Aggregate Event Profiles for Detecting Malicious Mobile Applications

    公开(公告)号:US20240070268A1

    公开(公告)日:2024-02-29

    申请号:US17821493

    申请日:2022-08-23

    IPC分类号: G06F21/55

    CPC分类号: G06F21/554 G06F2221/031

    摘要: Described systems and methods protect client devices such as personal computers and IoT devices against malicious software. In some embodiments, a plurality of client devices report the occurrence of various events to a security server, each such event caused by a local instance of a target application (e.g., mobile app) executing on a respective device. The security server then collates the behavior of the respective target application across the plurality of client devices. Some embodiments compute an aggregate event set and/or sequence combining events detected on one device with events detected on other devices, and determine whether the target application is malicious according to the aggregate event set/sequence.

    Systems and methods for behavioral threat detection

    公开(公告)号:US11089034B2

    公开(公告)日:2021-08-10

    申请号:US16215179

    申请日:2018-12-10

    IPC分类号: H04L29/06 G06N20/00

    摘要: In some embodiments, a behavioral computer security system protects clients and networks against threats such as malicious software and intrusion. A set of client profiles is constructed according to a training corpus of events occurring on clients, wherein each client profile represents a subset of protected machines, and each client profile is indicative of a normal or baseline pattern of using the machines assigned to the client respective profile. A client profile may group together machines having a similar event statistic. Following training, events detected on a client are selectively analyzed against a client profile associated with the respective client, to detect anomalous behavior. In some embodiments, individual events are analyzed in the context of other events, using a multi-dimensional event embedding space.

    Systems And Methods For Translating Natural Language Sentences Into Database Queries

    公开(公告)号:US20200004831A1

    公开(公告)日:2020-01-02

    申请号:US16020910

    申请日:2018-06-27

    摘要: Described systems and methods allow an automatic translation from a natural language (e.g., English) into an artificial language such as a structured query language (SQL). In some embodiments, a translator module includes an encoder component and a decoder component, both components comprising recurrent neural networks. Training the translator module comprises two stages. A first stage trains the translator module to produce artificial language (AL) output when presented with an AL input. For instance, the translator is first trained to reproduce an AL input. A second stage of training comprises training the translator to produce AL output when presented with a natural language (NL) input.

    Systems and methods for decrypting network traffic in a virtualized environment

    公开(公告)号:US10257170B2

    公开(公告)日:2019-04-09

    申请号:US16173490

    申请日:2018-10-29

    发明人: Radu Caragea

    摘要: Described systems and methods enable a decryption of encrypted communication between a client system and a remote party, for applications such as detection and analysis of malicious software, intrusion detection, and surveillance, among others. The client system executes a virtual machine and an introspection engine outside the virtual machine. The introspection engine is configured to identify memory pages whose contents have changed between a first session event (e.g., a ServerHello message) and a second session event (e.g., a ClientFinished message). The respective memory pages are likely to contain encryption key material for the respective communication session. A decryption engine may then attempt to decrypt an encrypted payload of the respective communication session using information derived from the content of the identified memory pages.