IP Library Granted Patent US 8,566,476
Granted Patent B2
US 8,566,476 · App. 12/024,858 · Granted Oct 22, 2013

Method and system for analyzing data related to an event

Inventors: Jason Shiffer (Vienna, VA); Matthew Frazier (New York, NY); Sean Cunningham (Washington, DC); Scott Hogsten (West Jefferson, OH); Eric Helvey (Alexandria, VA); Theodore Wilson (Alexandria, VA)
Assignee: Mandiant Corporation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,566,476
App. No.
12/024,858
Granted
Oct 22, 2013
Kind
B2
Abstract

A system and method for analyzing data from a plurality of computer environments. A user may search for computer environments that meet a certain criterion. The computer environments are authenticated and data is copied from the computer environments to a memory location. The data may be marked so that a user may determine which computer environment provided the data. The user may add notations to the data during a review. Changes to data on the computer environments may be provided to a user using a syndication feed.

Claims (49)

1. A method of analyzing data related to an event comprising:

(a) providing an interface to a user on a central computer;

(b) contacting a plurality of memory locations coupled to the central computer at a first time;

(c) copying data from the plurality of memory locations to the central computer;

(d) converting the data to a uniform format;

(e) providing the user access to the data through the interface;

(f) contacting the plurality of memory locations at a second time, comparing the data on the plurality of memory locations to the data on the central computer, and updating the display of the data to the user if data stored on the plurality of memory locations has changed more than a predetermined amount, the predetermined amount being a specific user-defined value;

(g) determining what has changed in the data stored on the plurality of memory locations; and

(h) conducting a timeline analysis to determine how the central computer has changed over time, the timeline analysis operable to exclude or include data based on a time period,

wherein only stored files of a file type requested by the user are able to be copied to the central computer;

wherein the display is updated using a syndication feed;

wherein the syndication feed is in Atom syndication format.

2. The method of claim 1 wherein the plurality of memory locations are coupled to the central computer through a network.

3. The method of claim 1 wherein converting the data to a uniform format occurs before copying data from the plurality of memory locations to the central computer.

4. The method of claim 1 wherein the uniform format is extensible markup language.

5. The method of claim 1 wherein providing the user access to the data through the interface further comprises executing a search query of the data requested by the user.

6. The method of claim 1 wherein the contacting the plurality of memory locations at a second time is repeated periodically.

7. The method of claim 6 wherein the contacting the plurality of memory locations at a second time is repeated periodically at a user-defined time interval.

8. The method of claim 1 wherein the predetermined amount is a number of modified files.

9. The method of claim 1 wherein the syndication feed comprises details of the data that has changed and upon which memory locations the data is located.

10. The method of claim 1 wherein the user is alerted when the display is updated.

11. The method of claim 10 wherein the user is presented with an option to copy any changed data from the memory locations to the central computer.

12. A method of tracking data comprising:

(a) contacting a plurality of computer environments coupled to a central computer;

(b) identifying stored files on the plurality of computer environments;

(c) copying the stored files to the central computer;

(d) converting the stored files into uniform files in a uniform file format;

(e) comparing the uniform files to the stored files on the plurality of computer environments;

(f) alerting the user if the difference between the uniform files and the stored files is greater than a predetermined amount, the predetermined amount being a specific user-defined value; and

(g) conducting, a timeline analysis to determine how the central computer has changed over time, the timeline analysis operable to exclude or include data based on a time period,

wherein only stored files of a file type requested by the user are able to be copied to the central computer;

wherein the display is updated using a syndication feed to provide any updates to the stored files to the user;

wherein the syndication feed is in Atom syndication format.

13. The method of claim 12 wherein the uniform file format is extensible markup language.

14. The method of claim 12 wherein comparing the uniform files to the stored files occurs periodically.

15. The method of claim 14 wherein comparing the uniform files to the stored files occurs periodically at user-defined time intervals.

16. The method of claim 12 further comprising creating a plurality of indexes of the uniform data.

17. The method of claim 16 further comprising executing a search of the indexes based on their defined search terms.

18. A system of analyzing data comprising:

(a) means for providing an interface to a user on a central computer;

(b) means for contacting a plurality of memory locations coupled to the central computer at a first time;

(c) means for copying data from the plurality of memory locations to the central computer;

(d) means for converting the data to a uniform format;

(e) means for providing the user access to the data through the interface; and

(f) means for contacting the plurality of memory locations at a second time, comparing the data on the memory locations to the data on the central computer, and alerting the user if data stored on the plurality of memory locations has changed more than a predetermined amount, the predetermined amount being a specific user-defined value: and

(g) conducting a timeline analysis to determine how the central computer has changed over time, the timeline analysis operable to exclude or include data based on a time period,

wherein only stored files of a file type requested by the user are able to be copied to the central computer;

wherein the display is updated using a syndication feed to provide any updates to the stored files to the user;

wherein the syndication feed is in Atom syndication format.

Assignments (16)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
MERGER Recorded Aug 13, 2024
From: FIREEYE SECURITY HOLDINGS US LLC
To: MUSARUBRA US LLC
Reel/Frame 068581/0279 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 16, 2023
From: MANDIANT, INC.
To: FIREEYE SECURITY HOLDINGS US LLC
Reel/Frame 063114/0701 →
CHANGE OF NAME Recorded Mar 16, 2023
From: FIREEYE, INC.
To: MANDIANT, INC.
Reel/Frame 063114/0766 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 11, 2021
From: FIREEYE SECURITY HOLDINGS US LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057772/0791 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Oct 11, 2021
From: FIREEYE SECURITY HOLDINGS US LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057772/0681 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 12, 2016
From: MANDIANT, LLC
To: FIREEYE, INC.
Reel/Frame 038571/0106 →
CHANGE OF NAME Recorded Mar 5, 2014
From: MERCURY MERGER LLC
To: MANDIANT, LLC
Reel/Frame 032351/0340 →
MERGER Recorded Mar 4, 2014
From: MANDIANT CORPORATION
To: MERCURY MERGER LLC
Reel/Frame 032342/0806 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 7, 2008
From: SHIFFER, JASON; CUNNINGHAM, SEAN; HOGSTEN, SCOTT; HELVEY, ERIC; WILSON, THEODORE; FRAZIER, MATTHEW
To: MANDIANT
Reel/Frame 020915/0607 →
Continuity (1)
Related Publication 20090198651A1 · Aug 6, 2009