Enterprise network threat detection
US11836664B2 · kind B2 · utility
Assignee
Inventors
Key dates
| Filing date | Jun 9, 2020 |
| Grant date | Dec 5, 2023 |
| Priority date | — |
| Expiry date | Dec 31, 2040 |
Classification
- Technology area (CPC G)Physics
- CPC primaryG06Q30/0283
- WIPO fieldComputer technology
- WIPO sectorElectrical engineering
Abstract
In a threat management platform, a number of endpoints log events in an event data recorder. A local agent filters this data and feeds a filtered data stream to a central threat management facility. The central threat management facility can locally or globally tune filtering by local agents based on the current data stream, and can query local event data recorders for additional information where necessary or helpful in threat detection or forensic analysis. The central threat management facility also stores and deploys a number of security tools such as a web-based user interface supported by machine learning models to identify potential threats requiring human intervention and other models to provide human-readable context for evaluating potential threats.
Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.