Invention Grant
- Patent Title: Automated creation of lightweight behavioral indicators of compromise (IOCS)
-
Application No.: US16131146Application Date: 2018-09-14
-
Publication No.: US11451561B2Publication Date: 2022-09-20
- Inventor: Jan Jusko , Danila Khikhlukha , Harshit Nayyar
- Applicant: Cisco Technology, inc.
- Applicant Address: US CA San Jose
- Assignee: Cisco Technology, inc.
- Current Assignee: Cisco Technology, inc.
- Current Assignee Address: US CA San Jose
- Agency: Behmke Innovation Group LLC
- Agent Kenneth J. Heywood; Jonathon P. Western
- Main IPC: H04L9/40
- IPC: H04L9/40 ; G06F16/28

Abstract:
In one embodiment, a device obtains execution records regarding executions of a plurality of binaries. The execution records comprise command line arguments used during the execution. The device determines measures of similarity between the executions of the binaries based on their command line arguments. The device clusters the executions into clusters based on the determined measures of similarity. The device flags the command line arguments for a particular one of the clusters as an indicator of compromise for malware, based on at least one of the binaries associated with the particular cluster being malware.
Public/Granted literature
- US20200092306A1 AUTOMATED CREATION OF LIGHTWEIGHT BEHAVIORAL INDICATORS OF COMPROMISE (IOCS) Public/Granted day:2020-03-19
Information query