IP Library Granted Patent US 11,853,779
Granted Patent B2
US 11,853,779 · App. 17/502,633 · Granted Dec 26, 2023

System and method for distributed security forensics

Inventors: Liron Levin (Herzliya, IL); Dima Stopel (Herzliya, IL); Ami Bizamcher (Kiryat Ono, IL); Michael Kletselman (Tel Aviv, IL); John Morello (La, CA)
Assignee: Twistlock, Ltd.
G06F9/455G06F9/44505G06F9/45558G06F16/2379G06F18/214G06F21/51G06F21/53G06F21/54G06N20/00H04L63/20G06F2009/45583G06F2009/45587G06F2009/45591G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,853,779
App. No.
17/502,633
Granted
Dec 26, 2023
Kind
B2
Abstract

A host device and methods for efficient distributed security forensics. The method includes creating, at a host device configured to run a virtualization entity, an event index for the virtualization entity; encoding a plurality of events related to the virtualization entity, wherein each event includes a process having a process path; and updating the event index based on the encoded plurality of events.

Claims (33)

1. A method for efficient distributed security forensics using process path codes, comprising:

creating, at a host device configured to run a virtualization entity, an event index for the virtualization entity;

encoding a plurality of events related to the virtualization entity, wherein each event includes a process having a process path; and

updating the event index based on the encoded plurality of events.

2. The method of claim 1 , wherein the event index is updated based further on a plurality of timestamp events between and among the encoded plurality of events.

3. The method of claim 1 , wherein the encoded plurality of events includes a first event having a first portion and a second portion, wherein the event index begins with the first portion of the first event and ends with the second portion of the first event.

4. The method of claim 1 , wherein the event index is only updated after a predetermined number of events has occurred since the last update.

5. The method of claim 1 , wherein encoding the plurality of events includes replacing at least a portion of each event with at least one code representing at least the process path of the respective process.

6. The method of claim 1 , wherein the host device is a first host device of a plurality of host devices, wherein the event index is a first event index of a plurality of event indices, wherein the virtualization entity is a first virtualization entity of a plurality of virtualization entities, further comprising:

sending the first event index to a master console, wherein the master console is configured to receive the plurality of event indices created by the plurality of host devices with respect to the plurality of virtualization entities.

7. The method of claim 6 , wherein the plurality of events is encoded based on an event profile of the virtualization entity, wherein the encoded plurality of events is decoded by the master console based on the event profile of the virtualization entity.

8. The method of claim 7 , wherein the event profile of the virtualization entity defines the encoding process used for encoding the plurality of events.

9. The method of claim 7 , wherein the event profile of the virtualization entity further includes the event index.

10. A non-transitory computer readable medium having stored thereon instructions executable by a processing circuitry to:

create, at a host device configured to run a virtualization entity, an event index for the virtualization entity;

encode a plurality of events related to the virtualization entity, wherein each event includes a process having a process path; and

update the event index based on the encoded plurality of events.

11. The non-transitory computer-readable medium of claim 10 , wherein the instructions to encode the plurality of events comprise instructions to replace at least a portion of each event with at least one code representing at least the process path of the respective process.

12. A host device for efficient distributed security forensics, wherein the host device is configured to run a virtualization entity, comprising:

a processing circuitry; and

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the host device to:

create, at the host device, an event index for the virtualization entity;

encode a plurality of events related to the virtualization entity, wherein each event includes a process having a process path; and

update the event index based on the encoded plurality of events.

13. The host device of claim 12 , wherein the event index is updated based further on a plurality of timestamp events between and among the encoded plurality of events.

14. The host device of claim 12 , wherein the encoded plurality of events includes a first event having a first portion and a second portion, wherein the event index begins with the first portion of the first event and ends with the second portion of the first event.

15. The host device of claim 12 , wherein the event index is only updated after a predetermined number of events has occurred since the last update.

16. The host device of claim 12 , wherein encoding the plurality of events includes replacing at least a portion of each event with at least one code representing at least the process path of the respective process.

17. The host device of claim 12 , wherein the host device is a first host device of a plurality of host devices, wherein the event index is a first event index of a plurality of event indices, wherein the virtualization entity is a first virtualization entity of a plurality of virtualization entities, wherein the first host device is further configured to:

send the first event index to a master console, wherein the master console is configured to receive the plurality of event indices created by the plurality of host devices with respect to the plurality of virtualization entities.

18. The host device of claim 17 , wherein the plurality of events is encoded based on an event profile of the virtualization entity, wherein the encoded plurality of events is decoded by the master console based on the event profile of the virtualization entity.

19. The host device of claim 18 , wherein the event profile of the virtualization entity defines the encoding process used for encoding the plurality of events.

20. The host device of claim 18 , wherein the event profile of the virtualization entity further includes the event index.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 19, 2024
From: TWISTLOCK LTD.
To: PALO ALTO NETWORKS, INC.
Reel/Frame 068685/0195 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 9, 2023
From: LEVIN, LIRON; STOPEL, DIMA; BIZAMCHER, AMI; KLETSELMAN, MICHAEL; MORELLO, JOHN
To: TWISTLOCK LTD.
Reel/Frame 065510/0436 →