The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Mar. 01, 2022

Filed:

Jun. 26, 2019
Applicant:

F-secure Corporation, Helsinki, FI;

Inventor:

Jarno Niemela, Kirkkonummi, FI;

Assignee:

F-Secure Corporation, Helsinki, FI;

Attorney:
Int. Cl.
CPC ...
H04L 29/06 (2006.01); G06N 20/00 (2019.01);
U.S. Cl.
CPC ...
H04L 63/1416 (2013.01); G06N 20/00 (2019.01); H04L 63/1425 (2013.01);
Abstract

A method comprising: monitoring events collected from a plurality of network nodes; detecting a first suspicious event among the monitored events by a detection mechanism; monitoring the behaviour of the first suspicious event and any related events; in case the monitored first suspicious event and/or a related event is detected to perform an activity triggering an IOC (indicator of compromise, generating a new IOC; monitoring new events when the activity ends; comparing the behaviour of the new events with the behaviour of the generated IOC; in case a matching behaviour is found, merging the new event with the first suspicious event and/or related events related to the generated IOC; and generating a security related decision on the basis of the IOC.


Find Patent Forward Citations

Loading…