| CPC H04L 63/1425 (2013.01) [G06F 21/552 (2013.01); G06F 21/554 (2013.01); H04L 63/1416 (2013.01); H04L 63/1441 (2013.01); H04L 63/1475 (2013.01)] | 20 Claims |

|
1. A method of threat detection in a computer network, the method comprising:
detecting, by a first node, a security threat at the first node;
collecting context information at the first node relating to the detected security threat;
reporting at least one detected security threat and the collected context information to at least a second node;
analyzing, at the second node, the received information relating to the security threat and collecting context information relating to the analysis at the second node; and
sending the threat related information with added analysis and context information collected from the second node to at least one further node or backend,
wherein the first node, the second node, and the at least one further node are computers, smartphones, tablets, or laptops.
|