发明名称 Application-Level Anomaly Detection
摘要 An example includes intercepting one or more activities performed by an application on a computing device. The intercepting uses an instrumentation layer separating the application from an operating system on the computing device. The one or more activities are compared with one or more anomaly detection policies in a policy configuration file to detect or not detect presence of one or more anomalies. In response to the comparison detecting presence of one or more anomalies, indication(s) of the one or more anomalies are stored. Another example includes receiving indication(s) of anomaly(ies) experienced by an application on computing device(s) and analyzing the indication(s) of the anomaly(ies) to determine whether corrective action(s) should be issued. Responsive to a determination corrective action(s) should be issued based on the analyzing, the corrective action(s) are issued to the computing device(s). Methods, program products, and apparatus are disclosed.
申请公布号 US2014137246(A1) 申请公布日期 2014.05.15
申请号 US201314030337 申请日期 2013.09.18
申请人 INTERNATIONAL BUSINESS MACHINES CORPORATION 发明人 BALUDA MAURO;CASTRO PAUL C.;PISTOIA MARCO;PONZO JOHN J.
分类号 G06F21/52 主分类号 G06F21/52
代理机构 代理人
主权项
地址