Invention Grant
- Patent Title: System and method for detection of anomalous events based on popularity of their convolutions
-
Application No.: US16015654Application Date: 2018-06-22
-
Publication No.: US10558801B2Publication Date: 2020-02-11
- Inventor: Alexey V. Monastyrsky , Mikhail A. Pavlyushchik , Alexey M. Romanenko , Maxim Y. Golovkin
- Applicant: AO Kaspersky Lab
- Applicant Address: RU Moscow
- Assignee: AO KASPERSKY LAB
- Current Assignee: AO KASPERSKY LAB
- Current Assignee Address: RU Moscow
- Agency: Arent Fox LLP
- Agent Michael Fainberg
- Priority: RU2017121120 20170616
- Main IPC: G06F21/00
- IPC: G06F21/00 ; G06F21/55 ; G06F21/54 ; G06F21/56 ; H04L29/06 ; H04W12/12

Abstract:
A system and method is provided for detecting anomalous events occurring in an operating system of a computing device. An exemplary method includes detecting an event that occurs in the operating system of the computing device during execution of a software process. Moreover, the method includes determining a context of the detected event and forming a convolution of the detected event based on selected features of the determined context of the detected event. Further, the method includes determining a popularity of the formed convolution by polling a database containing data relating to a frequency of detected events occurring in client devices in a network, where the detected events of the client devices correspond to the detected event in the computing device. If the determined popularity is below a threshold value, the method determines that the detected event is an anomalous event.
Public/Granted literature
- US20180365416A1 SYSTEM AND METHOD FOR DETECTION OF ANOMALOUS EVENTS BASED ON POPULARITY OF THEIR CONVOLUTIONS Public/Granted day:2018-12-20
Information query