IP Library Patent Application 18567308
Patent Application
App. No. 18/567,308

ANALYSING OPERATING SYSTEM CONFIGURATIONS

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/567,308
Abstract

At least in some examples, a non-transitory machine-readable storage medium can be encoded with instructions for analysing an operating system configuration, the instructions executable by a processor of a system, whereby to cause the system to generate a set of malware samples, each malware sample defined by a set of actions forming an attack chain representing a sequence of procedures, execute each of the malware samples on an instance of the operating system configuration to generate a set of logs, and using the set of logs, determine a set of actions detected by an anti-malware process of the operating system configuration.

Claims (39)

1 . A non-transitory machine-readable storage medium encoded with instructions for analysing an operating system configuration, the instructions executable by a processor of a system, whereby to cause the system to:

generate a set of malware samples, each malware sample defined by a set of actions forming an attack chain representing a sequence of procedures;

execute each of the malware samples on an instance of the operating system configuration to generate a set of logs; and

using the set of logs, determine a set of actions detected by an anti-malware process of the operating system configuration.

2 . The non-transitory machine-readable storage medium as claimed in claim 1 , further encoded with instructions, whereby to cause the system to:

generate a set of operating system instances, each operating system instance comprising a variant of the operating system.

3 . The non-transitory machine-readable storage medium as claimed in claim 2 , further encoded with instructions, whereby to cause the system to:

execute each of the malware samples on respective clean instances of each of the operating system instances.

4 . The non-transitory machine-readable storage medium as claimed in claim 2 , further encoded with instructions, whereby to cause the system to:

generate at least one operating system instance comprising an antivirus system.

5 . The non-transitory machine-readable storage medium as claimed in claim 2 , further encoded with instructions, whereby to cause the system to:

generate at least some operating system instances with respective different security configurations.

6 . The non-transitory machine-readable storage medium as claimed in claim 1 , further encoded with instructions, whereby to cause the system to:

detect whether a malware sample fully executes on the operating system instance.

7 . An apparatus, comprising:

a processor; and

a data storage system comprising instructions defining a set of procedures;

the processor to:

generate a set of malware samples, each malware sample comprising a sequence of procedures from the set of procedures and forming an attack chain corresponding to a preselected configuration;

apply each malware sample to an instance of an operating system configuration to generate log data comprising output data from at least one of a malware sample and an anti-malware process of the operating system configuration; and

determine, using the log data, a set of actions detected by the anti-malware process of the operating system configuration.

8 . The apparatus as claimed in claim 7 , the processor further to:

generate a set of operating system instances, each operating system instance comprising a variant of the operating system.

9 . The apparatus as claimed in claim 7 , the processor further to:

provide coordination data to respective ones of the procedures of the set of procedures forming the attack chain.

10 . The apparatus as claimed in claim 9 , the processor further to:

instantiate each clean instance of the each of the operating system instances on a virtual machine.

11 . The apparatus as claimed in claim 7 , the processor further to:

generate the operating system instance according to a predefined security configuration.

12 . The apparatus as claimed in claim 7 , the processor further to:

detect an action performed by a malware sample indicating successful execution of the malware sample.

13 . A method for analysing an operating system configuration, the method comprising:

generating a set of malware samples;

execute each malware sample on a clean instantiation of operating system configured according to a security configuration; and

generate log data representing detection of an action performed by a malware sample on the operating system instance.

14 . The method as claimed in claim 13 , further comprising:

generating a malware sample using a set of techniques configured to form an attack chain configured according to an attack specification.

15 . The method as claimed in claim 13 , further comprising:

passing coordination data between respective actions forming an attack chain of a malware sample.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 11, 2025
From: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
To: PERIDOT PRINT LLC
Reel/Frame 070187/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 16, 2024
From: PRUZINEC, JAKUB; NGUYEN, QUYNH ANH
To: NANYANG TECHNOLOGICAL UNIVERSITY
Reel/Frame 067120/0304 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 16, 2024
From: GRIFFIN, JONATHAN; BALDWIN, ADRIAN JOHN
To: HP INC UK LIMITED
Reel/Frame 067120/0501 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 16, 2024
From: HP INC UK LIMITED
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 067120/0701 →