-
公开(公告)号:US10102379B1
公开(公告)日:2018-10-16
申请号:US15639860
申请日:2017-06-30
Applicant: SAP SE
Inventor: Hartwig Seifert , Nan Zhang , Harish Mehta , Florian Chrosziel , Hristina Dinkova , Thomas Kunz , Lin Luo , Rita Merkel , Wei-Guo Peng , Eugen Pritzkau , Marco Rodeck
Abstract: Published enterprise threat detection (ETD) security notes are accessed in a computer data store. Applicability of the published ETD security notes are determined for an information technology computing (IT) landscape. A determination is made that a particular applicable ETD security note has not yet been implemented in the IT computing landscape. Aggregated impact of compromise (IoC) and state of compromise (SoC) values associated with the published ETD security note are analyzed and a computing system patching action is performed based on the aggregated IoC and SoC values.
-
公开(公告)号:US20180176234A1
公开(公告)日:2018-06-21
申请号:US15381567
申请日:2016-12-16
Applicant: SAP SE
Inventor: Thomas Kunz , Omar-Alexander Al-Hujaj , Jens Baumgart , Harish Mehta , Florian Chrosziel , Marco Rodeck , Thorsten Menke
CPC classification number: H04L63/1416 , G06F16/27 , H04L63/1425
Abstract: A content replication connector receives control data associated with replication of content data from a source system. Based on the control data, the content replication connector fetches the content data from the source system, converts the content data from a first data format to a second data format, and sends the content data to a content replication server. The content replication server replicates the content data, and a target system fetches the content data from the content replication server.
-
公开(公告)号:US20220006828A1
公开(公告)日:2022-01-06
申请号:US17479850
申请日:2021-09-20
Applicant: SAP SE
Inventor: Harish Mehta , Hartwig Seifert , Thomas Kunz , Anne Jacobi , Marco Rodeck , Florian Kraemer , Bjoern Brencher , Nan Zhang
IPC: H04L29/06
Abstract: A transfer of master data is executed in a backend computing system. The master data includes user data and system data. The transfer of master data includes receiving user data associated with a particular user identifier in the backend computing system, transferring the received user data to an event stream processor, receiving system data associated with a particular log providing computing system in the backend computing system, transferring the received user data to the event stream processor, and executing a transfer of log data associated with logs of computing systems connected to the backend computing system.
-
公开(公告)号:US10673879B2
公开(公告)日:2020-06-02
申请号:US15274569
申请日:2016-09-23
Applicant: SAP SE
Inventor: Florian Chrosziel , Jona Hassforther , Thomas Kunz , Harish Mehta , Rita Merkel , Kathrin Nos , Wei-Guo Peng , Eugen Pritzkau , Marco Rodeck , Hartwig Seifert , Nan Zhang , Thorsten Menke , Hristina Dinkova , Lin Luo
Abstract: An enterprise threat detection (ETD) forensic workspace is established according to a particular timeframe and permitting defining a selection of data types from available log data for an evaluation of events associated with one or more entities. A chart is defined illustrating a graphical distribution of a particular data type in the forensic workspace. A snapshot associated with the chart is generated, the snapshot saving a copy of all data necessary to re-create the chart into an associated snapshot object. The snapshot is associated with a snapshot page for containing the snapshot and the snapshot page is saved within the ETD forensic workspace.
-
公开(公告)号:US20190190935A1
公开(公告)日:2019-06-20
申请号:US15847478
申请日:2017-12-19
Applicant: SAP SE
Inventor: Wei-Guo PENG , Lin Luo , Hartwig Seifert , Nan Zhang , Harish Mehta , Florian Chrosziel , Rita Merkel , Eugen Pritzkau , Jona Hassforther , Thorsten Menke , Thomas Kunz , Kathrin Nos , Marco Rodeck
IPC: H04L29/06 , G06F21/55 , G06F3/0482
CPC classification number: H04L63/1425 , G06F3/0482 , G06F21/552
Abstract: One or more entities are selected for which logged Events are to be displayed in an Event Series Chart. One or more filters and a timeframe are selected. Events are fetched from one or more selected log files based on the one or more selected filters and the timeframe. The fetched Events are displayed in an Event Series Chart according to an associated timestamp and identification Event property value associated with each fetched Event.
-
公开(公告)号:US20190007442A1
公开(公告)日:2019-01-03
申请号:US16125256
申请日:2018-09-07
Applicant: SAP SE
Inventor: Harish Mehta , Hartwig Seifert , Thomas Kunz , Anne Jacobi , Marco Rodeck , Florian Kraemer , Bjoern Brencher , Nan Zhang
IPC: H04L29/06
Abstract: A transfer of master data is executed in a backend computing system. The master data includes user data and system data. The transfer of master data includes receiving user data associated with a particular user identifier in the backend computing system, transferring the received user data to an event stream processor, receiving system data associated with a particular log providing computing system in the backend computing system, transferring the received user data to the event stream processor, and executing a transfer of log data associated with logs of computing systems connected to the backend computing system.
-
公开(公告)号:US20190007435A1
公开(公告)日:2019-01-03
申请号:US15639907
申请日:2017-06-30
Applicant: SAP SE
Inventor: Eugen Pritzkau , Joscha Philipp Bohn , Daniel Kartmann , Wei-Guo Peng , Hristina Dinkova , Lin Luo , Thomas Kunz , Marco Rodeck , Hartwig Seifert , Harish Mehta , Nan Zhang , Rita Merkel , Florian Chrosziel
IPC: H04L29/06
CPC classification number: H04L63/1425 , G06F3/0482 , G06F16/3344 , G06F21/55 , H04L63/1416
Abstract: Search results are received from an initiated free text search of log data from one or more logs, where the free text is performed using search terms entered into a free text search graphical user interface. A set of at least one search result is selected from the search results containing an event desired to be identified in a completed enterprise threat detection (ETD) pattern. A forensic lab application is rendered to complete an ETD pattern. An event filter is added for an event type based on normalized log data to a path. A relative ETD pattern time range is set and an ETD pattern is completed based on the added event filter.
-
公开(公告)号:US11470094B2
公开(公告)日:2022-10-11
申请号:US15381567
申请日:2016-12-16
Applicant: SAP SE
Inventor: Thomas Kunz , Omar-Alexander Al-Hujaj , Jens Baumgart , Harish Mehta , Florian Chrosziel , Marco Rodeck , Thorsten Menke
Abstract: A content replication connector receives control data associated with replication of content data from a source system. Based on the control data, the content replication connector fetches the content data from the source system, converts the content data from a first data format to a second data format, and sends the content data to a content replication server. The content replication server replicates the content data, and a target system fetches the content data from the content replication server.
-
公开(公告)号:US11012465B2
公开(公告)日:2021-05-18
申请号:US16741071
申请日:2020-01-13
Applicant: SAP SE
Inventor: Eugen Pritzkau , Kathrin Nos , Marco Rodeck , Florian Chrosziel , Jona Hassforther , Rita Merkel , Thorsten Menke , Thomas Kunz , Hartwig Seifert , Harish Mehta , Wei-Guo Peng , Lin Luo , Nan Zhang , Hristina Dinkova
Abstract: A computer-implemented method generates a trigger registration for a selected triggering type. The generated trigger registration is stored in a triggering persistency. A received event from an event persistency is analyzed and data associated with the analyzed event is compared with the triggering persistency. Based on the comparison and using a pattern execution framework, an enterprise threat detection (ETD) pattern is processed to perform actions responsive to the received event.
-
公开(公告)号:US10986111B2
公开(公告)日:2021-04-20
申请号:US15847478
申请日:2017-12-19
Applicant: SAP SE
Inventor: Wei-Guo Peng , Lin Luo , Hartwig Seifert , Nan Zhang , Harish Mehta , Florian Chrosziel , Rita Merkel , Eugen Pritzkau , Jona Hassforther , Thorsten Menke , Thomas Kunz , Kathrin Nos , Marco Rodeck
IPC: G06F3/0485 , H04L29/06 , G06F3/0482 , G06F21/55 , G06F3/0484
Abstract: One or more entities are selected for which logged Events are to be displayed in an Event Series Chart. One or more filters and a timeframe are selected. Events are fetched from one or more selected log files based on the one or more selected filters and the timeframe. The fetched Events are displayed in an Event Series Chart according to an associated timestamp and identification Event property value associated with each fetched Event.
-
-
-
-
-
-
-
-
-