首页> 外国专利> APPARATUS AND METHOD FOR ENDPOINT DETECTION AND RESPONSE TERMINAL BASED ON ARTIFICIAL INTELLIGENCE BEHAVIOR ANALYSIS

APPARATUS AND METHOD FOR ENDPOINT DETECTION AND RESPONSE TERMINAL BASED ON ARTIFICIAL INTELLIGENCE BEHAVIOR ANALYSIS

机译:基于人工智能行为分析的端点检测和响应终端的装置和方法

摘要

The present invention relates to an EDR (Endpoint Detection and Response) technology based on artificial intelligence behavior analysis, in which an EDR device based on artificial intelligence behavior analysis is based on whether the existing file metadata has been changed based on the file metadata on the file to be tracked. A file change detection unit that detects a known anomaly behavior determination unit that determines whether an expected behavior in the traceable file generates a known threat through a first learning network formed through a file metadata population when the change is detected; and When the change is detected, an unknown abnormal behavior detection unit that determines a possibility that an expected behavior in the traceable file generates an unknown threat through a second learning network formed through the SYSCALL graph population is included.
机译:本发明涉及一种基于人工智能行为分析的EDR(端点检测和响应)技术,其中基于人工智能行为分析的EDR设备基于现有文件元数据是否基于文件元数据来改变要跟踪的文件。一种文件改变检测单元,其检测已知的异常行为确定单元,该确定单元确定可追踪文件中的预期行为是否通过在检测到更改时通过文件元数据群体形成的第一学习网络生成已知威胁;当检测到改变时,确定可追踪文件中的预期行为的未知异常行为检测单元通过包括通过Syscall图表群体形成的第二学习网络生成未知威胁。

著录项

  • 公开/公告号KR20210025448A

    专利类型

  • 公开/公告日2021-03-09

    原文格式PDF

  • 申请/专利权人 (주)하몬소프트;

    申请/专利号KR1020190126877

  • 发明设计人 노태상;금동하;이성기;

    申请日2019-10-14

  • 分类号H04L29/06;G06F21/16;

  • 国家 KR

  • 入库时间 2022-08-24 17:35:09

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号