Patent · US Active

Auto-detection of observables and auto-disposition of alerts in an endpoint detection and response (EDR) system using machine learning

US12316661B2 · kind B2 · utility

0Cited by
6References
20Claims
0Family size

Assignee

Inventors

Key dates

Filing dateOct 31, 2022
Grant dateMay 27, 2025
Priority date
Expiry dateAug 23, 2043

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L63/1441
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

A technique for threat response associated with an endpoint detection and response (EDR) system. The system uses a combination of automated observable detection, threat intelligence enrichment, graph analysis, and supervised machine learning to machine-predict analyst behavior in classifying (as ‘true’ or ‘false’ positives) the EDR alerts, and to support either (i) automated suppression of those alerts that the system classifies with sufficient confidence as either true or false, or (ii) for those alerts than cannot be so classified, the providing of recommendations to analysts to facilitate their activities. Auto-detection of observables for graph-based feature detection, together with the automated disposition of alerts where possible greatly reduces overall analyst workload for the EDR system. Further, and even where a machine-based prediction does not have sufficient confidence to enable bypassing the analyst, the system provides the analyst with additional context and enrichment to facilitate expedited (or at least more efficient) alert handling.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.