白丝美女被狂躁免费视频网站,500av导航大全精品,yw.193.cnc爆乳尤物未满,97se亚洲综合色区,аⅴ天堂中文在线网官网

Distributed digital security system

專利號
US11616790B2
公開日期
2023-03-28
申請人
CrowdStrike, Inc.(US CA Irvine)
發(fā)明人
David F. Diehl; Michael Edward Lusignan; Thomas Johann Essebier
IPC分類
H04L9/40; G06F16/2455; G06Q50/26
技術領域
event,data,security,engine,bounding,compute,rally,or,can,client
地域: CA CA Irvine

摘要

A distributed security system can include instances of a compute engine that can execute either locally in security agents on client devices or as cloud instances in a security network. Event data can be processed by elements of the distributed security system according to centrally-defined ontological definitions and/or configurations. Bounding managers of local security agents can control how much event data is sent to the security network. A storage engine in the security network can store event data received from client devices, can route event data to other elements of the security network, including cloud instances of the compute engine. An experimentation engine of the security network can also at least temporarily adjust other elements of the distributed security system during experiments or tests.

說明書

In some examples, one or more elements of the distributed security system 100 can store local copies or archives of ontological definitions 134 and/or interface fulfillment maps 140 previously received from the ontology service 110. However, if an element of the distributed security system 100 receives data in an unrecognized format, the element can obtain a corresponding ontological definition 134 or interface fulfillment map 140 from the ontology service 110 such that the element can understand and/or interpret the data. The ontology service 110 can also store archives of old ontological definitions 134 and/or interface fulfillment maps 140, such that elements of the distributed security system 100 can obtain copies of older ontological definitions 134 or interface fulfillment maps 140 if needed.

For instance, if for some reason a particular security agent 108 running on a client device 104 has not been updated in a year and is using an out-of-date configuration 132 based on old ontological definitions 134, that security agent 108 may be reporting event data 122 to the security network 106 based on an outdated context collection format 136 that more recently-updated cloud elements of the distributed security system 100 do not directly recognize. However, in this situation, cloud elements of the distributed security system 100 can retrieve old ontological definitions 134 from the ontology service 110 and thus be able to interpret event data 122 formatted according to an older context collection format 136.

權利要求

1
微信群二維碼
意見反饋