IP Library Granted Patent US 7,913,306
Granted Patent B2
US 7,913,306 · App. 12/154,405 · Granted Mar 22, 2011

System and methods for detecting intrusions in a computer system by monitoring operating system registry accesses

Assignee: The Trustees of Columbia University in the City of New York
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,913,306
App. No.
12/154,405
Granted
Mar 22, 2011
Kind
B2
Abstract

A method for detecting intrusions in the operation of a computer system is disclosed which comprises gathering features from records of normal processes that access the files system of the computer, such as the Windows registry, and generating a probabilistic model of normal computer system usage based on occurrences of said features. The features of a record of a process that accesses the Windows registry are analyzed to determine whether said access to the Windows registry is an anomaly. A system is disclosed, comprising a registry auditing module configured to gather records regarding processes that access the Windows registry; a model generator configured to generate a probabilistic model of normal computer system usage based on records of a plurality of processes that access the Windows registry and that are indicative of normal computer system usage; and a model comparator configured to determine whether the access of the Windows registry is an anomaly.

Claims (14)

1. A method for detecting intrusions in the operation of a computer system comprising:

(a) gathering features from records of normal processes that access the file system of the computer;

(b) generating a probabilistic model of normal computer system usage based on occurrences of the features and determining the likelihood of observing an event that was not observed during the gathering of features from the records of normal processes; and

(c) analyzing features from a record of a process that accesses the file system to detect deviations from normal computer system usage to determine whether the access to the file system is an anomaly.

2. The method according to claim 1 , wherein the step of gathering features from records of normal processes that access the file system of the computer comprises gathering a feature corresponding to a name of a process accessing the file system of the computer.

3. The method according to claim 1 , wherein gathering features from records of normal processes that access the file system of the computer comprises gathering a feature corresponding to a type of query being sent to the file system of the computer.

4. The method according to claim 3 , wherein gathering features from records of normal processes that access the file system of the computer comprises gathering a feature corresponding to an outcome of a query being sent to the file system of the computer.

5. The method according to claim 1 , wherein gathering features from records of normal processes that access the file system of the computer comprises gathering a feature corresponding to a name of a key being accessed in the file system of the computer.

6. The method according to claim 5 , wherein gathering features from records of normal processes that access the file system of the computer comprises gathering a feature corresponding to a value of the key being accessed.

7. The method according to claim 1 , wherein generating a probabilistic model of normal computer system usage comprises determining a likelihood of observing a feature in the records of processes that access the file system of the computer.

8. The method according to claim 7 , wherein determining a likelihood of observing a feature comprises determining a conditional probability of observing a first feature in the records of processes that access the file system of the computer given an occurrence of a second feature is the records.

9. The method according to claim 1 , wherein analyzing a record of a process that accesses the file system of the computer comprises, for each feature, performing a check to determine if a value of the feature has been previously observed for the feature.

10. The method according to claim 9 , further comprising, if the value of the feature has not been observed, computing a score based on a probability of observing the value of the feature.

11. The method according to claim 9 , further comprising, if the score is greater than a predetermined threshold, labeling the access to the file system of the computer as anomalous and labeling the process that accessed the file system of the computer as malicious.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 7, 2012
From: APAP, FRANK; HONIG, ANDREW; HERSHKOP, SHLOMO; ESKIN, ELEAZAR; STOLFO, SALVATORE J.
To: THE TRUSTEES OF COLUMBIA UNIVERSITY IN THE CITY OF NEW YORK
Reel/Frame 028742/0762 →
Continuity (3)
Continuation 10352343 · Jan 27, 2003
Provisional Application 60351857 · Jan 25, 2002
Related Publication 20090083855A1 · Mar 26, 2009