Invention Grant
- Patent Title: Automated classification of exploits based on runtime environmental features
-
Application No.: US15324659Application Date: 2016-02-11
-
Publication No.: US10402563B2Publication Date: 2019-09-03
- Inventor: Mordechai Guri , Michael Gorelik , Ronen Yehoshua
- Applicant: MORPHISEC INFORMATION SECURITY LTD.
- Applicant Address: IL Beer Sheva
- Assignee: MorphiSec Information Security Ltd.
- Current Assignee: MorphiSec Information Security Ltd.
- Current Assignee Address: IL Beer Sheva
- Agency: Fiala & Weaver P.L.L.C.
- International Application: PCT/IB2016/050712 WO 20160211
- International Announcement: WO2017/137804 WO 20170817
- Main IPC: G06F21/56
- IPC: G06F21/56 ; G06F21/50 ; G06F21/54 ; G06F21/55

Abstract:
Various approaches are described herein for the automated classification of exploit(s) based on snapshots of runtime environmental features of a computing process in which the exploit(s) are attempted. The foregoing is achieved with a server and local station(s). Each local station is configured to neutralize operation of malicious code being executed thereon, obtain snapshot(s) indicating the state thereof at the time of the exploitation attempt, and perform a classification process using the snapshot(s). The snapshot(s) are analyzed with respect to a local classification model maintained by the local station to find a classification of the exploit therein. If a classification is found, an informed decision is made as to how to handle the classified exploit. If a classification is not found, the snapshot(s) are provided to the server for classification thereby. The server provides an updated classification model containing a classification for the exploit to the local station(s).
Public/Granted literature
- US20180181752A1 AUTOMATED CLASSIFICATION OF EXPLOITS BASED ON RUNTIME ENVIRONMENTAL FEATURES Public/Granted day:2018-06-28
Information query