THREAT DETECTION USING REPUTATION DATA

Patent №

US 9,740,859

Granted

2017-08-22

Filed 2016

Owner

SOPHOS LIMITED

Lab

AI components

3

kr · planning · hardware

Assignment

Recorded

Dataset

AIPD

2023_r1 edition

Application

15235722

Threat detection is improved by monitoring variations in observable events and correlating these variations to malicious activity. The disclosed techniques can be usefully employed with any attribute or other metric that can be instrumented on an endpoint and tracked over time including observable events such as changes to files, data, software configurations, operating systems, and so forth. Correlations may be based on historical data for a particular machine, or a group of machines such as similarly configured endpoints. Similar inferences of malicious activity can be based on the nature of a variation, including specific patterns of variation known to be associated with malware and any other unexpected patterns that deviate from normal behavior. Embodiments described herein use variations in, e.g., server software updates or URL cache hits on an endpoint, but the techniques are more generally applicable to any endpoint attribute that varies in a manner correlated with malicious activity.

Knowledge representationPlanningAI hardwareG06F 21/552H04L 63/02H04L 63/1416H04L 63/20H04L 67/568

AI classification

AI hardware1.00
Knowledge representation0.99
Planning0.88
Machine learning0.08
Vision0.00
Evolutionary computation0.00
Natural language0.00
Speech0.00

Ownership

SOPHOS LIMITED

assignment · 396700648

Assignors

HARRIS, MARK D., RAY, KENNETH D.

On an employer assignment, the assignors are typically the inventors.

© 2026 NYSGPT2525 LLC