-
公开(公告)号:US20180176244A1
公开(公告)日:2018-06-21
申请号:US15846780
申请日:2017-12-19
申请人: Threat Stack, Inc.
发明人: Christopher Gervais , Sean T. Reed , Nicholas S. Goodwin , Joseph D. Baker , Samuel Bisbee-vonKaufmann , Nathan D. Cooprider , David G. Hagman , Lucas M. Dubois , Jennifer A. Andre
摘要: A cloud-based operating-system-event and data-access monitoring method includes collecting event information from a monitored cloud-based element. One or more structured event payloads based on the event information is then generated. The structured event payloads that produce one or more validated event collections are then validated. The one or more validated event collections are then serialized and filtered to remove redundant structured event payload data. The filtered validated structured event payloads are then de-serialized to produce a time-sequenced, ordered event stream. The time-sequenced, ordered event stream is de-duplicated to remove duplicate structured event payloads. The time-sequenced ordered event stream is then processed to generate processed information security results.
-
公开(公告)号:US11283822B2
公开(公告)日:2022-03-22
申请号:US17007400
申请日:2020-08-31
申请人: Threat Stack, Inc.
发明人: Christopher Gervais , Sean T. Reed , Nicholas S. Goodwin , Joseph D. Baker , Samuel Bisbee-vonKaufmann , Nathan D. Cooprider , David C. Hagman , Lucas M. Dubois , Jennifer A. Andre
IPC分类号: H04L29/06 , G06F16/174 , G06F21/55 , G06F21/60 , G06F11/30
摘要: A cloud-based operating-system-event and data-access monitoring method includes collecting event information from a monitored cloud-based element. One or more structured event payloads based on the event information is then generated. The structured event payloads that produce one or more validated event collections are then validated. The one or more validated event collections are then serialized and filtered to remove redundant structured event payload data. The filtered validated structured event payloads are then de-serialized to produce a time-sequenced, ordered event stream. The time-sequenced, ordered event stream is de-duplicated to remove duplicate structured event payloads. The time-sequenced ordered event stream is then processed to generate processed information security results.
-
公开(公告)号:US10791134B2
公开(公告)日:2020-09-29
申请号:US15846780
申请日:2017-12-19
申请人: Threat Stack, Inc.
发明人: Christopher Gervais , Sean T. Reed , Nicholas S. Goodwin , Joseph D. Baker , Samuel Bisbee-vonKaufmann , Nathan D. Cooprider , David G. Hagman , Lucas M. Dubois , Jennifer A. Andre
IPC分类号: H04L29/06 , G06F21/55 , G06F16/174 , G06F21/60
摘要: A cloud-based operating-system-event and data-access monitoring method includes collecting event information from a monitored cloud-based element. One or more structured event payloads based on the event information is then generated. The structured event payloads that produce one or more validated event collections are then validated. The one or more validated event collections are then serialized and filtered to remove redundant structured event payload data. The filtered validated structured event payloads are then de-serialized to produce a time-sequenced, ordered event stream. The time-sequenced, ordered event stream is de-duplicated to remove duplicate structured event payloads. The time-sequenced ordered event stream is then processed to generate processed information security results.
-
-