Invention Grant
- Patent Title: Detecting malicious activity on a computer system
-
Application No.: US16202149Application Date: 2018-11-28
-
Publication No.: US11023576B2Publication Date: 2021-06-01
- Inventor: Adam L. Griffin , Christopher D. Scott , Mary E. Rudden , Craig M. Trim , Rhonda L. Childress
- Applicant: INTERNATIONAL BUSINESS MACHINES CORPORATION
- Applicant Address: US NY Armonk
- Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
- Current Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
- Current Assignee Address: US NY Armonk
- Agency: Schmeiser, Olsen & Watts
- Agent William H. Hartwell
- Main IPC: G06F21/55
- IPC: G06F21/55 ; G06N3/08 ; G06N3/04 ; G06F16/901 ; G06F21/56 ; G10L13/08 ; G06F40/20

Abstract:
An approach is provided for detecting a malicious activity on a computer system. First process trees are identified for computer processes that have been executed on a computer system. Each of the first process trees are vectorized. The vectorized first process trees are associated with respective labels. Each label represents an amount by which a respective vectorized process tree reflects the malicious activity. An artificial neural network is trained by using the vectorized first process trees and the associated labels as training input. After the training of the artificial neural network is completed, second process trees for currently executing computer processes are vectorized and provided as input vectors to the artificial neural network. Responsive to the artificial neural network providing an output indicating that a combination of the input vectors indicates the malicious activity, a remedial action is performed.
Public/Granted literature
- US20200167464A1 DETECTING MALICIOUS ACTIVITY ON A COMPUTER SYSTEM Public/Granted day:2020-05-28
Information query