Invention Publication
- Patent Title: ENDPOINT WITH REMOTELY PROGRAMMABLE DATA RECORDER
-
Application No.: US18449315Application Date: 2023-08-14
-
Publication No.: US20240037477A1Publication Date: 2024-02-01
- Inventor: Beata Ladnai , Mark D. Harris , Andrew G. P. Smith , Kenneth D. Ray , Andrew J. Thomas , Russell Humphries
- Applicant: Sophos Limited
- Applicant Address: GB Abingdon
- Assignee: Sophos Limited
- Current Assignee: Sophos Limited
- Current Assignee Address: GB Abingdon
- Main IPC: G06Q10/0635
- IPC: G06Q10/0635 ; H04L9/40 ; G06N5/046 ; G06N20/00 ; G06F17/18 ; G06F21/56 ; G06Q10/0639 ; G06F16/955 ; G06F11/07 ; G06N7/00 ; G06F21/55 ; G06N5/04 ; G06F9/54 ; G06N5/022 ; G06N20/20 ; G06V20/52 ; G06F18/214 ; G06F18/21 ; G06F18/23213 ; G06F18/2413 ; G06N5/01

Abstract:
An endpoint coupled in a communicating relationship with an enterprise network may include a data recorder configured to store an event stream of data indicating events on the endpoint including types of changes to computing objects, a filter configured to locally process the event stream into a filtered event stream including a subset of types of changes to the computing objects, and a local security agent. The local security agent may be configured to transmit the filtered event stream to a threat management facility, respond to a filter adjustment from the threat management facility by adjusting the filter to modify the subset of types of changes included in the filtered event stream, and respond to a query from the threat management facility by retrieving data stored in the data recorder over a time window before the query and excluded from the filtered event stream.
Public/Granted literature
- US12079757B2 Endpoint with remotely programmable data recorder Public/Granted day:2024-09-03
Information query