- 专利标题: Malicious/benign computational behavior detection using parametric behavioral pattern definition
-
申请号: US17019166申请日: 2020-09-11
-
公开(公告)号: US11907370B2公开(公告)日: 2024-02-20
- 发明人: David F. Diehl , Daniel W. Brown , Aaron Javan Marks , Kirby J. Koster , Daniel T. Martin
- 申请人: CrowdStrike, Inc.
- 申请人地址: US CA Sunnyvale
- 专利权人: CROWDSTRIKE, INC.
- 当前专利权人: CROWDSTRIKE, INC.
- 当前专利权人地址: US CA Sunnyvale
- 代理机构: Lee & Hayes P.C.
- 分案原申请号: US15585156 2017.05.02
- 主分类号: G06F21/56
- IPC分类号: G06F21/56 ; H04L9/40 ; G06F21/55 ; G06N20/00
摘要:
A security agent implemented on a monitored computing device is described herein. The security agent has access to parametric behavioral pattern definitions that, in combination with canonical patterns of behavior, configure the security agent to match observed behavior with known computing behavior that is benign or malignant. This arrangement of the definitions and the pattern of behavior allow the security agent's behavior to be updated by a remote security service without updating a configuration of the security agent. The remote security service can create, modify, and disseminate these definitions and patterns of behavior, giving the security agent real-time ability to respond to new behaviors exhibited by the monitored computing device.
信息查询