US2017104777A1PendingUtilityA1
Device Time Accumulation
Est. expiryOct 13, 2035(~9.2 yrs left)· nominal 20-yr term from priority
H04L 43/067H04L 63/1425H04L 63/1408H04L 43/04H04L 43/08
39
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
A method, system and computer-usable medium are disclosed for performing a device time accumulation operation. With a device time accumulation operation systems within a security intelligence platform which accumulate events within the IT environment associate an event ingest time with the event. When the events are provided for analysis, the device time accumulation operation analyzes the ingest times as well as the emit time to take into account historical time data associated with the accumulated events.
Claims
exact text as granted — not AI-modified1 . A computer-implemented method for processing device time information, comprising:
monitoring a security intelligence platform for a plurality of events, the plurality of events being generated by at least one data source of the security intelligence environment; storing the plurality of events for later processing, the storing comprising associating an event emit time with each of the plurality of events, the event emit time representing a time when the event was generated; forwarding the plurality of events to a security platform, the forwarding comprising an event ingest time with each of the plurality of events, the event ingest time representing a time when the event was forwarded to the security platform; processing the plurality of events, the processing considering the event ingest time and the event emit time of each of the plurality of events.
2 . The method of claim 1 , wherein:
the at least one data source comprises at least one of a security device and an information processing system.
3 . The method of claim 1 , wherein:
the plurality of events comprises at least one of information relating to network and virtual activity, information relating to data activity, information relating to application activity, configuration information, vulnerability and threat information and information relating to users and identities.
4 . The method of claim 1 , wherein:
the plurality of events are stored within an event accumulation module.
5 . The method of claim 1 , wherein:
the processing further comprises using a set of criteria to group events together based upon similar properties and recording events over time.
6 . The method of claim 1 , wherein:
the processing further comprises creating accumulations of the plurality of events, the accumulations being used for analytics or to populate time-series graphs for graphical representation of the data.
7 - 20 . (canceled)Join the waitlist — get patent alerts
Track US2017104777A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.