The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Sep. 03, 2019

Filed:

Feb. 11, 2016
Applicant:

Morphisec Information Security Ltd., Beer Sheva, IL;

Inventors:

Mordechai Guri, Modiin, IL;

Michael Gorelik, Beer Sheva, IL;

Ronen Yehoshua, Matan, IL;

Assignee:
Attorney:
Primary Examiner:
Int. Cl.
CPC ...
G06F 21/56 (2013.01); G06F 21/50 (2013.01); G06F 21/54 (2013.01); G06F 21/55 (2013.01);
U.S. Cl.
CPC ...
G06F 21/566 (2013.01); G06F 21/50 (2013.01); G06F 21/54 (2013.01); G06F 21/554 (2013.01); G06F 21/56 (2013.01); G06F 2221/033 (2013.01);
Abstract

Various approaches are described herein for the automated classification of exploit(s) based on snapshots of runtime environmental features of a computing process in which the exploit(s) are attempted. The foregoing is achieved with a server and local station(s). Each local station is configured to neutralize operation of malicious code being executed thereon, obtain snapshot(s) indicating the state thereof at the time of the exploitation attempt, and perform a classification process using the snapshot(s). The snapshot(s) are analyzed with respect to a local classification model maintained by the local station to find a classification of the exploit therein. If a classification is found, an informed decision is made as to how to handle the classified exploit. If a classification is not found, the snapshot(s) are provided to the server for classification thereby. The server provides an updated classification model containing a classification for the exploit to the local station(s).


Find Patent Forward Citations

Loading…