CENTRALIZED EVENT DETECTION

A threat management facility stores a number of entity models that characterize reportable events from one or more entities. A stream of events from compute instances within an enterprise network can then be analyzed using these entity models to detect behavior that is inconsistent or anomalous for...

Full description

Saved in:
Bibliographic Details
Main Authors Thomas, Andrew J, Ray, Kenneth D, Levy, Joseph H, Schiappa, Daniel Salvatore
Format Patent
LanguageEnglish
Published 15.06.2023
Subjects
Online AccessGet full text

Cover

Loading…
More Information
Summary:A threat management facility stores a number of entity models that characterize reportable events from one or more entities. A stream of events from compute instances within an enterprise network can then be analyzed using these entity models to detect behavior that is inconsistent or anomalous for one or more of the entities that are currently active within the enterprise network.
Bibliography:Application Number: US202318096882