×

Server drift monitoring

  • US 9,774,613 B2
  • Filed: 12/15/2014
  • Issued: 09/26/2017
  • Est. Priority Date: 12/15/2014
  • Status: Active Grant
First Claim
Patent Images

1. A method comprising:

  • configuring a plurality of servers in a group of similarly configured servers with one or more executables in a known configuration, each one of the plurality of servers configured to provide services across a network to remote clients;

    instrumenting each of the plurality of servers to detect changes in the one or more executables in the plurality of servers, and to periodically or continuously provide updates with information about the changes;

    receiving the changes in the one or more executables at a threat management facility for an enterprise network that includes the plurality of servers;

    filtering the changes to exclude one or more changes by a valid user of one of the plurality of servers;

    detecting a drift in a first one of the plurality of servers, the drift including a deviation of the changes in the one or more executables in the first one of the plurality of servers relative to the changes in the one or more executables in other ones of the plurality of servers; and

    initiating a remedial action when the drift in the first one of the plurality of servers deviates beyond a predetermined threshold.

View all claims
  • 4 Assignments
Timeline View
Assignment View
    ×
    ×