Patent · US Active

Detecting malicious activity on a computer system

US11023576B2 · kind B2 · utility

8Cited by
16References
14Claims
0Family size

Assignee

Inventors

Key dates

Filing dateNov 28, 2018
Grant dateJun 1, 2021
Priority date
Expiry dateAug 9, 2039

Classification

  • Technology area (CPC G)Physics
  • CPC primaryG10L13/00
  • WIPO fieldComputer technology
  • WIPO sectorElectrical engineering

Abstract

An approach is provided for detecting a malicious activity on a computer system. First process trees are identified for computer processes that have been executed on a computer system. Each of the first process trees are vectorized. The vectorized first process trees are associated with respective labels. Each label represents an amount by which a respective vectorized process tree reflects the malicious activity. An artificial neural network is trained by using the vectorized first process trees and the associated labels as training input. After the training of the artificial neural network is completed, second process trees for currently executing computer processes are vectorized and provided as input vectors to the artificial neural network. Responsive to the artificial neural network providing an output indicating that a combination of the input vectors indicates the malicious activity, a remedial action is performed.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.