The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Dec. 19, 2023

Filed:

Dec. 23, 2020
Applicant:

Mcafee, Llc, San Jose, CA (US);

Inventors:

Celeste R. Fralick, Lubbock, TX (US);

Jonathan King, Forest Grove, OR (US);

Carl D. Woodward, San Jose, CA (US);

Andrew V. Holtzmann, Aurora, CO (US);

Kunal Mehta, Hillsboro, OR (US);

Sherin M. Mathews, San Jose, CA (US);

Assignee:

McAfee, LLC, San Jose, CA (US);

Attorney:
Primary Examiner:
Assistant Examiner:
Int. Cl.
CPC ...
G06F 21/56 (2013.01); G06F 21/60 (2013.01); H04L 9/30 (2006.01);
U.S. Cl.
CPC ...
G06F 21/56 (2013.01); G06F 21/602 (2013.01); H04L 9/30 (2013.01); G06F 2221/034 (2013.01);
Abstract

A method for halting malware includes: monitoring plural file system events with a system driver to detect an occurrence of a file system event having a predetermined file type and log event type; triggering a listening engine for file system event stream data of a file associated with the detection of the file system event, the file system event stream data indicating data manipulation associated with the file due to execution of a process; obtaining one or more feature values for each of plural different feature combinations of plural features of the file based on the file system event stream data; inputting one or more feature values into a data analytics model to predict a target label value based on the one or more feature values of the plural different feature combinations and agnostic to the process; and performing a predetermined operation based on the target label value.


Find Patent Forward Citations

Loading…