-
公开(公告)号:US20210006575A1
公开(公告)日:2021-01-07
申请号:US17024845
申请日:2020-09-18
Applicant: Secureworks Corp.
Inventor: Lewis McLean , Jon Ramsey , Nash Borges
Abstract: The present disclosure provides systems and methods for organizations to use security date to generate a risk scores associated with potential compromise based on clustering and/or similarities with other organizations that have or may have been compromised. For example, indicators of compromise can be used to create a similarity score rank over time that may be used as a similarity and risk measurement to generate a continual/dynamic score, which can change and/or be updated as new data is created or arrives to detect or prevent threats and/or malicious attacks.
-
公开(公告)号:US20190379678A1
公开(公告)日:2019-12-12
申请号:US16006236
申请日:2018-06-12
Applicant: Secureworks Corp.
Inventor: Lewis McLean , Jon Ramsey , Nash Borges
Abstract: The present disclosure provides systems and methods for organizations to use forensic to generate a risk scores associated with potential compromise based on clustering and/or similarities with other organizations that have or may have been compromised. For example, specific attributes or marks, such as low fidelity indicators of compromise can be used to create a similarity score rank over time that may be used as a similarity and risk measurement to generate a continual/dynamic score, which can change and/or be updated as new data is created or arrives to detect or prevent threats and/or malicious attacks.
-
公开(公告)号:US10785238B2
公开(公告)日:2020-09-22
申请号:US16006236
申请日:2018-06-12
Applicant: Secureworks Corp.
Inventor: Lewis McLean , Jon Ramsey , Nash Borges
Abstract: The present disclosure provides systems and methods for organizations to use forensic to generate a risk scores associated with potential compromise based on clustering and/or similarities with other organizations that have or may have been compromised. For example, specific attributes or marks, such as low fidelity indicators of compromise can be used to create a similarity score rank over time that may be used as a similarity and risk measurement to generate a continual/dynamic score, which can change and/or be updated as new data is created or arrives to detect or prevent threats and/or malicious attacks.
-
4.
公开(公告)号:US12034751B2
公开(公告)日:2024-07-09
申请号:US17491575
申请日:2021-10-01
Applicant: Secureworks Corp.
Inventor: Nash Borges
CPC classification number: H04L63/1425 , G06N20/20
Abstract: A method for detecting unauthorized and/or malicious hands-on-keyboard activity in an information handling system derived from the telemetry from one or more client systems, tokenizing a plurality of partial values/idiosyncrasies detected in the telemetry to form a plurality of tokens, aggregating the plurality of tokens or features over a selected time window to at least partially develop an aggregate feature vector, submitting the aggregate feature vector to one or more machine learning subsystems, and applying an ensemble model to one or more outputs from the one or more machine learning subsystems to generate an overall behavioral threat score of the potentially malicious hands-on-keyboard activity.
-
公开(公告)号:US11044263B2
公开(公告)日:2021-06-22
申请号:US17024845
申请日:2020-09-18
Applicant: Secureworks Corp.
Inventor: Lewis McLean , Jon Ramsey , Nash Borges
Abstract: The present disclosure provides systems and methods for organizations to use security date to generate a risk scores associated with potential compromise based on clustering and/or similarities with other organizations that have or may have been compromised. For example, indicators of compromise can be used to create a similarity score rank over time that may be used as a similarity and risk measurement to generate a continual/dynamic score, which can change and/or be updated as new data is created or arrives to detect or prevent threats and/or malicious attacks.
-
-
-
-