IP Library › Granted Patent US 9,842,206
Granted Patent B2
US 9,842,206 · App. 14/948,328 · Granted Dec 12, 2017

Using call stack snapshots to detect anomalous computer behavior

Inventors: Ron Peleg (Tel-Aviv, IL); Amir Ronen (Haifa, IL); Tamer Salman (Haifa, IL); Shmuel Regev (Tel-Aviv, IL); Ehud Aharoni (Kfar Saba, IL)
Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
G06F21/52G06F21/554G06F21/566G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,842,206
App. No.
14/948,328
Filed
Nov 22, 2015
Granted
Dec 12, 2017
Kind
B2
Art Unit
2494
USPC
726/23
Abstract

Detecting computer anomalies by determining probabilities of encountering call stack configurations at various depths, the call stacks being associated with software application instances on computers having the same operating system, where snapshots of the call stacks are recorded on the computers responsive to detecting predefined software application events, determining entropies of call stack configurations at various call stack depths using their associated probabilities, determining stack frame rarity scores of call stack configurations at various depths based on their associated stack frame entropies in accordance with a predefined rarity function, determining a call stack rarity score of any given call stack configuration as the maximum stack frame rarity score of the given configuration, and detecting an anomaly associated with any given one of the computers where any of the snapshots recorded on the given computer is of a call stack whose call stack rarity score meets a predefined anomaly condition.

Claims (16)

1. A computer anomaly detection and software execution management method comprising:

monitoring, on each of a plurality of computers running the same operating system, the execution of a software application on each of the computers, wherein the software application is executed in at least one instance on each of the computers;

determining stack frame probabilities of encountering various configurations of multiple call stacks at various call stack depths,

wherein the call stacks are associated with the instances of the software application on the computers, and

wherein multiple snapshots of the call stacks are recorded on the computers responsive to detecting a predefined event in connection with the software application;

determining stack frame entropies of various configurations of the call stacks at various call stack depths based on their associated stack frame probabilities;

determining stack frame rarity scores of various configurations of the call stacks at various call stack depths based on their associated stack frame entropies in accordance with a predefined rarity function;

determining a call stack rarity score of any given configuration of the call stacks as the maximum stack frame rarity score of the given configuration;

detecting an anomaly associated with any given one of the computers wherein any of the snapshots recorded on the given computer is of a call stack whose call stack rarity score meets a predefined anomaly condition, and

terminating any of the execution instances of the software application on any of the computers with which the anomaly is associated.

2. The method of claim 1 and further comprising:

recording the snapshots on the computers.

3. The method of claim 1 wherein the detecting comprises ranking the computers according to their associated call stack rarity scores of their associated snapshots for the predefined event detected for the software application.

4. The method of claim 1 wherein the detecting comprises detecting wherein the predefined anomaly condition is that a representative stack prefix based on the fewest stack frames associated with the call stack rarity score was not previously found in the snapshots.

5. The method of claim 1 wherein the detecting comprises applying a machine learning algorithm to the call stack rarity scores to determine that any call stack configuration of any of the snapshots is anomalous.

6. The method of claim 1 wherein the detecting comprises applying a machine learning algorithm to representative stack prefixes based on the fewest stack frames associated with any of the call stack rarity scores to determine that any call stack configuration of any of the snapshots is anomalous.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 22, 2015
From: PELEG, RON; RONEN, AMIR; SALMAN, TAMER; REGEV, SHMUEL; AHARONI, EHUD
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 037110/0649 →
Continuity (2)
Continuation 14926216 · Oct 29, 2015
Related Publication 20170124319A1 · May 4, 2017