Invention Grant
- Patent Title: Corrective action on malware intrusion detection using file introspection
-
Application No.: US16718174Application Date: 2019-12-17
-
Publication No.: US11544375B2Publication Date: 2023-01-03
- Inventor: Sirisha Myneni , Nafisa Mandliwala , Subrahmanyam Manuguri , Anirban Sengupta
- Applicant: VMware, Inc.
- Applicant Address: US CA Palo Alto
- Assignee: VMware, Inc.
- Current Assignee: VMware, Inc.
- Current Assignee Address: US CA Palo Alto
- Main IPC: G06F21/55
- IPC: G06F21/55 ; G06N5/04 ; G06N20/00

Abstract:
File events are correlated with intrusion detection alerts for corrective action. A monitoring component receives file events from a thin agent. An analysis component analyzes the file events and metadata obtained from the intrusion detection alerts, such as attack type or file name, to correlate a set of file events to at least one detected action (intrusion) described in the alert. A recommendation component identifies one or more options, including one or more corrective actions, which are applicable for remediating the alert. The set of options includes a recommended action from two or more possible corrective actions. The set of options are output or displayed to the user. The user selects which option/action to perform in response to the alert. In some examples, an automatic response is performed without user selection with respect to selected types of alerts, detected action(s), selected file(s) or other user-generated criteria.
Public/Granted literature
- US20210182388A1 CORRECTIVE ACTION ON MALWARE INTRUSION DETECTION USING FILE INTROSPECTION Public/Granted day:2021-06-17
Information query