×

SERVER DRIFT MONITORING

  • US 20170346835A1
  • Filed: 08/21/2017
  • Published: 11/30/2017
  • Est. Priority Date: 12/15/2014
  • Status: Active Grant
First Claim
Patent Images

1. A method comprising:

  • configuring a plurality of servers in a group of similarly configured servers with one or more executables in a known configuration, each one of the plurality of servers configured to provide services across a network to remote clients;

    instrumenting each of the plurality of servers to detect changes in the one or more executables in the plurality of servers, and to periodically or continuously provide updates with information about the changes;

    receiving the changes in the one or more executables at a threat management facility for an enterprise network that includes the plurality of servers;

    detecting a drift in a first one of the plurality of servers, the drift including a deviation of the changes in the one or more executables in the first one of the plurality of servers relative to the changes in the one or more executables in other ones of the plurality of servers, wherein detecting includes detecting by a number of classes of changes each specifying an actor initiating one of the changes; and

    initiating a remedial action when the drift in the first one of the plurality of servers deviates beyond a predetermined threshold, wherein the predetermined threshold is a different threshold for each of the number of classes of changes.

View all claims
  • 4 Assignments
Timeline View
Assignment View
    ×
    ×