IP Library › Granted Patent US 12,079,757
Granted Patent B2
US 12,079,757 · App. 18/449,315 · Granted Sep 3, 2024

Endpoint with remotely programmable data recorder

Inventors: Beata Ladnai (Altrincham, GB); Mark D. Harris (Oxon, GB); Andrew G. P. Smith (Oxford, GB); Kenneth D. Ray (Seattle, WA); Andrew J. Thomas (Oxfordshire, GB); Russell Humphries (Surrey, GB)
Assignee: Sophos Limited
G06Q10/0635G06F9/542G06F11/079G06F16/955G06F17/18G06F18/214G06F18/2178G06F18/23213G06F18/24143G06F21/554G06F21/56G06F21/562G06F21/565G06N5/01G06N5/022G06N5/04G06N5/046G06N7/00G06N20/00G06N20/20G06Q10/06395G06V20/52H04L63/0227H04L63/0263H04L63/1408H04L63/1416H04L63/1425H04L63/1433H04L63/1441H04L63/20G06Q30/0185G06Q30/0283
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,079,757
App. No.
18/449,315
Filed
Aug 14, 2023
Granted
Sep 3, 2024
Kind
B2
Art Unit
2436
USPC
726/23
Abstract

An endpoint coupled in a communicating relationship with an enterprise network may include a data recorder configured to store an event stream of data indicating events on the endpoint including types of changes to computing objects, a filter configured to locally process the event stream into a filtered event stream including a subset of types of changes to the computing objects, and a local security agent. The local security agent may be configured to transmit the filtered event stream to a threat management facility, respond to a filter adjustment from the threat management facility by adjusting the filter to modify the subset of types of changes included in the filtered event stream, and respond to a query from the threat management facility by retrieving data stored in the data recorder over a time window before the query and excluded from the filtered event stream.

Claims (38)

1. A computer program product comprising a non-transitory computer readable medium embodying computer executable code that, when executing on one or more computing devices, causes the one or more computing devices to perform steps of:

storing in a data recorder an event stream of data indicating events on an endpoint including a plurality of types of changes to a plurality of computing objects on the endpoint;

processing the event stream with a filter into a filtered event stream including a subset of the plurality of types of changes to the plurality of computing objects;

transmitting the filtered event stream over an enterprise network to a threat management facility;

responding to a local change in security posture detected on the endpoint by adjusting the filter to modify the subset of the plurality of types of changes included in the filtered event stream;

receiving a query from the threat management facility for additional event data from the event stream stored in the data recorder in response to the change in security posture; and

responding to the query from the threat management facility by retrieving data stored in the data recorder over a time window before the query and excluded from the filtered event stream.

2. The computer program product of claim 1 , wherein the local change is based on a reputation score for one or more processes on the endpoint.

3. The computer program product of claim 1 , wherein the local change is based on a reputation score for one or more files on the endpoint.

4. The computer program product of claim 1 , wherein the local change includes a change in policy compliance posture of the endpoint.

5. The computer program product of claim 1 , wherein the local change includes a malware detection.

6. The computer program product of claim 1 , wherein adjusting the filter includes decreasing filtering of the types of changes included in the filtered event stream.

7. The computer program product of claim 1 , wherein adjusting the filter includes decreasing filtering for one or more of the plurality of computing objects.

8. A method comprising:

storing, in a data recorder, an event stream of data indicating events on an endpoint including a plurality of types of changes to a plurality of computing objects on the endpoint;

processing the event stream with a filter into a filtered event stream including a subset of the plurality of types of changes to the plurality of computing objects;

transmitting the filtered event stream over an enterprise network to a threat management facility;

responding to a change in security posture of the endpoint by adjusting the filter to modify the subset of the plurality of types of changes included in the filtered event stream;

receiving a query from the threat management facility for additional event data from the event stream stored in the data recorder in response to the change in security posture; and

responding to the query from the threat management facility by retrieving data stored in the data recorder over a time window before the query and excluded from the filtered event stream.

9. The method of claim 8 , wherein the change in security posture includes a change in policy compliance of the endpoint.

10. The method of claim 8 , wherein the change in security posture includes a malware detection by a local security agent.

11. The method of claim 8 , wherein the change in security posture is based on a change in a reputation score for one or more processes on the endpoint.

12. The method of claim 8 , wherein the change in security posture is based on a change in a reputation score for one or more files on the endpoint.

13. The method of claim 8 , wherein adjusting the filter includes decreasing filtering for one or more of the plurality of computing objects.

14. An endpoint coupled in a communicating relationship with an enterprise network, the endpoint comprising:

a data recorder configured to store an event stream of data indicating events on the endpoint including a plurality of types of changes to a plurality of computing objects on the endpoint;

a filter configured to locally process the event stream into a filtered event stream including a subset of the plurality of types of changes to the plurality of computing objects; and

a local security software agent configured to:

transmit the filtered event stream over the enterprise network to a threat management facility;

respond to a change in a security posture of the endpoint by adjusting the filter to modify the subset of the plurality of types of changes included in the filtered event stream;

receive a query from the threat management facility for additional event data from the event stream stored in the data recorder in response to the change in security posture; and

respond to the query from the threat management facility by retrieving data stored in the data recorder over a time window before the query and excluded from the filtered event stream.

15. The endpoint of claim 14 , wherein the change in security posture includes a change in policy compliance of the endpoint.

16. The endpoint of claim 14 , wherein the change in security posture includes a malware detection by the local security software agent.

17. The endpoint of claim 14 , wherein the change in security posture is based on a change in a reputation score for one or more processes on the endpoint.

18. The endpoint of claim 14 , wherein the change in security posture is based on a change in a reputation score for one or more files on the endpoint.

19. The endpoint of claim 14 , wherein adjusting the filter includes decreasing filtering for one or more of the plurality of computing objects.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 23, 2023
From: LADNAI, BEATA; HARRIS, MARK D.; SMITH, ANDREW G. P.; RAY, KENNETH D.; THOMAS, ANDREW J.; HUMPHRIES, RUSSELL
To: SOPHOS LIMITED
Reel/Frame 064675/0760 →
Continuity (4)
Continuation 17705640 · Mar 28, 2022
Continuation 16129113 · Sep 12, 2018
Provisional Application 62726174 · Aug 31, 2018
Related Publication 20240037477A1 · Feb 1, 2024
Cited By (4)
US 12,354,043 US 12,361,358 US 12,670,455 US 12,725,106