IL302585A - מערכת ושיטה לגילוי ולתגובה על אירועים במכשיר ממוחשב - Google Patents

מערכת ושיטה לגילוי ולתגובה על אירועים במכשיר ממוחשב

Info

Publication number
IL302585A
IL302585A IL302585A IL30258523A IL302585A IL 302585 A IL302585 A IL 302585A IL 302585 A IL302585 A IL 302585A IL 30258523 A IL30258523 A IL 30258523A IL 302585 A IL302585 A IL 302585A
Authority
IL
Israel
Prior art keywords
edr
server
computerized
systematical
events
Prior art date
Application number
IL302585A
Other languages
English (en)
Inventor
Newman Andrew
Dudu Yaniv
Original Assignee
Reason Cybersecurity Ltd
Newman Andrew
Dudu Yaniv
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Reason Cybersecurity Ltd, Newman Andrew, Dudu Yaniv filed Critical Reason Cybersecurity Ltd
Priority to IL302585A priority Critical patent/IL302585A/he
Priority to PCT/IL2024/050367 priority patent/WO2024228181A1/en
Publication of IL302585A publication Critical patent/IL302585A/he

Links

Classifications

    • H—ELECTRICITY
    • H04—ELECTRIC COMMUNICATION TECHNIQUE
    • H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/40—Network security protocols
    • G—PHYSICS
    • G06—COMPUTING OR CALCULATING; COUNTING
    • G06F—ELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/55—Detecting local intrusion or implementing counter-measures
    • G06F21/554—Detecting local intrusion or implementing counter-measures involving event detection and direct action
    • G—PHYSICS
    • G06—COMPUTING OR CALCULATING; COUNTING
    • G06F—ELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G—PHYSICS
    • G06—COMPUTING OR CALCULATING; COUNTING
    • G06F—ELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/55—Detecting local intrusion or implementing counter-measures
    • G—PHYSICS
    • G06—COMPUTING OR CALCULATING; COUNTING
    • G06F—ELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/55—Detecting local intrusion or implementing counter-measures
    • G06F21/56—Computer malware detection or handling, e.g. anti-virus arrangements
    • G—PHYSICS
    • G06—COMPUTING OR CALCULATING; COUNTING
    • G06F—ELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60—Protecting data
    • G06F21/62—Protecting access to data via a platform, e.g. using keys or access control rules
    • G06F21/6218—Protecting access to data via a platform, e.g. using keys or access control rules to a system of files or objects, e.g. local or distributed file system or database
    • G06F21/6227—Protecting access to data via a platform, e.g. using keys or access control rules to a system of files or objects, e.g. local or distributed file system or database where protection concerns the structure of data, e.g. records, types, queries
    • H—ELECTRICITY
    • H04—ELECTRIC COMMUNICATION TECHNIQUE
    • H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00—Network architectures or network communication protocols for network security
    • H04L63/02—Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
    • H04L63/0227—Filtering policies
    • H—ELECTRICITY
    • H04—ELECTRIC COMMUNICATION TECHNIQUE
    • H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00—Network architectures or network communication protocols for network security
    • H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1408—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
    • H—ELECTRICITY
    • H04—ELECTRIC COMMUNICATION TECHNIQUE
    • H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00—Network architectures or network communication protocols for network security
    • H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1408—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
    • H04L63/1416—Event detection, e.g. attack signature detection
    • H—ELECTRICITY
    • H04—ELECTRIC COMMUNICATION TECHNIQUE
    • H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00—Network architectures or network communication protocols for network security
    • H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1408—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
    • H04L63/1425—Traffic logging, e.g. anomaly detection
    • H—ELECTRICITY
    • H04—ELECTRIC COMMUNICATION TECHNIQUE
    • H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00—Network architectures or network communication protocols for network security
    • H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1441—Countermeasures against malicious traffic
    • H—ELECTRICITY
    • H04—ELECTRIC COMMUNICATION TECHNIQUE
    • H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00—Network architectures or network communication protocols for network security
    • H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1441—Countermeasures against malicious traffic
    • H04L63/145—Countermeasures against malicious traffic the attack involving the propagation of malware through the network, e.g. viruses, trojans or worms
    • H—ELECTRICITY
    • H04—ELECTRIC COMMUNICATION TECHNIQUE
    • H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00—Network architectures or network communication protocols for network security
    • H04L63/20—Network architectures or network communication protocols for network security for managing network security; network security policies in general
    • H—ELECTRICITY
    • H04—ELECTRIC COMMUNICATION TECHNIQUE
    • H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00—Network architectures or network communication protocols for network security
    • H04L63/02—Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
    • H04L63/0227—Filtering policies
    • H04L63/0263—Rule management

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Hardware Design (AREA)
  • General Engineering & Computer Science (AREA)
  • Theoretical Computer Science (AREA)
  • Software Systems (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computing Systems (AREA)
  • General Physics & Mathematics (AREA)
  • Physics & Mathematics (AREA)
  • General Health & Medical Sciences (AREA)
  • Health & Medical Sciences (AREA)
  • Virology (AREA)
  • Databases & Information Systems (AREA)
  • Bioethics (AREA)
  • Computer And Data Communications (AREA)
IL302585A 2023-05-02 2023-05-02 מערכת ושיטה לגילוי ולתגובה על אירועים במכשיר ממוחשב IL302585A (he)

Priority Applications (2)

Application Number Priority Date Filing Date Title
IL302585A IL302585A (he) 2023-05-02 2023-05-02 מערכת ושיטה לגילוי ולתגובה על אירועים במכשיר ממוחשב
PCT/IL2024/050367 WO2024228181A1 (en) 2023-05-02 2024-04-15 System and method detecting and responding to events on computerized device

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
IL302585A IL302585A (he) 2023-05-02 2023-05-02 מערכת ושיטה לגילוי ולתגובה על אירועים במכשיר ממוחשב

Publications (1)

Publication Number Publication Date
IL302585A true IL302585A (he) 2024-12-01

Family

ID=93332836

Family Applications (1)

Application Number Title Priority Date Filing Date
IL302585A IL302585A (he) 2023-05-02 2023-05-02 מערכת ושיטה לגילוי ולתגובה על אירועים במכשיר ממוחשב

Country Status (2)

Country Link
IL (1) IL302585A (he)
WO (1) WO2024228181A1 (he)

Family Cites Families (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2022114689A1 (ko) * 2020-11-26 2022-06-02 주식회사 엔피코어 이미지 기반 악성코드 탐지 방법 및 장치와 이를 이용하는 인공지능 기반 엔드포인트 위협탐지 및 대응 시스템
GB2626472A (en) * 2021-10-11 2024-07-24 Sophos Ltd Augmented threat investigation

Also Published As

Publication number Publication date
WO2024228181A1 (en) 2024-11-07

Similar Documents

Publication Publication Date Title
IL289426B2 (he) שיטה ומכשיר לניהול אבטחה ברשת מחשבים
IL295777A (he) שיטה ומערכת לניהול אירועי מידע על אבטחת משתמש מקוון
IL297006A (he) הגנה על נכסי מחשב מפני התקפות זדוניות
IL276972B1 (he) סימולטור יריב אינטליגנטי
IL296554A (he) למידת מכונה במחשוב קוונטי עבור איומי אבטחה
IL283695B2 (he) מערכות ושיטות לגילוי איומים התנהגותיים
IL283698B1 (he) מערכות ושיטות לגילוי איומים התנהגותיים
IL266200A (he) מחוון מוניטין דינמי למיטוב פעולות אבטחה במחשב
US20230421582A1 (en) Cybersecurity operations case triage groupings
IL323163A (he) פיענוח ספקולטיבי במודלי בינה מלאכותית מחוללים אוטו-רגרסיביים
IL295223A (he) מערכת, שיטה ותוכנת מחשב לטכנולוגית קליטה, עיבוד, שמירה וחיפוש מידע
IL283697B2 (he) מערכות ושיטות לגילוי איומים התנהגותיים
US20100251369A1 (en) Method and system for preventing data leakage from a computer facilty
Čisar et al. The framework of runtime application self-protection technology
US20240414204A1 (en) Cybersecurity ai-driven workflow generation using policies
Saber et al. Automated penetration testing, a systematic review
IL307998A (he) שיטה ומערכת להעשרת מרכז תפעול אבטחת מידע
Katiyar Cyber security using artificial intelligence
IL267368B2 (he) מערכות לבדיקת מוצר אלקטרוני
IL286952B2 (he) זיהוי קשרים ומניעת קשרים תלויים
Kant How Cyber Threat Intelligence (CTI) Ensures Cyber Resilience Using Artificial Intelligence and Machine Learning
IL309475A (he) מערכת ושיטה לעדכון מסלול תקיפה
IL305720A (he) מערכת ושיטה ליצירת מודיעין איומים על ידי שימוש במודל שפה גדול
CN117370701A (zh) 浏览器风险检测方法、装置、计算机设备和存储介质
US20230214209A1 (en) Correlation Engine for Detecting Security Vulnerabilities in Continuous Integration/Continuous Delivery Pipelines