×

Systems and user interfaces for dynamic and interactive investigation based on automatic clustering of related data in various data structures

  • US 10,264,014 B2
  • Filed: 10/30/2015
  • Issued: 04/16/2019
  • Est. Priority Date: 03/15/2013
  • Status: Active Grant
First Claim
Patent Images

1. A computer-implemented method comprising:

  • generating, based on a plurality of captured communications, a filtered collection of captured communications by selecting captured communications that include a user-agent string and removing captured communications with destinations on an approved list of destinations, wherein the approved list of destinations indicate destinations that are unlikely to be related to malware activity;

    determining, based on the filtered collection of captured communications, a first set of captured communications associated with a test time period and a second set of captured communications associated with a reference time period;

    identifying a first captured communication in the first set that is not included among the second set of captured communications, wherein the first captured communication indicates a new user-agent string not previously associated with the reference time period; and

    designating the new user-agent string as a seed; and

    generating a data item cluster based on the seed, wherein generating the data item cluster comprises;

    adding the seed to the data item cluster; and

    adding to the data item cluster one or more user-agent-related data items determined to be associated with the seed, wherein the one or more user-agent-related data items comprises information associated with a computing device.

View all claims
  • 8 Assignments
Timeline View
Assignment View
    ×
    ×