IP Library › Granted Patent US 12,579,258
Granted Patent B2
US 12,579,258 · App. 18/110,271 · Granted Mar 17, 2026

Advanced persistent threat detection

Inventor: Phani Bhushan Avadhanam (San Diego, CA)
Assignee: Oracle International Corporation
G06F21/554G06F21/552
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,579,258
App. No.
18/110,271
Granted
Mar 17, 2026
Kind
B2
Abstract

Techniques are described herein for advanced persistent threat detection. An example method can include a device receiving a message identifying an instruction loaded onto an instruction cache of a secure processer. The device can transmit a control instruction to configure a kernel image to collect a metric over a first time interval, the metric being generated based at least in part on the secure processor executing the instruction during the first time interval. The device can receive the first metric from the kernel image, the metric being indicative of a transition of the secure processor from a non-secure state to a secure state. The device can determine whether the secure processor is undergoing a computing attack based on the metric. The device can transmit the determination of whether the secure processor is undergoing a computing attack to a sender of the message.

Claims (48)

1 . A method, comprising:

receiving, by a computing device, a message identifying an instruction loaded onto an instruction cache of a secure processor;

transmitting, by the computing device, a control instruction to configure a kernel image to collect a first metric over a first time interval and a second metric over a second time interval, the first metric being generated based at least in part on the secure processor executing the instruction during the first time interval;

receiving, by the computing device, the first metric from the kernel image, the first metric being indicative of a transition of the secure processor from a non-secure state to a secure state;

receiving, by the computing device, the second metric from the kernel image, wherein the second metric is collected by the kernel image during the second time interval;

determining, by the computing device, an average value of a first value of the first metric and a second value of the second metric;

comparing, by the computing device, the average value to a second threshold;

determining, by the computing device, whether the secure processor is undergoing a transient attack or a sustained attack based at least in part on the comparison; and

determining, by the computing device, whether to transmit the determination of whether the secure processor is undergoing the computing attack based at least in part on whether the computing attack is the transient attack or the sustained attack.

2 . The method of claim 1 , wherein the first metric is collected using a secure processer application programming interface (API).

3 . The method of claim 1 , wherein the first metric is collected using an instruction cache driver.

4 . The method of claim 1 , wherein the computing attack is an advanced persistent threat (APT) attack.

5 . The method of claim 1 , wherein the message is generated based at least in part on a memory mapping of the message.

6 . The method of claim 1 , wherein the secure processor is a first secure processor, and wherein a workload is rerouted from the first secure processor to a second secure processor based at least in part on transmitting the determination of whether the secure processor is undergoing the computing attack.

7 . A computing device, comprising:

a processor; and

a computer-readable medium including instructions that, when executed by the processor, cause the processor to perform operations comprising:

receiving a message identifying an instruction loaded onto an instruction cache of a secure processor;

transmitting a control instruction to configure a kernel image to collect a first metric over a first time interval and a second metric over a second time interval, the first metric being generated based at least in part on the secure processor executing the instruction during the first time interval;

receiving the first metric from the kernel image, the first metric being indicative of a transition of the secure processor from a non-secure state to a secure state;

receiving the second metric from the kernel image, wherein the second metric is collected by the kernel image during the second time interval;

determining an average value of a first value of the first metric and a second value of the second metric;

comparing the average value to a second threshold;

determining whether the secure processor is undergoing a transient attack or a sustained attack based at least in part on the comparison; and

determining whether to transmit the determination of whether the secure processor is undergoing the computing attack based at least in part on whether the computing attack is the transient attack or the sustained attack.

8 . The computing device of claim 7 , wherein the first metric is collected using a secure processer application programming interface (API).

9 . The computing device of claim 7 , wherein the first metric is collected using an instruction cache driver.

10 . The computing device of claim 7 , wherein the computing attack is an advanced persistent threat (APT) attack.

11 . The computing device of claim 7 , wherein instructions that, when executed by the processor, further cause the processor to perform operations comprising:

determining an average value of a first value of the first metric and a second value of the second metric;

comparing the average value to a second threshold;

determining whether the secure processor is undergoing a transient attack or a sustained attack based at least in part on the comparison; and

determining whether to transmit the determination of whether the secure processor is undergoing the computing attack based at least in part on whether the computing attack is the transient attack or the sustained attack.

12 . The computing device of claim 7 , wherein the message is generated based at least in part on a memory mapping of the message.

13 . The computing device of claim 7 , wherein the secure processor is a first secure processor, and wherein a workload is rerouted from the first secure processor to a second secure processor based at least in part on transmitting the determination of whether the secure processor is undergoing the computing attack.

14 . A non-transitory computer-readable medium including stored thereon a sequence of instructions that, when executed by a processor, causes the processor to perform operations comprising:

receiving a message identifying an instruction loaded onto an instruction cache of a secure processor;

transmitting a control instruction to configure a kernel image to collect a first metric over a first time interval and a second metric over a second time interval, the first metric being generated based at least in part on the secure processor executing the instruction during the first time interval;

receiving the first metric from the kernel image, the first metric being indicative of a transition of the secure processor from a non-secure state to a secure state;

receiving the second metric from the kernel image, wherein the second metric is collected by the kernel image during the second time interval;

determining an average value of a first value of the first metric and a second value of the second metric;

comparing the average value to a second threshold;

determining whether the secure processor is undergoing a transient attack or a sustained attack based at least in part on the comparison; and

determining whether to transmit the determination of whether the secure processor is undergoing the computing attack based at least in part on whether the computing attack is the transient attack or the sustained attack.

15 . The non-transitory computer-readable medium of claim 14 , wherein the first metric is collected using a secure processer application programming interface (API).

16 . The non-transitory computer-readable medium of claim 14 , wherein the first metric is collected using an instruction cache driver.

17 . The non-transitory computer-readable medium of claim 14 , wherein the computing attack is an advanced persistent threat (APT) attack.

18 . The non-transitory computer-readable medium of claim 14 , wherein the message is generated based at least in part on a memory mapping of the message.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 15, 2023
From: AVADHANAM, PHANI BHUSHAN
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 062712/0876 →
Continuity (1)
Related Publication 20240273193A1 · Aug 15, 2024
References Cited (20)
US 9665715B1 · Roundy · 2017 [cited by examiner]
US 10200259B1 · Pukish · 2019 [cited by examiner]
US 10901918B2 · Ramasamy et al. · 2021 [cited by applicant]
US 12518006B2 · Avadhanam · 2026 [cited by applicant]
US 20040153672A1 · Watt · 2004 [cited by examiner]
US 20100235647A1 · Buer · 2010 [cited by examiner]
US 20150096024A1 · Haq · 2015 [cited by examiner]
US 20150128274A1 · Giokas · 2015 [cited by examiner]
US 20160173525A1 · Thomas · 2016 [cited by examiner]
US 20170093804A1 · Boivie · 2017 [cited by examiner]
US 20170244731A1 · Hu · 2017 [cited by examiner]
US 20180032724A1 · Tang · 2018 [cited by examiner]
US 20180048667A1 · Tang · 2018 [cited by examiner]
US 20180307807A1 · Tronel · 2018 [cited by applicant]
US 20210019409A1 · Parshin · 2021 [cited by examiner]
US 20210203676A1 · Pendse · 2021 [cited by examiner]
US 20210248433A1 · Dabon · 2021 [cited by examiner]
US 20210400058A1 · Filonov · 2021 [cited by examiner]
WO WO2018110735A1 · 2018 [cited by examiner]
U.S. Appl. No. 18/110,268 , Non-Final Office Action, Mailed on Jan. 16, 2025, 8 pages. [cited by applicant]