-
1.
公开(公告)号:US11907370B2
公开(公告)日:2024-02-20
申请号:US17019166
申请日:2020-09-11
Applicant: CrowdStrike, Inc.
Inventor: David F. Diehl , Daniel W. Brown , Aaron Javan Marks , Kirby J. Koster , Daniel T. Martin
CPC classification number: G06F21/566 , G06F21/552 , H04L63/14 , H04L63/1416 , G06N20/00
Abstract: A security agent implemented on a monitored computing device is described herein. The security agent has access to parametric behavioral pattern definitions that, in combination with canonical patterns of behavior, configure the security agent to match observed behavior with known computing behavior that is benign or malignant. This arrangement of the definitions and the pattern of behavior allow the security agent's behavior to be updated by a remote security service without updating a configuration of the security agent. The remote security service can create, modify, and disseminate these definitions and patterns of behavior, giving the security agent real-time ability to respond to new behaviors exhibited by the monitored computing device.