×

THREAT DETECTION USING ENDPOINT VARIANCE

  • US 20160173509A1
  • Filed: 12/15/2014
  • Published: 06/16/2016
  • Est. Priority Date: 12/15/2014
  • Status: Active Grant
First Claim
Patent Images

1. A method comprising:

  • selecting a metric that objectively and quantitatively characterizes an endpoint property;

    monitoring a change in the metric on a group of endpoints over time;

    creating a model that evaluates whether a new value for the metric at a point in time is within a range of expected values for the metric at the point in time;

    instrumenting an endpoint to detect a current value for the metric at a current time;

    applying the model to determine whether the current value is within the range of expected values for the metric at the current time; and

    reporting an indication of compromise for the endpoint when the current value is not within the range of expected values for the metric at the current time.

View all claims
  • 4 Assignments
Timeline View
Assignment View
    ×
    ×