会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 50. 发明申请
    • MULTI-HOST THREAT TRACKING
    • 多主机威胁追踪
    • WO2017160770A1
    • 2017-09-21
    • PCT/US2017/022181
    • 2017-03-13
    • CARBON BLACK, INC.
    • KRAEMER, Jeffrey AlbinGOPALAN, Ranganathan
    • H04L29/06
    • A system and method for tracking data security threats within an organization is proposed. A threat aggregator process executing on an analysis computer system within the organization receives events indicating possible threats observed by and sent from different user devices and aggregates related events into threats. This enables the threats to be analyzed and acted upon at a level of the organization (e.g., across user devices) rather than at the level of the individual user devices. An endpoint telemetry system analyzes threats sent from the aggregator and provides security policies for responding to the threats. In examples, the system can identify attacks of related threats and act upon the related threats of the attack collectively, and can characterize false positive threats sent from multiple user devices as a single extraneous threat. This has advantages over the per¬ user device focus for responding to threats provided by current systems and methods.
    • 提出了用于跟踪组织内的数据安全威胁的系统和方法。 在组织内的分析计算机系统上执行的威胁聚合器进程接收指示由不同用户设备观察并从不同用户设备发送的可能威胁的事件,并将相关事件聚集成威胁。 这使得可以在组织级别(例如跨用户设备)而不是在各个用户设备的级别上分析和采取威胁。 端点遥测系统分析聚合器发送的威胁,并提供安全策略来响应威胁。 在示例中,系统可以识别相关威胁的攻击并集体地对攻击的相关威胁进行操作,并且可以将来自多个用户设备的误报威胁表征为单个无关威胁。 这比每一个都有优势。 用户设备专注于响应当前系统和方法提供的威胁。