Processing device and method of edr-based message queue
A message queue and processing device technology, applied in the field of network security, can solve the problems of unable to ensure orderly sending of log information, unable to accurately match target objects, etc.
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Embodiment 1
[0039] figure 1 and figure 2 It is a schematic diagram of an EDR-based message queue processing device provided in Embodiment 1 of the present invention.
[0040] refer to figure 1 and figure 2 , the device is applied on a server, and the device includes a processing module 1, a matching module 2 and a process 3, wherein the processing module 1 includes an engine;
[0041] The processing module 1 is used to receive the log information sent by the terminal detection and response EDR client, and send the log information to the engine;
[0042] Here, after receiving the log information sent by the responding EDR client, the processing module 1 can determine which EDR client sends it according to the ID of the EDR client.
[0043] The engine is used to obtain the time information of receiving the log information according to the log information, and associate the identifier ID of the EDR client in the log information, the time information and the ID of the engine to obtain t...
Embodiment 2
[0064] image 3 It is a flow chart of the processing method of the EDR-based message queue provided by Embodiment 2 of the present invention.
[0065] refer to image 3 , applied on the server, the method includes the following steps:
[0066] Step S101, the receiving terminal detects and responds to the log information sent by the EDR client, and sends the log information to the engine;
[0067] Step S102, the engine obtains the time information of receiving the log information according to the log information, and associates the identifier ID of the EDR client in the log information, the time information and the ID of the engine to obtain the associated ID;
[0068] Step S103, look up the corresponding process ID according to the association ID, and send the association ID to the corresponding process according to the process ID.
[0069] Further, the method also includes the following steps:
[0070] Step S201, analyzing the associated ID to obtain the ID of the EDR cli...
PUM
Abstract
Description
Claims
Application Information
- R&D Engineer
- R&D Manager
- IP Professional
- Industry Leading Data Capabilities
- Powerful AI technology
- Patent DNA Extraction
Browse by: Latest US Patents, China's latest patents, Technical Efficacy Thesaurus, Application Domain, Technology Topic, Popular Technical Reports.
© 2024 PatSnap. All rights reserved.Legal|Privacy policy|Modern Slavery Act Transparency Statement|Sitemap|About US| Contact US: help@patsnap.com