Patent №
US 9,740,859
Granted
2017-08-22
Filed 2016
Owner
SOPHOS LIMITED
Lab
—
AI components
3
kr · planning · hardware
Assignment
Recorded
Dataset
AIPD
2023_r1 edition
Application
15235722
Threat detection is improved by monitoring variations in observable events and correlating these variations to malicious activity. The disclosed techniques can be usefully employed with any attribute or other metric that can be instrumented on an endpoint and tracked over time including observable events such as changes to files, data, software configurations, operating systems, and so forth. Correlations may be based on historical data for a particular machine, or a group of machines such as similarly configured endpoints. Similar inferences of malicious activity can be based on the nature of a variation, including specific patterns of variation known to be associated with malware and any other unexpected patterns that deviate from normal behavior. Embodiments described herein use variations in, e.g., server software updates or URL cache hits on an endpoint, but the techniques are more generally applicable to any endpoint attribute that varies in a manner correlated with malicious activity.
AI classification
Ownership
SOPHOS LIMITED
assignment · 396700648
Assignors
HARRIS, MARK D., RAY, KENNETH D.
On an employer assignment, the assignors are typically the inventors.