Invention Grant
- Patent Title: Malicious enterprise behavior detection tool
-
Application No.: US16917318Application Date: 2020-06-30
-
Publication No.: US11556636B2Publication Date: 2023-01-17
- Inventor: Joshua Charles Neil , Evan John Argyle , Anna Swanson Bertiger , Lior Granit , Yair Tsarfaty , David Natan Kaplan
- Applicant: MICROSOFT TECHNOLOGY LICENSING, LLC
- Applicant Address: US WA Redmond
- Assignee: MICROSOFT TECHNOLOGY LICENSING, LLC
- Current Assignee: MICROSOFT TECHNOLOGY LICENSING, LLC
- Current Assignee Address: US WA Redmond
- Agency: Shook, Hardy & Bacon L.L.P.
- Main IPC: G06F21/55
- IPC: G06F21/55 ; G06F16/951 ; G06F21/57

Abstract:
Embodiments of the present disclosure provide systems, methods, and non-transitory computer storage media for identifying malicious enterprise behaviors within a large enterprise. At a high level, embodiments of the present disclosure identify sub-graphs of behaviors within an enterprise based on probabilistic and deterministic methods. For example, starting with the node or edge having the highest risk score, embodiments of the present disclosure iteratively crawl a list of neighbors associated with the nodes or edges to identify subsets of behaviors within an enterprise that indicate potentially malicious activity based on the risk scores of each connected node and edge. In another example, embodiments select a target node and traverse the connected nodes via edges until a root-cause condition is met. Based on the traversal, a sub-graph is identified indicating a malicious execution path of traversed nodes with associated insights indicating the meaning or activity of the node.
Public/Granted literature
- US20210406365A1 MALICIOUS ENTERPRISE BEHAVIOR DETECTION TOOL Public/Granted day:2021-12-30
Information query