-
公开(公告)号:US12047399B2
公开(公告)日:2024-07-23
申请号:US18094303
申请日:2023-01-06
Applicant: CrowdStrike, Inc.
Inventor: David F. Diehl , Nora Lillian Sandler , Matthew Edward Noonan , Christopher Robert Gwinn , Thomas Johann Essebier
IPC: G06F21/54 , H04L9/40 , H04L41/042 , H04L41/28
CPC classification number: H04L63/1416 , G06F21/54 , H04L41/042 , H04L41/28 , H04L63/1441
Abstract: A distributed security system can include instances of a compute engine that can execute either locally in security agents on client devices or as cloud instances in a security network. Event data can be processed by elements of the distributed security system according to centrally-defined ontological definitions and/or configurations. Bounding managers of local security agents can control how much event data is sent to the security network. A storage engine in the security network can store event data received from client devices, can route event data to other elements of the security network, including cloud instances of the compute engine. An experimentation engine of the security network can also at least temporarily adjust other elements of the distributed security system during experiments or tests.
-
公开(公告)号:US20210329012A1
公开(公告)日:2021-10-21
申请号:US16849411
申请日:2020-04-15
Applicant: CrowdStrike, Inc.
Inventor: David F. Diehl , Nora Lillian Sandler , Matthew Edward Noonan , Christopher Robert Gwinn , Thomas Johann Essebier
Abstract: A distributed security system can include instances of a compute engine that can execute either locally in security agents on client devices or as cloud instances in a security network. Event data can be processed by elements of the distributed security system according to centrally-defined ontological definitions and/or configurations. Bounding managers of local security agents can control how much event data is sent to the security network. A storage engine in the security network can store event data received from client devices, can route event data to other elements of the security network, including cloud instances of the compute engine. An experimentation engine of the security network can also at least temporarily adjust other elements of the distributed security system during experiments or tests.
-
公开(公告)号:US20240346111A1
公开(公告)日:2024-10-17
申请号:US18301720
申请日:2023-04-17
Applicant: CrowdStrike, Inc.
Inventor: Matthew Edward Noonan
CPC classification number: G06F17/17 , G06F9/45508
Abstract: Interpolant pattern matching reflects a runtime environment. Any interpolant finite automata (such as a DFA) using a regular expression may be modified with an interpolant string to create an interpolant finite automata (such as an IDFA). The interpolant string incorporates a placeholder that is then modified according to the runtime environment. An environmental variable or a directory path, for example, may be inserted into the placeholder at runtime. An input string may be pattern matched to the IDFA that reflects the runtime environment.
-
公开(公告)号:US20230164151A1
公开(公告)日:2023-05-25
申请号:US18094303
申请日:2023-01-06
Applicant: CrowdStrike, Inc.
Inventor: David F. Diehl , Nora Lillian Sandler , Matthew Edward Noonan , Christopher Robert Gwinn , Thomas Johann Essebier
IPC: H04L9/40 , G06F21/54 , H04L41/042 , H04L41/28
CPC classification number: H04L63/1416 , G06F21/54 , H04L41/042 , H04L41/28 , H04L63/1441
Abstract: A distributed security system can include instances of a compute engine that can execute either locally in security agents on client devices or as cloud instances in a security network. Event data can be processed by elements of the distributed security system according to centrally-defined ontological definitions and/or configurations. Bounding managers of local security agents can control how much event data is sent to the security network. A storage engine in the security network can store event data received from client devices, can route event data to other elements of the security network, including cloud instances of the compute engine. An experimentation engine of the security network can also at least temporarily adjust other elements of the distributed security system during experiments or tests.
-
公开(公告)号:US11563756B2
公开(公告)日:2023-01-24
申请号:US16849411
申请日:2020-04-15
Applicant: Crowdstrike, Inc.
Inventor: David F. Diehl , Nora Lillian Sandler , Matthew Edward Noonan , Christopher Robert Gwinn , Thomas Johann Essebier
IPC: G06F11/00 , H04L9/40 , G06F21/54 , H04L41/042 , H04L41/28
Abstract: A distributed security system can include instances of a compute engine that can execute either locally in security agents on client devices or as cloud instances in a security network. Event data can be processed by elements of the distributed security system according to centrally-defined ontological definitions and/or configurations. Bounding managers of local security agents can control how much event data is sent to the security network. A storage engine in the security network can store event data received from client devices, can route event data to other elements of the security network, including cloud instances of the compute engine. An experimentation engine of the security network can also at least temporarily adjust other elements of the distributed security system during experiments or tests.
-
-
-
-