LEARNING BASED PROTECTION OF INFORMATION TECHNOLOGY INFRASTRUCTURE
A system manages resources based on a hardware transactional memory unit. The system stores a system profile map comprising system profiles of applications. The system profile of an application stores information describing system resource utilization of the application. If a request for resources for executing a new application is received, a hardware transactional memory unit determines an amount of memory to be allocated for executing the new application and allocates memory partitions for executing the new application. The system profile of the new application is compared with system profiles in the system profile map. If there are any indicators of compromise representing potential compromise of the new application the request for resources for the new application is denied. The system generates and uses true random numbers.
1 . A computer-implemented method, comprising:
receiving a request for execution of an application on one or more computing systems;
generating a process graph for the application based on an execution of the application;
accessing a system profile map storing characteristics of applications known to be uncompromised;
comparing characteristics of the process graph of the application with characteristics of the process graph of a matching uncompromised application in the system profile map;
storing information describing differences in characteristics of the process graph of the application with characteristics of the process graph of a matching uncompromised application; and
using the stored differences in characteristics for subsequently identifying compromised applications.