Identifizierungsverfahren für Verdächtige Aktivitätsmuster auf der Basis von Abstammungsbeziehungen

EP3531324 Art B1 25. August 2021

Anmelder: CrowdStrike, Inc. 🇺🇸

Details

Veröffentlichungs-Nr.
EP3531324
Aktenzeichen
EP19156473
Anmeldetag
11. Februar 2019
Veröffentlichung
25. August 2021
Erteilung
25. August 2021
Rechtsraum
EP
IPC
G06F21/55H04L29/06H04W12/12
Offizieller Volltext

Abstract

A security service system and method for using a process based on ancestry relationship as a pattern for identifying a suspicious activity, such as a possible malicious attack or malware, are described herein. The security service system identifies a trigger command in a process running on a monitored computing device, identifies an ancestry command associated with the trigger command, determines an ancestry level of the ancestry command, and upon determining that the ancestry level of the ancestry command is different from an expected ancestry level of the ancestry command for the trigger command, identify a pattern based on the trigger command, the ancestry command, and the ancestry level of the ancestry command.

Anmelder

Firma
CrowdStrike, Inc.
Land
🇺🇸 USA
🇺🇸 CrowdStrike

US-amerikanisches Unternehmen für Cybersicherheit, das cloudbasierte Plattformen zum Schutz von Endgeräten, Netzwerken und Cloud-Umgebungen vor Cyberangriffen anbietet.

132 Patente in unserer Datenbank

Noch Fragen?

Wir helfen Ihnen gerne weiter. Schreiben Sie uns einfach.

Kontakt aufnehmen