Patent · US Active

Method and apparatus for providing forensic visibility into systems and networks

US9578045B2 · kind B2 · utility

121Cited by
0References
19Claims
0Family size

Assignee

Inventors

Key dates

Filing dateMay 5, 2014
Grant dateFeb 21, 2017
Priority date
Expiry dateMay 5, 2034

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L63/1425
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

Methods and systems for providing forensic visibility into systems and networks are provided. More particularly, a sensor agent may receive events defining an action of a first object acting on a target. The object, the event, and the target are then correlated to at least one originating object such that an audit trail for each individual event is created. A global perspective indicating an age, popularity, a determination as to whether the object may be malware, and IP/URL information associated with the event may then be applied to at least one of the object, the event, the target, and the originating object. A priority may then be determined and assigned to the event based on at least the global perspective. An event line containing event information is then transmitted to an end recipient where the information may be heuristically displayed.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.