×

System and method of determining malicious processes

  • US 10,439,904 B2
  • Filed: 06/02/2016
  • Issued: 10/08/2019
  • Est. Priority Date: 06/05/2015
  • Status: Active Grant
First Claim
Patent Images

1. A method comprising:

  • capturing data from a first capturing agent at a physical layer within a network, a second capturing agent at a hypervisor layer of the network and a third capturing agent at a virtual layer of the network;

    developing, the data, a lineage for a process associated with network activity;

    analyzing the lineage, for any anomaly within the network; and

    identifying an anomaly in the network in response to the analyzing revealing at least one of the following conditions;

    the process was triggered by an external command;

    the process was triggered by a hidden command that was not accidental;

    the lineage does not follow an expected pattern;

    wherein the lineage is a sequence of commands and/or processes that triggered the process associated with network activity.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×