CENTRALIZED EVENT DETECTION
A threat management facility stores a number of entity models that characterize reportable events from one or more entities. A stream of events from compute instances within an enterprise network can then be analyzed using these entity models to detect behavior that is inconsistent or anomalous for...
Saved in:
Main Authors | , , , |
---|---|
Format | Patent |
Language | English |
Published |
15.06.2023
|
Subjects | |
Online Access | Get full text |
Cover
Loading…
Summary: | A threat management facility stores a number of entity models that characterize reportable events from one or more entities. A stream of events from compute instances within an enterprise network can then be analyzed using these entity models to detect behavior that is inconsistent or anomalous for one or more of the entities that are currently active within the enterprise network. |
---|---|
Bibliography: | Application Number: US202318096882 |