Check Point Software Technologies Ltd.
Method and system for identifying uncorrelated suspicious events during an attack

Last updated:

Abstract:

Computerized methods and systems identify events associated with an attack initiated on an endpoint client. A listing of processes executed or created on the endpoint during the attack is obtained. The listing of processes includes a first process and at least one subsequent process executed or created by the first process. The computerized methods and systems analyze for the occurrence of at least one event during a time interval associated with the attack. The computerized methods and systems determine whether the listing of processes includes a process that when executed caused the occurrence of the at least one event. If the listing of processes excludes process that when executed caused the occurrence of the at least one event, the at least one event and the causing process are stored, for example, in a database or memory.

Status:
Grant
Type:

Utility

Filling date:

13 Oct 2016

Issue date:

29 Oct 2019