- Patent Title: Systems and methods for remote identification of enterprise threats
-
Application No.: US16820395Application Date: 2020-03-16
-
Publication No.: US11082443B2Publication Date: 2021-08-03
- Inventor: Elgan David Jones , Thomas Langer , Winston Krone
- Applicant: Kivu Consulting, Inc.
- Applicant Address: US CA San Francisco
- Assignee: Kivu Consulting, Inc.
- Current Assignee: Kivu Consulting, Inc.
- Current Assignee Address: US CA San Francisco
- Agency: Womble Bond Dickinson (US) LLP
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F21/57

Abstract:
Embodiments of the present invention provide techniques, systems, and methods for remote, agent-less enterprise computer threat data collection, malicious threat analysis, and identification and reporting of potential and real threats present on an enterprise computer system. Specifically, embodiments are directed to a system that securely collects system information from computers across the enterprise, internally encrypts and analyzes the collected information for indicators of compromise, threatening behavior, and known vulnerabilities, and generates alerts regarding known and potential threats for further analysis and remediation. If potential threats are identified, the system may deploy a memory analysis module that takes a deeper analysis of the potentially compromised computer to obtain more information about the potential threat. The remote, agent-less collection, analysis, and identification process can be repeated periodically to obtain additional information over time in order to identify the nature of the threat, and may delete itself after completion to avoid detection.
Public/Granted literature
- US20200220895A1 SYSTEMS AND METHODS FOR REMOTE IDENTIFICATION OF ENTERPRISE THREATS Public/Granted day:2020-07-09
Information query