Sicherheitsverletzungserkennung eines Computersicherheitsereignisses

EP3654216 Art B1 28. Juli 2021

Anmelder: CrowdStrike, Inc. 🇺🇸

Details

Veröffentlichungs-Nr.
EP3654216
Aktenzeichen
EP19207848
Anmeldetag
7. November 2019
Veröffentlichung
28. Juli 2021
Erteilung
28. Juli 2021
Rechtsraum
EP
IPC
G06F21/55
Offizieller Volltext

Abstract

Example techniques herein determine that an event associated with a monitored computing device is associated with a security violation. Terms are extracted from at least two command lines associated with the event. Term representations of the at least two terms are determined based at least in part on a trained representation mapping. Two or more first filter outputs are determined based at least in part on the term representations of terms in a respective first subset of the terms. An indication of whether the event is associated with a security violation is determined at least partly by operating a trained classification computational model (CM) based at least in part on the two or more first filter outputs. Various examples train a word2vec or other x2vec model to provide the representation mapping. Various examples train a CM having convolutional and classification sections to provide the indication.

Anmelder

Firma
CrowdStrike, Inc.
Land
🇺🇸 USA
🇺🇸 CrowdStrike

US-amerikanisches Unternehmen für Cybersicherheit, das cloudbasierte Plattformen zum Schutz von Endgeräten, Netzwerken und Cloud-Umgebungen vor Cyberangriffen anbietet.

132 Patente in unserer Datenbank

Noch Fragen?

Wir helfen Ihnen gerne weiter. Schreiben Sie uns einfach.

Kontakt aufnehmen