Real-time detection of attacks on software programs

By using trained detection models to detect the behavior changes of software programs in real time, the problem of preventing software program attacks in the prior art is solved, and real-time attack recognition and dynamic response to software programs are realized.

CN120303660APending Publication Date: 2025-07-11ELEKTROBIT AUTOMOTIVE GMBH
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202380083867.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2022-12-08
Filing Date
2023-11-06
Publication Date
2025-07-11

AI Technical Summary

Technical Problem

现有的入侵检测系统无法有效防止对软件程序的攻击,尤其是零日攻击和滥用软件程序,无法实时检测这些威胁。

Method used

By using a trained detection model, predicting its behavior based on the behavior of a software program and comparing it with the measured fragments, detecting attacks in real time. This model can use machine learning algorithms such as deep learning and long-term memory networks, and combine the performance indicators of software programs such as execution time and power consumption to build a real-time intrusion detection system.

Benefits of technology

Real-time attack detection of software programs is realized, false alarm rate is reduced, attack types can be identified and appropriate actions are applicable to various software programs and hardware platforms, including motor vehicles, medical devices and cloud devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120303660A_ABST
    Figure CN120303660A_ABST
Patent Text Reader

Abstract

The invention relates to a method, computer program code and a device for real-time detection of attacks on a software program running on a platform. The invention further relates to a method, computer program code and a device for providing a detection model for such a method, computer program code or device. The invention also relates to a corresponding detection model. In a first step, a fragment of the behavior of the software program is predicted (S1) based on one or more previous fragments of the behavior of the software program using the trained detection model. Furthermore, a segment of behavior of the software program is measured (S2). The predicted segment is then compared with the measured segment (S3). If the measured segment does not conform to the predicted segment, it is determined (S4) that an attack has occurred and a security event is reported (S6). Optionally, the type of attack may be identified (S5) and included in the reported security event.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The present invention relates to a method, computer program code and apparatus for detecting in real time attacks on a software program running on a platform. The present invention further relates to a method, computer program code and apparatus for providing a detection model for such a method, computer program code or apparatus. The present invention also relates to a corresponding detection model.

[0002] Modern motor vehicles, medical devices, cloud devices, home appliances, etc. are equipped with a steadily increasing number of processors and are also increasingly capable of communicating with external entities. Therefore, there is a risk that advanced attacks could penetrate the vehicle or appliance network to inject malicious code or interrupt normal execution, etc.

[0003] An intrusion detection system (IDS) is a security control system designed to detect malicious activities in a system or network. There are various types of intrusion detection systems, including network intrusion detection systems, host intrusion detection systems, etc. Two detection methods used in intrusion detection systems can be distinguished, namely, static checking and anomaly detection.

[0004] Static inspection uses a series of detection sensors, such as form sensors, position sensors, frequency sensors, etc., to detect possible intrusions into the system.

[0005] Anomaly detection is often based on using machine learning to build a model of normal behavior and consider any different behavior as an anomaly.

[0006] In this regard, the following article by M. Müter et al. discusses the use of anomaly detection systems in automotive in-vehicle networks: "A Structured Approach to anomaly detection for in-vehicle networks" 2010 Sixth International Conference on Information Assurance and Security, pp. 92-98. Based on the characteristics of typical vehicle networks, such as the Controller Area Network (CAN), a set of anomaly detection sensors are introduced that enable the identification of attacks during vehicle operation.

[0007] US2019 / 0215329 A1 discloses a solution for malware detection using machine learning. A synthetic training set for machine learning is created by identifying and modifying the code functional features in an existing malware training set. By filtering the resulting synthetic code to measure the impact and novelty of malware, a training set for predicting novel malware can be created and an attempt can be made to preemptively exhaust the space of new malware. These synthetic training sets can then be used to improve the training of machine learning models.

[0008] Current methods focus on network intrusion detection systems or malware detection using machine learning. This has the following drawbacks: It is unable to prevent the abuse of software programs, such as security startup applications, security diagnostic applications, other applications running on top of the OS, etc. In addition, it is unable to prevent zero-day attacks on software programs.

[0009] The object of the present invention is to provide a solution for detecting attacks on software programs, which solution is capable of detecting attempts to exploit software programs in real time.

[0010] This object is achieved by the method according to claim 1 or 10, the computer program code for implementing the method according to claim 7 or 13, and the device according to claim 8 or 14. This object is further achieved by the machine according to claim 9 and the detection model according to claim 15. The dependent claims include advantageous further developments and improvements of the principles of the present invention as described below.

[0011] According to a first aspect, a method for real-time detecting an attack on a software program running on a platform comprises the following steps:

[0012] - Using a trained detection model to predict a segment of the behavior of the software program based on one or more previous segments of the behavior of the software program;

[0013] - Comparing the predicted segment of the behavior of the software program with a measured segment; and

[0014] - Reporting a security event in case the measured segment does not match the predicted segment.

[0015] Correspondingly, a computer program code comprises instructions which, when executed by at least one processor, cause the at least one processor to perform the following steps to real-time detect an attack on a software program running on a platform:

[0016] - Using a trained detection model to predict a segment of the behavior of the software program based on one or more previous segments of the behavior of the software program;

[0017] - Compare a predicted segment of the behavior of the software program with a measured segment; and

[0018] - Report a security event if the measured segment does not match the predicted segment.

[0019] The term computer must be understood in a broad sense. In particular, it also includes embedded devices, electronic control units, and other processor-based data processing devices.

[0020] For example, computer program code can be used for electronic retrieval or stored on a computer-readable storage medium.

[0021] According to another aspect, an apparatus for real-time detection of attacks on a software program running on a platform includes:

[0022] - A processing unit configured to: use a trained detection model to predict a segment of the behavior of the software program based on one or more previous segments of the behavior of the software program, and compare the predicted segment of the behavior of the software program with a measured segment; and

[0023] - A reporting unit configured to report a security event if the measured segment does not match the predicted segment.

[0024] According to the present invention, a trained detection model is used for real-time intrusion detection of any software program, i.e., the trained detection model serves as a security sensor for the software program. The behavior of the software program is reflected in many features. The basic assumption is that an attack on the software program causes detectable changes in the behavior. Therefore, the detection model predicts a segment of the behavior of the software program based on previous segments of the behavior of the software program. Then the predicted behavior segment is compared with the measured behavior to check for possible attempts to attack the system. These security checks are performed during multiple time spans during the execution of the software program, thereby ensuring real-time detection of attempts to attack the system. Once a possible attack is detected, a security event is generated. In response to the security event, actions can be taken in real time to avoid exploitation of the system. Alternatively or additionally, further analysis can be triggered. The solution described can be used with any type of software program (e.g., embedded applications running on an operating system or real-time operating system, applications for secure boot or secure diagnosis, web applications, containers, etc.), but can also be used with operating system modules and supervision modules.

[0025] In an advantageous embodiment, the predicted segment includes a trust boundary of the behavior of the software program. Adding a trust boundary to the predicted segment helps to avoid false positives, i.e., reduces the risk of false detection of attacks.

[0026] In an advantageous embodiment, the time period covered by the prediction segments is constant or adjustable. The detection model calculates segments of the behavior for subsequent time periods. These time periods can be equal or different, depending on what is most suitable for the target software program.

[0027] In an advantageous embodiment, the behavior encompasses one or more software or hardware performance metrics. For example, these performance metrics can at least include one or more of the following: execution time, power consumption, memory consumption, loop counters, the number of issued and / or retired instructions, and cache misses. The behavior of a software program is based on the characteristics of the software program when running on a target hardware-software platform. For example, modern processors have a performance monitor unit (PMU), which allows various statistics regarding the operation of the core and its memory system to be collected during runtime. The performance monitor unit provides a number of performance event counters that can be used as characteristics of the behavior of a software program running on that particular hardware-software platform. Additionally, the power consumption of a software program can be used, as power consumption is related to the activity of the software program. This characteristic is also platform-dependent.

[0028] In an advantageous embodiment, the type of attack is identified. As part of the detection model or as a separate entity, once an attack is detected, a trained classifier can detect the type of attack. Then the information regarding the type of attack can be used to select an appropriate action to take.

[0029] Advantageously, a machine includes the apparatus according to the present invention or is configured to execute a method according to the present invention for real-time detection of attacks on a software program running on the platform of the machine. For example, the machine can be a motor vehicle or a household appliance. For example, the motor vehicle can be a (semi)-autonomous or manually driven connected car. However, the described solution is equally suitable for other types of motor vehicles, such as drones, airplanes, or ships. Of course, the use of the present invention is not limited to these types of machines. Other fields of use are the Internet of Things or cloud-native technologies, such as containers or microservices.

[0030] According to another aspect, a method for providing a detection model for real-time detection of attacks on a software program running on a platform includes the following steps:

[0031] - Collecting training data when the software program is executed normally and when the software program is executed under one or more attacks;

[0032] - Training one or more detection models using the training data; and

[0033] - Selecting a detection model from the one or more trained detection models.

[0034] Accordingly, a computer program code includes instructions that, when executed by at least one processor, cause the at least one processor to perform the following steps to provide a detection model for real-time detection of attacks on a software program running on a platform:

[0035] - Collect training data when the software program is executed normally and when it is executed under one or more attacks;

[0036] - Train one or more detection models using the training data; and

[0037] - Select a detection model from the one or more trained detection models.

[0038] The term computer must be understood in a broad sense. In particular, it also includes workstations, distributed systems, and other processor-based data processing devices.

[0039] For example, the computer program code can be used for electronic retrieval or stored on a computer-readable storage medium.

[0040] According to another aspect, an apparatus for providing a detection model for real-time detection of attacks on a software program running on a platform includes:

[0041] - A collection unit configured to collect training data when the software program is executed normally and when it is executed under one or more attacks;

[0042] - A processing unit configured to train one or more detection models using the training data; and

[0043] - An evaluation unit configured to select a detection model from the one or more trained detection models.

[0044] Advantageously, the solution according to the present invention provides a detection model for real-time detection of attacks on a software program running on a platform.

[0045] As mentioned above, the behavior of a software program is reflected in many features. According to the present invention, such features are used to train a machine learning model. The selected features are extracted in a sampling mode to construct data samples into a time series for training the real-time detection model. Training and test data are collected when the program is executed normally and under attacks. Advantageously, various artificial intelligence algorithms are used and trained. Then the best models in terms of, for example, accuracy and performance are selected and used. Various types of artificial intelligence algorithms can be used for these models, for example, machine learning algorithms. Deep learning algorithms (such as deep neural networks (DNN) or long short-term memory (LSTM) networks) are particularly suitable for this purpose.

[0046] In advantageous embodiments, the training data covers one or more software or hardware performance metrics. For example, these performance metrics can at least include one or more of the following: execution time, power consumption, memory consumption, loop counters, the number of issued and / or retired instructions, and cache misses. The behavior of a software program is based on the characteristics of the software program when it runs on a target hardware-software platform.

[0047] In advantageous embodiments, machine learning classifiers are built for multiple attack types. Assuming that multiple attack types are used during training, the training and test data when executed under attack can be used to build machine learning classifiers for each attack type. If the detection model detects an exploitation of the system or an attempt to exploit the system, these trained classifiers can detect the attack type.

[0048] Further features of the present invention will become apparent from the following description and the appended claims, in conjunction with the accompanying drawings. Description of the Drawings

[0049] Figure 1 Schematically shows a method for real-time detection of attacks on a software program running on a platform;

[0050] Figure 2 Schematically shows a first embodiment of an apparatus for real-time detection of attacks on a software program running on a platform;

[0051] Figure 3 Schematically shows a second embodiment of an apparatus for real-time detection of attacks on a software program running on a platform;

[0052] Figure 4 Schematically shows a machine in which the solution according to the present invention is implemented;

[0053] Figure 5 Schematically shows a method for providing a detection model for real-time detection of attacks on a software program running on a platform;

[0054] Figure 6 Schematically shows a first embodiment of an apparatus for providing a detection model for real-time detection of attacks on a software program running on a platform;

[0055] Figure 7 Schematically shows a second embodiment of an apparatus for providing a detection model for real-time detection of attacks on a software program running on a platform;

[0056] Figure 8 Schematically shows an intrusion detection system;

[0057] Figure 9Shows a high - level concept of a solution for detecting attacks on software programs according to the present invention;

[0058] Figure 10 Shows a machine - learning - based framework for providing security sensors for software programs;

[0059] Figure 11 Shows an intrusion detection system using a trained model as a security sensor;

[0060] Figure 12 Shows real - time detection of attacks during software program execution; and

[0061] Figure 13 Shows the use of a trained classifier for detecting the types of attacks on software programs. Detailed Description

[0062] This specification demonstrates the principles of the present disclosure. Thus, it will be understood that those skilled in the art will be able to design various arrangements which, although not explicitly described or shown herein, embody the principles of the present disclosure.

[0063] All of the examples and conditional language recited herein are for the purpose of instruction and are intended to help the reader understand the principles of the present disclosure and the concepts contributed by the inventor to further the art, and are to be construed as not being limited to these specifically recited examples and conditions.

[0064] In addition, all statements herein reciting principles, aspects, and embodiments of the present disclosure and their specific examples are intended to include their structural and functional equivalents. Moreover, such equivalents are intended to include both currently known equivalents and equivalents developed in the future, i.e., any elements developed to perform the same function, regardless of their structure.

[0065] Thus, for example, those skilled in the art will understand that the figures presented herein represent conceptual diagrams of illustrative circuit systems embodying the principles of the present disclosure.

[0066] The functions of the various elements shown in the figures can be provided by using dedicated hardware as well as hardware capable of executing software in association with appropriate software. When provided by a processor, these functions can be provided by a single dedicated processor, a single shared processor, multiple independent processors (some of which may be shared), a graphics processing unit (GPU), or a group of GPUs. Additionally, the explicit use of the terms "processor" or "controller" should not be construed as specifically referring to hardware capable of executing software and can implicitly include, but is not limited to, digital signal processor (DSP) hardware, system - on - a - chip, microcontrollers, read - only memory (ROM) for storing software, random access memory (RAM), and non - volatile memory.

[0067] It may also include other conventional and / or customized hardware. Similarly, any switches shown in the figures are merely conceptual. The functions of these switches can be performed by the operation of program logic, by dedicated logic, by the interaction of program control and dedicated logic, or even manually, and the specific technique can be selected by the implementer, which can be more specifically understood from the context.

[0068] In the claims herein, any element expressed as a means for performing a particular function is intended to cover any way of performing that function, including, for example, a combination of circuit elements that perform that function or any form of software, and thus includes firmware, microcode, etc., which is combined with appropriate circuitry for executing the software to perform that function. The disclosure defined by such a claim lies in the fact that the functions provided by the various means mentioned are combined and put together in the manner required by the claim. Accordingly, any means that can provide those functions is considered equivalent to the means shown herein.

[0069] Figure 1 Schematically shown is a method for real-time detection of attacks on a software program running on a platform according to the present invention. In a first step, a trained detection model is used to predict a segment of the behavior of the software program S1 based on one or more previous segments of the behavior of the software program. The behavior can cover one or more software or hardware performance metrics. The predicted segment can include the trust boundaries of the behavior of the software program. The time period covered by the predicted segment can be constant or adjustable. In addition, a segment of the behavior of the software program S2 is measured. Then the predicted segment is compared with the measured segment S3. In the case where the measured segment does not match the predicted segment, it is determined S4 that an attack has occurred, and a security event S6 is reported. Optionally, the type of attack S5 can be identified and included in the reported security event.

[0070] Figure 2 Schematically shown is a block diagram of a first embodiment of an apparatus 10 for real-time detection of attacks on a software program running on a platform according to the present invention. The apparatus 10 has an input terminal 11, via which the processing unit 12 receives a segment MS of the behavior of the software program n-1 、MS n . The processing unit 12 is configured to use a trained detection model M i based on one or more previous segments MS of the behavior of the software program n-1 to predict a segment PS of the behavior of the software program n . The behavior can cover one or more software or hardware performance metrics. The predicted segment can include the trust boundaries of the behavior of the software program. By the predicted segment PS nThe covered time period can be constant or adjustable. The processing unit 12 is further configured to predict a segment PS of the behavior of a software program n with a measurement segment MS n and compare them. In the case where the measurement segment MS n does not match the predicted segment PS n , it is determined by the processing unit 12 that an attack has occurred. Optionally, a trained classifier TC i can be used by the processing unit 12 to identify the type of attack. In the case where an attack is determined to have occurred, a security event SE is reported by the reporting unit 13. For this purpose, a report R can be provided via the output terminal 16 of the device 10. The output terminal 16 can be combined with the input terminal 11 into a single interface. A local storage unit 15 is provided for storing data during processing.

[0071] The processing unit 12 and the reporting unit 13 can be controlled by the control unit 14. A user interface 17 can be provided to enable a user to modify the settings of the processing unit 12, the reporting unit 13, or the control unit 14. The processing unit 12, the reporting unit 13, and the control unit 14 can be embodied as dedicated hardware units. Of course, they can equally well be fully or partially combined into a single unit or implemented as software running on a processor (e.g., a CPU or a GPU).

[0072] Figure 3 shows a block diagram of a second embodiment of a device 20 for real-time detection of attacks on a software program running on a platform according to the present invention. The device 20 includes a processing device 22 and a memory device 21. For example, the device 20 can be a computer, an electronic control unit, or an embedded system. The memory device 21 has stored instructions which, when executed by the processing device 22, cause the device 20 to perform the steps of one of the described methods. Thus, the instructions stored in the memory device 21 tangibly embody an instruction program executable by the processing device 22 to perform the program steps as described herein according to the principles of the present invention. The device 20 has an input terminal 23 for receiving data. Data generated by the processing device 22 can be provided via an output terminal 24. Additionally, such data can be stored in the memory device 21. The input terminal 23 and the output terminal 24 can be combined into a single bidirectional interface.

[0073] The processing device 22 used herein can include one or more processing units, such as a microprocessor, a digital signal processor, or a combination thereof.

[0074] The local storage unit 15 and the memory device 21 can include volatile and / or non-volatile memory areas and storage devices (such as a hard disk drive, an optical drive, and / or a solid-state memory).

[0075] Figure 4Schematically shows a machine 30 in which a solution according to the present invention is implemented. In this example, the machine 30 is a motor vehicle. The motor vehicle has at least one processing system 31, which provides a hardware-software platform. The processing system 31 can process data collected by sensors 32 of the motor vehicle and provide an autonomous driving function. A data transmission unit 33 can allow connection to a remote backend or other motor vehicles or infrastructure units. A memory 34 can be used to store data. Data exchange between different components of the motor vehicle takes place via a network 35. A device 10 according to the present invention is provided for real-time detection of attacks on software programs running on the hardware-software platform.

[0076] Figure 5 Schematically shows a method for providing a detection model for real-time detection of attacks on software programs running on a platform. In a first step, training data S10 is collected during normal execution of the software program and during execution of the software program under one or more attacks. The training data can cover one or more software or hardware performance metrics. Then, one or more detection models S11 are trained using the training data. In addition, a machine learning classifier S12 can be constructed for multiple attack types. Finally, one detection model S13 is selected from one or more trained detection models.

[0077] Figure 6 Schematically shows a block diagram of a first embodiment of a device 40 according to the present invention for providing a detection model for real-time detection of attacks on software programs running on a platform. The device 40 has an input end 41, via which a collection unit 42 collects training data TD during normal execution of the software program and during execution of the software program under one or more attacks. The training data TD can cover one or more software or hardware performance metrics PI i . A processing unit 43 is configured to train one or more detection models M using the training data TD i . The processing unit 43 can further be configured to construct a machine learning classifier TC for multiple attack types i . An evaluation unit 44 is configured to select one detection model M from one or more trained detection models M i . The selected detection model M i and the machine learning classifier TC i can be made available via an output end 47 of the device 40 i . The output end 47 can be combined with the input end 41 into a single interface. A local storage unit 46 is provided for storing data during processing.

[0078] The collection unit 42, the processing unit 43, and the evaluation unit 44 can be controlled by the control unit 45. A user interface 48 can be provided to enable a user to modify the settings of the collection unit 42, the processing unit 43, the evaluation unit 44, or the control unit 45. The collection unit 42, the processing unit 43, the evaluation unit 44, and the control unit 45 can be embodied as dedicated hardware units. Of course, they can equally well be fully or partly combined into a single unit or implemented as software running on a processor (e.g., a CPU or a GPU).

[0079] Figure 7 The block diagram of a second embodiment of a device 50 for providing a detection model for real-time detection of attacks on a software program running on a platform according to the present invention is shown. The device 50 includes a processing device 52 and a memory device 51. For example, the device 50 can be a computer, a workstation, or a distributed system. The memory device 51 has stored instructions which, when executed by the processing device 52, cause the device 50 to perform the steps according to one of the described methods. Thus, the instructions stored in the memory device 51 tangibly embody an instruction program executable by the processing device 52 to perform the program steps as described herein according to the principles of the present invention. The device 50 has an input terminal 53 for receiving data. The data generated by the processing device 52 can be provided via an output terminal 54. Additionally, such data can be stored in the memory device 51. The input terminal 53 and the output terminal 54 can be combined into a single bidirectional interface.

[0080] The processing device 52 used herein can include one or more processing units, such as a microprocessor, a digital signal processor, or a combination thereof.

[0081] The local storage unit 46 and the memory device 51 can include volatile and / or non-volatile memory areas and storage devices (such as, a hard disk drive, an optical drive, and / or a solid-state memory).

[0082] Further details of the solution according to the present invention will be given hereinafter.

[0083] Figure 8Schematically shows the overall concept of an intrusion detection system IDS with components specified in AUTOSAR. The security sensor S reports security events SE to the intrusion detection system manager IdsM. The security sensor S is implemented in the AUTOSAR basic software or as a software component. The intrusion detection system manager IdsM provides a standardized interface for receiving notifications of security events SE. The intrusion detection system manager IdsM performs the authentication of security events SE to obtain qualified security events QSE. The intrusion detection system manager IdsM can also hold the qualified security events QSE in the security event memory SEM. The intrusion detection system reporter IdsR receives the qualified security events QSE from instances of the intrusion detection system manager IdsM running in different electronic control units and enriches the data, for example, by adding the corresponding geographical location. Then, this data can be propagated to the security operation center SOC for further analysis.

[0084] Figure 9 Shows a high-level concept of a solution for real-time detection of attacks on a software program SP running on a platform P i as Figure 9 shown, the software program SP i can run directly on the hardware HW or on top of an optional software platform SW (e.g., an operating system). The described solution is based on the assumption that any software program SP i has a specific behavior B, which can be reflected by various performance metrics. If the software program SP i is running different use cases (b1, b2, …, b n ), these use cases can be included in B = {b1, b2, …, b n}, then the behavior can be different. A further assumption is that an attack on the software program SP i will change the behavior B by a detectable amount.

[0085] According to the present invention, the behavior B of the software program SP i is extracted based on the characteristics of the software program when running on the target hardware-software platform. For example, modern processors have performance monitor units, which allow various statistical data about the operation of the cores and their memory systems to be collected during runtime. The performance monitor units provide many performance metrics that can be recorded for a specific software program SP i during its genuine runtime and derive the corresponding genuine behavior of the software program SP i on this specific hardware-software platform. In addition, the power consumption of the software program SP i can also be used, because the power consumption is related to the software program SP iis related to the activities. This feature is also platform-related.

[0086] Figure 10 illustrates an artificial intelligence (e.g., machine learning)-based framework for providing a security sensor for a software program SP i According to the present invention, machine learning is used to create a trusted activity model for any software program SP i This model will check any execution of the software program SP for possible malicious activities i The framework is preferably automated and accepts the software program SP i as input. As output, the framework generates a corresponding machine learning model M i The model M i is used as a security sensor to detect possible exploitation of the software program SP i As Figure 10 shown, for an embedded software program SP i , training and test data are collected during normal execution and during execution under one or more attacks A i Then this data is used to train one or more models. For this purpose, various machine learning algorithms can be used, such as deep neural networks or long short-term memory networks. Then the model M that is best, for example, in terms of accuracy and performance i is selected and integrated into the intrusion detection system.

[0087] Figure 11 illustrates an intrusion detection system IDS that uses the trained models M1, …, M i , …, M n as security sensors. For each software program SP i , a corresponding model M i can be constructed. Similarly, models M i can be constructed only for the selected software programs SP that are found to be relevant (e.g., software programs SP i that have a greater impact on the protection or security of the system) i The models M1, …, M i , …, M n report security events SE to the intrusion detection system manager IdsM.

[0088] Figure 12 illustrates the real-time detection of attacks during the execution of the software program SP i Real-time anomaly detection aims to detect abnormal behavior during the runtime of the software program SP i For this purpose, the behavior of the software program SP i is regarded as a time series. The trained model M iPredict the behavior for the next time period and compare it with the actual behavior during that time period. Based on this comparison, determine whether an anomaly exists. As an example, software program SP i can have an execution time real-time detection model M i calculate time period T j the theoretical time series TS′ at the start, where j ∈ {1, 2, …, v}. Depending on what is most suitable for the target software program SP j the time periods (T1, T2, …, T i ) can be equal or different. The time span required to calculate TS′ v is t < T j . j .

[0089] At the end of T j the measured trace TS will be obtained j . The real-time detection model M i will compare the measured trace TS j with the calculated trace TS′ j . At the end of each time period T j a detection decision D j is made such that if the measured trace TS j does indeed match the calculated trace TS′ j , then D j = 1; while if the measured trace TS j does not match the calculated trace TS j , then D j = 0. In the latter case, a security event is reported and various actions can be taken in real time to avoid exploitation of the system. For the next time span T j+1 the real-time detection model M i considers the previously measured trace TS j to predict TS′ j+1 .

[0090] To avoid false alarms, a confidence boundary TB can be added to the predicted time series such that TS″ j,t = TS′ j,t + TB, where TS″ j,t and TS′ j,t are the values of the predicted time series at time t with and without the confidence boundary TB respectively.

[0091] Figure 13 shows the use of a trained classifier TC i for detecting the type of attack on the software program. Once the trained detection model M i is based on performance metric PIi When an anomaly is detected, the behavior can be provided to the trained classifier TC i to obtain further information about the attack. These classifiers TC i can be Figure 10 part of the same framework as shown in, where the corresponding classifier TC can be trained using the data generated by the execution under the same attack A i i Regarding where to use the trained classifier TC i there are multiple options. For example, the trained classifier TC i can be deployed in Figure 8 the security operation center shown in.

[0092] Reference numeral

[0093] 10 Device

[0094] 11 Input terminal

[0095] 12 Processing unit

[0096] 13 Reporting unit

[0097] 14 Control unit

[0098] 15 Local storage unit

[0099] 16 Output terminal

[0100] 17 User interface

[0101] 20 Device

[0102] 21 Memory device

[0103] 22 Processing device

[0104] 23 Input terminal

[0105] 24 Output terminal

[0106] 30 Machine

[0107] 31 Processing system

[0108] 32 Sensor

[0109] 33 Data transmission unit

[0110] 34 Memory

[0111] 35 Network

[0112] 40 Device

[0113] 41 Input terminal

[0114] ​42 Collection Unit

[0115] 43 Processing Unit

[0116] 44 Evaluation Unit

[0117] 45 Control Unit

[0118] 46 Local Storage Unit

[0119] 47 Output Terminal

[0120] 48 User Interface

[0121] 50 Device

[0122] 51 Memory Device

[0123] 52 Processing Device

[0124] 53 Input Terminal

[0125] 54 Output Terminal

[0126] A i Attack

[0127] B Behavior

[0128] HW Hardware

[0129] IDS Intrusion Detection System

[0130] IdsM Intrusion Detection System Manager

[0131] IdsR Intrusion Detection System Reporter

[0132] M i Trained Detection Model

[0133] MS n Measurement Segment

[0134] P Platform

[0135] PI i Performance Indicator

[0136] PS n Prediction Segment

[0137] QSE Qualified Security Event

[0138] R Report

[0139] S Security Sensor

[0140] SE Security Event

[0141] SEM Security Event Memory

[0142] SOC Security Operations Center

[0143] SP i Software program

[0144] SW Software platform

[0145] TC i Trained classifier

[0146] TD Training data

[0147] S1 Segment of predicted behavior

[0148] S2 Segment of measured behavior

[0149] S3 Compare the predicted segment with the measured segment

[0150] S4 Determine that an attack has occurred

[0151] S5 Identify the type of attack

[0152] S6 Report a security incident

[0153] S10 Collect training data

[0154] S11 Train a detection model

[0155] S12 Build a machine learning classifier

[0156] S13 Select a detection model

Claims

1. A method for real-time detection of attacks on a software program (SP) running on a platform (P i ), the method comprising: - Use the trained detection model (M i ) to predict (S1) a fragment (PS i ) of the behavior of the software program (SP n-1 ) based on one or more previous fragments (MS n ) of the behavior of the software program; - Predictive segment (PS i ) of the behavior of the software program (SP n ) is compared with the measurement segment (MS n ) (S3); and - In the case where the measurement segment (MS n ) does not match the prediction segment (PS n ), report (S6) a safety event (SE).

2. The method according to claim 1, wherein, The prediction segment (PS n ) includes the trusted boundaries of the behavior of the software program (SP i ).

3. The method according to claim 1 or 2, wherein The time period covered by the prediction segment (PS n ) is constant or adjustable.

4. The method according to one of the preceding claims, wherein, This behavior covers one or more software or hardware performance indicators (PI i ).

5. The method according to claim 4, wherein These performance indicators (PIs i ) include at least one or more of the following: execution time, power consumption, memory consumption, loop counters, the number of issued and / or retired instructions, and cache misses.

6. The method according to one of the preceding claims, further comprising identifying (S5) the type of attack.

7. A computer program code comprising instructions which, when executed by at least one processor, cause the at least one processor to perform the method for real-time detection of an attack on a software program (SP i ) running on a platform (P) according to any one of claims 1 to 6.

8. An apparatus (10) for real-time detection of an attack on a software program (SP i ) running on a platform (P), the apparatus (10) comprising: - A processing unit (12) configured to: use a trained detection model (M i ) to predict (S1) a segment (PS i ) of the behavior of the software program (SP n-1 ) based on one or more previous segments (MS n ) of the behavior of the software program, and compare (S3) the predicted segment (PS i ) of the behavior of the software program (SP n ) with a measured segment (MS n ); And - Reporting unit (13), which is configured to report (S6) a safety event when the measurement segment (MS n ) does not match the prediction segment (PS n ).

9. A machine (30), wherein, The machine (30) includes the device (10) according to claim 8, or is configured to perform the method according to any one of claims 1 to 6 for real-time detection of an attack on a software program (SP i ) running on the platform (P) of the machine (30).

10. A method for providing a detection model (M i ) for real-time detection of attacks on a software program (SP i ) running on a platform (P), the method comprising: -Collect (S10) training data (TD) during normal execution of the software program (SP i ) and during execution of the software program (SP i ) under one or more attacks; - Train (S11) one or more detection models (M i ) using the training data; And - Select (S13) a detection model (M i ) from the one or more trained detection models (M i ).

11. The method according to claim 10, wherein, The training data covers one or more software or hardware performance indicators (PI i ).

12. The method according to claim 10 or 11, further comprising constructing (S12) a machine learning classifier (TC i ) for a plurality of attack types.

13. A computer program code comprising instructions which, when executed by at least one processor, cause the at least one processor to perform the method according to any one of claims 10 to 12 for providing a detection model (M i ) for detecting attacks on a software program (SP i ) running on a platform (P).

14. An apparatus (40) for providing a detection model (M i ) for real-time detection of attacks on a software program (SP i ) running on a platform (P), the apparatus (40) comprising: - Collection unit (42), which is configured to collect (S10) training data (TD) during normal execution of the software program (SP i ) and during execution of the software program (SP i ) under one or more attacks; - A processing unit (43) configured to train (S11) one or more detection models (M i ) using the training data; And - An evaluation unit (44), which is configured to select (S13) one detection model (M i ) from the one or more trained detection models (M i ).

15. A detection model (M i ) for real-time detection of attacks on a software program (SP i ) running on a platform (P), wherein The detection model (M i ) is provided by the method according to any one of claims 10 to 12.

Citation Information

Patent Citations

  • Malware detection using machine learning

    US20190215329A1