×

Method and system for detecting and remediating polymorphic attacks across an enterprise

  • US 10,511,616 B2
  • Filed: 11/06/2018
  • Issued: 12/17/2019
  • Est. Priority Date: 12/09/2015
  • Status: Active Grant
First Claim
Patent Images

1. A method for detecting potential malware comprising:

  • a)

         1) obtaining an attack tree representative of an attack on a network, the attack tree formed of objects;

    2) analyzing the objects to determine whether each of the objects is classified as known or unknown, in accordance with predefined criteria; and

    ,3) representing the unknown objects in the attack tree as generalized objects, resulting in the creation of a first generalized attack tree from the obtained attack tree;

    b) dividing the first generalized attack tree into subtrees including first generalized objects;

    c) obtaining at least one subtree including second generalized objects associated with a subsequent generalized attack tree;

    d) comparing at least one of the subtrees from the first generalized attack tree to the at least one subtree associated with the subsequent generalized attack tree, based on at least partial matches of the first generalized objects and the second generalized objects, the least partial matches including matching less than all of the first generalized objects with the second generalized objects; and

    ,e) augmenting the first generalized attack tree by adding the second generalized objects, which do not match the first generalized objects, to the first generalized attack tree, to detect potentially unknown malware.

View all claims
  • 0 Assignments
Timeline View
Assignment View
    ×
    ×