METHODS AND CLOUD-BASED SYSTEMS FOR CORRELATING MALWARE DETECTIONS BY ENDPOINT DEVICES AND SERVERS
Patent №
US 11,070,570
Granted
2021-07-20
Filed 2019
Owner
—
Lab
—
AI components
5
ml · nlp · kr · planning · hardware
Assignment
None on record
Dataset
AIPD
2023_r1 edition
Application
16290009
Disclosed herein are systems and method for correlating malware detections by endpoint devices and servers. In one aspect, an exemplary method comprises receiving, by a correlator, from one or more servers, one or more events collected without invasive techniques, one or more events collected using one or more invasive techniques, and one or more final verdicts, correlating the one or more events collected without invasive techniques with one or more events collected using the one or more invasive techniques, creating a suspicious pattern when an event of the one or more events collected without invasive techniques is correlated with an event of the one or more events collected using the one or more invasive techniques, and the event of the one or more events collected using one or more invasive techniques is used to detect a malware, and updating databases of one or more endpoint devices with created suspicious patterns.