Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

17 results about "Heuristic analysis" patented technology

Systems And Methods For Detecting Maliciousness Of Network Communications Through Deployment Of Artificial Intelligence Techniques

A computerized method is disclosed including obtaining an electronic message, performing a cyberthreat detection process thereon, which includes a first sub-analysis of the body and subject line information of deploying a probabilistic generative model resulting in determination of a likelihood that the electronic message is directed to one of a predefined set of topics, and when the likelihood that the electronic message is directed to one of the predefined set of topics meets or exceeds a first threshold, deploying one or more artificial intelligence models to determine or classify a semantics of the email body or subject, and a second sub-analysis of the header information of performing a heuristic analysis thereof, and performing a determination operation by either a relationship compiler resulting in a determination as to whether the electronic message is malicious or benign, and generating a display that provides the maliciousness determination.
Owner:INCEPTIONCYBER AI INC

Generative artificial intelligence-based multi-stage composite event processing

A data platform monitors a compute environment by performing multi-stage heuristic analysis of event data representing a plurality of events occurring within the environment. The platform utilizes multiple event analyzers, each configured according to a distinct analysis heuristic, to evaluate different subsets of the event data and generate corresponding output signals. A higher-level event analyzer applies a further heuristic to the multiple output signals to generate a composite alert signal, indicating whether the combination of analyzed events collectively represents a security intrusion or other anomalous condition of sufficient severity to warrant alerting. Based on the composite alert signal, the platform performs an alert-based operation, such as generating a user-facing alert, initiating an automated mitigation, or updating a contextual model of system behavior. By combining the analytical outputs of heterogeneous heuristics, the disclosed architecture enhances the accuracy and contextual relevance of automated intrusion detection within complex computing environments.
Owner:FORTINET INC

Virtual file honey pots for computing systems behavior-based protection against ransomware attacks

Systems and methods for ransomware protection in advanced injection-based attacks. Events from a driver are analyzed to identify a potentially malicious actor. A confidence level is calculated for the potentially malicious actor identification to weigh the probability that the actor is malware or a source of malware. Behavior associated with the potentially malicious actor can be collected, if it is likely that the potentially malicious actor is associated with malware, such as if the confidence level is over a predetermined threshold. Subsequently, one or more virtual honeypots are generated for the suspicious processes and the response to the virtual honeypots is included in anti-ransomware heuristic analysis.
Owner:ACRONIS INT

System and method for synthetic intrusion data generation and remediation via machine learning

Systems, computer program products, and methods are described herein for synthetic intrusion data generation and remediation via machine learning. The present disclosure includes training a first machine learning model using a plurality of malicious code segments from a code repository, generating, using the first machine learning model, a predetermined number of generated code segments, training a second machine learning model using the plurality of malicious code segments, generating, by using the second machine learning model, at least one generated heuristic mitigation resource for the generated code segments, analyzing, via a static heuristics analysis, stored code on an endpoint device, and applying the at least one generated heuristic mitigation resource upon a first condition wherein the static heuristics analysis identifies a malicious activity.
Owner:BANK OF AMERICA CORP

Heuristic-based robotic grasps

In some cases, images and depth maps can define bins with objects in random configurations. It is recognized herein that current approaches to training deep neural networks to perform grasp computations lack capabilities and efficiencies, such that the resulting grasp computations and grasps can be imprecise or cumbersome, among other shortcomings. Synthetic depth images can be labeled with grasp annotations that are generated based on heuristic-based analyses, so as to define annotated synthetic datasets. The annotated synthetic datasets can be used to train neural networks to determine the best grasp locations for different objects arranged in a variety of positions with respect to each other.
Owner:SIEMENS AG

Passive vulnerability risk detection system based on traffic fingerprints

The invention belongs to the technical field of network security vulnerability detection, and discloses a passive vulnerability risk detection system based on a traffic fingerprint, which can capture asset communication abnormity in real time through combination of a three-dimensional asset fingerprint and an LSTM model, and then is linked with MITREATTamp; unknown attacks missed by traditional static matching can be identified without depending on frequent manual updating of rules; for example, for protocol variant or version fuzzy vulnerabilities, the dynamic weight model can automatically adjust the matching priority, the vulnerabilities related to core services cannot be missed due to rule lagging, and the conversion from passive rule identification to active rule identification is realized; by collecting encrypted traffic metadata, such as TLS handshake parameters and JA3 fingerprints, and marking non-standard encryption behaviors through heuristic analysis, suspicious traffic can be positioned without decryption; and meanwhile, through the low interference characteristic of the fault bypass switch, the original service flow is normally transmitted in the acquisition process, and the service delay is not influenced by analyzing the encrypted flow.
Owner:BEIJING LANGU TECHNOLOGY CO LTD

Systems and methods for detecting maliciousness of network communications through deployment of artificial intelligence techniques

A computerized method is disclosed including obtaining an electronic message, performing a cyberthreat detection process thereon, which includes a first sub-analysis of the body and subject line information of deploying a probabilistic generative model resulting in determination of a likelihood that the electronic message is directed to one of a predefined set of topics, and when the likelihood that the electronic message is directed to one of the predefined set of topics meets or exceeds a first threshold, deploying one or more artificial intelligence models to determine or classify a semantics of the email body or subject, and a second sub-analysis of the header information of performing a heuristic analysis thereof, and performing a determination operation by either a relationship compiler resulting in a determination as to whether the electronic message is malicious or benign, and generating a display that provides the maliciousness determination.
Owner:INCEPTIONCYBER AI INC

Virtual file honey pots for computing systems behavior-based protection against ransomware attacks

Systems and methods for ransomware protection in advanced injection-based attacks. Events from a driver are analyzed to identify a potentially malicious actor. A confidence level is calculated for the potentially malicious actor identification to weigh the probability that the actor is malware or a source of malware. Behavior associated with the potentially malicious actor can be collected, if it is likely that the potentially malicious actor is associated with malware, such as if the confidence level is over a predetermined threshold. Subsequently, one or more virtual honeypots are generated for the suspicious processes and the response to the virtual honeypots is included in anti-ransomware heuristic analysis.
Owner:ACRONIS INT

Inline detection of dictionary DGA domain names with reduced cost and latency

A service includes a trained model comprising a classifier that predicts whether domain names are dictionary DGA generated. Using passive DNS data and / or a heuristic analysis based on natural language processing of the domain name, the service filters domain names that are not candidate (i.e., potential) dictionary DGA domain names out of the detection pipeline. There domain names are thus classified without being fed into the model for more computationally expensive processing. Domain names that are not filtered out are queued for input into an instance of the model and classification by the model, with the queued domain names processed in small batches and load balanced across model instances. Predicted domain name classes output by the model are cached for subsequent cache reads to avoid multiple runs of the model for one domain name.
Owner:PALO ALTO NETWORKS INC

Flow network intermediate representation for optimization problems

A heuristic that solves an optimization problem is analyzed to determine how and why it underperforms a benchmark solution. A novel intermediate representation (IR) is used to construct a network flow graph that models the optimization problem. Solutions to the optimization problem are defined programmatically with reference to the network flow graph. A compiler translates the programmatic definitions of the heuristic and a benchmark solution to a low-level model of constraints and objectives. A heuristic analyzer iteratively analyzes the constraints and objectives to identify inputs that cause the heuristic to yield inefficient results relative to the benchmark. Properties of inputs and properties of the heuristic that cause the heuristic to underperform are identified, and an explanation of when, how, and why the heuristic underperforms is generated.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Inline detection of dictionary DGA domain names with reduced cost and latency

A service includes a trained model comprising a classifier that predicts whether domain names are dictionary DGA generated. Using passive DNS data and / or a heuristic analysis based on natural language processing of the domain name, the service filters domain names that are not candidate (i.e., potential) dictionary DGA domain names out of the detection pipeline. There domain names are thus classified without being fed into the model for more computationally expensive processing. Domain names that are not filtered out are queued for input into an instance of the model and classification by the model, with the queued domain names processed in small batches and load balanced across model instances. Predicted domain name classes output by the model are cached for subsequent cache reads to avoid multiple runs of the model for one domain name.
Owner:PALO ALTO NETWORKS INC

Inline malicious XML detection with combined heuristic analysis and deep learning

A traffic filter executing as part of a cybersecurity appliance detects network traffic that includes XML files. The traffic filter forwards the XML file identified in the network traffic to a malicious XML detector for further analysis. The detector heuristically analyzes the XML header and analyzes the XML document with a combination of heuristic analysis and deep learning. The detector analyzes the XML header with heuristics-based rules. The detector also analyzes the XML document using additional heuristics-based rules and / or with a model trained to predict whether XML documents are malicious. If the results of the analyses yields a verdict that the XML document is malicious, the detector returns a verdict indicating that the XML file is malicious to the traffic filter for the malicious XML file to be blocked accordingly.
Owner:PALO ALTO NETWORKS INC

Systems and methods for determining maliciousness of network communications through deployment of artificial intelligence techniques and header information analysis

A computerized method is disclosed analyzing maliciousness of an electronic message including operations of analyzing header information of the electronic message including a heuristic analysis and a name entity recognition analysis, determining a probability that the electronic message is directed to one of a predefined set of topics by deploying a probabilistic generative model, generating a prompt for a language model based on a first topic, providing the prompt to the language model and generating a semantic result based on a response thereto. Additional operations include classifying the electronic message as malicious or benign based on a semantic result based on the response to the prompt from the language model, and semantics of the header information, and generating a graphical user interface display that indicates whether the electronic message has been classified as malicious or benign.
Owner:INCEPTIONCYBER AI INC

Ransomware protection in advanced injection-based attacks

Systems and methods for ransomware protection in advanced injection-based attacks. The call stack(s) of injected threads are analyzed and a preliminary verdict of benign or malicious can be determined. Additional sensors collect data to associate injected threads with other activities or actors to further estimate the injected thread being benign or malicious. If the threat level is high enough, such as over a given threshold, the preliminary verdict can be determined to be malicious. Subsequently, one or more virtual honeypots are generated for the suspicious threads and the injected thread's response to the virtual honeypots included in anti-ransomware heuristic analysis.
Owner:ACRONIS INT

System and method for synthetic intrusion data generation and remediation via machine learning

Systems, computer program products, and methods are described herein for synthetic intrusion data generation and remediation via machine learning. The present disclosure includes training a first machine learning model using a plurality of malicious code segments from a code repository, generating, using the first machine learning model, a predetermined number of generated code segments, training a second machine learning model using the plurality of malicious code segments, generating, by using the second machine learning model, at least one generated heuristic mitigation resource for the generated code segments, analyzing, via a static heuristics analysis, stored code on an endpoint device, and applying the at least one generated heuristic mitigation resource upon a first condition wherein the static heuristics analysis identifies a malicious activity.
Owner:BANK OF AMERICA CORP

Systems and methods for detecting maliciousness of network communications through deployment of artificial intelligence techniques

A computerized method is disclosed including obtaining an electronic message, performing a cyberthreat detection process thereon, which includes a first sub-analysis of the body and subject line information of deploying a probabilistic generative model resulting in determination of a likelihood that the electronic message is directed to one of a predefined set of topics, and when the likelihood that the electronic message is directed to one of the predefined set of topics meets or exceeds a first threshold, deploying one or more artificial intelligence models to determine or classify a semantics of the email body or subject, and a second sub-analysis of the header information of performing a heuristic analysis thereof, and performing a determination operation by either a relationship compiler resulting in a determination as to whether the electronic message is malicious or benign, and generating a display that provides the maliciousness determination.
Owner:INCEPTIONCYBER AI INC

Detecting ransomware

There is disclosed in one example a ransomware mitigation engine, including: a processor; a convolutional neural network configured to provide file type identification (FTI) services including: identifying an access operation of a file as a write to the file or newly creating the file; computing a byte correlation factor for the file; classifying the file as belonging to a file type; determining with a screening confidence that the file type is correct for the file; determining that the screening confidence is below a screening confidence threshold; and circuitry and logic to provide heuristic analysis including: receiving notification that the confidence is below the confidence threshold; performing a statistical analysis of the file to determine a difference between an expected value and a computed value; determining from the difference, with a detection confidence, that the file has been compromised; and identifying the file as having been compromised by a ransomware attack.
Owner:MCAFEE LLC