Invention Grant
- Patent Title: System and method of adding tags for use in detecting computer attacks
-
Application No.: US17098777Application Date: 2020-11-16
-
Publication No.: US11489855B2Publication Date: 2022-11-01
- Inventor: Sergey V. Gordeychik , Konstantin V. Sapronov , Yury G. Parshin , Teymur S. Kheirkhabarov , Sergey V. Soldatov
- Applicant: AO Kaspersky Lab
- Applicant Address: RU Moscow
- Assignee: AO Kaspersky Lab
- Current Assignee: AO Kaspersky Lab
- Current Assignee Address: RU Moscow
- Agency: ArentFox Schiff LLP
- Agent Michael Fainberg
- Priority: RU2017133842 20170929
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L9/40 ; H04L67/306 ; G06F21/50 ; G06F16/27 ; G06F16/951

Abstract:
Disclosed are systems and methods of adding tags for use in detecting computer attacks. In one aspect, the system comprises a computer protection module configured to: receive a security notification, extract an object from the security notification, search for the extracted object in a threat database, add a first tag corresponding to the extracted object in the threat database only when the extracted object is found in the threat database, search for signs of suspicious activity in a database of suspicious activities based on the received security notification and the added first tag, and when at least one sign of suspicious activity is found, extract a second tag from the database of suspicious activities and add the second tag to an object database, wherein the object database is used for identifying signature of targeted attacks based on security notifications, objects, first tags and second tags.
Public/Granted literature
- US20210067529A1 SYSTEM AND METHOD OF ADDING TAGS FOR USE IN DETECTING COMPUTER ATTACKS Public/Granted day:2021-03-04
Information query