The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Jun. 03, 2025

Filed:

Mar. 30, 2022
Applicant:

Rapid7, Inc., Boston, MA (US);

Inventors:

Matthew Berninger, Denver, CO (US);

Roy Hodgman, Cambridge, MA (US);

Katherine Wilbur, Brookline, MA (US);

Vasudha Shivamoggi, Arlington, MA (US);

Lauren Johnson, Boston, MA (US);

Jacqueline Daniel, Bainbridge Island, WA (US);

Luke Ludington, Stratham, NH (US);

Assignee:

Rapid7, Inc., Boston, MA (US);

Attorneys:
Primary Examiner:
Assistant Examiner:
Int. Cl.
CPC ...
G06F 21/56 (2013.01); G06F 21/55 (2013.01);
U.S. Cl.
CPC ...
G06F 21/566 (2013.01); G06F 21/554 (2013.01); G06F 2221/034 (2013.01);
Abstract

A method includes obtaining a command captured at a computing device to start a process on the computing device submitted via a command line interface. The command is of a plurality of commands captured at respective computing devices that triggered respective alerts to review the plurality of commands. The method includes parsing the command to generate a plurality of tokens that represent the command according to dictionary of features of commands submitted via the command line interface, generating a feature vector based, at least in part, on the plurality of tokens, applying a classification model, trained on other commands submitted via the command line interface to predict benign commands, to the feature vector to determine a score indicative of a probability that the command is benign, and, responsive to a determination that the score is above a confidence threshold, removing the command from the plurality of commands to be reviewed.


Find Patent Forward Citations

Loading…