JP7389806B2 - 挙動による脅威検出のためのシステムおよび方法 - Google Patents

挙動による脅威検出のためのシステムおよび方法 Download PDF

Info

Publication number
JP7389806B2
JP7389806B2 JP2021533157A JP2021533157A JP7389806B2 JP 7389806 B2 JP7389806 B2 JP 7389806B2 JP 2021533157 A JP2021533157 A JP 2021533157A JP 2021533157 A JP2021533157 A JP 2021533157A JP 7389806 B2 JP7389806 B2 JP 7389806B2
Authority
JP
Japan
Prior art keywords
event
target
client
events
sequence
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active
Application number
JP2021533157A
Other languages
English (en)
Japanese (ja)
Other versions
JP2022512195A5 (https=
JP2022512195A (ja
Inventor
ディチウ,ダニエル
ニクラエ,ステファン
ボシンチェアヌ,エレーナ・エイ
ザムフィル,ソリナ・エヌ
ディンチュ,アンドレーア
アポストアエ,アンドレイ・エイ
Original Assignee
ビットディフェンダー アイピーアール マネジメント リミテッド
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by ビットディフェンダー アイピーアール マネジメント リミテッド filed Critical ビットディフェンダー アイピーアール マネジメント リミテッド
Publication of JP2022512195A publication Critical patent/JP2022512195A/ja
Publication of JP2022512195A5 publication Critical patent/JP2022512195A5/ja
Application granted granted Critical
Publication of JP7389806B2 publication Critical patent/JP7389806B2/ja
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1408Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
    • H04L63/1416Event detection, e.g. attack signature detection
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/55Detecting local intrusion or implementing counter-measures
    • G06F21/552Detecting local intrusion or implementing counter-measures involving long-term monitoring or reporting
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/55Detecting local intrusion or implementing counter-measures
    • G06F21/554Detecting local intrusion or implementing counter-measures involving event detection and direct action
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06NCOMPUTING ARRANGEMENTS BASED ON SPECIFIC COMPUTATIONAL MODELS
    • G06N5/00Computing arrangements using knowledge-based models
    • G06N5/02Knowledge representation; Symbolic representation
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1408Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
    • H04L63/1425Traffic logging, e.g. anomaly detection

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Theoretical Computer Science (AREA)
  • General Engineering & Computer Science (AREA)
  • Software Systems (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Physics & Mathematics (AREA)
  • Physics & Mathematics (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Artificial Intelligence (AREA)
  • Computational Linguistics (AREA)
  • Data Mining & Analysis (AREA)
  • Evolutionary Computation (AREA)
  • Mathematical Physics (AREA)
  • Computer And Data Communications (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)
  • Radar Systems Or Details Thereof (AREA)
  • Ultra Sonic Daignosis Equipment (AREA)
JP2021533157A 2018-12-10 2019-12-10 挙動による脅威検出のためのシステムおよび方法 Active JP7389806B2 (ja)

Applications Claiming Priority (3)

Application Number Priority Date Filing Date Title
US16/215,251 2018-12-10
US16/215,251 US11153332B2 (en) 2018-12-10 2018-12-10 Systems and methods for behavioral threat detection
PCT/EP2019/084312 WO2020120429A1 (en) 2018-12-10 2019-12-10 Systems and methods for behavioral threat detection

Publications (3)

Publication Number Publication Date
JP2022512195A JP2022512195A (ja) 2022-02-02
JP2022512195A5 JP2022512195A5 (https=) 2022-07-14
JP7389806B2 true JP7389806B2 (ja) 2023-11-30

Family

ID=68841136

Family Applications (1)

Application Number Title Priority Date Filing Date
JP2021533157A Active JP7389806B2 (ja) 2018-12-10 2019-12-10 挙動による脅威検出のためのシステムおよび方法

Country Status (11)

Country Link
US (1) US11153332B2 (https=)
EP (1) EP3895048B1 (https=)
JP (1) JP7389806B2 (https=)
KR (1) KR102403629B1 (https=)
CN (1) CN113168469B (https=)
AU (1) AU2019400060B2 (https=)
CA (1) CA3120423C (https=)
ES (1) ES2946062T3 (https=)
IL (1) IL283698B2 (https=)
SG (1) SG11202105054UA (https=)
WO (1) WO2020120429A1 (https=)

Families Citing this family (20)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US10805331B2 (en) 2010-09-24 2020-10-13 BitSight Technologies, Inc. Information technology security assessment system
US9438615B2 (en) 2013-09-09 2016-09-06 BitSight Technologies, Inc. Security risk management
US10257219B1 (en) 2018-03-12 2019-04-09 BitSight Technologies, Inc. Correlated risk in cybersecurity
US10521583B1 (en) 2018-10-25 2019-12-31 BitSight Technologies, Inc. Systems and methods for remote detection of software through browser webinjects
KR102165494B1 (ko) * 2018-12-28 2020-10-14 네이버 주식회사 온라인 서비스에서의 비정상 사용 행위 식별 방법, 장치 및 컴퓨터 프로그램
US10726136B1 (en) * 2019-07-17 2020-07-28 BitSight Technologies, Inc. Systems and methods for generating security improvement plans for entities
US11032244B2 (en) 2019-09-30 2021-06-08 BitSight Technologies, Inc. Systems and methods for determining asset importance in security risk management
US10893067B1 (en) 2020-01-31 2021-01-12 BitSight Technologies, Inc. Systems and methods for rapidly generating security ratings
US11023585B1 (en) 2020-05-27 2021-06-01 BitSight Technologies, Inc. Systems and methods for managing cybersecurity alerts
US20220284433A1 (en) * 2021-03-04 2022-09-08 Capital One Services, Llc Unidimensional embedding using multi-modal deep learning models
US12353563B2 (en) 2021-07-01 2025-07-08 BitSight Technologies, Inc. Systems and methods for accelerating cybersecurity assessments
US12425437B2 (en) 2021-09-17 2025-09-23 BitSight Technologies, Inc. Systems and methods for precomputation of digital asset inventories
US12282564B2 (en) 2022-01-31 2025-04-22 BitSight Technologies, Inc. Systems and methods for assessment of cyber resilience
CN115456789B (zh) * 2022-11-10 2023-04-07 杭州衡泰技术股份有限公司 基于交易模式识别的异常交易检测方法及其系统
US12321450B2 (en) 2023-03-02 2025-06-03 Bitdefender IPR Management Ltd. Antimalware systems and methods using optimal triggering of artificial intelligence modules
US20250094582A1 (en) * 2023-09-15 2025-03-20 International Business Machines Corporation Selectively prioritizing alerts received for an advanced cybersecurity threat prioritization system
US12225026B1 (en) * 2023-09-29 2025-02-11 Citibank, N.A. Detecting malicious activity using user-specific parameters
WO2026009439A1 (ja) * 2024-07-05 2026-01-08 Ntt株式会社 文書処理装置
JP2026014482A (ja) 2024-07-19 2026-01-29 富士通株式会社 データ処理方法、データ処理装置およびプログラム
US20260089179A1 (en) * 2024-09-24 2026-03-26 Oracle International Corporation Detecting stealing of principals in a cloud environment

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2007242002A (ja) 2006-02-10 2007-09-20 Mitsubishi Electric Corp ネットワーク管理装置及びネットワーク管理方法及びプログラム
US20140215618A1 (en) 2013-01-25 2014-07-31 Cybereason Inc Method and apparatus for computer intrusion detection
JP2017126282A (ja) 2016-01-15 2017-07-20 富士通株式会社 検知プログラム、検知方法および検知装置
US20170279829A1 (en) 2016-03-25 2017-09-28 Cisco Technology, Inc. Dynamic device clustering using device profile information
JP2018520419A (ja) 2015-05-17 2018-07-26 ビットディフェンダー アイピーアール マネジメント リミテッド コンピュータセキュリティアプリケーション用のカスケード型分類器

Family Cites Families (46)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6526405B1 (en) * 1999-12-17 2003-02-25 Microsoft Corporation Determining similarity between event types in sequences
AU2001262958A1 (en) 2000-04-28 2001-11-12 Internet Security Systems, Inc. Method and system for managing computer security information
US6742124B1 (en) 2000-05-08 2004-05-25 Networks Associates Technology, Inc. Sequence-based anomaly detection using a distance matrix
US6973577B1 (en) 2000-05-26 2005-12-06 Mcafee, Inc. System and method for dynamically detecting computer viruses through associative behavioral analysis of runtime state
US7818797B1 (en) 2001-10-11 2010-10-19 The Trustees Of Columbia University In The City Of New York Methods for cost-sensitive modeling for intrusion detection and response
US7035863B2 (en) 2001-11-13 2006-04-25 Koninklijke Philips Electronics N.V. Method, system and program product for populating a user profile based on existing user profiles
US7234166B2 (en) 2002-11-07 2007-06-19 Stonesoft Corporation Event sequence detection
US7716739B1 (en) 2005-07-20 2010-05-11 Symantec Corporation Subjective and statistical event tracking incident management system
WO2008055156A2 (en) 2006-10-30 2008-05-08 The Trustees Of Columbia University In The City Of New York Methods, media, and systems for detecting an anomalous sequence of function calls
US8448249B1 (en) 2007-07-31 2013-05-21 Hewlett-Packard Development Company, L.P. Methods and systems for using lambda transitions for processing regular expressions in intrusion-prevention systems
WO2009097610A1 (en) 2008-02-01 2009-08-06 Northeastern University A vmm-based intrusion detection system
US20090328215A1 (en) 2008-06-30 2009-12-31 Microsoft Corporation Semantic networks for intrusion detection
GB0816556D0 (en) 2008-09-10 2008-10-15 Univ Napier Improvements in or relating to digital forensics
US8370931B1 (en) 2008-09-17 2013-02-05 Trend Micro Incorporated Multi-behavior policy matching for malware detection
US20120137367A1 (en) 2009-11-06 2012-05-31 Cataphora, Inc. Continuous anomaly detection based on behavior modeling and heterogeneous information analysis
US8661034B2 (en) 2010-02-03 2014-02-25 Gartner, Inc. Bimodal recommendation engine for recommending items and peers
US8752171B2 (en) 2010-09-03 2014-06-10 Mcafee, Inc. Behavioral tracking system, method, and computer program product for undoing events based on user input
US8572239B2 (en) 2010-09-20 2013-10-29 Microsoft Corporation Node clustering
US20120278354A1 (en) 2011-04-29 2012-11-01 Microsoft Corporation User analysis through user log feature extraction
EP2754049A4 (en) * 2011-09-09 2015-08-26 Hewlett Packard Development Co SYSTEMS AND METHOD FOR EVALUATING EVENTS BASED ON A REFERENCE BASE LINE AFTER THE TIME POSITION IN A SUCCESS OF EVENTS
US9058486B2 (en) 2011-10-18 2015-06-16 Mcafee, Inc. User behavioral risk assessment
US8839435B1 (en) 2011-11-04 2014-09-16 Cisco Technology, Inc. Event-based attack detection
US9129227B1 (en) 2012-12-31 2015-09-08 Google Inc. Methods, systems, and media for recommending content items based on topics
US20140230062A1 (en) 2013-02-12 2014-08-14 Cisco Technology, Inc. Detecting network intrusion and anomaly incidents
US9225737B2 (en) 2013-03-15 2015-12-29 Shape Security, Inc. Detecting the introduction of alien content
US9166993B1 (en) 2013-07-25 2015-10-20 Symantec Corporation Anomaly detection based on profile history and peer history
GB2519941B (en) 2013-09-13 2021-08-25 Elasticsearch Bv Method and apparatus for detecting irregularities on device
US10346465B2 (en) 2013-12-20 2019-07-09 Qualcomm Incorporated Systems, methods, and apparatus for digital composition and/or retrieval
US20170039198A1 (en) * 2014-05-15 2017-02-09 Sentient Technologies (Barbados) Limited Visual interactive search, scalable bandit-based visual interactive search and ranking for visual interactive search
US9798883B1 (en) * 2014-10-06 2017-10-24 Exabeam, Inc. System, method, and computer program product for detecting and assessing security risks in a network
WO2016081516A2 (en) 2014-11-18 2016-05-26 Vectra Networks, Inc. Method and system for detecting threats using passive cluster mapping
US9652316B2 (en) 2015-03-31 2017-05-16 Ca, Inc. Preventing and servicing system errors with event pattern correlation
US9536072B2 (en) * 2015-04-09 2017-01-03 Qualcomm Incorporated Machine-learning behavioral analysis to detect device theft and unauthorized device usage
US20160352759A1 (en) 2015-05-25 2016-12-01 Yan Zhai Utilizing Big Data Analytics to Optimize Information Security Monitoring And Controls
CN105989849B (zh) 2015-06-03 2019-12-03 乐融致新电子科技(天津)有限公司 一种语音增强方法、语音识别方法、聚类方法及装置
US20170140384A1 (en) * 2015-11-12 2017-05-18 Fair Isaac Corporation Event sequence probability enhancement of streaming fraud analytics
EP3387814B1 (en) 2015-12-11 2024-02-14 ServiceNow, Inc. Computer network threat assessment
US9762611B2 (en) 2016-02-16 2017-09-12 Cylance Inc. Endpoint-based man in the middle attack detection using machine learning models
CN109564575B (zh) 2016-07-14 2023-09-05 谷歌有限责任公司 使用机器学习模型来对图像进行分类
US10832165B2 (en) 2016-12-02 2020-11-10 Facebook, Inc. Systems and methods for online distributed embedding services
US10552501B2 (en) 2017-03-28 2020-02-04 Oath Inc. Multilabel learning via supervised joint embedding of documents and labels
US10726128B2 (en) 2017-07-24 2020-07-28 Crowdstrike, Inc. Malware detection using local computational models
US12061954B2 (en) 2017-10-27 2024-08-13 Intuit Inc. Methods, systems, and computer program product for dynamically modifying a dynamic flow of a software application
US20190296933A1 (en) 2018-03-20 2019-09-26 Microsoft Technology Licensing, Llc Controlling Devices Based on Sequence Prediction
US11636287B2 (en) 2018-03-28 2023-04-25 Intuit Inc. Learning form-based information classification
US20190340615A1 (en) * 2018-05-04 2019-11-07 International Business Machines Corporation Cognitive methodology for sequence of events patterns in fraud detection using event sequence vector clustering

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2007242002A (ja) 2006-02-10 2007-09-20 Mitsubishi Electric Corp ネットワーク管理装置及びネットワーク管理方法及びプログラム
US20140215618A1 (en) 2013-01-25 2014-07-31 Cybereason Inc Method and apparatus for computer intrusion detection
JP2018520419A (ja) 2015-05-17 2018-07-26 ビットディフェンダー アイピーアール マネジメント リミテッド コンピュータセキュリティアプリケーション用のカスケード型分類器
JP2017126282A (ja) 2016-01-15 2017-07-20 富士通株式会社 検知プログラム、検知方法および検知装置
US20170279829A1 (en) 2016-03-25 2017-09-28 Cisco Technology, Inc. Dynamic device clustering using device profile information

Also Published As

Publication number Publication date
KR102403629B1 (ko) 2022-05-31
US20200186546A1 (en) 2020-06-11
IL283698B1 (en) 2024-01-01
IL283698B2 (en) 2024-05-01
CN113168469B (zh) 2024-04-23
EP3895048A1 (en) 2021-10-20
CN113168469A (zh) 2021-07-23
KR20210102897A (ko) 2021-08-20
CA3120423A1 (en) 2020-06-18
SG11202105054UA (en) 2021-06-29
EP3895048B1 (en) 2023-04-05
AU2019400060B2 (en) 2024-01-11
IL283698A (en) 2021-07-29
AU2019400060A1 (en) 2021-06-03
JP2022512195A (ja) 2022-02-02
CA3120423C (en) 2024-05-28
US11153332B2 (en) 2021-10-19
WO2020120429A1 (en) 2020-06-18
ES2946062T3 (es) 2023-07-12

Similar Documents

Publication Publication Date Title
JP7389806B2 (ja) 挙動による脅威検出のためのシステムおよび方法
JP7319370B2 (ja) 挙動による脅威検出のためのシステムおよび方法
JP7319371B2 (ja) 挙動による脅威検出のためのシステムおよび方法
CA3120156C (en) Systems and methods for behavioral threat detection
RU2772549C1 (ru) Системы и способы детектирования поведенческих угроз
RU2778630C1 (ru) Системы и способы детектирования поведенческих угроз
RU2803399C2 (ru) Системы и способы детектирования поведенческих угроз
HK40048546A (en) Systems and methods for behavioral threat detection
HK40048545B (zh) 用於行为威胁检测的系统及方法
HK40048545A (en) Systems and methods for behavioral threat detection
HK40049002A (en) Systems and methods for behavioral threat detection
HK40048546B (zh) 用於行为威胁检测的系统及方法

Legal Events

Date Code Title Description
A521 Request for written amendment filed

Free format text: JAPANESE INTERMEDIATE CODE: A523

Effective date: 20220706

A621 Written request for application examination

Free format text: JAPANESE INTERMEDIATE CODE: A621

Effective date: 20220706

A977 Report on retrieval

Free format text: JAPANESE INTERMEDIATE CODE: A971007

Effective date: 20230621

A131 Notification of reasons for refusal

Free format text: JAPANESE INTERMEDIATE CODE: A131

Effective date: 20230626

A521 Request for written amendment filed

Free format text: JAPANESE INTERMEDIATE CODE: A523

Effective date: 20230828

TRDD Decision of grant or rejection written
A01 Written decision to grant a patent or to grant a registration (utility model)

Free format text: JAPANESE INTERMEDIATE CODE: A01

Effective date: 20231019

A61 First payment of annual fees (during grant procedure)

Free format text: JAPANESE INTERMEDIATE CODE: A61

Effective date: 20231117

R150 Certificate of patent or registration of utility model

Ref document number: 7389806

Country of ref document: JP

Free format text: JAPANESE INTERMEDIATE CODE: R150