GPU Malicious Process Detection via Behavior Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional anti-malware solutions fail to monitor computing devices' graphics processing units (GPUs), allowing malicious bots to infiltrate and form large-scale botnets without detection, as they are not typically monitored by these solutions.

Innovation Solution

A system and method that identifies GPUs associated with computing devices, analyzes their behavior, and performs security actions if potentially malicious processes are detected, including comparing computing loads and processes with known lists to determine if the GPU is executing malicious processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional anti-malware solutions are used to monitor computing devices, then CPU processes are detected and blocked, but GPU processes remain undetected and vulnerable to malware infiltration

Engineering Contradiction:
Improvemalware detection capabilityVSAvoidmonitoring coverage scope
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The security system is extended to perform multiple monitoring functions across different computing components. The patent applies the same malware detection methodology to both CPU and GPU processes, making the security solution universal across different processor types. This allows the system to detect malicious processes regardless of which computing component they inhabit, thereby improving both reliability and adaptability simultaneously.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If GPU monitoring is added to detect malicious processes, then detection coverage is improved, but system complexity increases

Engineering Contradiction:
ImproveGPU malware detectionVSAvoidmonitoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies the monitoring methodology used for CPU processes as a template or copy for GPU process monitoring. By replicating the same detection approach, data collection methods, and analysis techniques across different processor types, the system extends coverage to GPUs without requiring entirely new monitoring infrastructure. This copying strategy improves detection reliability while minimizing the increase in system complexity.

Inventive Principle:
Principle #26Copying

3Measurement precision

If comprehensive GPU behavior analysis is performed to identify malicious processes, then detection accuracy is improved, but processing overhead and system performance may deteriorate

Engineering Contradiction:
Improvemalicious process identification accuracyVSAvoidsystem processing efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent implements a tiered monitoring approach where basic monitoring is performed on all GPU processes, and more intensive analysis is applied only to suspicious or high-risk processes. This partial action strategy allows the system to maintain high detection accuracy for malicious processes while avoiding the performance penalty of applying comprehensive analysis to every single process. The system performs excessive analysis only when necessary, thereby balancing precision and productivity.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9104873B1Systems and methods for determining whether graphics processing units are executing potentially malicious processes
Publication Date: 2015.08.11 CA TECH INC
  • US9104873B1 patent drawing
  • US9104873B1 patent drawing
  • US9104873B1 patent drawing

AI summary

A computer-implemented method for determining whether GPUs are executing potentially malicious processes may include (1) identifying at least one GPU associated with a computing device, (2) analyzing the behavior of the GPU associated with the computing device, (3) determining that the analyzed behavior of the GPU indicates that the GPU is executing at least one potentially malicious process, and then (4) performing at least one security action on the GPU in response to determining that the analyzed behavior indicates that the GPU is executing the potentially malicious process. Various other methods, systems, and computer-readable media are also disclosed.