Invention Grant
- Patent Title: Computer augmented threat evaluation
-
Application No.: US17188909Application Date: 2021-03-01
-
Publication No.: US11755974B2Publication Date: 2023-09-12
- Inventor: Joshua Daniel Saxe , Andrew J. Thomas , Russell Humphries , Simon Neil Reed , Kenneth D. Ray , Joseph H. Levy
- Applicant: Sophos Limited
- Applicant Address: GB Abingdon
- Assignee: Sophos Limited
- Current Assignee: Sophos Limited
- Current Assignee Address: GB Abingdon
- Agency: Strategic Patents, P.C.
- Main IPC: G06F16/955
- IPC: G06F16/955 ; G06Q10/0635 ; H04L9/40 ; G06N5/046 ; G06N20/00 ; G06F17/18 ; G06F21/56 ; G06Q10/0639 ; G06F11/07 ; G06N7/00 ; G06F21/55 ; G06N5/04 ; G06F9/54 ; G06N5/022 ; G06N20/20 ; G06V20/52 ; G06F18/214 ; G06F18/21 ; G06F18/23213 ; G06F18/2413 ; G06N5/01 ; G06Q30/018 ; G06Q30/0283

Abstract:
An automated system attempts to characterize code as safe or unsafe. For intermediate code samples not placed with sufficient confidence in either category, human-readable analysis is automatically generated to assist a human reviewer in reaching a final disposition. For example, a random forest over human-interpretable features may be created and used to identify suspicious features in a manner that is understandable to, and actionable by, a human reviewer. Similarly, a k-nearest neighbor algorithm may be used to identify similar samples of known safe and unsafe code based on a model for, e.g., a file path, a URL, an executable, and so forth. Similar code may then be displayed (with other information) to a user for evaluation in a user interface. This comparative information can improve the speed and accuracy of human interventions by providing richer context for human review of potential threats.
Public/Granted literature
- US20210211440A1 COMPUTER AUGMENTED THREAT EVALUATION Public/Granted day:2021-07-08
Information query