Invention Grant
- Patent Title: Context for malware forensics and detection
-
Application No.: US17472464Application Date: 2021-09-10
-
Publication No.: US11949694B2Publication Date: 2024-04-02
- Inventor: Jun Wang , Wei Xu
- Applicant: Palo Alto Networks, Inc.
- Applicant Address: US CA Santa Clara
- Assignee: Palo Alto Networks, Inc.
- Current Assignee: Palo Alto Networks, Inc.
- Current Assignee Address: US CA Santa Clara
- Agency: Van Pelt, Yi & James LLP
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F21/56 ; H04L9/40

Abstract:
A malware profile is received. The malware profile comprises a set of n-tuples of attributes that describe one or more activities associated with executing a copy of a known malicious application that is associated with the malware profile. A set of one or more log entries is analyzed for a set of entries that matches the malware profile. Based at least in part on identifying the set of entries matching the malware profile, a determination is made that a host was compromised. In response to determining that the host has been compromised, a remedial action is taken with respect to the host.
Public/Granted literature
- US20210409431A1 CONTEXT FOR MALWARE FORENSICS AND DETECTION Public/Granted day:2021-12-30
Information query