Snapshot of a forensic investigation for enterprise threat detection

US10673879B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10673879-B2
Application numberUS-201615274569-A
CountryUS
Kind codeB2
Filing dateSep 23, 2016
Priority dateSep 23, 2016
Publication dateJun 2, 2020
Grant dateJun 2, 2020

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

An enterprise threat detection (ETD) forensic workspace is established according to a particular timeframe and permitting defining a selection of data types from available log data for an evaluation of events associated with one or more entities. A chart is defined illustrating a graphical distribution of a particular data type in the forensic workspace. A snapshot associated with the chart is generated, the snapshot saving a copy of all data necessary to re-create the chart into an associated snapshot object. The snapshot is associated with a snapshot page for containing the snapshot and the snapshot page is saved within the ETD forensic workspace.

First claim

Opening claim text (preview).

What is claimed is: 1. A computer-implemented method, comprising: establishing an enterprise threat detection (ETD) forensic workspace according to a particular timeframe and permitting defining a selection of data types from available log data for an evaluation of events associated with one or more entities, wherein the forensic workspace is configured with functionality to define a filter path containing a series of filters to define a particular sub set of the available log data; defining a chart illustrating a graphical distribution of a particular data type in the forensic workspace; generating a snapshot associated with the chart, the snapshot saving a copy of all data necessary to re-create the chart into an associated snapshot object; associating the snapshot with a snapshot page for containing the snapshot; and saving the snapshot page within the ETD forensic workspace. 2. The computer-implemented method of claim 1 , wherein the chart includes a structured query language (SQL) SELECT statement for selecting events from the available log data and a user interface (UI) permitting interactive functionality with the chart. 3. The computer-implemented method of claim 1 , wherein the snapshot page is a data container that is persisted with a reference to the snapshot stored in a data store. 4. The computer-implemented method of claim 1 , wherein the data saved by the snapshot includes at least one of log data, environmental variables, environmental conditions, chart data, chart UI information, a selected path and filter data or functionality to search for the same configuration of the chart at a different timeframe. 5. The computer-implemented method of claim 1 , comprising configuring the snapshot object as immutable once the snapshot is generated. 6. The computer-implemented method of claim 1 , comprising: loading the saved snapshot page within the ETD forensic workspace; retrieving data from the snapshot object of the snapshot associated with the saved snapshot page; and re-creating the chart on the snapshot page. 7. The computer-implemented method of claim 1 , comprising transferring the saved snapshot page to a third-party for collaborative analysis. 8. A non-transitory, computer-readable medium storing one or more instructions executable by a computer system to perform operations comprising: establishing an enterprise threat detection (ETD) forensic workspace according to a particular timeframe and permitting defining a selection of data types from available log data for an evaluation of events associated with one or more entities, wherein the forensic workspace is configured with functionality to define a filter path containing a series of filters to define a particular sub set of the available log data; defining a chart illustrating a graphical distribution of a particular data type in the forensic workspace; generating a snapshot associated with the chart, the snapshot saving a copy of all data necessary to re-create the chart into an associated snapshot object; associating the snapshot with a snapshot page for containing the snapshot; and saving the snapshot page within the ETD forensic workspace. 9. The non-transitory, computer-readable medium of claim 8 , wherein the chart includes a structured query language (SQL) SELECT statement for selecting events from the available log data and a user interface (UI) permitting interactive functionality with the chart. 10. The non-transitory, computer-readable medium of claim 8 , wherein the snapshot page is a data container that is persisted with a reference to the snapshot stored in a data store. 11. The non-transitory, computer-readable medium of claim 8 , wherein the data saved by the snapshot includes at least one of log data, environmental variables, environmental conditions, chart data, chart UI information, a selected path and filter data or functionality to search for the same configuration of the chart at a different timeframe. 12. The non-transitory, computer-readable medium of claim 8 , comprising one or more instructions to configure the snapshot object as immutable once the snapshot is generated. 13. The non-transitory, computer-readable medium of claim 8 , comprising one or more instructions to: load the saved snapshot page within the ETD forensic workspace; retrieve data from the snapshot object of the snapshot associated with the saved snapshot page; and re-create the chart on the snapshot page. 14. The non-transitory, computer-readable medium of claim 8 , comprising one or more instructions to transfer the saved snapshot page to a third-party for collaborative analysis. 15. A computer-implemented system, comprising: a computer memory; and a hardware processor interoperably coupled with the computer memory and configured to perform operations comprising: establishing an enterprise threat detection (ETD) forensic workspace according to a particular timeframe and permitting defining a selection of data types from available log data for an evaluation of events associated with one or more entities, wherein the forensic workspace is configured with functionality to define a filter path containing a series of filters to define a particular subset of the available log data; defining a chart illustrating a graphical distribution of a particular data type in the forensic workspace; generating a snapshot associated with the chart, the snapshot saving a copy of all data necessary to re-create the chart into an associated snapshot object; associating the snapshot with a snapshot page for containing the snapshot; and saving the snapshot page within the ETD forensic workspace. 16. The computer-implemented system of claim 15 , wherein the chart includes a structured query language (SQL) SELECT statement for selecting events from the available log data and a user interface (UI) permitting interactive functionality with the chart. 17. The computer-implemented system of claim 15 , wherein the snapshot page is a data container that is persisted with a reference to the snapshot stored in a data store. 18. The computer-implemented system of claim 15 , wherein the data saved by the snapshot is configured as immutable once the snapshot is generated and wherein the snapshot includes at least one of log data, environmental variables, environmental conditions, chart data, chart UI information, a selected path and filter data or functionality to search for the same configuration of the chart at a different timeframe. 19. The computer-implemented system of claim 15 , further configured to: load the saved snapshot page within the ETD forensic workspace; retrieve data from the snapshot object of the snapshot associated with the saved snapshot page; and re-create the chart on the snapshot page. 20. The computer-implemented system of claim 15 , further configured to transfer the saved snapshot page to a third-party for collaborative analysis.

Assignees

Inventors

Classifications

  • Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity · CPC title

  • Traffic logging, e.g. anomaly detection · CPC title

  • Visualisation of programs or trace data · CPC title

  • Monitoring · CPC title

  • Risk analysis of enterprise or organisation activities · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10673879B2 cover?
An enterprise threat detection (ETD) forensic workspace is established according to a particular timeframe and permitting defining a selection of data types from available log data for an evaluation of events associated with one or more entities. A chart is defined illustrating a graphical distribution of a particular data type in the forensic workspace. A snapshot associated with the chart is …
Who is the assignee on this patent?
Sap Se
What technology area does this patent fall under?
Primary CPC classification H04L63/1425. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Jun 02 2020 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).