×

EVENT CORRELATION ACROSS HETEROGENEOUS OPERATIONS

  • US 20160301704A1
  • Filed: 08/31/2015
  • Published: 10/13/2016
  • Est. Priority Date: 04/09/2015
  • Status: Active Grant
First Claim
Patent Images

1. A computer-implemented method for correlating domain activity data, the method being executed by one or more processors and comprising:

  • receiving first domain activity data from a first network domain and second domain activity data from a second network domain, the first domain activity data and the second domain activity data including events, alerts, or both from the respective first and second network domains;

    filtering the first domain activity data and the second domain activity data to remove irrelevant activity data, based on a first set of profile data for devices in the first network domain and a second set of profile data for devices in the second network domain;

    aggregating unfiltered first domain activity data and unfiltered second domain activity data;

    correlating aggregated unfiltered first domain activity data and unfiltered second domain activity data to determine an attack path for an attack that occurs across the first network domain and the second network domain, based on attack signatures and profiles associated with previously identified attacks; and

    generating a visualization of the attack path.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×