Automated blackbox inference of external origin user behavior
Abstract:
Methods and systems for security analysis include determining whether a process has an origin internal to a system or external to the system using a processor based on monitored behavior events associated with the process. A security analysis is performed on only processes that have an external origin to determine if any of the processes having an external origin represent a security threat. A security action is performed if a process having an external origin is determined to represent a security threat.
Public/Granted literature
Information query
Patent Agency Ranking
0/0