The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Jan. 17, 2023

Filed:

May. 05, 2020
Applicant:

Cylance Inc., Irvine, CA (US);

Inventors:

Xuan Zhao, Irvine, CA (US);

Aditya Kapoor, Portland, OR (US);

Matthew Wolff, Laguna Niguel, CA (US);

Andrew Davis, Portland, OR (US);

Derek A. Soeder, Irvine, CA (US);

Ryan Permeh, Laguna Hills, CA (US);

Assignee:

Cylance Inc., San Ramon, CA (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
H04L 9/40 (2022.01); G06F 21/56 (2013.01); G06N 3/08 (2006.01); G06N 20/00 (2019.01); G06N 3/04 (2006.01); G06N 5/02 (2006.01); G06N 7/00 (2006.01); G06F 3/048 (2013.01); G06N 5/00 (2006.01); G06N 20/20 (2019.01); G06N 20/10 (2019.01);
U.S. Cl.
CPC ...
G06F 21/566 (2013.01); G06N 3/0445 (2013.01); G06N 3/08 (2013.01); G06N 5/025 (2013.01); G06N 7/005 (2013.01); G06N 20/00 (2019.01); H04L 63/145 (2013.01); G06F 3/048 (2013.01); G06N 5/003 (2013.01); G06N 20/10 (2019.01); G06N 20/20 (2019.01);
Abstract

In some implementations there may be provided a system. The system may include a processor and a memory. The memory may include program code which causes operations when executed by the processor. The operations may include analyzing a series of events contained in received data. The series of events may include events that occur during the execution of a data object. The series of events may be analyzed to at least extract, from the series of events, subsequences of events. A machine learning model may determine a classification for the received data. The machine learning model may classify the received data based at least on whether the subsequences of events are malicious. The classification indicative of whether the received data is malicious may be provided. Related methods and articles of manufacture, including computer program products, are also disclosed.


Find Patent Forward Citations

Loading…