IP Library › Granted Patent US 10,673,879
Granted Patent B2
US 10,673,879 · App. 15/274,569 · Granted Jun 2, 2020

Snapshot of a forensic investigation for enterprise threat detection

Inventors: Florian Chrosziel (St. Leon-Rot, DE); Jona Hassforther (Heidelberg, DE); Thomas Kunz (Lobbach/Lobenfeld, DE); Harish Mehta (Wiesenbach, DE); Rita Merkel (Ilvesheim, DE); Kathrin Nos (Nussloch, DE); Wei-Guo Peng (Dallau, DE); Eugen Pritzkau (Wiesloch, DE); Marco Rodeck (Maikammer, DE); Hartwig Seifert (Elchesheim-Illingen, DE); Nan Zhang (Schriesheim, DE); Thorsten Menke (Bad Iburg, DE); Hristina Dinkova (Nussloch, DE); Lin Luo (Wiesloch, DE)
Assignee: SAP SE
H04L63/1425G06F11/30G06F11/302G06F11/3051G06F11/323G06F16/128G06F16/248G06F21/00G06Q10/0635G06F2201/865
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,673,879
App. No.
15/274,569
Filed
Sep 23, 2016
Granted
Jun 2, 2020
Kind
B2
Art Unit
2494
USPC
726/23
Abstract

An enterprise threat detection (ETD) forensic workspace is established according to a particular timeframe and permitting defining a selection of data types from available log data for an evaluation of events associated with one or more entities. A chart is defined illustrating a graphical distribution of a particular data type in the forensic workspace. A snapshot associated with the chart is generated, the snapshot saving a copy of all data necessary to re-create the chart into an associated snapshot object. The snapshot is associated with a snapshot page for containing the snapshot and the snapshot page is saved within the ETD forensic workspace.

Claims (46)

1. A computer-implemented method, comprising:

establishing an enterprise threat detection (ETD) forensic workspace according to a particular timeframe and permitting defining a selection of data types from available log data for an evaluation of events associated with one or more entities, wherein the forensic workspace is configured with functionality to define a filter path containing a series of filters to define a particular sub set of the available log data;

defining a chart illustrating a graphical distribution of a particular data type in the forensic workspace;

generating a snapshot associated with the chart, the snapshot saving a copy of all data necessary to re-create the chart into an associated snapshot object;

associating the snapshot with a snapshot page for containing the snapshot; and

saving the snapshot page within the ETD forensic workspace.

2. The computer-implemented method of claim 1 , wherein the chart includes a structured query language (SQL) SELECT statement for selecting events from the available log data and a user interface (UI) permitting interactive functionality with the chart.

3. The computer-implemented method of claim 1 , wherein the snapshot page is a data container that is persisted with a reference to the snapshot stored in a data store.

4. The computer-implemented method of claim 1 , wherein the data saved by the snapshot includes at least one of log data, environmental variables, environmental conditions, chart data, chart UI information, a selected path and filter data or functionality to search for the same configuration of the chart at a different timeframe.

5. The computer-implemented method of claim 1 , comprising configuring the snapshot object as immutable once the snapshot is generated.

6. The computer-implemented method of claim 1 , comprising:

loading the saved snapshot page within the ETD forensic workspace;

retrieving data from the snapshot object of the snapshot associated with the saved snapshot page; and

re-creating the chart on the snapshot page.

7. The computer-implemented method of claim 1 , comprising transferring the saved snapshot page to a third-party for collaborative analysis.

8. A non-transitory, computer-readable medium storing one or more instructions executable by a computer system to perform operations comprising:

establishing an enterprise threat detection (ETD) forensic workspace according to a particular timeframe and permitting defining a selection of data types from available log data for an evaluation of events associated with one or more entities, wherein the forensic workspace is configured with functionality to define a filter path containing a series of filters to define a particular sub set of the available log data;

defining a chart illustrating a graphical distribution of a particular data type in the forensic workspace;

generating a snapshot associated with the chart, the snapshot saving a copy of all data necessary to re-create the chart into an associated snapshot object;

associating the snapshot with a snapshot page for containing the snapshot; and

saving the snapshot page within the ETD forensic workspace.

9. The non-transitory, computer-readable medium of claim 8 , wherein the chart includes a structured query language (SQL) SELECT statement for selecting events from the available log data and a user interface (UI) permitting interactive functionality with the chart.

10. The non-transitory, computer-readable medium of claim 8 , wherein the snapshot page is a data container that is persisted with a reference to the snapshot stored in a data store.

11. The non-transitory, computer-readable medium of claim 8 , wherein the data saved by the snapshot includes at least one of log data, environmental variables, environmental conditions, chart data, chart UI information, a selected path and filter data or functionality to search for the same configuration of the chart at a different timeframe.

12. The non-transitory, computer-readable medium of claim 8 , comprising one or more instructions to configure the snapshot object as immutable once the snapshot is generated.

13. The non-transitory, computer-readable medium of claim 8 , comprising one or more instructions to:

load the saved snapshot page within the ETD forensic workspace;

retrieve data from the snapshot object of the snapshot associated with the saved snapshot page; and

re-create the chart on the snapshot page.

14. The non-transitory, computer-readable medium of claim 8 , comprising one or more instructions to transfer the saved snapshot page to a third-party for collaborative analysis.

15. A computer-implemented system, comprising:

a computer memory; and

a hardware processor interoperably coupled with the computer memory and configured to perform operations comprising:

establishing an enterprise threat detection (ETD) forensic workspace according to a particular timeframe and permitting defining a selection of data types from available log data for an evaluation of events associated with one or more entities, wherein the forensic workspace is configured with functionality to define a filter path containing a series of filters to define a particular subset of the available log data;

defining a chart illustrating a graphical distribution of a particular data type in the forensic workspace;

generating a snapshot associated with the chart, the snapshot saving a copy of all data necessary to re-create the chart into an associated snapshot object;

associating the snapshot with a snapshot page for containing the snapshot; and

saving the snapshot page within the ETD forensic workspace.

16. The computer-implemented system of claim 15 , wherein the chart includes a structured query language (SQL) SELECT statement for selecting events from the available log data and a user interface (UI) permitting interactive functionality with the chart.

17. The computer-implemented system of claim 15 , wherein the snapshot page is a data container that is persisted with a reference to the snapshot stored in a data store.

18. The computer-implemented system of claim 15 , wherein the data saved by the snapshot is configured as immutable once the snapshot is generated and wherein the snapshot includes at least one of log data, environmental variables, environmental conditions, chart data, chart UI information, a selected path and filter data or functionality to search for the same configuration of the chart at a different timeframe.

19. The computer-implemented system of claim 15 , further configured to:

load the saved snapshot page within the ETD forensic workspace;

retrieve data from the snapshot object of the snapshot associated with the saved snapshot page; and

re-create the chart on the snapshot page.

20. The computer-implemented system of claim 15 , further configured to transfer the saved snapshot page to a third-party for collaborative analysis.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 17, 2016
From: CHROSZIEL, FLORIAN; HASSFORTHER, JONA; KUNZ, THOMAS; MEHTA, HARISH; MERKEL, RITA; NOS, KATHRIN; PENG, WEI-GUO; PRITZKAU, EUGEN; RODECK, MARCO; SEIFERT, HARTWIG; ZHANG, NAN; MENKE, THORSTEN; DINKOVA, HRISTINA; LUO, LIN
To: SAP SE
Reel/Frame 040376/0967 →
Continuity (1)
Related Publication 20180091535A1 · Mar 29, 2018