Invention Grant
- Patent Title: Capturing data relating to a threat
- Patent Title (中): 捕获有关威胁的数据
-
Application No.: US12472086Application Date: 2009-05-26
-
Publication No.: US08805995B1Publication Date: 2014-08-12
- Inventor: Ian Oliver
- Applicant: Ian Oliver
- Applicant Address: US CA Mountain View
- Assignee: Symantec Corporation
- Current Assignee: Symantec Corporation
- Current Assignee Address: US CA Mountain View
- Agency: Holland & Hart LLP
- Main IPC: G06F15/173
- IPC: G06F15/173

Abstract:
A method of capturing data relating to a threat in a server processing system is described. Event history data that comprises a sequential chain of one or more events performed by a client processing system is received. Performance of the one or more events in the chain leads to a trigger event. The trigger event that occurred in the client processing system is also received. The server processing system receives the event history data in response to the client processing system detecting the trigger event. The events in the chain are analyzed in a reverse order to determine a starting point for the chain of events. The event history data is compared against past event history data received from a plurality of client processing systems in order to determine if the event history data and the past event history data comprise a series of common events. An entity associated with the series of common events is identified.
Information query