- 专利标题: Endpoint inter-process activity extraction and pattern matching
-
申请号: US16158798申请日: 2018-10-12
-
公开(公告)号: US11184374B2公开(公告)日: 2021-11-23
- 发明人: Xiaokui Shu , Zhongshu Gu , Heqing Huang , Marc Philippe Stoecklin , Jialong Zhang
- 申请人: International Business Machines Corporation
- 申请人地址: US NY Armonk
- 专利权人: International Business Machines Corporation
- 当前专利权人: International Business Machines Corporation
- 当前专利权人地址: US NY Armonk
- 代理商 Jeffrey S. LaBaw; David H. Judson
- 主分类号: H04L29/06
- IPC分类号: H04L29/06 ; G06N20/00 ; G06F16/951
摘要:
An automated method for cyberattack detection and prevention in an endpoint. The technique monitors and protects the endpoint by recording inter-process events, creating an inter-process activity graph based on the recorded inter-process events, matching the inter-process activity (as represented in the activity graph) against known malicious or suspicious behavior (as embodied in a set of one or more pattern graphs), and performing a post-detection operation in response to a match between an inter-process activity and a known malicious or suspicious behavior pattern. Preferably, matching involves matching a subgraph in the activity graph with a known malicious or suspicious behavior pattern as represented in the pattern graph. During this processing, preferably both direct and indirect inter-process activities at the endpoint (or across a set of endpoints) are compared to the known behavior patterns. The approach herein provides for systematic modeling of inter-process behaviors for characterizing malicious or suspicious patterns among processes.
信息查询