Invention Grant
- Patent Title: Managing incident response operations based on monitored network activity
-
Application No.: US16107509Application Date: 2018-08-21
-
Publication No.: US10594718B1Publication Date: 2020-03-17
- Inventor: Joel Benjamin Deaguero , Edmund Hope Driggs , Xue Jun Wu , Nicholas Jordan Braun , Michael Kerber Krause Montague , Michael Christopher Kelly
- Applicant: ExtraHop Networks, Inc.
- Applicant Address: US WA Seattle
- Assignee: ExtraHop Networks, Inc.
- Current Assignee: ExtraHop Networks, Inc.
- Current Assignee Address: US WA Seattle
- Agency: Lowe Graham Jones PLLC
- Agent John W. Branch
- Main IPC: G06F11/00
- IPC: G06F11/00 ; H04L29/06 ; H04L12/26 ; H04L12/24 ; H04L29/08 ; G06N5/04 ; G06N20/00 ; G06F12/14

Abstract:
Embodiments are directed to monitoring network traffic associated with networks to provide metrics. A monitoring engine may determine an anomaly based on the metrics exceeding threshold values. An inference engine may be instantiated to provide an anomaly profile based on portions of the network traffic that are associated with the anomaly. The inference engine may provide an investigation profile based on the anomaly profile such that the investigation profile includes information associated with investigation activities associated with an investigation of the anomaly. The inference engine may monitor the investigation of the anomaly based on other portions of the network traffic such that the other portions of the network traffic are associated with monitoring an occurrence of the investigation activities. The inference engine may modify a performance score associated with the investigation profile based on the occurrence of the investigation activities and a completion status of the investigation.
Public/Granted literature
- US20200067952A1 MANAGING INCIDENT RESPONSE OPERATIONS BASED ON MONITORED NETWORK ACTIVITY Public/Granted day:2020-02-27
Information query