- 专利标题: METHOD AND SYSTEM FOR DETECTING MALICIOUS OR SUSPICIOUS ACTIVITY BY BASELINING HOST BEHAVIOR
-
申请号: US16858817申请日: 2020-04-27
-
公开(公告)号: US20210336973A1公开(公告)日: 2021-10-28
- 发明人: Tamara LEIDERFARB , Lior Arzi , Ilana Danan
- 申请人: CHECK POINT SOFTWARE TECHNOLOGIES LTD.
- 申请人地址: IL Tel Aviv
- 专利权人: CHECK POINT SOFTWARE TECHNOLOGIES LTD.
- 当前专利权人: CHECK POINT SOFTWARE TECHNOLOGIES LTD.
- 当前专利权人地址: IL Tel Aviv
- 主分类号: H04L29/06
- IPC分类号: H04L29/06
摘要:
The disclosed subject matter includes a system, which when installed in a specific host, such as an end point, or end point computer, will model its behavior over time, score new activities in real time and calculate outliers, by creating and analyzing vectors. The vectors are formed of feature values, extracted from executable processes, and the analysis includes the determining and evaluating the distance between a current vector and a cluster of vectors.
公开/授权文献
- US1290004A Aeroplane-fitting. 公开/授权日:1918-12-31
信息查询