×

System and method thereof for identifying and responding to security incidents based on preemptive forensics

  • US 10,270,805 B2
  • Filed: 12/12/2017
  • Issued: 04/23/2019
  • Est. Priority Date: 11/19/2014
  • Status: Active Grant
First Claim
Patent Images

1. A computerized method of managing data security comprising:

  • continuously collecting forensic data related to a plurality of network-connected user devices by a mine component comprising a plurality of agents installed on the plurality of user devices and a main component installed on the computer, which communicates with the plurality of agents, wherein the forensic data comprises at least an event log indicating activities and events that occurred in the respective client;

    determining, by the computer, at least one normal behavior pattern associated with at least one of the plurality of user devices based on the collected forensic data;

    identifying, by the computer, at least one abnormal behavior in the forensic data based on the determined at least one normal behavior pattern wherein the identified abnormal behavior is a suspicious event;

    in response to the identifying of the at least one abnormal behavior, by the computer, outputting a security incident notification, wherein, the security incident comprises contextual data associated with the security incident;

    in response to the suspicious event, determining if a security incident has occurred based on a pre-stored criteria and the forensics data;

    in response to the determining that the security incident occurred, outputting a graphical user interface showing at least two attributes of the security incident,in response to the determined that the security incident has not occurred, outputting a notification indicating that the security incident has not been identified, andgenerating, by the computer, a real-time damage assessment respective of the security incident based on the forensic data.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×