Patent · US Active

SIEM system and methods for exfiltrating event data

US11196759B2 · kind B2 · utility

0Cited by
3References
20Claims
0Family size

Assignee

Inventors

Key dates

Filing dateJun 26, 2019
Grant dateDec 7, 2021
Priority date
Expiry dateMar 2, 2040

Classification

  • Technology area (CPC G)Physics
  • CPC primaryG05B19/0428
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

Embodiments provide for a security information and event management (SIEM) system utilizing distributed agents that can intelligently traverse a network to exfiltrate data in an efficient and secure manner. A plurality of agent devices can dynamically learn behavioral patterns and/or service capabilities of other agent devices in the networking environment, and select optimal routes for exfiltrating event data from within the network. The agent devices can independently, selectively, or collectively pre-process event data for purposes of detecting a suspect event from within the network. When a suspect event is detected, agent devices can select a target device based on the learned service capabilities and networking environment, and communicate the pre-processed event data to the target device. The pre-processed event data is thus traversed through the network along an optimal route until it is exfiltrated from the network and stored on a remote server device for storage and further analysis.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.