Mandiant, Inc.
System and method for detecting malicious scripts through natural language processing modeling
Last updated:
Abstract:
A method for detecting a cyberattack on a network device is described. The method features receiving script text and performing a normalization operation on the script text to produce a normalized script text. The normalized script text includes a plurality of analytic tokens each being an instance of a sequence of characters grouped together as a useful semantic unit for natural language processing (NLP). Thereafter, a NLP model is applied to the normalized script text to classify a script associated with the script text as malicious or benign. Responsive to the script being classified as malicious, generating an alert message provided to an administrator to identify the malicious script.
Status:
Grant
Type:
Utility
Filling date:
13 Dec 2018
Issue date:
23 Mar 2021