System and method for analyzing a device
A system and method for analyzing a device are disclosed. In an aspect, a method can comprise determining a parameter of a device at a kernel level of a software stack associated with the device, analyzing the parameter to determine an event state, comparing the event state to a white list to determine a state of an alert trigger, and generating an alert in response to the determined state of the alert trigger.
1 . An apparatus comprising:
one or more processors; and
memory storing processor executable instructions that, when executed by the one or more processors, cause the apparatus to:
monitor one or more of logical access to embedded software of a user device or physical access to hardware ports and sockets of the user device;
determine, based on the monitoring of the one or more of the logical access to embedded software of the user device or the physical access to hardware ports and sockets of the user device, a physical pattern of operation associated with the user device;
determine, based on one or more acceptable patterns of operation of the user device, that the physical pattern of operation associated with the user device is associated with a pattern of operation corresponding to a security issue; and
cause, based on the physical pattern of operation associated with the user device being associated with the pattern of operation corresponding to the security issue, the user device to be prevented from accessing hardware ports and sockets of the apparatus and an adjustment of a monitoring protocol of data traffic associated with the user device.
2 . The apparatus of claim 1 , wherein the processor executable instructions, when executed by the one or more processors, further cause the apparatus to send, based on the physical pattern of operation associated with the user device being associated with the pattern of operation corresponding to the security issue, a notification to the user device indicating that an account is suspended.
3 . The apparatus of claim 1 , wherein the physical pattern of operation corresponding to the security issue comprises one or more of an unauthorized interaction with a hardware interface associated with the user device, one or more unauthorized secure shell (SSH) commands, or one or more unauthorized Telnet commands.
4 . The apparatus of claim 1 , wherein the processor executable instructions that, when executed by the one or more processors, cause the apparatus to determine the physical pattern of operation associated with the user device, further cause the apparatus to determine a change to an operational process of the user device.
5 . The apparatus of claim 1 , wherein the processor executable instructions, when executed by the one or more processors, further cause the apparatus to change, based on the physical pattern of operation associated with the user device being associated with the pattern of operation corresponding to the security issue, one or more services associated with the user device.
6 . The apparatus of claim 1 , wherein the processor executable instructions, when executed by the one or more processors, further cause the apparatus to suspend, based on the physical pattern of operation associated with the user device being associated with the pattern of operation corresponding to the security issue, one or more services associated with the user device.
7 . The apparatus of claim 1 , wherein the pattern of operation corresponding to the security issue comprises a pattern of physical events.
8 . The apparatus of claim 1 , wherein the processor executable instructions that, when executed by the one or more processors, cause the apparatus to determine the physical pattern of operation associated with the user device further cause the apparatus to receive the physical pattern of operation from the user device.
9 . One or more non-transitory computer-readable media storing processor-executable instructions that, when executed by at least one processor, cause the at least one processor to:
monitor, by a computing device, one or more of logical access to embedded software of a user device or physical access to hardware ports and sockets of the user device;
determine, based on the monitoring of the one or more of the logical access to embedded software of the user device or the physical access to hardware ports and sockets of the user device, a physical pattern of operation associated with the user device;
determine, based on one or more acceptable patterns of operation of the user device, that the physical pattern of operation associated with the user device is associated with a pattern of operation corresponding to a security issue; and
cause, based on the physical pattern of operation associated with the user device being associated with the pattern of operation corresponding to the security issue, the user device to be prevented from accessing hardware ports and sockets of the computing device and an adjustment of a monitoring protocol of data traffic associated with the user device.
10 . The non-transitory computer-readable media of claim 9 , wherein the processor-executable instructions, when executed by the at least one processor, further cause the at least one processor to send, based on the physical pattern of operation associated with the user device being associated with the pattern of operation corresponding to the security issue, a notification to the user device indicating that an account is suspended.
11 . The non-transitory computer-readable media of claim 9 , wherein the physical pattern of operation corresponding to the security issue comprises one or more of an unauthorized interaction with a hardware interface associated with the user device, one or more unauthorized secure shell (SSH) commands, or one or more unauthorized Telnet commands.
12 . The non-transitory computer-readable media of claim 9 , wherein the processor-executable instructions that, when executed by the at least processor, cause the at least one processor to determine the physical pattern of operation associated with the user device, further cause the at least one processor to determine a change to an operational process of the user device.
13 . The non-transitory computer-readable media claim 9 , wherein the processor-executable instructions, when executed by the at least one processor, further cause the at least one processor to change, based on the physical pattern of operation associated with the user device being associated with the pattern of operation corresponding to the security issue, one or more services associated with the user device.
14 . The non-transitory computer-readable media claim 9 , wherein the-processor-executable instructions, when executed by the at least one processor, further cause the at least one processor to suspend, based on the physical pattern of operation associated with the user device being associated with the pattern of operation corresponding to the security issue, one or more services associated with the user device.
15 . The non-transitory computer-readable media of claim 9 , wherein the pattern of operation corresponding to the security issue comprises a pattern of physical events.
16 . The non-transitory computer-readable media of claim 9 , wherein the processor-executable instructions that, when executed by the at least one processor, cause the at least one processor to determine the physical pattern of operation associated with the user device, further cause the at least one processor to receive the physical pattern of operation from the user device.
17 . A system comprising:
a user device configured to:
send telemetry data; and
a computing device configured to:
monitor one or more of logical access to embedded software of the user device or physical access to hardware ports and sockets of the user device;
determine, based on the telemetry data and based on the monitoring of the one or more of the logical access to embedded software of the user device or the physical access to hardware ports and sockets of the user device, a physical pattern of operation,
determine, based on one or more acceptable patterns of operation of the user device, that the physical pattern of operation is associated with a pattern of operation corresponding to a security issue, and
cause, based on the physical pattern of operation being associated with the pattern of operation corresponding to the security issue, the user device to be prevented from accessing hardware ports and sockets of the computing device and an adjustment of a monitoring protocol of data traffic associated with the user device.
18 . The system of claim 17 , wherein the physical pattern of operation corresponding to the security issue comprises one or more of an unauthorized interaction with a hardware interface associated with the user device, one or more unauthorized secure shell (SSH) commands, or one or more unauthorized Telnet commands.
19 . The system of claim 17 , wherein the computing device is further configured to determine a change to an operational process of the user device.
20 . The system of claim 17 , wherein the computing device is further configured to change, based on the physical pattern of operation being associated with the pattern of operation corresponding to the security issue, one or more services associated with the user device.
21 . The system of claim 17 , wherein the computing device is further configured to suspend, based on the physical pattern of operation being associated with the pattern of operation corresponding to the security issue, one or more services associated with the user device.
22 . The system of claim 17 , wherein the pattern of operation corresponding to the security issue comprises a pattern of physical events.
23 . An apparatus comprising:
one or more processors; and
memory storing processor executable instructions that, when executed by the one or more processors, cause the apparatus to:
monitor one or more of logical access to embedded software of a user device or physical access to hardware ports and sockets of the user device;
determine, based on the monitoring of the one or more of the logical access to embedded software of the user device or the physical access to hardware ports and sockets of the user device, a parameter indicating a physical pattern of operation associated with the user device;
determine, based on the parameter, a security issue;
determine, based on the security issue, an alert;
determine, based on the alert, an alert priority; and
cause, based on the alert priority, the user device to be prevented from accessing hardware ports and sockets of the apparatus and an adjustment of a monitoring protocol of data traffic associated with the user device.
24 . The apparatus of claim 23 , wherein the processor executable instructions, when executed by the one or more processors, further cause the apparatus to determine, by a detection element embedded in a software stack associated with the user device, the parameter.
25 . The apparatus of claim 23 , wherein the processor executable instructions that, when executed by the one or more processors, cause the apparatus to determine the parameter, further cause the apparatus to determine a change to an internal process associated with the user device.
26 . The apparatus of claim 23 , wherein the processor executable instructions, when executed by the one or more processors, further cause the apparatus to send, based on the alert priority, a notification to the user device indicating that an account is suspended.
27 . The apparatus of claim 26 , wherein the processor executable instructions, when executed by the one or more processors, further cause the apparatus to change, based on the alert priority, one or more services associated with the user device.
28 . The apparatus of claim 26 , wherein the processor executable instructions, when executed by the one or more processors, further cause the apparatus to suspend, based on the alert priority, a service associated with the user device.
29 . The apparatus of claim 23 , wherein the processor executable instructions, when executed by the one or more processors, further cause the apparatus to determine, based on one or more of an unauthorized interaction with a hardware interface associated with the user device, one or more unauthorized secure shell (SSH) commands, or one or more unauthorized Telnet commands, a change to the parameter.
30 . One or more non-transitory computer-readable media storing processor-executable instructions that, when executed by at least one processor, cause the at least one processor to:
monitor, by computing device, one or more of logical access to embedded software of a user device or physical access to hardware ports and sockets of the user device;
determine, based on the monitoring of the one or more of the logical access to embedded software of the user device or the physical access to hardware ports and sockets of the user device, a parameter indicating a physical pattern of operation associated with the user device;
determine, based on the parameter, a security issue;
determine, based on the security issue, an alert;
determine, based on the alert, an alert priority; and
cause, based on the alert priority, the user device to be prevented from accessing hardware ports and sockets of the computing device and an adjustment of a monitoring protocol of data traffic associated with the user device.
31 . The non-transitory computer-readable media claim 30 , wherein the processor-executable instructions, when executed by the at least one processor, further cause the at least one processor to determine, by a detection element embedded in a software stack associated with the user device, the parameter.
32 . The non-transitory computer-readable media claim 30 , wherein processor-executable instructions that, when executed by the at least one processor, cause the at least one processor to determine the parameter, further cause the at least one processor to determine a change to an internal process associated with the user device.
33 . The non-transitory computer-readable media claim 30 , wherein the processor-executable instructions, when executed by the at least one processor, further cause the at least one processor to send, based on the alert priority, a notification to the user device indicating that an account is suspended.
34 . The non-transitory computer-readable media claim 33 , wherein the processor-executable instructions, when executed by the at least one processor, further cause the at least one processor to change, based on the alert priority, one or more services associated with the user device.
35 . The non-transitory computer-readable media claim 33 , wherein the-processor-executable instructions, when executed by the at least one processor, further cause the at least one processor to suspend a service associated with the user device.
36 . The non-transitory computer-readable media claim 30 , wherein the processor-executable instructions, when executed by the at least one processor, further cause the at least one processor to determine, based on one or more of an unauthorized interaction with a hardware interface associated with the user device, one or more unauthorized secure shell (SSH) commands, or one or more unauthorized Telnet commands, a change to the parameter.
37 . A system comprising:
a user device configured to:
send telemetry data; and
a computing device configured to:
monitor one or more of logical access to embedded software of the user device or physical access to hardware ports and sockets of the user device;
determine, based on the telemetry data and based on the monitoring of the one or more of the logical access to embedded software of the user device or the physical access to hardware ports and sockets of the user device, a parameter indicating a physical pattern of operation,
determine, based on the parameter, a security issue,
determine, based on the security issue, an alert,
determine, based on the alert, an alert priority, and
cause, based on the alert priority, the user device to be prevented from accessing hardware ports and sockets of the computing device and an adjustment of a monitoring protocol of data traffic associated with the user device.
38 . The system of claim 37 , wherein the computing device is further configured to determine, by a detection element embedded in a software stack associated with the user device, the parameter.
39 . The system of claim 37 , wherein the computing device is further configured to determine the parameter based on a change to an internal process associated with the user device indicated by the telemetry data.
40 . The system of claim 37 , wherein the computing device is further configured to send, based on the alert priority, a notification to the user device indicating that an account is suspended.
41 . The system of claim 40 , wherein the computing device is further configured to change, based on the alert priority, one or more services associated with the user device.
42 . The system of claim 40 , wherein the computing device is further configured to suspend a service associated with the user device.
43 . The system of claim 40 , wherein the user device is further configured to receive the notification indicating that the account is suspended.
44 . The system of claim 43 , wherein the computing device is configured to determine, based on the parameter, the security issue, the computing device is further configured to determine, based on a change in the parameter, the security issue.
45 . The system of claim 37 , wherein the computing device is further configured to determine, based on one or more of an unauthorized interaction with a hardware interface associated with the user device, one or more unauthorized secure shell (SSH) commands, or one or more unauthorized Telnet commands, a change to the parameter.