Identifizierungsverfahren für Verdächtige Aktivitätsmuster auf der Basis von Abstammungsbeziehungen
Anmelder: CrowdStrike, Inc. 🇺🇸
Details
- Veröffentlichungs-Nr.
- EP3531324
- Aktenzeichen
- EP19156473
- Anmeldetag
- 11. Februar 2019
- Veröffentlichung
- 25. August 2021
- Erteilung
- 25. August 2021
- Rechtsraum
- EP
- IPC
- G06F21/55H04L29/06H04W12/12
Abstract
A security service system and method for using a process based on ancestry relationship as a pattern for identifying a suspicious activity, such as a possible malicious attack or malware, are described herein. The security service system identifies a trigger command in a process running on a monitored computing device, identifies an ancestry command associated with the trigger command, determines an ancestry level of the ancestry command, and upon determining that the ancestry level of the ancestry command is different from an expected ancestry level of the ancestry command for the trigger command, identify a pattern based on the trigger command, the ancestry command, and the ancestry level of the ancestry command.
Anmelder
- Firma
- CrowdStrike, Inc.
- Land
- 🇺🇸 USA
US-amerikanisches Unternehmen für Cybersicherheit, das cloudbasierte Plattformen zum Schutz von Endgeräten, Netzwerken und Cloud-Umgebungen vor Cyberangriffen anbietet.
132 Patente in unserer Datenbank