IP Library › Granted Patent US 12,462,023
Granted Patent B2
US 12,462,023 · App. 18/227,257 · Granted Nov 4, 2025

Threat classification in a streaming system

Inventor: Andrei Cotiga (Bragaddiru, RO)
Assignee: CrowdStrike, Inc.
G06F21/554G06F21/564G06F21/566
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,462,023
App. No.
18/227,257
Granted
Nov 4, 2025
Kind
B2
Abstract

Techniques for identify data usable for generating security recommendations are discussed herein. A system can determine unique identifiers for events associated with a data stream, and determine a frequency of different events occurring in the data stream. The system can generate recommendation data usable for defending the data stream from future malicious events based on a number of similar events occurring over a time period.

Claims (74)

1 . A system comprising:

one or more processors; and

one or more non-transitory computer-readable media storing computer-executable instructions that, when executed, cause the one or more processors to perform operations comprising:

receiving detection data comprising a) event information in a data stream associated with a computing device, and b) metadata associated with an event;

determining an identifier for the event based at least in part on applying a function to the detection data;

receiving a set of identifiers associated with a set of events from a previous time;

determining a value indicating similarity between the identifier and each identifier in the set of identifiers; and

configuring recommendation data for the computing device based at least in part on the value, the recommendation data including information indicating a portion of the data stream to protect from a future malicious event.

2 . The system of claim 1 , wherein determining the identifier comprises applying a hash function to the detection data to output a hash value that identifies the event relative to another event.

3 . The system of claim 1 , the operations further comprising:

comparing the value to a similarity threshold; and

transmitting the recommendation data to the computing device based at least in part on the comparing.

4 . The system of claim 1 , the identifier represents a first hash value and the set of identifiers represents a second hash value and a third hash value, and the operations further comprising:

comparing the first hash value with the second hash value and the third hash value; and

determining, based at least in part on the comparing, first similarity between the first hash value and the second hash value and second similarity between the first hash value and the third hash value;

wherein determining the value is based at least in part on the first similarity and the second similarity.

5 . The system of claim 4 , the operations further comprising:

determining that the first similarity or the second similarity meets or exceeds a similarity threshold;

wherein determining the value is further based at least in part on the first similarity or the second similarity meeting or exceeding the similarity threshold.

6 . The system of claim 1 , wherein:

the detection data identifies a malicious process or thread in the event,

the identifier represents a set of concatenated attributes,

the value indicates a number of times the identifier is included in the set of identifiers, and

the metadata comprises one or more of: an operating system identifier of the computing device, a type of object changed, an operation type, an object path, a filesystem path, a registry path, a new object path, a process name, a creation time of the event, or a user identifier.

7 . One or more non-transitory computer-readable media storing instructions executable by one or more processors, wherein the instructions, when executed, cause the one or more processors to perform operations comprising:

receiving first data comprising a) event information in a data stream associated with a computing device, and b) metadata associated with an event;

determining an identifier for the event based at least in part on applying a function to the first data;

receiving a set of identifiers associated with a set of events from a previous time;

determining a value indicating similarity between the identifier and each identifier in the set of identifiers; and

configuring second data for the computing device based at least in part on the value, the second data including information indicating a portion of the data stream to protect from a future malicious event.

8 . The one or more non-transitory computer-readable media of claim 7 , wherein determining the identifier comprises applying a hash function to the first data to output a hash value that identifies the event relative to another event.

9 . The one or more non-transitory computer-readable media of claim 7 , the operations further comprising:

performing File Integrity Monitoring to monitor an entity for a malicious event; and

determining the first data based at least in part on a result of performing the File Integrity Monitoring.

10 . The one or more non-transitory computer-readable media of claim 7 , the identifier represents a first hash value and the set of identifiers represents a second hash value and a third hash value, and the operations further comprising:

comparing the first hash value with the second hash value and the third hash value; and

determining, based at least in part on the comparing, first similarity between the first hash value and the second hash value and second similarity between the first hash value and the third hash value;

wherein determining the value is based at least in part on the first similarity and the second similarity.

11 . The one or more non-transitory computer-readable media of claim 10 , the operations further comprising:

determining that the first similarity or the second similarity meets or exceeds a similarity threshold;

wherein determining the value is further based at least in part on the first similarity or the second similarity meeting or exceeding the similarity threshold.

12 . The one or more non-transitory computer-readable media of claim 7 , wherein:

the first data identifies a malicious process or thread in the event,

the identifier represents a set of concatenated attributes,

the value indicates a number of times the identifier is included in the set of identifiers, and

the metadata comprises one or more of: an operating system identifier of the computing device, a type of object changed, an operation type, an object path, a filesystem path, a registry path, a new object path, a process name, a creation time of the event, or a user identifier.

13 . The one or more non-transitory computer-readable media of claim 7 , the operations further comprising:

comparing a first attribute of the identifier with multiple attributes associated with the set of identifiers; and

determining, based at least in part on the comparing, similarity between the identifier and one or more identifiers in the set of identifiers;

wherein determining the value is based at least in part on the similarity.

14 . The one or more non-transitory computer-readable media of claim 7 , the operations further comprising:

determining a number of previous identifiers similar to the identifier within a threshold value,

wherein configuring the second data is based at least in part on the number of previous identifiers similar to the identifier within the threshold value.

15 . The one or more non-transitory computer-readable media of claim 7 , the operations further comprising:

determining a first weight for a first attribute of the first data and a second weight for a second attribute;

wherein determining the identifier for the event is further based at least in part on applying the function to the first weight for the first attribute and the second weight for the second attribute.

16 . The one or more non-transitory computer-readable media of claim 7 , the operations further comprising:

receiving a message from the computing device requesting recommendation data for protecting the data stream from the future malicious event; and

accessing, based at least in part on receiving the message, a profile associated with the computing device from a database,

wherein configuring the second data is based at least in part on accessing the profile.

17 . A computer-implemented method comprising:

receiving first data comprising a) event information in a data stream associated with a computing device, and b) metadata associated with an event;

determining an identifier for the event based at least in part on applying a function to the first data;

receiving a set of identifiers associated with a set of events from a previous time;

determining a value indicating similarity between the identifier and each identifier in the set of identifiers; and

configuring second data for the computing device based at least in part on the value, the second data including information indicating a portion of the data stream to protect from a future malicious event.

18 . The computer-implemented method of claim 17 , wherein determining the identifier comprises applying a hash function to the first data to output a hash value that identifies the event relative to another event.

19 . The computer-implemented method of claim 17 , further comprising:

comparing the value to a similarity threshold; and

transmitting the second data to the computing device based at least in part on the comparing.

20 . The computer-implemented method of claim 17 , wherein the identifier represents a first hash value and the set of identifiers represents a second hash value and a third hash value, and further comprising:

comparing the first hash value with the second hash value and the third hash value; and

determining, based at least in part on the comparing, first similarity between the first hash value and the second hash value and second similarity between the first hash value and the third hash value;

wherein determining the value is based at least in part on the first similarity and the second similarity.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 27, 2023
From: COTIGA, ANDREI
To: CROWDSTRIKE, INC.
Reel/Frame 064410/0934 →
Continuity (1)
Related Publication 20250036756A1 · Jan 30, 2025
References Cited (7)
US 8060747B1 · Leonard · 2011 [cited by examiner]
US 20210224390A1 · Kovác · 2021 [cited by examiner]
US 20240289475A1 · Vedovati · 2024 [cited by examiner]
WO WO2016135729A1 · 2016 [cited by examiner]
WO WO2017049045A1 · 2017 [cited by examiner]
WO WO2017131645A1 · 2017 [cited by examiner]
West, A.G., Mohaisen, A. (2014). Metadata-Driven Threat Classification of Network Endpoints Appearing in Malware. In: Dietrich, S. (eds) Detection of Intrusions and Malware, and Vulnerability Assessment. DIMVA 2014. Lec… [cited by examiner]