Patent · US Active

Enterprise network threat detection

US11836664B2 · kind B2 · utility

5Cited by
53References
20Claims
0Family size

Assignee

Inventors

Key dates

Filing dateJun 9, 2020
Grant dateDec 5, 2023
Priority date
Expiry dateDec 31, 2040

Classification

  • Technology area (CPC G)Physics
  • CPC primaryG06Q30/0283
  • WIPO fieldComputer technology
  • WIPO sectorElectrical engineering

Abstract

In a threat management platform, a number of endpoints log events in an event data recorder. A local agent filters this data and feeds a filtered data stream to a central threat management facility. The central threat management facility can locally or globally tune filtering by local agents based on the current data stream, and can query local event data recorders for additional information where necessary or helpful in threat detection or forensic analysis. The central threat management facility also stores and deploys a number of security tools such as a web-based user interface supported by machine learning models to identify potential threats requiring human intervention and other models to provide human-readable context for evaluating potential threats.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.