US20030191962A1

System, method and program product for automatically collecting state information for computer system intrusion analysis

Claim Score by NHIP

Read claim 9, the broadest

Abstract

A system, method and program product for automatically collecting state information for computer system intrusion analysis is provided. Specifically, the present invention is used to automatically collect state information in the event of computer network intrusion. When executed, the present invention will detect a type of a platform operating on a computer system (e.g., the server). Then, using the utilities of the platform, the desired state information will be located and/or collected. Thus, the present invention provides the uniformity of information collection that was not previously possible due to manual collection techniques and varying platform types.

US20030191962A1, drawing sheet 1
Sheet 1 of 4

Term

Term ended

Projected expiry passed 30 June 2024, 2.2 years ago.

  1. Priority and filed
  2. Published
  3. Projected expiry
  4. Today

23 claims: 3 independent, 20 dependent

  1. 1
    A system for automatically collecting state information for computer system intrusion analysis, comprising:a platform identification system for automatically identifying a type of a platform loaded on a computer system;and a state system for automatically collecting state information pertaining to a state of the computer system, wherein the state information is located with utilities of the identified platform.
  2. 9
    Broadest claimClaim Score 85, broad(NHIP)A method for automatically collecting state information for computer system intrusion analysis, comprising the steps of:identifying a type of a platform loaded on a computer system;locating state information pertaining to a state of the computer system using utilities of the identified platform;and automatically collecting the located state information from the computer system.
  3. 16
    A program product stored on a recordable medium for automatically collecting state information for computer system intrusion analysis, which when executed comprises:program code for automatically identifying a type of a platform loaded on a computer system;and program code for automatically collecting state information pertaining to a state of the computer system, wherein the state information is located with utilities of the identified platform.