Generating readable, compressed event trace logs from raw event trace logs

    公开(公告)号:US11989161B2

    公开(公告)日:2024-05-21

    申请号:US17810518

    申请日:2022-07-01

    CPC classification number: G06F16/1744 G06F16/1734

    Abstract: Method and apparatus for compressing raw event logs into smaller readable formats are described. An example includes receiving an uncompressed log file including traces of events executed on a computing system. In the uncompressed log file, a number of consecutive events are identified referencing an action performed with different parameters, and the uncompressed log file is modified by replacing the identified consecutive events with a record indicating that an event has been repeated the number of times. In the modified log file, repeated sequences of events are identified, a compressed log file is generated by replacing, in the modified log file, repeated sequences of events with a record referencing an initial repetition of events and a difference between parameters included in the initial repetition of events and a respective repeated sequence, and the generated compressed log file is output.

    Particle encoding for automatic sample processing

    公开(公告)号:US11868471B1

    公开(公告)日:2024-01-09

    申请号:US17159824

    申请日:2021-01-27

    CPC classification number: G06F21/564 G06F16/24578 G06F2221/033

    Abstract: A method of particle-based threat scanning may include obtaining a sample from a sample source, generating a plurality of particles from the sample, wherein each particle from the plurality of particles is an array of unique bytes generated based on one or more particle properties, and determining whether the sample is associated with a known threat by comparing the plurality of particles to particle threat signatures in a threat database.

    Optimization of high entropy data particle extraction

    公开(公告)号:US11803642B1

    公开(公告)日:2023-10-31

    申请号:US17219438

    申请日:2021-03-31

    CPC classification number: G06F21/565 G06F16/2237 G06F21/566 G06F2221/033

    Abstract: Techniques for particle-based threat scanning are described. A method of extracting particles from high entropy data may include obtaining a sample from a sample source, identifying an anchor particle in the sample, generating a plurality of particles following the anchor particle based on a particle limit, wherein each particle from the plurality of particles is an array of unique bytes generated based on one or more particle properties, and storing the plurality of particles following the anchor particle in a particle database.

    Generating readable, compressed event trace logs from raw event trace logs

    公开(公告)号:US11379421B1

    公开(公告)日:2022-07-05

    申请号:US16451799

    申请日:2019-06-25

    Abstract: Method and apparatus for compressing raw event logs into smaller readable formats are described. An example includes receiving an uncompressed log file including traces of events executed on a computing system. In the uncompressed log file, a number of consecutive events are identified referencing an action performed with different parameters, and the uncompressed log file is modified by replacing the identified consecutive events with a record indicating that an event has been repeated the number of times. In the modified log file, repeated sequences of events are identified, a compressed log file is generated by replacing, in the modified log file, repeated sequences of events with a record referencing an initial repetition of events and a difference between parameters included in the initial repetition of events and a respective repeated sequence, and the generated compressed log file is output.

Patent Agency Ranking