Invention Grant
- Patent Title: Enterprise network threat detection
-
Application No.: US16896676Application Date: 2020-06-09
-
Publication No.: US11836664B2Publication Date: 2023-12-05
- Inventor: Karl Ackerman , Russell Humphries , Mark Anthony Russo , Andrew J. Thomas
- Applicant: Sophos Limited
- Applicant Address: GB Abingdon
- Assignee: Sophos Limited
- Current Assignee: Sophos Limited
- Current Assignee Address: GB Abingdon
- Agency: Strategic Patents, P.C.
- Main IPC: G06Q10/06
- IPC: G06Q10/06 ; G06Q10/0635 ; H04L9/40 ; G06N5/046 ; G06N20/00 ; G06F17/18 ; G06F21/56 ; G06Q10/0639 ; G06F16/955 ; G06F11/07 ; G06N7/00 ; G06F21/55 ; G06N5/04 ; G06F9/54 ; G06N5/022 ; G06N20/20 ; G06V20/52 ; G06F18/214 ; G06F18/21 ; G06F18/23213 ; G06F18/2413 ; G06N5/01 ; G06Q10/00 ; G06Q30/018 ; G06Q30/0283

Abstract:
In a threat management platform, a number of endpoints log events in an event data recorder. A local agent filters this data and feeds a filtered data stream to a central threat management facility. The central threat management facility can locally or globally tune filtering by local agents based on the current data stream, and can query local event data recorders for additional information where necessary or helpful in threat detection or forensic analysis. The central threat management facility also stores and deploys a number of security tools such as a web-based user interface supported by machine learning models to identify potential threats requiring human intervention and other models to provide human-readable context for evaluating potential threats.
Public/Granted literature
- US20200304528A1 ENTERPRISE NETWORK THREAT DETECTION Public/Granted day:2020-09-24
Information query