发明名称 Security Agent
摘要 A security agent is described herein. The security agent is configured to observe events, filter the observed events using configurable filters, route the filtered events to one or more event consumers, and utilize the one or more event consumers to take action based at least on one of the filtered events. In some implementations, the security agent detects a first action associated with malicious code, gathers data about the malicious code, and in response to detecting subsequent action(s) of the malicious code, performs a preventative action. The security agent may also deceive an adversary associated with malicious code. Further, the security agent may utilize a model representing chains of execution activities and may take action based on those chains of execution activities.
申请公布号 US2017109530(A1) 申请公布日期 2017.04.20
申请号 US201615393797 申请日期 2016.12.29
申请人 CrowdStrike, Inc. 发明人 Diehl David F.;Alperovitch Dmitri;Ionescu Ion-Alexandru;Kurtz George Robert
分类号 G06F21/56;G06N5/04 主分类号 G06F21/56
代理机构 代理人
主权项 1. A computer-implemented method comprising: detecting a first action associated with malicious code; responsive to detecting the first action, gathering data associated with the first action while refraining from taking a preventative action; upon detecting one or more subsequent actions associated with malicious code, the one or more subsequent actions occurring after the first action, performing the preventative action.
地址 Irvine CA US
您可能感兴趣的专利