Enterprise network threat detection

In a threat management platform, a number of endpoints log events in an event data recorder. A local agent filters this data and feeds a filtered data stream to a central threat management facility. The central threat management facility can locally or globally tune filtering by local agents based o...

Full description

Saved in:
Bibliographic Details
Main Authors Ackerman, Karl, Thomas, Andrew J, Russo, Mark Anthony, Humphries, Russell
Format Patent
LanguageEnglish
Published 05.12.2023
Subjects
Online AccessGet full text

Cover

Loading…
More Information
Summary:In a threat management platform, a number of endpoints log events in an event data recorder. A local agent filters this data and feeds a filtered data stream to a central threat management facility. The central threat management facility can locally or globally tune filtering by local agents based on the current data stream, and can query local event data recorders for additional information where necessary or helpful in threat detection or forensic analysis. The central threat management facility also stores and deploys a number of security tools such as a web-based user interface supported by machine learning models to identify potential threats requiring human intervention and other models to provide human-readable context for evaluating potential threats.
Bibliography:Application Number: US202016896676