IP Library Patent Application 11313710
Patent Application
App. No. 11/313,710

System and method for managing events

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
11/313,710
Abstract

Systems and methods to manage logs from log sources distributed across one or more networks using a log event management system, herein called a Thunder console. The Thunder console is a log aggregator that allows networks to deploy servers which collect, normalize, and analyze a large number of log events. These logs can be stored for a specific period of time. Alerts can be generated to communicate information regarding the log events.

Claims (28)

1 . A method for managing log events in a network, comprising:

receiving a plurality of log messages in SYSLOG format from log sources across the network;

detecting log events from the plurality of log messages;

normalizing detected log events to generate normalized log events; and

analyzing the normalized log events.

2 . The method of claim 1 , further comprising:

communicating an alert when a deviation occurs.

3 . The method of claim 1 , wherein analyzing includes correlating the normalized log events with intrusion events and vulnerability information.

4 . The method of claim 1 , wherein normalizing includes using statistical profiling.

5 . The method of claim 1 , further comprising receiving at an agent bundled log messages; and

detecting log events from the bundled log messages.

6 . The method of claim 1 , wherein the log sources include at least three sources from the group: firewalls, intrusion prevention systems, operating systems, network devices, applications, intrusion detection systems, honeypots, virus detection systems and network monitors.

7 . The method of claim 1 , wherein normalizing includes determining whether a log event is unique.

8 . The method of claim 1 , wherein detecting includes extracting source and destination IP addresses.

9 . The method of claim 1 , wherein normalizing includes computing a normal load for each log source.

10 . A system for managing log events in a network, comprising:

a plurality of log sources distributed across the network; and

a centralized log aggregation system for receiving a plurality of log messages in SYSLOG format from the plurality of log sources,

wherein the centralized log aggregation system detects log events from the plurality of log messages, normalizes detected log events to generate normalized log events, and analyzes the normalized log events.

11 . The system of claim 10 , wherein the centralized log aggregation system communicates an alert when a deviation occurs.

12 . The system of claim 10 , wherein the centralized log aggregation system correlates the normalized log events with intrusion events and vulnerability information.

13 . The system of claim 10 , wherein the centralized log aggregation system uses statistical profiling to normalized log events.

14 . The system of claim 10 , further comprising:

a first agent for receiving, processing and forwarding bundled log messages from a log source or a second agent to the centralized log aggregation system.

15 . The system of claim 10 , wherein the plurality of log sources include at least three sources from the group: firewalls, intrusion prevention systems, operating systems, network devices, applications, intrusion detection systems, honeypots, virus detection systems and network monitors.

16 . The system of claim 10 , wherein the centralized log aggregation system determines whether a log event is unique when normalizing.

17 . The system of claim 10 , wherein the centralized log aggregation system extracts source and destination IP addresses when detecting.

18 . The system of claim 10 , wherein the centralized log aggregation system computer a normal load for each log source when normalizing.

Assignments (2)
CHANGE OF NAME Recorded Aug 29, 2018
From: TENABLE NETWORK SECURITY, INC.
To: TENABLE, INC.
Reel/Frame 046974/0077 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 30, 2006
From: GULA, RONALD JOSEPH; DERAISON, RENAUD MARIE MAURICE; HAYTON, MATTHEW TODD
To: TENABLE NETWORK SECURITY, INC.
Reel/Frame 017745/0033 →