×

SYSTEM AND METHOD FOR IDENTIFYING INFECTED NETWORKS AND SYSTEMS FROM UNKNOWN ATTACKS

  • US 20150128274A1
  • Filed: 11/03/2014
  • Published: 05/07/2015
  • Est. Priority Date: 11/04/2013
  • Status: Active Grant
First Claim
Patent Images

1. A method of managing security on network infrastructure, comprising:

  • receiving, by a log collector configured on a processor of a network security monitor via a first computer network, a plurality of logs of a second computer network, the plurality of logs indicative of a status of the second computer network determined by a monitoring agent executing on the second computer network;

    generating, by a log indexer configured on the network security monitor, indexed logs from the plurality of logs based on log format;

    retrieving, by the network security monitor, a list of threat indicators from a database based on a schema from a plurality of threat indicators received from a plurality of heterogeneous repositories via the first computer network;

    comparing, by a log correlation engine configured on the network security monitor, the list of threat indicators with the indexed logs; and

    generating, by a report engine configured on the network security monitor, a report based on the comparing to identify a threat.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×