Pattern creation in enterprise threat detection
US10530794B2 · kind B2 · utility
Assignee
Inventors
Key dates
| Filing date | Jun 30, 2017 |
| Grant date | Jan 7, 2020 |
| Priority date | — |
| Expiry date | Oct 24, 2037 |
Classification
- Technology area (CPC G)Physics
- CPC primaryG06F16/3344
- WIPO fieldComputer technology
- WIPO sectorElectrical engineering
Abstract
Search results are received from an initiated free text search of log data from one or more logs, where the free text is performed using search terms entered into a free text search graphical user interface. A set of at least one search result is selected from the search results containing an event desired to be identified in a completed enterprise threat detection (ETD) pattern. A forensic lab application is rendered to complete an ETD pattern. An event filter is added for an event type based on normalized log data to a path. A relative ETD pattern time range is set and an ETD pattern is completed based on the added event filter.
Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.