Invention Grant
- Patent Title: Skewness in indicators of compromise
-
Application No.: US16936872Application Date: 2020-07-23
-
Publication No.: US11669615B2Publication Date: 2023-06-06
- Inventor: Niall Fitzgerald , Steven Grobman , Jonathan B. King , Sorcha Bairbre Healy , Gerard Donal Murphy
- Applicant: McAfee, LLC
- Applicant Address: US CA San Jose
- Assignee: McAfee, LLC
- Current Assignee: McAfee, LLC
- Current Assignee Address: US CA San Jose
- Agency: Patent Capital Group
- Main IPC: G06F21/55
- IPC: G06F21/55 ; G06F16/23 ; G06F16/245

Abstract:
There is disclosed in one example a computer-implemented method of detecting a statistically-significant security event and automating a response thereto, including: querying, or causing to be queried, a security intelligence database for sector-wise historical norms for an indicator of compromise (IoC); obtaining sector-wise expected prevalence data for the IoC; receiving observed sector-wise prevalence data for the IoC; computing a first test statistic from a goodness-of-fit test between the observed and expected prevalences; from the observed sector-wise prevalence data, computing a second test statistic from a difference between a highest prevalence and a next-highest prevalence; computing a third test statistic from a difference between the observed prevalence of a highest prevalence sector and the expected prevalence for the highest prevalence sector; selecting a least significant statistic from among the first, second, and third test statistics; and determining from the least significant statistic whether to notify a subscriber.
Public/Granted literature
- US20220027463A1 SKEWNESS IN INDICATORS OF COMPROMISE Public/Granted day:2022-01-27
Information query