Improves threat detection speed and accuracy
Novelty Rating:
5
/5
Technology
|
IT-Security
|
Classification
Detecting anomalous process chains in real time using a multistage classifier.
Imagine your computer starts acting weird, one program quickly opens another, then another, like dominoes falling. This tool watches those domino patterns and says, “Hmm, that’s not normal,” catching cyber threats before they cause damage.
It’s like having a bouncer who doesn’t just check IDs at the door, but watches how someone moves through the club, if they rush from room to room acting shady, they get flagged.
Darktrace developed a multistage classifier to detect rapid, unusual sequences of processes (called process chains) that are commonly seen in cyber-attacks like ransomware. Traditional rule-based systems struggle with such fast-changing threats, but this AI approach analyzes behavior patterns in real time, using both context and a layered evaluation to flag abnormal activity. The classifier identifies patterns indicative of malicious behavior even when the individual actions may seem benign in isolation, reducing false positives and increasing threat detection efficiency.
Timeline:
3–4 months
Cost:
$150,000
Headcount:
4