The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Nov. 21, 2017

Filed:

Oct. 24, 2007
Applicants:

Anurag Singla, Mountain View, CA (US);

Kumar Saurabh, Daly City, CA (US);

Kenny C. Tidwell, Los Altos, CA (US);

Inventors:

Anurag Singla, Mountain View, CA (US);

Kumar Saurabh, Daly City, CA (US);

Kenny C. Tidwell, Los Altos, CA (US);

Assignee:

EntIT Software LLC, Sunnyvale, CA (US);

Attorney:
Primary Examiner:
Assistant Examiner:
Int. Cl.
CPC ...
G06F 17/00 (2006.01); G06F 17/30 (2006.01); H04L 29/12 (2006.01); H04L 29/06 (2006.01); H04L 29/08 (2006.01);
U.S. Cl.
CPC ...
G06F 17/30333 (2013.01); G06F 17/30492 (2013.01); G06F 17/30551 (2013.01); H04L 29/12783 (2013.01); H04L 61/35 (2013.01); H04L 63/1408 (2013.01); H04L 63/20 (2013.01); H04L 67/142 (2013.01);
Abstract

A session table includes one or more records, where each record represents a session. Session record information is stored in various fields, such as key fields, value fields, and timestamp fields. Session information is described as keys and values in order to support query/lookup operations. A session table is associated with a filter, which describes a set of keys that can be used for records in that table. A session table is populated using data contained in security information/events. Rules are created to identify events related to session information, extract the session information, and use the session information to modify a session table. A session table is partitioned so that the number of records in each session table partition is decreased. A session table is processed periodically so that active sessions are moved to the current partition.


Find Patent Forward Citations

Loading…