Patent · US Active

Cognitive malicious activity identification and handling

US11070588B2 · kind B2 · utility

0Cited by
8References
17Claims
0Family size

Assignee

Inventors

Key dates

Filing dateJun 11, 2018
Grant dateJul 20, 2021
Priority date
Expiry dateOct 17, 2038

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L63/302
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

Mechanisms are provided to implement a malicious activity response system (MARS) that automatically identifies and handles malicious activities within the data processing system. The MARS identifies threat intelligence associated with characteristics of malicious activity. The MARS forms a hypothesis for the malicious attack to identify a malicious attack that is occurring. The MARS identifies a trap for use in isolating the malicious activity; deploys the trap and automatically reconfiguring a network associated with the data processing system such that the malicious activity is routed to the trap thereby isolating the malicious activity, observes a behavior of the malicious activity within the trap; and extracts features associated with the malicious activity in the trap. The MARS then utilizes the extracted features to improve an operation of the malicious activity response system in handling future malicious activity.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.