Patent · US Active

Identifying malware-suspect end points through entropy changes in consolidated logs

US11916934B2 · kind B2 · utility

0Cited by
25References
17Claims
0Family size

Assignee

Inventors

Key dates

Filing dateMay 16, 2022
Grant dateFeb 27, 2024
Priority date
Expiry dateMay 16, 2042

Classification

  • Technology area (CPC G)Physics
  • CPC primaryG06N20/20
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

Example methods disclosed herein to determine whether a first monitored device is compromised include determining a first entropy value for the first monitored device based on a first number of unique event identifiers included in log entries obtained for the first monitored device, the log entries associated with a first time window. Disclosed example methods also include determining a second entropy value for the first monitored device based on numbers of unique event identifiers included in corresponding groups of log entries obtained for respective ones of a plurality of monitored devices including the first monitored device, the groups of log entries associated with the first time window. Disclosed example methods further include determining whether the first monitored device is compromised based on the first entropy value and the second entropy value, and performing an action in response to a determination that the first monitored device is compromised.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.