Palo Alto Networks, Inc.
CONTEXT INFORMED ABNORMAL ENDPOINT BEHAVIOR DETECTION

Last updated:

Abstract:

Adaptive normal profiles are generated at a hierarchical scope corresponding to a set of endpoints and a process. Abnormal endpoint activity is detected by verifying whether event data tracking activity on the set of endpoints conforms to the adaptive normal profiles. False positives are reduced by verifying alarms correspond to normal endpoint activity. Abnormal event data is forwarded to a causality chain identifier that identifies abnormal chains of processes for the abnormal endpoint activity. A trained threat detection model receives abnormal causality chains from the causality chain identifier and indicates a likelihood of corresponding to a malicious attack that indicates abnormal endpoint behavior.

Status:
Application
Type:

Utility

Filling date:

30 Aug 2019

Issue date:

4 Mar 2021