SecureWorks Corp.
SYSTEMS AND METHODS OF HIERARCHIAL BEHAVIOR ACTIVITY MODELING AND DETECTION FOR SYSTEMS-LEVEL SECURITY

Last updated:

Abstract:

The present disclosure provides systems and methods for detection of one or more security threats or malicious actions. According to the present disclosure, data can be received from one or more data producers and provided to a behavior processor. The behavior processor extracts, identifies, or detects one or more behaviors from the data based on one or more datum, features, or characteristics included therein, and provides the one or more identified behaviors to a tactic processor. The tactic processor extracts, identifies, or detects one or more tactics based on the one or more identified behaviors, and submits the one or more identified tactics to a tactic classifier to determine whether the one or more identified tactics are indicative of the one or more security threats or malicious actions. Other aspects are also described.

Status:
Application
Type:

Utility

Filling date:

7 May 2019

Issue date:

12 Nov 2020