Invention Grant
- Patent Title: Computer augmented threat evaluation
-
Application No.: US16128984Application Date: 2018-09-12
-
Publication No.: US10938838B2Publication Date: 2021-03-02
- Inventor: Joshua Daniel Saxe , Andrew J. Thomas , Russell Humphries , Simon Neil Reed , Kenneth D. Ray , Joseph H. Levy
- Applicant: Sophos Limited
- Applicant Address: GB Abingdon
- Assignee: Sophos Limited
- Current Assignee: Sophos Limited
- Current Assignee Address: GB Abingdon
- Agency: Strategic Patents, P.C.
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06N5/04 ; G06N20/00 ; G06F17/18 ; G06F21/56 ; G06Q10/06 ; G06F16/955 ; G06F11/07 ; G06K9/62 ; G06N7/00 ; G06F21/55 ; G06F9/54

Abstract:
An automated system attempts to characterize code as safe or unsafe. For intermediate code samples not placed with sufficient confidence in either category, human-readable analysis is automatically generated to assist a human reviewer in reaching a final disposition. For example, a random forest over human-interpretable features may be created and used to identify suspicious features in a manner that is understandable to, and actionable by, a human reviewer. Similarly, a k-nearest neighbor algorithm may be used to identify similar samples of known safe and unsafe code based on a model for, e.g., a file path, a URL, an executable, and so forth. Similar code may then be displayed (with other information) to a user for evaluation in a user interface. This comparative information can improve the speed and accuracy of human interventions by providing richer context for human review of potential threats.
Public/Granted literature
- US20200074078A1 COMPUTER AUGMENTED THREAT EVALUATION Public/Granted day:2020-03-05
Information query