×

Adaptive parsing and normalizing of logs at MSSP

  • US 10,599,668 B2
  • Filed: 10/31/2017
  • Issued: 03/24/2020
  • Est. Priority Date: 10/31/2017
  • Status: Active Grant
First Claim
Patent Images

1. A security system for a network, comprising:

  • an event management center including at least one processor configured to;

    receive security logs including security log data from a plurality of monitored devices;

    determine whether one or more parsing scripts or rules are available to parse or normalize the security log data in the received security logs; and

    if one or more parsing scripts or rules are available;

    apply the one or more parsing scripts or rules to the security log data; and

    normalize the security log data and organize the normalized securing log data into a structured format; and

    if one or more parsing scripts or rules are not available, provide the security data to one or more engines for parsing or normalization thereof, wherein the one or more engines are stored in a memory of or accessible by the at least one processor, and at least one of the engines is configured to;

    receive one or more security logs that comprise the security log data in an unrecognized format or include the security log data that is at least partially unpayable by the one or more parsing scripts or rules accessible by the at least one processor;

    identify one or more attributes of the security log data;

    determine a probability that the one or more identified attributes represent one or more recognized security log entities; and

    if the determined probability meets or exceeds a predetermined threshold probability, isolate and/or tag recognized security log entities and organize isolated and/or tagged recognized security log entities into a structured format to generate normalized security logs;

    wherein the normalized security logs are reviewable to determine if a security threat has been detected.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×