Invention Grant
- Patent Title: Adaptive parsing and normalizing of logs at MSSP
-
Application No.: US16826883Application Date: 2020-03-23
-
Publication No.: US10977271B2Publication Date: 2021-04-13
- Inventor: Lewis McLean
- Applicant: SECUREWORKS CORP.
- Applicant Address: US DE Wilmington
- Assignee: SECUREWORKS CORP.
- Current Assignee: SECUREWORKS CORP.
- Current Assignee Address: US DE Wilmington
- Agency: Womble Bond Dickinson (US) LLP
- Main IPC: G06F21/00
- IPC: G06F21/00 ; G06F16/25 ; H04L29/06 ; G06F16/23 ; G06F40/205 ; H04L12/26 ; H04L12/24 ; G06F40/295

Abstract:
A method of normalizing security log data can include receiving one or more security logs including unstructured data from a plurality of devices and reviewing unstructured data of the one or more security logs. The method also can include automatically applying a probabilistic model of one or more engines to identify one or more attributes or features of the unstructured data, and determine whether the identified attributes or features are indicative of identifiable entities, and tagging one or more identifiable entities of the identifiable entities, as well as organizing tagged entities into one or more normalized logs having a readable format with a prescribed schema. In addition, the method can include reviewing the one or more normalized logs for potential security events.
Public/Granted literature
- US20200265063A1 ADAPTIVE PARSING AND NORMALIZING OF LOGS AT MSSP Public/Granted day:2020-08-20
Information query