发明名称 DATA BEHAVIORAL TRACKING
摘要 Threat detection instrumentation is simplified by providing and updating labels for computing objects in a context-sensitive manner. This may include simple labeling schemes to distinguish between objects, e.g., trusted/untrusted processes or corporate/private data. This may also include more granular labeling schemes such as a three-tiered scheme that identifies a category (e.g., financial, e-mail, game), static threat detection attributes (e.g., signatures, hashes, API calls), and explicit identification (e.g., what a file or process calls itself). By tracking such data for various computing objects and correlating these labels to malware occurrences, rules can be written for distribution to endpoints to facilitate threat detection based on, e.g., interactions of labeled objects, changes to object labels, and so forth. In this manner, threat detection based on complex interactions of computing objects can be characterized in a platform independent manner and pre-processed on endpoints without requiring significant communications overhead with a remote threat management facility.
申请公布号 US2016080419(A1) 申请公布日期 2016.03.17
申请号 US201414485765 申请日期 2014.09.14
申请人 Sophos Limited 发明人 Schiappa Dan;Ray Kenneth D.
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项 1. A method comprising: collecting a plurality of behaviors of data on an endpoint using a monitoring facility thereby forming a plurality of collected behaviors; processing the plurality of collected behaviors to obtain a baseline of known behaviors; observing a specific behavior of the data on the endpoint using the monitoring facility; applying a rule in response to the specific behavior to detect a reportable event, the rule including a comparison to the baseline of known behaviors; and transmitting information to a threat management facility about the reportable event, the information including a description of the reportable event and the specific behavior.
地址 Abingdon GB
您可能感兴趣的专利