The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Jan. 03, 2023

Filed:

Feb. 19, 2019
Applicant:

Darktrace Holdings Limited, Cambridge, GB;

Inventors:

Andrew Woodford, Cheltenham, GB;

Jacob Araiza, Monmouth, GB;

Alex Markham, Cambridgeshire, GB;

Matthew Dunn, Cambridgeshire, GB;

Assignee:
Attorney:
Primary Examiner:
Int. Cl.
CPC ...
H04L 9/40 (2022.01); G06N 20/10 (2019.01); G06N 20/00 (2019.01); G06F 21/36 (2013.01); H04L 43/045 (2022.01); G06F 16/2455 (2019.01); G06F 3/04842 (2022.01); G06F 3/0486 (2013.01); H04L 41/22 (2022.01); G06K 9/62 (2022.01); G06F 40/40 (2020.01); G06V 30/10 (2022.01); H04L 51/42 (2022.01); H04L 51/212 (2022.01); H04L 51/224 (2022.01); G06F 21/55 (2013.01); G06N 20/20 (2019.01);
U.S. Cl.
CPC ...
H04L 63/1425 (2013.01); G06F 3/0486 (2013.01); G06F 3/04842 (2013.01); G06F 16/2455 (2019.01); G06F 21/36 (2013.01); G06F 21/554 (2013.01); G06F 21/556 (2013.01); G06F 40/40 (2020.01); G06K 9/622 (2013.01); G06K 9/6218 (2013.01); G06N 20/00 (2019.01); G06N 20/10 (2019.01); G06V 30/10 (2022.01); H04L 41/22 (2013.01); H04L 43/045 (2013.01); H04L 51/212 (2022.05); H04L 51/224 (2022.05); H04L 51/42 (2022.05); H04L 63/0209 (2013.01); H04L 63/0428 (2013.01); H04L 63/101 (2013.01); H04L 63/14 (2013.01); H04L 63/1416 (2013.01); H04L 63/1433 (2013.01); H04L 63/1441 (2013.01); H04L 63/1483 (2013.01); H04L 63/20 (2013.01); G06N 20/20 (2019.01);
Abstract

A cyber security appliance has modules that utilize probes to interact with entities in a cloud infrastructure environment (CIE). A cloud module can 1) use the information about relevant changes in the CIE fed from the probes, and 2) use machine learning models that are trained on a normal behavior of at least a first entity associated with the CIE; and thus, indicate when a behavior of the first entity falls outside of being a normal pattern of life. A cyber threat module can use machine learning models trained on cyber threats in the CIE and examine at least the behaviors of the first entity falling outside of the normal pattern of life to determine what is a likelihood of 'a chain of unusual behaviors under analysis that fall outside of being the normal behavior' is a cyber threat. An autonomous response module can cause actions to contain the cyber threat.


Find Patent Forward Citations

Loading…