- 专利标题: System and method for generating rules for attack detection feedback system
-
申请号: US15707641申请日: 2017-09-18
-
公开(公告)号: US10581880B2公开(公告)日: 2020-03-03
- 发明人: Nikita Igorevich Kislitsin
- 申请人: GROUP-IB TDS LTD.
- 申请人地址: RU Moscow
- 专利权人: GROUP-IB TDS LTD.
- 当前专利权人: GROUP-IB TDS LTD.
- 当前专利权人地址: RU Moscow
- 代理机构: BCF LLP
- 优先权: RU2016137336U 20160919
- 主分类号: H04L29/06
- IPC分类号: H04L29/06 ; G06F21/55 ; G06F21/57
摘要:
There is provided a method for auto-generation of decision rules for attack detection feedback systems. The method is executed on a server. The method comprises: receiving at least one event from an event database, the event database having been generated from data obtained by at least one sensor; analyzing the at least one event to determine whether the at least one event belongs to a class of malware control center interactions; if the at least one event belongs to the class of malware control center interactions, extracting at least one attribute from the at least one event; generating decision rules using the at least one attribute; and saving the decision rules; saving the decision rules, the decision rules being instrumental in updating what type of further data is obtained by the at least one sensor based on the decision rule.
公开/授权文献
信息查询