Invention Grant
- Patent Title: System and method thereof for identifying and responding to security incidents based on preemptive forensics
-
Application No.: US14944773Application Date: 2015-11-18
-
Publication No.: US09888031B2Publication Date: 2018-02-06
- Inventor: Gil Barak , Shai Morag
- Applicant: SEC.DO TECHNOLOGIES LTD.
- Applicant Address: IL Ra'anana
- Assignee: CYBER SECDO LTD.
- Current Assignee: CYBER SECDO LTD.
- Current Assignee Address: IL Ra'anana
- Agency: Sughrue Mion, PLLC
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
A system is connected to a plurality of user devices coupled to an enterprise's network. The system continuously collects, stores, and analyzes forensic data related to the enterprise's network. Based on the analysis, the system is able to determine normal behavior of the network and portions thereof and thereby identify abnormal behaviors within the network. Upon identification of an abnormal behavior, the system determines whether the abnormal behavior relates to a security incident. Upon determining a security incident in any portion of the enterprise's network, the system extracts forensic data respective of the security incident and enables further assessment of the security incident as well as identification of the source of the security incident. The system provides real-time damage assessment respective of the security incident as well as the security incident's attributions.
Public/Granted literature
Information query