Invention Grant
- Patent Title: Logging attack context data
-
Application No.: US15462841Application Date: 2017-03-18
-
Publication No.: US09917857B2Publication Date: 2018-03-13
- Inventor: Wei David Wang , Dayong Zhou , Ihab Khalil
- Applicant: Fortinet, Inc.
- Applicant Address: US CA Sunnyvale
- Assignee: Fortinet, Inc.
- Current Assignee: Fortinet, Inc.
- Current Assignee Address: US CA Sunnyvale
- Agency: Hamilton, DeSanctis & Cha LLP
- Main IPC: G06F21/55
- IPC: G06F21/55 ; H04L29/06

Abstract:
Methods and systems for improved attack context data logging are provided. According to one embodiment, prior to a logging event being triggered (i) it is determined by a network security device whether a received packet is potentially associated with a threat or undesired activity by analyzing the packet; (ii) when the determination is negative, the packet is stored within a circular buffer; and (iii) when the determination is affirmative, (a) the logging event is triggered, (b) pre-attack context information regarding the threat is captured by extracting information from packets within the circular buffer and (c) the pre-attack context information is stored within a log. After the logging event has been triggered and until information regarding a predefined quantity of packets has been logged, post-attack context information regarding the threat is captured by extracting information from subsequently received packets and the post-attack context information is stored within the log.
Public/Granted literature
- US20170195355A1 LOGGING ATTACK CONTEXT DATA Public/Granted day:2017-07-06
Information query