IL252500A

Systems and methods for malicious code detection accuracy assurance

Abstract

This record has no abstract on file.

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

27 claims: 3 independent, 24 dependent

  1. 1
    33 WHAT IS CLAIMED IS:1. A method for authenticating an attempt at establishment of a network connection by allowed code, comprising: providing a dataset having a plurality of previously observed stack trace templates each representing a stack trace pattern prevailing in stack traces recorded by monitoring a plurality of stacks of a plurality of clients executing an allowed code during a connection establishment process for establishing network connections related to the allowed code;receiving a new stack trace recorded during a new connection establishment process for a new network connection by a new client;measuring a similarity between the new stack trace and the plurality of stack trace templates to identify a match to a stack trace template;evaluating the matched stack trace template for a predefined rule requirement;and updating a rule-set database with the matched stack trace template to authenticate new network connection establishments associated with stack templates matching the matched stack trace template;wherein evaluating the matched stack trace template comprises: incrementing a value of a counter indicative of a number of previous stack trace template matches from different clients, and evaluating the value against the predefined rule requirement of a number of matches.
  2. 18
    A system for authenticating an attempt at establishment of a network connection by allowed code, comprising:a dataset having a plurality of previously observed stack trace templates each representing a stack trace pattern prevailing in stack traces recorded by monitoring a plurality of stacks of a plurality of clients executing an allowed code during a connection establishment process for establishing network connections related to the allowed code;and at least one event management server including a code implementable by a processor of the at least one event management server to: receive a new stack trace recorded at a certain new client of a plurality of clients during a new connection establishment process for a new network connection by the certain new client;measure a similarity between the new stack trace and the plurality of stack trace templates to identify a match to a stack template;36 evaluate the matched stack trace template for a predefined requirement by: incrementing a value of a counter indicative of a number of previous stack trace template matches from different clients, and evaluating the value against the predefined rule requirement of a number of matches;and update a rule-set database with the matched stack trace template to authenticate new network connection establishments associated with stack templates matching the matched stack trace template.
  3. 27
    A computer program product for authenticating an attempt at establishment of a network connection by allowed code, the computer program product comprising:program instructions to provide a dataset having a plurality of previously observed stack trace templates each representing a stack trace pattern prevailing in stack traces recorded by monitoring a plurality of stacks of a plurality of clients executing an allowed code during a connection establishment process for establishing network connections related to the allowed code;program instructions to receive a new stack trace recorded during a new connection establishment process for a new network connection by a new client;program instructions to measure a similarity between the new stack trace and the plurality of stack trace templates to identify a match to a stack trace template;program instructions to evaluate the matched stack trace template for a predefined rule requirement;and program instructions to update a rule-set database with the matched stack trace template to authenticate new network connection establishments associated with stack templates matching the matched stack trace template;wherein evaluating the matched stack trace template comprises: incrementing a value of a counter indicative of a number of previous stack trace template matches from different clients, and evaluating the value against the predefined rule requirement of a number of matches. Roy S. Melzer, Adv. Patent Attorney G.E. Ehrlich (1995) Ltd. 11 Menachem Begin Road 5268104 Ramat Gan