首页> 外国专利> Identifying and responding to security incidents based on preemptive forensics

Identifying and responding to security incidents based on preemptive forensics

机译:基于先发取证的识别和响应安全事件

摘要

A system is connected to a plurality of user devices coupled to an enterprise's network. The system continuously collects, stores, and analyzes forensic data related to the enterprise's network. Based on the analysis, the system is able to determine normal behavior of the network and portions thereof and thereby identify abnormal behaviors within the network. Upon identification of an abnormal behavior, the system determines whether the abnormal behavior relates to a security incident. Upon determining a security incident in any portion of the enterprise's network, the system extracts forensic data respective of the security incident and enables further assessment of the security incident as well as identification of the source of the security incident. The system provides real-time damage assessment respective of the security incident as well as the security incident's attributions.
机译:系统连接到耦合到企业网络的多个用户设备。该系统连续收集,存储和分析与企业网络有关的取证数据。基于该分析,系统能够确定网络及其部分的正常行为,从而识别网络内的异常行为。在识别出异常行为之后,系统确定异常行为是否与安全事件有关。在确定企业网络的任何部分中的安全事件后,系统都会提取与该安全事件相应的取证数据,并能够进一步评估安全事件以及识别安全事件的来源。该系统提供有关安全事件以及安全事件归因的实时损害评估。

著录项

  • 公开/公告号US10652274B2

    专利类型

  • 公开/公告日2020-05-12

    原文格式PDF

  • 申请/专利权人 PALO ALTO NETWORKS INC.;

    申请/专利号US201916391285

  • 发明设计人 GIL BARAK;SHAI MORAG;

    申请日2019-04-22

  • 分类号H04L29/06;

  • 国家 US

  • 入库时间 2022-08-21 11:31:05

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号