The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Jul. 13, 2021

Filed:

Nov. 15, 2018
Applicant:

Crowdstrike, Inc., Irvine, CA (US);

Inventors:

Cory-Khoi Quang Nguyen, Lafayette, IN (US);

John Lee, Cleveland, OH (US);

Assignee:

CrowdStrike, Inc., Irvine, CA (US);

Attorney:
Primary Examiner:
Assistant Examiner:
Int. Cl.
CPC ...
G06F 21/00 (2013.01); G06F 21/55 (2013.01); G06F 40/284 (2020.01); G06F 40/157 (2020.01); G06F 9/54 (2006.01); G06F 11/30 (2006.01); G06F 21/56 (2013.01); G06K 9/62 (2006.01); G06N 3/02 (2006.01); H04L 29/06 (2006.01);
U.S. Cl.
CPC ...
G06F 21/554 (2013.01); G06F 9/542 (2013.01); G06F 11/3006 (2013.01); G06F 11/3072 (2013.01); G06F 21/566 (2013.01); G06F 40/157 (2020.01); G06F 40/284 (2020.01); G06K 9/6267 (2013.01); G06N 3/02 (2013.01); H04L 63/1416 (2013.01); H04L 63/1441 (2013.01); G06F 2201/86 (2013.01); G06F 2201/875 (2013.01);
Abstract

Example techniques herein determine that an event associated with a monitored computing device is associated with a security violation. Terms are extracted from at least two command lines associated with the event. Term representations of the at least two terms are determined based at least in part on a trained representation mapping. Two or more first filter outputs are determined based at least in part on the term representations of terms in a respective first subset of the terms. An indication of whether the event is associated with a security violation is determined at least partly by operating a trained classification computational model (CM) based at least in part on the two or more first filter outputs. Various examples train a word2vec or other x2vec model to provide the representation mapping. Various examples train a CM having convolutional and classification sections to provide the indication.


Find Patent Forward Citations

Loading…