IP Library Granted Patent US 7,644,438
Granted Patent B1
US 7,644,438 · App. 10/975,962 · Granted Jan 5, 2010

Security event aggregation at software agent

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,644,438
App. No.
10/975,962
Granted
Jan 5, 2010
Kind
B1
Abstract

A network security system can have a plurality of distributed software agents configured to collect security events from network devices. In one embodiment, the agents are configured to aggregate the security events. In one embodiment of the present invention, an agent includes a device interface to receive a security event from a network device, a plurality of aggregation profiles, and an agent aggregate module to select one of the plurality of aggregation profiles, and increment an event count of an aggregate event representing the received security event using the selected aggregation profile.

Claims (56)

1. In a network security system, a method for aggregating security events, the method comprising:

receiving a security event from a network device;

selecting one of a plurality of aggregation profiles, wherein the selected aggregation profile defines a maximum time range;

identifying an aggregate event corresponding to the selected aggregation profile, wherein the aggregate event includes a count field whose value indicates how many security events are represented by the aggregate event;

incrementing the count field value to represent the received security event; and

transmitting the aggregate event when the time range of the security events represented by the aggregate event exceeds the maximum time range.

2. The method of claim 1 , wherein selecting the one aggregation profile comprises selecting an aggregation profile associated with an event filter when the received security event satisfies the event filter.

3. The method of claim 1 , wherein the selected aggregation profile further defines parameters for security events that are represented by the aggregate event.

4. The method of claim 1 , wherein the selected aggregation profile enumerates one or more event fields whose values must match for two events to be considered satisfactorily similar for aggregation.

5. The method of claim 4 , wherein the aggregate event contains only fields enumerated in the selected aggregation profile.

6. The method of claim 1 , wherein the selected aggregation profile further defines a maximum event count.

7. The method of claim 6 , further comprising transmitting the aggregate event when the incremented event count equals the maximum event count.

8. The method of claim 1 , further comprising:

selecting a second aggregation profile of the plurality of aggregation profiles;

identifying a second aggregate event corresponding to the second selected aggregation profile, wherein the second aggregate event includes a count field whose value indicates how many security events are represented by the second aggregate event; and

incrementing the count field value of the second aggregate event to represent the received security event.

9. The method of claim 8 , further comprising transmitting the second aggregate event to an entity different from the entity receiving the aggregate event.

10. The method of claim 1 , wherein the network device comprises a firewall or an intrusion detection system.

11. An agent of a network security system, the agent comprising:

a device interface to receive a security event from a network device;

a plurality of aggregation profiles; and

an agent aggregate module to:

select one of the plurality of aggregation profiles, wherein the selected aggregation profile defines a maximum time range;

identify an aggregate event corresponding to the selected aggregation profile, wherein the aggregate event includes a count field whose value indicates how many security events are represented by the aggregate event;

increment the count field value to represent the received security event; and

transmit the aggregate event when the time range of the security events represented by the aggregate event exceeds the maximum time range.

12. The agent of claim 11 , wherein the agent aggregate module comprises one or more event filters used to select the aggregation profile.

13. The agent of claim 11 , wherein the selected aggregation profile further defines parameters for security events that are represented by the aggregate event.

14. The agent of claim 11 , wherein the selected aggregation profile enumerates one or more event fields whose values must match for two events to be considered satisfactorily similar for aggregation.

15. The agent of claim 11 , wherein the selected aggregation profile enumerates one or more event fields preserved by the aggregate event.

16. The agent of claim 11 , wherein the selected aggregation profile further defines a maximum event count.

17. The agent of claim 11 , wherein the network device comprises a firewall or an intrusion detection system.

18. A machine-readable medium having stored thereon data representing instructions that, when executed by a processor, cause the processor to perform operations comprising:

receiving a security event from a network device;

selecting one of a plurality of aggregation profiles, wherein the selected aggregation profile defines a maximum time range;

identifying an aggregate event corresponding to the selected aggregation profile, wherein the aggregate event includes a count field whose value indicates how many security events are represented by the aggregate event;

incrementing the count field value to represent the received security event; and

transmitting the aggregate event when the time range of the security events represented by the aggregate event exceeds the maximum time range.

19. The machine-readable medium of claim 18 , wherein selecting the one aggregation profile comprises selecting an aggregation profile associated with an event filter when the received security event satisfies the event filter.

20. The machine-readable medium of claim 18 , wherein the selected aggregation profile further defines parameters for security events that are represented by the aggregate event.

21. The machine-readable medium of claim 18 , wherein the selected aggregation profile enumerates one or more event fields whose values must match for two events to be considered satisfactorily similar for aggregation.

22. The machine-readable medium of claim 21 , wherein the aggregate event contains only fields enumerated in the selected aggregation profile.

23. The machine-readable medium of claim 18 , wherein the selected aggregation profile further defines a maximum event count for the aggregate event.

24. The machine-readable medium of claim 18 , wherein the instructions further cause the processor to perform operations comprising:

selecting a second aggregation profile of the plurality of aggregation profiles;

identifying a second aggregate event corresponding to the second selected aggregation profile, wherein the second aggregate event includes a count field whose value indicates how many security events are represented by the second aggregate event; and

incrementing the count field value of the second aggregate event to represent the received security event.

25. The agent of claim 16 , wherein the agent aggregate module is further configured to transmit the aggregate event when the incremented event count equals the maximum event count.

26. The agent of claim 11 , wherein the agent aggregate module is further configured to:

select a second aggregation profile of the plurality of aggregation profiles;

identify a second aggregate event corresponding to the second selected aggregation profile, wherein the second aggregate event includes a count field whose value indicates how many security events are represented by the second aggregate event; and

increment the count field value of the second aggregate event to represent the received security event.

27. The agent of claim 26 , wherein the agent aggregate module is further configured to transmit the second aggregate event to an entity different from the entity receiving the aggregate event.

28. The machine-readable medium of claim 23 , wherein the instructions further cause the processor to perform operations comprising transmitting the aggregate event when the incremented event count equals the maximum event count.

29. The machine-readable medium of claim 24 , wherein the instructions further cause the processor to perform operations comprising transmitting the second aggregate event to an entity different from the entity receiving the aggregate event.

30. The machine-readable medium of claim 18 , wherein the network device comprises a firewall or an intrusion detection system.

Assignments (9)
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0577 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC)
Reel/Frame 063560/0001 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
CHANGE OF NAME Recorded Aug 8, 2019
From: ENTIT SOFTWARE LLC
To: MICRO FOCUS LLC
Reel/Frame 050004/0001 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ENTIT SOFTWARE LLC; ARCSIGHT, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0577 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 9, 2017
From: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
To: ENTIT SOFTWARE LLC
Reel/Frame 042746/0130 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 9, 2015
From: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 037079/0001 →
CERTIFICATE OF CONVERSION Recorded Nov 16, 2012
From: ARCSIGHT, INC.
To: ARCSIGHT, LLC.
Reel/Frame 029308/0908 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 16, 2012
From: ARCSIGHT, LLC.
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 029308/0929 →