×

Automated forensics of computer systems using behavioral intelligence

  • US 9,979,739 B2
  • Filed: 01/15/2014
  • Issued: 05/22/2018
  • Est. Priority Date: 01/16/2013
  • Status: Active Grant
First Claim
Patent Images

1. A method for computer system forensics, comprising:

  • collecting behavioral intelligence from sensors monitoring traffic passing through network switching elements in a computer network;

    based on the collected behavioral intelligence, identifying a plurality of host computers on the network that exhibited an anomalous behavior;

    assembling a plurality of respective positive images of the identified plurality of host computers using image information collected with regard to a configuration of software components running on the host computers, by respective monitoring programs running on the host computers;

    assembling a plurality of negative images using image information collected with respect to a plurality of host computers not currently exhibiting the anomalous behavior or collected with respect to the at least one host computer prior to the anomalous behavior;

    making a comparison between the plurality of positive images and the plurality of negative images using the following criteria;

    an exact match, an approximate match, or a probabilistic match;

    wherein the match is between properties among the assembled positive images; and

    a negative match which is between properties that exist in the assembled negative images and do not exist in the assembled positive images; and

    based on the comparison, extracting from the positive and negative images a feature of the configuration of the software components that distinguishes between the positive and negative images, to serve as a forensic indicator of the anomalous behavior.

View all claims
  • 4 Assignments
Timeline View
Assignment View
    ×
    ×