The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Nov. 26, 2019

Filed:

Sep. 29, 2017
Applicant:

AO Kaspersky Lab, Moscow, RU;

Inventors:

Alexey V. Monastyrsky, Moscow, RU;

Mikhail A. Pavlyushchik, Moscow, RU;

Alexey M. Romanenko, Moscow, RU;

Maxim Y. Golovkin, Moscow, RU;

Assignee:

AO Kaspersky Lab, Moscow, RU;

Attorneys:
Primary Examiner:
Int. Cl.
CPC ...
G06F 21/00 (2013.01); G06F 21/55 (2013.01); G06F 21/54 (2013.01); G06F 21/56 (2013.01); H04L 29/06 (2006.01); H04W 12/12 (2009.01);
U.S. Cl.
CPC ...
G06F 21/554 (2013.01); G06F 21/54 (2013.01); G06F 21/561 (2013.01); H04L 63/1408 (2013.01); H04L 63/1441 (2013.01); G06F 2221/033 (2013.01); G06F 2221/034 (2013.01); H04L 63/145 (2013.01); H04W 12/12 (2013.01);
Abstract

A system and method is provided for detecting anomalous events occurring in an operating system of a computing device. An exemplary method includes detecting an event that occurs in the operating system of the computing device during execution of a software process. Moreover, the method includes determining a context of the detected event and forming a convolution of the detected event based on selected features of the determined context of the detected event. Further, the method includes determining a popularity of the formed convolution by polling a database containing data relating to a frequency of detected events occurring in client devices in a network, where the detected events of the client devices correspond to the detected event in the computing device. If the determined popularity is below a threshold value, the method determines that the detected event is an anomalous event.


Find Patent Forward Citations

Loading…