US 11,868,479 B2
Runtime adaptive risk assessment and automated mitigation
Roman Lysecky, Tucson, AZ (US); Jerzy Rozenblit, Tucson, AZ (US); Johannes Sametinger, Linz (AT); Aakarsh Rao, Tucson, AZ (US); and Nadir Carreon, Tucson, AZ (US)
Assigned to ARIZONA BOARD OF REGENTS ON BEHALF OF THE UNIVERSITY OF ARIZONA, Tucson, AZ (US); and JOHANNES KEPLER UNIVERSITY LINZ, Linz (AT)
Appl. No. 17/290,627
Filed by Arizona Board of Regents on Behalf of the University of Arizona, Tucson, AZ (US)
PCT Filed Nov. 1, 2019, PCT No. PCT/US2019/059551
§ 371(c)(1), (2) Date Apr. 30, 2021,
PCT Pub. No. WO2020/093020, PCT Pub. Date May 7, 2020.
Claims priority of provisional application 62/755,110, filed on Nov. 2, 2018.
Prior Publication US 2022/0035927 A1, Feb. 3, 2022
Int. Cl. G06F 21/57 (2013.01); G16H 20/17 (2018.01); A61B 5/00 (2006.01); A61N 1/362 (2006.01); A61N 1/372 (2006.01); G06F 21/56 (2013.01); A61M 5/142 (2006.01)
CPC G06F 21/577 (2013.01) [A61B 5/0022 (2013.01); A61B 5/0031 (2013.01); A61N 1/362 (2013.01); A61N 1/37223 (2013.01); G06F 21/566 (2013.01); G16H 20/17 (2018.01); A61M 5/14276 (2013.01); G06F 2221/034 (2013.01)] 24 Claims
OG exemplary drawing
 
1. A system for detecting malware in a device, said system comprising:
said device having a computer processor, wherein the device is able to be connected to a network or external computer system; and
a module implemented on the computer processor able to model normal system behavior of the device, compare current system operation to the modeled normal system behavior, and estimate a probability of the current system operation being affected by malware based on performance deviation between the current system operation and the modeled normal system behavior,
wherein the compared current system operation comprises execution times of one or more operations performed by the device, and wherein estimating the probability of the current system operation being affected by malware comprises determining a number of execution times that fall outside predefined upper and lower timing boundaries in the modeled normal system behavior for the performed operations.