The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Apr. 04, 2023

Filed:

Sep. 25, 2019
Applicant:

Mandiant, Inc., Reston, VA (US);

Inventors:

Vikram Hegde, Milpitas, CA (US);

Chunsheng Victor Fang, Mountain View, CA (US);

Assignee:

Mandiant, Inc., Reston, VA (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
G06F 21/55 (2013.01); G06N 20/00 (2019.01); G06K 9/62 (2022.01); G06N 3/088 (2023.01); G06N 3/04 (2023.01);
U.S. Cl.
CPC ...
G06F 21/554 (2013.01); G06K 9/6256 (2013.01); G06K 9/6267 (2013.01); G06N 3/04 (2013.01); G06N 3/088 (2013.01); G06N 20/00 (2019.01);
Abstract

The presently disclosed subject matter includes a system for monitoring a set of command lines or calls to executable scripts configured to be executed by an operating system. Each command line from the set of command lines is associated with an executable script configured to be executed by an operating system. The apparatus classifies, via a machine learning model, a command line from the set of command lines into an obfuscation category and prevents the operating system from executing the command line and generates a notification signal when the obfuscation category indicates that the command line is part of a cybersecurity attack. The apparatus allows the operating system to execute the command line or call to the executable script when the obfuscation category indicates that the command line is not part of a cybersecurity attack.


Find Patent Forward Citations

Loading…