IP Library Granted Patent US 11,711,379
Granted Patent B2
US 11,711,379 · App. 16/849,496 · Granted Jul 25, 2023

Distributed digital security system

Inventors: David F. Diehl (Minneapolis, MN); Thomas Johann Essebier (Brisbane, AU)
Assignee: CrowdStrike, Inc.
H04L63/1416H04L41/042H04L41/28H04L43/06H04L63/1441H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,711,379
App. No.
16/849,496
Granted
Jul 25, 2023
Kind
B2
Abstract

A distributed security system can include instances of a compute engine that can execute either locally in security agents on client devices or as cloud instances in a security network. Event data can be processed by elements of the distributed security system according to centrally-defined ontological definitions and/or configurations. Bounding managers of local security agents can control how much event data is sent to the security network. A storage engine in the security network can store event data received from client devices, can route event data to other elements of the security network, including cloud instances of the compute engine. An experimentation engine of the security network can also at least temporarily adjust other elements of the distributed security system during experiments or tests.

Claims (54)

1. A method, comprising:

receiving, by a bounding manager executing on a client device, event data associated with an occurrence of an event on the client device, wherein the bounding manager comprises different selectors associated with different reporting criteria;

generating, by the different selectors of the bounding manager, based on the different reporting criteria, different reporting recommendations associated with the event data wherein:

the different reporting recommendations are independent recommendations of whether or not to send the event data, associated with the occurrence of the event, from the client device to a security network that is remote from the client device, and

the different reporting recommendations, generated by the different selectors, have priority values associated with, or determined by, the different selectors;

identifying, by the bounding manager, a highest-priority reporting recommendation from among the different reporting recommendations, based on a comparison of the priority values of the different reporting recommendations; and

determining, by the bounding manager, whether or not to send the event data from the client device to the security network based on the highest-priority reporting recommendation.

2. The method of claim 1 , further comprising: adding, by the bounding manager, markup to the event data, wherein the markup is associated with one or more of the different selectors that generate positive reporting recommendations, and wherein the markup indicates reasons why the one or more of the different selectors recommended sending the event data to the security network.

3. The method of claim 2 , wherein the markup includes experimental markup associated with an experimental selector, of the different selectors, in addition to non-experimental markup associated with one or more non-experimental selectors of the different selectors.

4. The method of claim 1 , wherein a selector, of the different selectors, generates a reporting recommendation, of the different reporting recommendations, based on a determination of whether statistical data about a type of the event data meets reporting criteria for the selector.

5. The method of claim 4 , wherein the reporting criteria includes at least one of an upper bound or a lower bound of a count or a reporting rate.

6. The method of claim 1 , wherein: at least one of the different selectors is configured according to one or more channel files received from a bounding service of the security network, and the one or more channel files comprise at least one of global channel files, customer channel files, customer group channel files, or agent-specific channel files targeted to the client device.

7. The method of claim 1 , wherein at least one of the different selectors is configured according to specialized event data received from the security network.

8. The method of claim 7 , wherein the specialized event data causes the bounding manager to immediately modify at least one of reporting criteria or a priority value associated with the at least one of the different selectors.

9. The method of claim 1 , wherein:

the different reporting recommendations include positive reporting recommendations, negative reporting recommendations, and neutral reporting recommendations, and

the bounding manager is configured to disregard the neutral reporting recommendations and to identify the highest-priority reporting from among the positive reporting recommendations and the negative reporting recommendations.

10. The method of claim 1 , further comprising:

receiving, by the bounding manager, additional event data associated with additional occurrences of events on the client device that have common attributes;

generating, by the bounding manager, statistical data that tracks a count of the additional occurrences of events; and

sending, by the bounding manager, the statistical data to the security network.

11. A client device, comprising:

one or more processors;

memory storing computer-executable instructions that, when executed by the one or more processors, cause the client device to perform operations comprising:

detecting event data associated with an occurrence of an event on the client device;

generating, by different selectors of a bounding manager executing on the client device, the different selectors being associated with different reporting criteria, different reporting recommendations associated with the event data, wherein: the different reporting recommendations are independent recommendations of whether or not to send

the event data, associated with the occurrence of the event, associated with the occurrence of the event, from the client device to a security network that is remote from the client device, and

the different reporting recommendations, generated by the different selectors, have priority values associated with, or determined by, the different selectors;

identifying a highest-priority reporting recommendation from among the different reporting recommendations, based on a comparison of the priority values of the different reporting recommendations; and

determining whether or not to send the event data from the client device to the security network based on the highest-priority reporting recommendation.

12. The client device of claim 11 , wherein: the operations further comprise adding markup to the event data, the markup is associated with one or more of the different selectors that generate positive reporting recommendations, and the markup indicates reasons why the one or more of the different selectors recommended sending the event data to the security network.

13. The client device of claim 11 , wherein a selector, of the different selectors, generates a reporting recommendation, of the different reporting recommendations, based on a determination of whether statistical data about a type of the event data meets reporting criteria for the selector, the reporting criteria including at least one of an upper bound or a lower bound of a count or a reporting rate.

14. The client device of claim 11 , wherein at least one of the different selectors is configured according to one or more configurations received from the security network.

15. The client device of claim 11 , wherein the operations further comprise:

receiving additional event data associated with additional occurrences of events on the client device that have common attributes;

generating statistical data that tracks a count of the additional occurrences of events; and

sending the statistical data to the security network.

16. One or more non-transitory computer-readable media storing computer-executable instructions for a client device that, when executed by one or more processors of the client device, cause the client device to perform operations comprising:

detecting event data associated with an occurrence of an event on the client device;

generating, by different selectors of a bounding manager executing on the client device, the different selectors being associated with different reporting criteria, different reporting recommendations associated with the event data, wherein:

the different reporting recommendations are independent recommendations of whether or not to send the event data, associated with the occurrence of the event, from the client device to a security network that is remote from the client device, and

the different reporting recommendations, generated by the different selectors, have priority values associated with, or determined by, the different selectors;

identifying a highest-priority reporting recommendation from among the different reporting recommendations, based on a comparison of the priority values of the different reporting recommendations; and

determining whether or not to send the event data from the client device to the security network based on the highest-priority reporting recommendation.

17. The one or more non-transitory computer-readable media of claim 16 , wherein:

the operations further comprise adding markup to the event data,

the markup is associated with one or more of the different selectors that generate positive reporting recommendations, and

the markup indicates reasons why the one or more of the different selectors recommended sending the event data to the security network.

18. The one or more non-transitory computer-readable media of claim 16 , wherein a selector, of the different selectors, generates a reporting recommendation, of the different reporting recommendations, based on a determination of whether statistical data about a type of the event data meets reporting criteria for the selector, the reporting criteria including at least one of an upper bound or a lower bound of a count or a reporting rate.

19. The one or more non-transitory computer-readable media of claim 16 , wherein at least one of the different selectors is configured according to one or more configurations received from the security network.

20. The one or more non-transitory computer-readable media of claim 16 , wherein the operations further comprise:

receiving additional event data associated with additional occurrences of events on the client device that have common attributes;

generating statistical data that tracks a count of the additional occurrences of events; and

sending the statistical data to the security network.

Assignments (3)
RELEASE OF SECURITY INTEREST Recorded Jan 6, 2026
From: FIRST-CITIZENS BANK & TRUST COMPANY
To: CROWDSTRIKE HOLDINGS, INC.; CROWDSTRIKE, INC.
Reel/Frame 074202/0710 →
PATENT SECURITY AGREEMENT Recorded Jan 5, 2021
From: CROWDSTRIKE HOLDINGS, INC.; CROWDSTRIKE, INC.
To: SILICON VALLEY BANK, AS ADMINISTRATIVE AGENT
Reel/Frame 054899/0848 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 15, 2020
From: DIEHL, DAVID F.; ESSEBIER, THOMAS JOHANN
To: CROWDSTRIKE, INC.
Reel/Frame 052410/0549 →
Continuity (1)
Related Publication 20210329014A1 · Oct 21, 2021