Invention Grant
- Patent Title: Discriminant power based threat detection
-
Application No.: US16194536Application Date: 2018-11-19
-
Publication No.: US10922407B2Publication Date: 2021-02-16
- Inventor: Raymund Lin , Charlie Wu , Youngja Park
- Applicant: International Business Machines Corporation
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agency: Cantor Colburn LLP
- Agent Richard Wilhelm
- Main IPC: G06F21/56
- IPC: G06F21/56

Abstract:
Examples of techniques for discriminant power based threat detection are described herein. An aspect includes identifying a plurality of detector names associated with an indicator of compromise, wherein each of the plurality of detector names has a respective associated discriminant power. Another aspect includes determining a plurality of malware families, wherein each malware family of the plurality of malware families is linked to at least one detector name of the plurality of detector names. Another aspect includes, for each malware family of the plurality of malware families, determining a sum of the associated discriminant power of any detector names that are linked to the malware family. Another aspect includes determining that the indicator of compromise belongs to a malware family of the plurality of malware families that has a highest sum.
Public/Granted literature
- US20200159920A1 DISCRIMINANT POWER BASED THREAT DETECTION Public/Granted day:2020-05-21
Information query