IP Library › Granted Patent US 11,658,986
Granted Patent B2
US 11,658,986 · App. 17/123,342 · Granted May 23, 2023

Detecting attacks on computing devices

Inventors: Puneet Sharma (Milpitas, CA); Anand Mudgerikar (Palo Alto, CA)
Assignee: Hewlett Packard Enterprise Development LP
H04L63/1416H04L9/3236H04L9/3242H04L9/3297H04L63/08H04L63/14H04L63/145
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,658,986
App. No.
17/123,342
Granted
May 23, 2023
Kind
B2
Abstract

An example system may comprise a first computing device comprising instructions executable by a hardware processor to: create, responsive to detecting a second computing device initially attempting to connect to a network, an unpopulated baseline profile for the second computing device; populate the baseline profile with initial processes running on the second computing device and initial system calls made by the initial processes during an initial operation time period of the second computing device; monitor, during a subsequent operation time period of the second computing device, subsequent processes running on the second computing device and subsequent system calls made by the subsequent processes; and detect an attack on the second computing device based on a comparison of the subsequent processes and the subsequent system calls to the populated baseline profile.

Claims (18)

1. A system comprising:

a first computing device comprising instructions executable by a hardware processor to:

transmit, responsive to detecting a second computing device initially attempting to connect to the network for a first time, an agent to the second computing device to generate log files of initial processes running on the second computing device during an initial operation time period of the second computing device, initial system calls made by the initial processes during the initial operation time period, subsequent processes running on the second computing device during a subsequent operation time period of the second computing device, and subsequent system calls made by the subsequent processes during the subsequent operation time period, wherein the initial system calls comprise initial programmatic requests of services from a kernel of an operating system executing on the second computing device, and the subsequent system calls comprise subsequent programmatic requests of services from the kernel;

create, responsive to detecting the second computing device initially attempting to connect to the network, an unpopulated baseline profile for the second computing device;

populate the baseline profile with the initial processes and the initial system calls;

monitor, during the subsequent operation time period, the subsequent processes and the subsequent system calls; and

detect an attack on the second computing device based on a comparison of the subsequent processes and the subsequent system calls to the populated baseline profile.

2. The system of claim 1 , wherein the instructions executable to detect the attack include instructions executable to detect the attack by identifying the subsequent processes and the subsequent system calls do not match a portion of the initial processes and the initial system calls.

3. The system of claim 1 , wherein the instructions executable to detect the attack include instructions executable to detect the attack by identifying a duration of the subsequent processes and the subsequent system calls do not match a duration of a portion of the initial processes and the initial system calls.

4. The system of claim 1 , wherein the instructions executable to monitor the subsequent processes and the subsequent system calls include instructions to monitor the subsequent processes and the subsequent system calls from a log file periodically received from the second computing device.

5. The system of claim 4 , including the instructions executable to assign a public-private key pair to the unpopulated baseline profile.

6. The system of claim 5 , including the instructions executable to detect that the log file is tampered with when the log file fails authentication.

7. A system comprising:

a first computing device comprising instructions executable by a hardware processor to:

create, responsive to detecting a second computing device initially attempting to connect to a network, an unpopulated baseline profile for the second computing device;

populate the baseline profile with initial processes running on the second computing device and initial system calls made by the initial processes during an initial operation time period of the second computing device, wherein the initial system calls comprise initial programmatic requests of services from a kernel of an operating system executing on the second computing device;

monitor, during a subsequent operation time period of the second computing device, subsequent processes running on the second computing device and subsequent system calls made by the subsequent processes, wherein the subsequent system calls comprise subsequent programmatic requests of services from the kernel of the operating system executing on the second computing device; and

detect an attack on the second computing device based on a comparison of the subsequent processes and the subsequent system calls to the populated baseline profile, wherein detection of the attack comprises identifying a duration of the subsequent processes and the subsequent system calls do not match a duration of a portion of the initial processes and the initial system calls.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 15, 2021
From: SHARMA, PUNEET; MUDGERIKAR, ANAND
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 054931/0888 →
Continuity (2)
Division 15885447 · Jan 31, 2018
Related Publication 20210136092A1 · May 6, 2021