The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Apr. 14, 2020

Filed:

Nov. 15, 2016
Applicant:

Ziften Technologies, Inc., Austin, TX (US);

Inventors:

Ryan Holeman, Austin, TX (US);

Al Hartmann, Round Rock, TX (US);

Josh Harriman, Austin, TX (US);

Josh Applebaum, Austin, TX (US);

Assignee:

Ziften Technologies, Inc., Austin, TX (US);

Attorney:
Primary Examiner:
Assistant Examiner:
Int. Cl.
CPC ...
H04L 29/06 (2006.01); G06F 9/455 (2018.01); H04L 12/24 (2006.01); H04L 29/08 (2006.01); H04L 12/26 (2006.01);
U.S. Cl.
CPC ...
H04L 63/1425 (2013.01); G06F 9/45558 (2013.01); H04L 41/046 (2013.01); H04L 43/02 (2013.01); H04L 43/026 (2013.01); H04L 67/10 (2013.01); H04L 67/12 (2013.01); H04L 67/2842 (2013.01); H04L 67/40 (2013.01); G06F 2009/45591 (2013.01); G06F 2009/45595 (2013.01); H04L 41/5096 (2013.01); H04L 63/1441 (2013.01);
Abstract

Techniques are disclosed for supplementing network flow analysis with data collected from endpoint computer systems in a network. An endpoint analysis agent may run on endpoints to collect information relating to computing activity internal to the endpoint, including system configuration information, event information, and network, user, process, and file activity. This information may be reported to a network flow analyzer using an extensible flow data record format. The flow analyzer may then correlate this information with network flow data records received from flow collectors in the network to perform a security analysis. In various embodiments, the endpoint analysis agent may cache the collected information when the endpoint is offline. The agent may also perform data reduction operations (such as compression) on the collected information before reporting; data may be further reduced by reporting data only during specified time periods. An analysis agent may also be deployed in a cloud environment.


Find Patent Forward Citations

Loading…