发明名称 MONITORING VARIATIONS IN OBSERVABLE EVENTS FOR THREAT DETECTION
摘要 Threat detection is improved by monitoring variations in observable events and correlating these variations to malicious activity. The disclosed techniques can be usefully employed with any attribute or other metric that can be instrumented on an endpoint and tracked over time including observable events such as changes to files, data, software configurations, operating systems, and so forth. Correlations may be based on historical data for a particular machine, or a group of machines such as similarly configured endpoints. Similar inferences of malicious activity can be based on the nature of a variation, including specific patterns of variation known to be associated with malware and any other unexpected patterns that deviate from normal behavior. Embodiments described herein use variations in, e.g., server software updates or URL cache hits on an endpoint, but the techniques are more generally applicable to any endpoint attribute that varies in a manner correlated with malicious activity.
申请公布号 WO2016097686(A1) 申请公布日期 2016.06.23
申请号 WO2015GB53676 申请日期 2015.12.02
申请人 SOPHOS LIMITED 发明人 RAY, KENNETH D.;HARRIS, MARK D.;REED, SIMON NEIL;WATKISS, NEIL ROBERT TYNDALE;THOMAS, ANDREW J.
分类号 G06F21/56 主分类号 G06F21/56
代理机构 代理人
主权项
地址