The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Jan. 17, 2023

Filed:

Jun. 27, 2019
Applicant:

Fireeye, Inc., Milpitas, CA (US);

Inventors:

Philip Tully, New York, NY (US);

Matthew Haigh, New York, NY (US);

Jay Gibble, Leesburg, VA (US);

Michael Sikorski, New York, NY (US);

Assignee:

Mandiant, Inc., Milpitas, CA (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
G06F 21/56 (2013.01); G06N 20/00 (2019.01); H04L 9/40 (2022.01);
U.S. Cl.
CPC ...
G06F 21/562 (2013.01); G06N 20/00 (2019.01); H04L 63/145 (2013.01); G06F 2221/033 (2013.01);
Abstract

An automated system and method for analyzing a set of extracted strings from a binary is disclosed including processing the binary with a string-extraction logic that can locate strings within the binary and output an extracted string set for use in cybersecurity analysis. The logic retrieves a set of training data comprising a plurality of previously analyzed extracted string sets where each element of the previously analyzed extracted string set comprises at least one extracted string and a corresponding previously determined threat prediction score. A prediction model based upon the training data is generated and the extracted string set is processed by the prediction model to determine a threat prediction score for each string. Ranking of the located strings is based upon the determined threat prediction score, and an output of a ranked string list is generated.


Find Patent Forward Citations

Loading…