×

Malware communications detection

  • US 10,389,738 B2
  • Filed: 10/30/2015
  • Issued: 08/20/2019
  • Est. Priority Date: 08/31/2015
  • Status: Active Grant
First Claim
Patent Images

1. A method comprising:

  • receiving, by a computer system, event data associated with a communication between an internal entity within a computer network and an external entity outside the computer network;

    generating, by the computer system, a plurality of entity-specific feature scores by processing the event data, wherein each of the entity-specific features scores is representative of a quantified evaluation of a level of risk associated with a particular entity, each of the feature scores generated by a different one of a plurality of different types of analyses of the event data, the particular entity being the internal entity or the external entity;

    wherein the plurality of entity-specific feature scores include;

    a first entity-specific feature score based on a lexical analysis of an identifier associated with the particular entity; and

    a second entity-specific feature score based on an analysis of the timing or sequencing of communications by the particular entity;

    generating, by the computer system, an entity profile associated with the particular entity, the entity profile including the plurality of entity-specific feature scores;

    generating, by the computer system, an anomaly score based on the entity profile; and

    detecting, by the computer system, an anomaly if the anomaly score satisfies a specified criterion.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×