首页> 外国专利> FORENSIC QUERY OF LOCAL EVENT STREAMS IN AN ENTERPRISE NETWORK

FORENSIC QUERY OF LOCAL EVENT STREAMS IN AN ENTERPRISE NETWORK

机译:企业网络中局部事件流的法证查询

摘要

Activity on an endpoint is monitored in two stages with a local agent. In a first stage, particular computing objects on the endpoint are selected for tracking. In a second stage, particular types of changes to those objects are selected. By selecting objects and object changes in this manner, a compact data stream of information highly relevant to threat detection can be provided from an endpoint to a central threat management facility. At the same time, a local data recorder creates a local record of a wider range of objects and changes. The system may support forensic activity by facilitating queries to the local data recorder on the endpoint to retrieve more complete records of local activity when the compact data stream does not adequately characterize a particular context.
机译:端点上的活动由本地代理分两个阶段进行监控。在第一阶段,选择端点上的特定计算对象进行跟踪。在第二阶段,选择对那些对象的特定类型的更改。通过以这种方式选择对象和对象更改,可以从端点向中央威胁管理设施提供与威胁检测高度相关的紧凑信息数据流。同时,本地数据记录器会创建一个范围更广的对象和更改的本地记录。当紧凑数据流不能充分表征特定上下文时,系统可以通过促进对端点上的本地数据记录器的查询来支持取证活动,以检索本地活动的更完整记录。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号