Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

9 results about "Heuristic analysis" patented technology

Generative artificial intelligence-based multi-stage composite event processing

A data platform monitors a compute environment by performing multi-stage heuristic analysis of event data representing a plurality of events occurring within the environment. The platform utilizes multiple event analyzers, each configured according to a distinct analysis heuristic, to evaluate different subsets of the event data and generate corresponding output signals. A higher-level event analyzer applies a further heuristic to the multiple output signals to generate a composite alert signal, indicating whether the combination of analyzed events collectively represents a security intrusion or other anomalous condition of sufficient severity to warrant alerting. Based on the composite alert signal, the platform performs an alert-based operation, such as generating a user-facing alert, initiating an automated mitigation, or updating a contextual model of system behavior. By combining the analytical outputs of heterogeneous heuristics, the disclosed architecture enhances the accuracy and contextual relevance of automated intrusion detection within complex computing environments.
Owner:FORTINET INC

System and method for synthetic intrusion data generation and remediation via machine learning

ActiveUS20260039674A1Securing communicationHeuristicsEngineering
Systems, computer program products, and methods are described herein for synthetic intrusion data generation and remediation via machine learning. The present disclosure includes training a first machine learning model using a plurality of malicious code segments from a code repository, generating, using the first machine learning model, a predetermined number of generated code segments, training a second machine learning model using the plurality of malicious code segments, generating, by using the second machine learning model, at least one generated heuristic mitigation resource for the generated code segments, analyzing, via a static heuristics analysis, stored code on an endpoint device, and applying the at least one generated heuristic mitigation resource upon a first condition wherein the static heuristics analysis identifies a malicious activity.
Owner:BANK OF AMERICA CORP

Passive vulnerability risk detection system based on traffic fingerprints

The invention belongs to the technical field of network security vulnerability detection, and discloses a passive vulnerability risk detection system based on a traffic fingerprint, which can capture asset communication abnormity in real time through combination of a three-dimensional asset fingerprint and an LSTM model, and then is linked with MITREATTamp; unknown attacks missed by traditional static matching can be identified without depending on frequent manual updating of rules; for example, for protocol variant or version fuzzy vulnerabilities, the dynamic weight model can automatically adjust the matching priority, the vulnerabilities related to core services cannot be missed due to rule lagging, and the conversion from passive rule identification to active rule identification is realized; by collecting encrypted traffic metadata, such as TLS handshake parameters and JA3 fingerprints, and marking non-standard encryption behaviors through heuristic analysis, suspicious traffic can be positioned without decryption; and meanwhile, through the low interference characteristic of the fault bypass switch, the original service flow is normally transmitted in the acquisition process, and the service delay is not influenced by analyzing the encrypted flow.
Owner:BEIJING LANGU TECHNOLOGY CO LTD

Virtual file honey pots for computing systems behavior-based protection against ransomware attacks

Systems and methods for ransomware protection in advanced injection-based attacks. Events from a driver are analyzed to identify a potentially malicious actor. A confidence level is calculated for the potentially malicious actor identification to weigh the probability that the actor is malware or a source of malware. Behavior associated with the potentially malicious actor can be collected, if it is likely that the potentially malicious actor is associated with malware, such as if the confidence level is over a predetermined threshold. Subsequently, one or more virtual honeypots are generated for the suspicious processes and the response to the virtual honeypots is included in anti-ransomware heuristic analysis.
Owner:ACRONIS INT

Inline detection of dictionary DGA domain names with reduced cost and latency

A service includes a trained model comprising a classifier that predicts whether domain names are dictionary DGA generated. Using passive DNS data and / or a heuristic analysis based on natural language processing of the domain name, the service filters domain names that are not candidate (i.e., potential) dictionary DGA domain names out of the detection pipeline. There domain names are thus classified without being fed into the model for more computationally expensive processing. Domain names that are not filtered out are queued for input into an instance of the model and classification by the model, with the queued domain names processed in small batches and load balanced across model instances. Predicted domain name classes output by the model are cached for subsequent cache reads to avoid multiple runs of the model for one domain name.
Owner:PALO ALTO NETWORKS INC

Inline detection of dictionary DGA domain names with reduced cost and latency

A service includes a trained model comprising a classifier that predicts whether domain names are dictionary DGA generated. Using passive DNS data and / or a heuristic analysis based on natural language processing of the domain name, the service filters domain names that are not candidate (i.e., potential) dictionary DGA domain names out of the detection pipeline. There domain names are thus classified without being fed into the model for more computationally expensive processing. Domain names that are not filtered out are queued for input into an instance of the model and classification by the model, with the queued domain names processed in small batches and load balanced across model instances. Predicted domain name classes output by the model are cached for subsequent cache reads to avoid multiple runs of the model for one domain name.
Owner:PALO ALTO NETWORKS INC

Inline malicious XML detection with combined heuristic analysis and deep learning

A traffic filter executing as part of a cybersecurity appliance detects network traffic that includes XML files. The traffic filter forwards the XML file identified in the network traffic to a malicious XML detector for further analysis. The detector heuristically analyzes the XML header and analyzes the XML document with a combination of heuristic analysis and deep learning. The detector analyzes the XML header with heuristics-based rules. The detector also analyzes the XML document using additional heuristics-based rules and / or with a model trained to predict whether XML documents are malicious. If the results of the analyses yields a verdict that the XML document is malicious, the detector returns a verdict indicating that the XML file is malicious to the traffic filter for the malicious XML file to be blocked accordingly.
Owner:PALO ALTO NETWORKS INC

Systems and methods for determining maliciousness of network communications through deployment of artificial intelligence techniques and header information analysis

A computerized method is disclosed analyzing maliciousness of an electronic message including operations of analyzing header information of the electronic message including a heuristic analysis and a name entity recognition analysis, determining a probability that the electronic message is directed to one of a predefined set of topics by deploying a probabilistic generative model, generating a prompt for a language model based on a first topic, providing the prompt to the language model and generating a semantic result based on a response thereto. Additional operations include classifying the electronic message as malicious or benign based on a semantic result based on the response to the prompt from the language model, and semantics of the header information, and generating a graphical user interface display that indicates whether the electronic message has been classified as malicious or benign.
Owner:INCEPTIONCYBER AI INC

System and method for synthetic intrusion data generation and remediation via machine learning

ActiveUS12568104B2Securing communicationHeuristicsEngineering
Systems, computer program products, and methods are described herein for synthetic intrusion data generation and remediation via machine learning. The present disclosure includes training a first machine learning model using a plurality of malicious code segments from a code repository, generating, using the first machine learning model, a predetermined number of generated code segments, training a second machine learning model using the plurality of malicious code segments, generating, by using the second machine learning model, at least one generated heuristic mitigation resource for the generated code segments, analyzing, via a static heuristics analysis, stored code on an endpoint device, and applying the at least one generated heuristic mitigation resource upon a first condition wherein the static heuristics analysis identifies a malicious activity.
Owner:BANK OF AMERICA CORP