Invention Grant
- Patent Title: Method for threat control in a computer network security system
-
Application No.: US16452748Application Date: 2019-06-26
-
Publication No.: US11265335B2Publication Date: 2022-03-01
- Inventor: Jarno Niemela
- Applicant: F-Secure Corporation
- Applicant Address: FI Helsinki
- Assignee: F-Secure Corporation
- Current Assignee: F-Secure Corporation
- Current Assignee Address: FI Helsinki
- Agency: Harrington & Smith
- Priority: GB1810705 20180629
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06N20/00

Abstract:
A method comprising: monitoring events collected from a plurality of network nodes; detecting a first suspicious event among the monitored events by a detection mechanism; monitoring the behaviour of the first suspicious event and any related events; in case the monitored first suspicious event and/or a related event is detected to perform an activity triggering an IOC (indicator of compromise, generating a new IOC; monitoring new events when the activity ends; comparing the behaviour of the new events with the behaviour of the generated IOC; in case a matching behaviour is found, merging the new event with the first suspicious event and/or related events related to the generated IOC; and generating a security related decision on the basis of the IOC.
Public/Granted literature
- US20200007560A1 Method for Threat Control in a Computer Network Security System Public/Granted day:2020-01-02
Information query