- 专利标题: Method of threat detection
-
申请号: US17094414申请日: 2020-11-10
-
公开(公告)号: US11811803B2公开(公告)日: 2023-11-07
- 发明人: Paolo Palumbo , Dmitriy Komashinskiy
- 申请人: F-Secure Corporation
- 申请人地址: FI Helsinki
- 专利权人: WITHSECURE CORPORATION
- 当前专利权人: WITHSECURE CORPORATION
- 当前专利权人地址: FI Helsinki
- 代理机构: Meunier Carlin & Curfman LLC
- 优先权: GB 16345 2019.11.11
- 主分类号: G06F21/00
- IPC分类号: G06F21/00 ; H04L9/40
摘要:
There is provided a method comprising: detecting a new process start at a network node of a computer network; determining that said process requires external code modules; observing the times at which one or more external code modules required by the new process are loaded relative to the process starting time; determining that the usage of an external code module required by the new process is anomalous when the time elapsed between the start of the process and loading of said external code module lies outside predetermined expected boundaries; and taking further action to protect the network node and/or the computer network based on determining that the usage of the external code module required by the detected new process is anomalous.
公开/授权文献
- US20210144165A1 METHOD OF THREAT DETECTION 公开/授权日:2021-05-13
信息查询