Invention Grant
- Patent Title: Forensic analysis of computing activity
-
Application No.: US15946026Application Date: 2018-04-05
-
Publication No.: US10516682B2Publication Date: 2019-12-24
- Inventor: Beata Ladnai , Mark David Harris , Andrew J. Thomas , Andrew G. P. Smith , Russell Humphries , Kenneth D. Ray
- Applicant: Sophos Limited
- Applicant Address: GB Abingdon
- Assignee: Sophos Limited
- Current Assignee: Sophos Limited
- Current Assignee Address: GB Abingdon
- Agency: Strategic Patents, P.C.
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F16/901 ; G06Q10/06 ; G06Q50/26

Abstract:
A data recorder stores endpoint activity on an ongoing basis as sequences of events that causally relate computer objects such as processes and files. When a security event is detected, an event graph may be generated based on these causal relationships among the computing objects. For a root cause analysis, the event graph may be traversed in a reverse order from the point of an identified security event (e.g., a malware detection event) to preceding computing objects, while applying one or more cause identification rules to identify a root cause of the security event. Once a root cause is identified, the event graph may be traversed forward from the root cause to identify other computing objects that are potentially compromised by the root cause.
Public/Granted literature
- US20180227320A1 FORENSIC ANALYSIS OF COMPUTING ACTIVITY Public/Granted day:2018-08-09
Information query