US 12,079,330 B2
Systems and methods for generating cyberattack predictions and responses
Avi Chesla, Tel Aviv (IL)
Assigned to Cybereason Inc., Boston, MA (US)
Filed by Cybereason Inc., Boston, MA (US)
Filed on Nov. 10, 2021, as Appl. No. 17/454,343.
Claims priority of provisional application 63/112,029, filed on Nov. 10, 2020.
Prior Publication US 2022/0147622 A1, May 12, 2022
Int. Cl. G06F 21/00 (2013.01); G06F 21/55 (2013.01); G06F 21/57 (2013.01); G06N 7/01 (2023.01)
CPC G06F 21/552 (2013.01) [G06F 21/577 (2013.01); G06N 7/01 (2023.01)] 31 Claims
OG exemplary drawing
 
1. A method for generating a predictive response to a cyberattack comprising:
detecting information indicative of a cyberattack on an endpoint;
configuring the information as an input to a directed graph model, wherein the directed graph model comprises a plurality of nodes, each node representing an attack state;
providing the input to the directed graph model;
computing, via the directed graph model, a prediction result, the prediction result comprising one or more predicted nodes from the plurality of nodes and one or more associated probabilities;
classifying the one or more predicted nodes; and
determining, based on the classifying and the prediction result, one or more actions for responding to the cyberattack, the one or more actions comprising:
identifying a plurality of parent nodes of the prediction result; and
at least one of:
setting the one or more actions based on risk levels of the plurality of parent nodes;
if each of the plurality of parent nodes comprise equal risk levels, setting the one or more actions based on a union of actions from the plurality of parent nodes;
setting the one or more actions based on a level of specificity of a parent node;
setting the one or more actions based on probabilities of the plurality of parent nodes; or
if each of the plurality of parent nodes comprise equal probability levels, setting the one or more actions based on a union of actions from the plurality of parent nodes.