Patent · US Active

Snapshot of a forensic investigation for enterprise threat detection

US10673879B2 · kind B2 · utility

0Cited by
60References
20Claims
0Family size

Assignee

Inventors

Key dates

Filing dateSep 23, 2016
Grant dateJun 2, 2020
Priority date
Expiry dateSep 23, 2036

Classification

  • Technology area (CPC G)Physics
  • CPC primaryG06F2201/865
  • WIPO fieldComputer technology
  • WIPO sectorElectrical engineering

Abstract

An enterprise threat detection (ETD) forensic workspace is established according to a particular timeframe and permitting defining a selection of data types from available log data for an evaluation of events associated with one or more entities. A chart is defined illustrating a graphical distribution of a particular data type in the forensic workspace. A snapshot associated with the chart is generated, the snapshot saving a copy of all data necessary to re-create the chart into an associated snapshot object. The snapshot is associated with a snapshot page for containing the snapshot and the snapshot page is saved within the ETD forensic workspace.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.