- 专利标题: COMPUTER AUGMENTED THREAT EVALUATION
-
申请号: US16128984申请日: 2018-09-12
-
公开(公告)号: US20200074078A1公开(公告)日: 2020-03-05
- 发明人: Joshua Daniel Saxe , Andrew J. Thomas , Russell Humphries , Simon Neil Reed , Kenneth D. Ray , Joseph H. Levy
- 申请人: Sophos Limited
- 主分类号: G06F21/55
- IPC分类号: G06F21/55 ; G06N5/04 ; G06K9/62 ; G06N99/00 ; G06F21/56
摘要:
An automated system attempts to characterize code as safe or unsafe. For intermediate code samples not placed with sufficient confidence in either category, human-readable analysis is automatically generated to assist a human reviewer in reaching a final disposition. For example, a random forest over human-interpretable features may be created and used to identify suspicious features in a manner that is understandable to, and actionable by, a human reviewer. Similarly, a k-nearest neighbor algorithm may be used to identify similar samples of known safe and unsafe code based on a model for, e.g., a file path, a URL, an executable, and so forth. Similar code may then be displayed (with other information) to a user for evaluation in a user interface. This comparative information can improve the speed and accuracy of human interventions by providing richer context for human review of potential threats.
公开/授权文献
- US10938838B2 Computer augmented threat evaluation 公开/授权日:2021-03-02
信息查询