHERN METHODIST UNIVERSITY
Reel/Frame 045187/0172 →
Continuity (1)
Related Publication 20200279043A1 · Sep 3, 2020
Cited By (1)
US 12,462,031