GPU Malicious Process Detection via Behavior Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional anti-malware solutions fail to monitor computing devices' graphics processing units (GPUs), allowing malicious bots to infiltrate and form large-scale botnets without detection, as they are not typically monitored by these solutions.
Innovation Solution
A system and method that identifies GPUs associated with computing devices, analyzes their behavior, and performs security actions if potentially malicious processes are detected, including comparing computing loads and processes with known lists to determine if the GPU is executing malicious processes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional anti-malware solutions are used to monitor computing devices, then CPU processes are detected and blocked, but GPU processes remain undetected and vulnerable to malware infiltration
Solution Approach 1:
The security system is extended to perform multiple monitoring functions across different computing components. The patent applies the same malware detection methodology to both CPU and GPU processes, making the security solution universal across different processor types. This allows the system to detect malicious processes regardless of which computing component they inhabit, thereby improving both reliability and adaptability simultaneously.
2Reliability
If GPU monitoring is added to detect malicious processes, then detection coverage is improved, but system complexity increases
Solution Approach 1:
The patent applies the monitoring methodology used for CPU processes as a template or copy for GPU process monitoring. By replicating the same detection approach, data collection methods, and analysis techniques across different processor types, the system extends coverage to GPUs without requiring entirely new monitoring infrastructure. This copying strategy improves detection reliability while minimizing the increase in system complexity.
3Measurement precision
If comprehensive GPU behavior analysis is performed to identify malicious processes, then detection accuracy is improved, but processing overhead and system performance may deteriorate
Solution Approach 1:
The patent implements a tiered monitoring approach where basic monitoring is performed on all GPU processes, and more intensive analysis is applied only to suspicious or high-risk processes. This partial action strategy allows the system to maintain high detection accuracy for malicious processes while avoiding the performance penalty of applying comprehensive analysis to every single process. The system performs excessive analysis only when necessary, thereby balancing precision and productivity.
Data Source
AI summary
A computer-implemented method for determining whether GPUs are executing potentially malicious processes may include (1) identifying at least one GPU associated with a computing device, (2) analyzing the behavior of the GPU associated with the computing device, (3) determining that the analyzed behavior of the GPU indicates that the GPU is executing at least one potentially malicious process, and then (4) performing at least one security action on the GPU in response to determining that the analyzed behavior indicates that the GPU is executing the potentially malicious process. Various other methods, systems, and computer-readable media are also disclosed.


