Computer security threat data collection and aggregation with user privacy protection
First Claim
1. A system for collecting computer security threat data, the system comprising:
- a first computer in a first computer network, the first computer detects a first computer security threat event and generates first computer security threat data for the first computer security threat event, the first computer security threat data comprising first user identifiable data that can be used to identify a first user in the first computer network, the first computer encrypts the first user identifiable data prior to sending the first computer security threat data to a protection server;
a second computer in a second computer network separate from the first computer network, the second computer detects a second computer security threat event and generates second computer security threat data for the second computer security threat event, the second computer security threat data comprising second user identifiable data that can be used to identify a second user in the second computer network, the second computer encrypts the second user identifiable data prior to sending the second computer security threat data to a protection server; and
the protection server computer receives and aggregates the first and second computer security threat data to identify a common computer security threat in both the first and second computer networks, the protection server computer not belonging to either the first or second computer network and cannot decrypt the encrypted first user identifiable data and the second user identifiable data.
1 Assignment
0 Petitions
Accused Products
Abstract
An endpoint computer in an enterprise network is configured to detect computer security threat events, such as presence of a computer virus. Upon detection of a threat event, the endpoint computer generates computer security threat data for the threat event. The threat data may include user identifiable data that can be used to identify a user in the enterprise network. The endpoint computer encrypts the user identifiable data prior to sending the threat data to a smart protection network or to an enterprise server where threat data from various enterprise networks are collected for analysis. The endpoint computer may also encrypt an identifier for the threat data and provide the encrypted identifier to the smart protection network and to an enterprise server in the enterprise network. The enterprise server may use the encrypted identifier to retrieve the threat data from the smart protection network to generate user-specific reports.
155 Citations
7 Claims
-
1. A system for collecting computer security threat data, the system comprising:
-
a first computer in a first computer network, the first computer detects a first computer security threat event and generates first computer security threat data for the first computer security threat event, the first computer security threat data comprising first user identifiable data that can be used to identify a first user in the first computer network, the first computer encrypts the first user identifiable data prior to sending the first computer security threat data to a protection server; a second computer in a second computer network separate from the first computer network, the second computer detects a second computer security threat event and generates second computer security threat data for the second computer security threat event, the second computer security threat data comprising second user identifiable data that can be used to identify a second user in the second computer network, the second computer encrypts the second user identifiable data prior to sending the second computer security threat data to a protection server; and the protection server computer receives and aggregates the first and second computer security threat data to identify a common computer security threat in both the first and second computer networks, the protection server computer not belonging to either the first or second computer network and cannot decrypt the encrypted first user identifiable data and the second user identifiable data. - View Dependent Claims (2, 3, 4, 5, 6, 7)
-
Specification