×

AUTOMATIC ANALYSIS OF SECURITY RELATED INCIDENTS IN COMPUTER NETWORKS

  • US 20130055399A1
  • Filed: 08/29/2011
  • Published: 02/28/2013
  • Est. Priority Date: 08/29/2011
  • Status: Active Grant
First Claim
Patent Images

1. A security server for responding to security-related incidents in a computer network including a plurality of client computers, the security server comprising:

  • an event collection module communicatively coupled to the computer network, an event analysis module operatively coupled to the event collection module, and a solution module operatively coupled to the event analysis module;

    wherein the event collection module is configured to obtain incident-related information that includes event-level information from at least one client computer of the plurality of client computers, the incident-related information being associated with at least a first incident which was detected by that at least one client computer and provided to the event collection module in response to that detection;

    wherein the event analysis module is configured to reconstruct at least one chain of events causally related to the first incident and indicative of a root cause of the first incident based on the incident-related information; and

    wherein the solution module is configured to formulate at least one recommendation for use by the at least one client computer, the at least one recommendation being based on the at least one chain of events, and including corrective/preventive action particularized for responding to the first incident.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×