IP Library Granted Patent US 12699640
Granted Patent B2
US 12699640 · App. 17/492,339 · Granted Aug 4, 2026

Systems and methods for assessing operational states of a computer environment

Inventor: Amine Hamdi (Boston, MA)
Assignee: Acentium Inc.
G06F11/3457G06F9/5077G06F11/0706G06F11/0754G06F11/0793G06F11/3055
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12699640
App. No.
17/492,339
Granted
Aug 4, 2026
Kind
B2
Abstract

Systems and methods for threat response in computer environments can include detecting, by one or more processors, using performance data of a computer environment, an event that occurred and that is indicative of abnormal performance of the computer environment. The one or more processors can identify, among a plurality of assets of the computer environment, a subset of assets associated with the event, and determine from a predefined set of resolutions a plurality of resolutions executable to address a cause of the event. The one or more processors can execute, for each resolution of the plurality of resolutions, a trained model to simulate the resolution for the subset of assets, and select, based at least on results of simulation of each resolution, a resolution among the plurality of resolutions to be implemented.

Claims (62)

1 . A system comprising:

one or more processors; and

a memory storing computer code instructions, the computer code instructions, when executed by the one or more processors, cause the one or more processors to:

detect, using performance data of a computer environment, an event that occurred and that is indicative of abnormal performance of the computer environment;

identify, among a plurality of assets of the computer environment, a subset of assets associated with the event;

select, based on a type of the event, from a predefined set of resolutions stored in one or more data structures, a plurality of resolutions executable to address a cause of the event;

retrieve, from a database, for each resolution of the plurality of resolutions, a version of a trained model, of a plurality of versions of the trained model, of at least a subsystem of the computer environment corresponding to each resolution, each version of the trained model including a plurality of asset models corresponding to the subset of assets associated with the event, each version of the trained model comprising a neural network trained with past performance data and configured to represent a corresponding resolution of the plurality of resolutions, each corresponding resolution comprising one or more modifications to one or more configuration parameters of one or more of the subset of assets different from one or more modifications of another resolution;

execute a simulation, for each resolution of the plurality of resolutions, using each version of the trained model to simulate each resolution for the subset of assets, the one or more processors providing as input, to each version of the trained model, a traffic load corresponding to a traffic at a time of the event; and

select, based at least on results of simulation of each resolution using each version of the trained model, a resolution among the plurality of resolutions that did not reach a fail state.

2 . The system of claim 1 , wherein the one or more processors are further configured to implement the selected resolution within the computer environment.

3 . The system of claim 1 , wherein the one or more processors are further configured to provide information related to implementation of the selected resolution for display on a display device.

4 . The system of claim 1 , wherein the one or more processors are configured to detect the event upon determining that a performance parameter of the computer environment exceeds a predefined threshold value over at least a predefined time duration.

5 . The system of claim 1 , wherein the one or more processors are configured to detect the event upon detecting one or more predefined states for one or more assets of the computer environment.

6 . The system of claim 1 , wherein the plurality of resolutions can include at least one of:

increasing redundancy for one or more assets of the subset of assets;

adding a load balancer to the computer environment;

adding more storage resources to the computer environment;

adding more computing resources to the computer environment;

modifying an architecture of the subset of assets; or

modifying a configuration parameter of one or more assets of the computer environment.

7 . The system of claim 1 , wherein the one or more processors are configured to select the plurality of resolutions based on the type of the event.

8 . The system of claim 1 , wherein the one or more processors are configured to provide as input to execution of the trained model a processing load corresponding to a processing load of the subset of assets at the time of the event.

9 . The system of claim 1 , wherein the one or more processors are further configured to display a simulation window for executing the trained model, the simulation window depicting simulation progress of the resolution corresponding to the executing trained model.

10 . The system of claim 1 , wherein the performance data of the computer environment includes at least one of:

one or more parameters indicative of an amount of usage of computational resources;

one or more parameters indicative of an amount of usage of memory resources;

one or more parameters indicative of an amount of usage of network resources; or

indications of states of the plurality of assets of the computer environment.

11 . A method comprising:

detecting, by one or more processors, using performance data of a computer environment, an event that occurred and that is indicative of abnormal performance of the computer environment;

identifying, by the one or more processors, among a plurality of assets of the computer environment, a subset of assets associated with the event;

selecting, by the one or more processors based on a type of the event, from a predefined set of resolutions stored in one or more data structures, a plurality of resolutions executable to address a cause of the event;

retrieving, by the one or more processors, from a database, for each resolution of the plurality of resolutions, a version of a trained model, of a plurality of versions of the trained model, of at least a subsystem of the computer environment corresponding to each resolution, each version of the trained model including a plurality of asset models corresponding to the subset of assets associated with the event, each version of the trained model comprising a neural network trained with past performance data and configured to represent a corresponding resolution of the plurality of resolutions, each corresponding resolution comprising one or more modifications to one or more configuration parameters of one or more of the subset of assets different from one or more modifications of another resolution;

executing, by the one or more processors, a simulation for each resolution of the plurality of resolutions, using each version of the trained model to simulate each resolution for the subset of assets, the one or more processors providing as input, to each version of the trained model, a traffic load corresponding to a traffic at a time of the event; and

selecting, by the one or more processors, based at least on results of simulation of each resolution using each version of the trained model, a resolution among the plurality of resolutions that did not reach a fail state.

12 . The method of claim 11 , further comprising at least one of:

implementing the selected resolution within the computer environment; or

providing information related to implementation of the selected resolution for display on a display device.

13 . The method of claim 11 , comprising detecting the event upon determining that a performance parameter of the computer environment exceeds a predefined threshold value over at least a predefined time duration.

14 . The method of claim 11 , comprising detecting the event upon detecting one or more predefined states for one or more assets of the computer environment.

15 . The method of claim 11 , wherein the plurality of resolutions can include at least one of:

increasing redundancy for one or more assets of the subset of assets;

adding a load balancer to the computer environment;

adding more storage resources to the computer environment;

adding more computing resources to the computer environment;

modifying an architecture of the subset of assets; or

modifying a configuration parameter of one or more assets of the computer environment.

16 . The method of claim 11 , comprising selecting the plurality of resolutions based on the type of the event.

17 . The method of claim 11 , wherein executing the trained model to simulate the plurality of resolutions for the subset of assets includes providing as input to executing the trained model a processing load corresponding to a processing load of the subset of assets at the time of the event.

18 . The method of claim 11 , wherein the one or more processors are further configured to display a simulation window for executing trained model, the simulation window depicting simulation progress of the resolution corresponding to the executing trained model.

19 . The method of claim 11 , wherein the performance data of the computer environment includes at least one of:

one or more parameters indicative of an amount of usage of computational resources;

one or more parameters indicative of an amount of usage of memory resources;

one or more parameters indicative of an amount of usage of network resources; or

indications of states of the plurality of assets of the computer environment.

20 . A non-transitory computer-readable medium storing computer executable instructions, the computer executable instructions when executed by one or more processors cause the one or more processors to:

detect, using performance data of a computer environment, an event that occurred and that is indicative of abnormal performance of the computer environment;

identify, among a plurality of assets of the computer environment, a subset of assets associated with the event;

select, based on a type of the event, from a predefined set of resolutions stored in one or more data structures, a plurality of resolutions executable to address a cause of the event;

retrieve, from a database, for each resolution of the plurality of resolutions, a version of a trained model, of a plurality of versions of the trained model, of at least a subsystem of the computer environment corresponding to each resolution, each version of the trained model including a plurality of asset models corresponding to the subset of assets associated with the event, each version of the trained model comprising a neural network trained with past performance data and configured to represent a corresponding resolution of the plurality of resolutions, each corresponding resolution comprising one or more modifications to one or more configuration parameters of one or more of the subset of assets different from one or more modifications of another resolution;

execute a simulation, for each resolution of the plurality of resolutions, using each version of the trained model to simulate the each resolution for the subset of assets, the one or more processors providing as input, to each version of the trained model, a traffic load corresponding to a traffic at a time of the event; and

select, based at least on results of simulation of each resolution using each version of the trained model, a resolution among the plurality of resolutions that did not reach a fail state.