- 专利标题: Server drift monitoring
-
申请号: US15681501申请日: 2017-08-21
-
公开(公告)号: US10038702B2公开(公告)日: 2018-07-31
- 发明人: Andrew J. Thomas , Kenneth D. Ray , Mark D. Harris
- 申请人: Sophos Limited
- 申请人地址: GB Abingdon
- 专利权人: Sophos Limited
- 当前专利权人: Sophos Limited
- 当前专利权人地址: GB Abingdon
- 代理机构: Strategic Patents, P.C.
- 主分类号: H04L12/26
- IPC分类号: H04L12/26 ; G06F21/00 ; H04L29/06
摘要:
Threat detection is improved by monitoring variations in observable events and correlating these variations to malicious activity. The disclosed techniques can be usefully employed with any attribute or other metric that can be instrumented on an endpoint and tracked over time including observable events such as changes to files, data, software configurations, operating systems, and so forth. Correlations may be based on historical data for a particular machine, or a group of machines such as similarly configured endpoints. Similar inferences of malicious activity can be based on the nature of a variation, including specific patterns of variation known to be associated with malware and any other unexpected patterns that deviate from normal behavior. Embodiments described herein use variations in, e.g., server software updates or URL cache hits on an endpoint, but the techniques are more generally applicable to any endpoint attribute that varies in a manner correlated with malicious activity.
公开/授权文献
- US20170346835A1 SERVER DRIFT MONITORING 公开/授权日:2017-11-30
信息查询