Invention Grant
- Patent Title: Causality identification and attributions determination of processes in a network
-
Application No.: US15398070Application Date: 2017-01-04
-
Publication No.: US10554672B2Publication Date: 2020-02-04
- Inventor: Gil Barak
- Applicant: Palo Alto Networks, Inc.
- Applicant Address: US CA Santa Clara
- Assignee: PALO ALTO NETWORKS INC.
- Current Assignee: PALO ALTO NETWORKS INC.
- Current Assignee Address: US CA Santa Clara
- Agency: Gilliam IP PLLC
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
Processes in a network which cause and are attributable to security incidents are identified. Processes which are initiated on devices in an enterprise network at boot of the devices are identified. The enterprise network is continuously monitored to collect data about processes which were initiated or spawned on devices in the enterprise network after the boot of the devices. Each process is determined to be a major system process, a minor system process, or a non-system process based, at least in part, on the collected data which indicates associations among the processes. Based on matching a security incident alert to a first of the processes, it is determined whether the first process is a non-system process to validate the security incident alert.
Public/Granted literature
Information query