The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Jul. 29, 2025

Filed:

May. 08, 2023
Applicant:

Sophos Limited, Abingdon, GB;

Inventors:

Adarsh Dinesh Kyadige, Thornton, CO (US);

Ben Uri Gelman, Reston, VA (US);

Konstantin Berlin, Potomac, MD (US);

Assignee:

Sophos Limited, Abingdon, GB;

Attorneys:
Primary Examiner:
Int. Cl.
CPC ...
H04L 9/40 (2022.01); G06N 20/00 (2019.01);
U.S. Cl.
CPC ...
H04L 63/1441 (2013.01); G06N 20/00 (2019.01); H04L 63/1416 (2013.01); H04L 63/1425 (2013.01); H04L 63/20 (2013.01);
Abstract

In example embodiments, techniques are provided to detect LOLBin attacks using a trained machine learning model that classifies command lines as benign or malicious. The machine learning model may be trained using a dataset of command line data that describes executed binary executable files, sourced from the log of events of compute instances. The dataset may be sampled using an approximate content-based logarithmic sampling algorithm (e.g., an algorithm that employs logarithmic sampling based on a locality sensitive hash, for example, a MinHash). The dataset may be labeled and featurized. The featurized labeled dataset may be used to train the machine learning model, which is then deployed to detect LOLBin attacks on a compute instance. In response to detection of a LOLBin attack, a remedial action may be performed on the compute instance.


Find Patent Forward Citations

Loading…