The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
May. 31, 2022

Filed:

Feb. 24, 2021
Applicant:

Netskope, Inc., Santa Clara, CA (US);

Inventors:

Ghanashyam Satpathy, Bangalore, IN;

Benjamin Chang, Fremont, CA (US);

Assignee:

Netskope, Inc., Santa Clara, CA (US);

Attorneys:
Primary Examiner:
Int. Cl.
CPC ...
H04L 29/06 (2006.01); H04L 9/40 (2022.01); G06N 20/00 (2019.01); G06F 21/56 (2013.01);
U.S. Cl.
CPC ...
H04L 63/145 (2013.01); G06F 21/562 (2013.01); G06N 20/00 (2019.01); G06F 2221/033 (2013.01);
Abstract

The technology disclosed relates to cybersecurity attacks and cloud-based security. A method and apparatus is provided for detecting documents with embedded threats in the form of malicious Object Linking & Embedding (OLE) objects. The technology disclosed detects obfuscated malicious code using a trained machine learning model to predict documents having malicious code without a known signature. The technology disclosed can thus predict which documents include signatureless malicious code. Feature engineering is used to define a set of features for detecting malicious macros and malicious OLE objects, based on features selected from a list of known characteristics and attributes possessed by files that have historically indicated malicious content. The selected features are used to train a supervised machine learning model, which is used to classify documents as safe, suspicious, or malicious.


Find Patent Forward Citations

Loading…