×

Forensic analysis of computing activity

  • US 9,967,267 B2
  • Filed: 04/15/2016
  • Issued: 05/08/2018
  • Est. Priority Date: 04/15/2016
  • Status: Active Grant
First Claim
Patent Images

1. A computer program product for forensic analysis for computer processes, the computer program product comprising computer executable code embodied in a non-transitory computer readable medium that, when executing on a computing device, performs the steps of:

  • instrumenting a first endpoint to monitor a number of causal relationships among a number of computing objects, and to record a sequence of events causally relating the number of computing objects;

    detecting a security event associated with one of the number of computing objects, wherein detecting the security event includes detecting a potential data leakage;

    in response to detecting the security event, traversing an event graph based on the sequence of events in a reverse order from the one of the number of computing objects associated with the security event to one or more preceding ones of the number of computing objects;

    applying a cause identification rule to the one or more preceding ones of the number of computing objects and the number of causal relationships while traversing the event graph to identify one of the number of computing objects as a cause of the security event; and

    traversing the event graph forward from the cause of the security event to identify one or more other ones of the number of computing objects affected by the cause.

View all claims
  • 4 Assignments
Timeline View
Assignment View
    ×
    ×