Method and system for identifying uncorrelated suspicious events during an attack

    公开(公告)号:US10462160B2

    公开(公告)日:2019-10-29

    申请号:US15292169

    申请日:2016-10-13

    IPC分类号: H04L29/06 G06F21/56

    摘要: Computerized methods and systems identify events associated with an attack initiated on an endpoint client. A listing of processes executed or created on the endpoint during the attack is obtained. The listing of processes includes a first process and at least one subsequent process executed or created by the first process. The computerized methods and systems analyze for the occurrence of at least one event during a time interval associated with the attack. The computerized methods and systems determine whether the listing of processes includes a process that when executed caused the occurrence of the at least one event. If the listing of processes excludes process that when executed caused the occurrence of the at least one event, the at least one event and the causing process are stored, for example, in a database or memory.