The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Feb. 13, 2024

Filed:

Jul. 10, 2019
Applicant:

Crowdstrike, Inc., Sunnyvale, CA (US);

Inventors:

Cory-Khoi Quang Nguyen, Lafayette, IN (US);

Jaron Michael Bradley, Mason, MI (US);

William Leon Charles Pauley, Ann Arbor, MI (US);

Assignee:

CrowdStrike, Inc., Sunnyvale, CA (US);

Attorney:
Primary Examiner:
Assistant Examiner:
Int. Cl.
CPC ...
G06N 3/08 (2023.01); G06N 3/044 (2023.01); G06F 21/55 (2013.01); G06V 30/196 (2022.01);
U.S. Cl.
CPC ...
G06F 21/554 (2013.01); G06N 3/044 (2023.01); G06N 3/08 (2013.01); G06V 30/1985 (2022.01); G06F 2221/034 (2013.01);
Abstract

An event can be analyzed for association with a security violation. Characters or other values of event data (e.g., command-line text) associated with the event can be provided sequentially to a trained representation mapping to determine respective representation vectors. Respective indicators can be determined by applying the vectors to a trained classifer. A token in the event data can be located based on the indicators. The event's can be determined to be associated with a security violation based on the token satisfying a token-security criterion. The representation mapping can be trained by adjusting model parameters so the trained representation predicts, based on a character of training command-line text, an immediately following character in the training command-line text. The classifier can be determined based on the trained representation mapping and classification training data indicating whether respective portions of training event data are associated with security violations.


Find Patent Forward Citations

Loading…