IP Library Granted Patent US 10,972,485
Granted Patent B2
US 10,972,485 · App. 16/129,143 · Granted Apr 6, 2021

Enterprise network threat detection

Inventors: Beata Ladnai (Altrincham, GB); Mark David Harris (Oxon, GB); Andrew G. P. Smith (Kennington, GB); Kenneth D. Ray (Seattle, WA); Andrew J. Thomas (Oxfordshire, GB); Russell Humphries (Horley, GB)
Assignee: Sophos Limited
H04L63/1416G06F9/542G06F11/079G06F16/955G06F17/18G06F21/554G06F21/56G06F21/562G06F21/565G06K9/6223G06K9/6256G06N5/04G06N5/046G06N7/00G06N20/00G06Q10/0635G06Q10/06395H04L63/0227H04L63/0263H04L63/1425H04L63/1433H04L63/1441H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,972,485
App. No.
16/129,143
Filed
Sep 12, 2018
Granted
Apr 6, 2021
Kind
B2
Examiner
KORSAK, OLEG
Art Unit
2492
USPC
726/23
Abstract

In a threat management platform, a number of endpoints log events in an event data recorder. A local agent filters this data and feeds a filtered data stream to a central threat management facility. The central threat management facility can locally or globally tune filtering by local agents based on the current data stream, and can query local event data recorders for additional information where necessary or helpful in threat detection or forensic analysis. The central threat management facility also stores and deploys a number of security tools such as a web-based user interface supported by machine learning models to identify potential threats requiring human intervention and other models to provide human-readable context for evaluating potential threats.

Claims (23)

1. A system comprising:

an enterprise network;

an endpoint coupled to the enterprise network, the endpoint having computing objects, a data recorder that stores locally on the endpoint an unfiltered event stream of event data for changes detected on the endpoint occurring to the computing objects, a local agent executing a filter on the endpoint for creating a filtered event stream with a subset of event data for changes detected on the endpoint from the unfiltered event stream as the unfiltered event stream is captured by the data recorder, and a query interface for receiving queries to the data recorder from a remote resource, the endpoint further including a local security agent configured to detect malware on the endpoint based on event data stored by the data recorder, and further configured to communicate the filtered event stream over the enterprise network; and

a threat management facility coupled in a communicating relationship with the endpoint and a plurality of other endpoints through the enterprise network, the threat management facility configured to receive the filtered event stream from the endpoint, detect malware on the endpoint based on the filtered event stream, and remediate the endpoint when malware is detected, the threat management facility further configured to modify security functions within the enterprise network based on a security state of the endpoint.

2. The system of claim 1 wherein the threat management facility is configured to adjust reporting of event data through the filter in response to a change in the filtered event stream received from the endpoint.

3. The system of claim 2 wherein the threat management facility is configured to adjust reporting of event data through the filter when the filtered event stream indicates a compromised security state of the endpoint.

4. The system of claim 1 wherein the threat management facility is configured to adjust reporting of event data from one or more other endpoints in response to a change in the filtered event stream received from the endpoint.

5. The system of claim 1 wherein the threat management facility is configured to adjust reporting of event data through the filter when the filtered event stream indicates a compromised security state of the endpoint.

6. The system of claim 1 wherein the threat management facility is configured to request additional data from the data recorder when the filtered event stream indicates a compromised security state of the endpoint.

7. The system of claim 1 wherein the threat management facility is configured to request additional data from the data recorder when a security agent of the endpoint reports a security compromise independently from the filtered event stream.

8. The system of claim 1 wherein the data recorder records one or more events from a kernel driver.

9. The system of claim 1 wherein the data recorder records at least one change to a registry of system settings for the endpoint.

10. The system of claim 1 wherein the threat management facility is configured to adjust handling of network traffic at a gateway to the enterprise network in response to a predetermined change in the filtered event stream.

11. The system of claim 10 wherein the threat management facility includes a machine learning model for identifying potentially malicious activity on the endpoint based on the filtered event stream.

12. The system of claim 1 wherein the endpoint includes a server.

13. The system of claim 1 wherein the endpoint includes a firewall for the enterprise network.

14. The system of claim 1 wherein the endpoint includes a gateway for the enterprise network.

15. The system of claim 1 wherein the endpoint is coupled to the enterprise network through a virtual private network.

16. The system of claim 1 wherein the endpoint is coupled to the enterprise network through a wireless network.

17. The system of claim 1 wherein the threat management facility is configured to detect potentially malicious activity based on a plurality of filtered event streams from a plurality of endpoints.

18. The system of claim 1 wherein the endpoint is configured to periodically transmit a snapshot of aggregated, unfiltered data from the data recorder to the threat management facility for remote storage.

19. The system of claim 18 wherein the data recorder is configured to delete records in the data recorder corresponding to the snapshot in order to free memory for additional recording.

20. The system of claim 1 wherein the threat management facility is configured to detect malware on the endpoint based on the filtered event stream and additional context for the endpoint.

Assignments (4)
RELEASE OF SECURITY INTEREST IN PATENTS AT R/F 053476/0681 Recorded Mar 9, 2021
From: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
To: SOPHOS LIMITED
Reel/Frame 056469/0815 →
PATENT SECURITY AGREEMENT FIRST LIEN Recorded Jul 6, 2020
From: SOPHOS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 053124/0350 →
PATENT SECURITY AGREEMENT SECOND LIEN Recorded Jul 6, 2020
From: SOPHOS LIMITED
To: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 053476/0681 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 6, 2019
From: LADNAI, BEATA; HARRIS, MARK DAVID; SMITH, ANDREW G. P.; RAY, KENNETH D.; THOMAS, ANDREW J.; HUMPHRIES, RUSSELL
To: SOPHOS LIMITED
Reel/Frame 048275/0749 →
Cited By (11)
US 12,204,870 US 12,255,915 US 12,265,526 US 12,306,959 US 12,354,043 US 12,361,358 US 12,470,599 US 12,500,927 US 12,526,289 US 12,556,550 US 12,670,455