IP Library Granted Patent US 8,352,589
Granted Patent B2
US 8,352,589 · App. 11/316,452 · Granted Jan 8, 2013

System for monitoring computer systems and alerting users of faults

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,352,589
App. No.
11/316,452
Granted
Jan 8, 2013
Kind
B2
Abstract

A System is monitored by detecting activity signatures of network components. Some of the activity signatures are generated by sensing patterns of operations in data streams. Some of the activity signatures are precompiled in the system, or are standard in computer systems. The activity signatures are stored in a database. Select information about select baselined attributes generates monitoring profiles (MPs) for the baselined attributes. The MPs are defined so abnormal behavior of end points and/or system components can be detected. The system compiles baseline values for baselined attributes of MP's. By properly analyzing deviating end points or components one can determine what is causing a problem or who is effected by a problem based on which identifying attributes are common to the deviating end points or components.

Claims (37)

1. A method of adaptively monitoring a computer network, the method comprising:

providing a computer network that includes a plurality of associated network components and a plurality of terminals connected thereto, the pluralities of network components and terminals configured to run a plurality of application programs at least one of which is configured to perform one or more user initiated activities, two or more of the network components and/or terminals being associated with one or more identifying attributes, each identifying attribute being a value that can be determined at a given time for any network component or terminal;

providing one or more activity signatures each usable to detect that a specific activity has been performed;

detecting, using the one or more activity signatures, one or more baselined attributes of one or more user initiated activities of the two or more of the network components and/or terminals, each baselined attribute being defined by its own signature that may extend beyond an associated activity signature;

measuring, after the detecting, one or more of the same baselined attribute values of the two or more network components and/or terminals; and

grouping network components and/or terminals into a plurality of subsets thereof based on the measured attribute values so as to yield group descriptions, each group description describing a group of the network components and/or terminals whose members share related characteristics in the measured baselined attribute values, the yielded group descriptions being monitoring profiles that are usable to detect abnormal behavior of a member or members of the described group.

2. The method of claim 1 , wherein, depending on sensitivity settings and types of problems a user wishes to detect, critical values to be used by a detection system for each monitoring profile are generated.

3. The method of claim 1 , wherein one or more of the activity signatures is adaptively generated using an adaptive monitoring method.

4. The method of claim 1 , wherein the activity signatures are a series of opcodes each indicating that a unique operation of a specific user driven activity has been executed by an application, and

wherein each activity signature indicates a start and an end of a specific user driven activity.

5. The method of claim 1 , wherein at least one of the activity signatures is defined by a user.

6. The method of claim 1 , wherein the grouping is done by using logistic regression.

7. The method of claim 1 , wherein the grouping is done by using decision tree logic.

8. The method of claim 1 , wherein at least one of the network components and/or terminals is described by two or more group descriptions.

9. A method of adaptively monitoring a computer network the method comprising:

providing a computer network that includes a plurality of associated network components and a plurality of terminals connected thereto, the pluralities of network components and terminals configured to run a plurality of application programs at least one of which is configured to perform one or more user initiated activities, the execution of each activity generating a data stream;

detecting opcodes in one or more data streams resulting from the execution of the one or more activities multiple times, each opcode indicating that a unique operation of a specific user driven activity has been executed by an application;

providing one or more activity signatures each usable to detect that a specific activity has been performed;

detecting, using the one or more activity signatures, one or more baselined attributes of one or more user initiated activities of the two or more of the network components and/or terminals;

measuring, after the detecting, one or more of the same baselined attributes of the two or more network components and/or terminals, each baselined attribute defined by its own signature that may extend beyond an associated activity signature;

grouping network components and/or terminals into a plurality of subsets thereof based on (i) the measured attribute values and (ii) the identifying characteristics so as to yield group descriptions, each group description describing a group of the network components and/or terminals whose members share related characteristics in the measured baselined attribute values, the yielded descriptions being monitoring profiles; and

using the monitoring profiles as identifiable groups of network components and/or terminals to detect abnormal behavior of a member or members of the yielded groups by comparing the measured baselined values against expected baselined values in real time.

10. A system for adaptively monitoring a computer network, the system comprising:

a plurality of associated network components and a plurality of terminals connected thereto, the pluralities of network components and terminals configured to run a plurality of application programs at least one of which is configured to perform one or more user initiated activities, two or more of the network components and/or terminals being associated with one or more identifying attributes, each identifying attribute being a value that can be determined at a given time for any network component or terminal;

a storage section that provides one or more activity signatures each usable to detect that a specific activity has been performed;

a detecting section that detects, using the one or more activity signatures, one or more baselined attributes of one or more user initiated activities of the two or more of the network components and/or terminals, each baselined attribute being defined by its own signature that may extend beyond an associated activity signature;

a measuring section that measures, after the detecting, one or more of the same baselined attribute values of the two or more network components and/or terminals; and

a logic section that groups network components and/or terminals into a plurality of subsets thereof based on the measured attribute values so as to yield group descriptions, each group description describing a group of the network components and/or terminals whose members share related characteristics in the measured baselined attribute values, the yielded descriptions being monitoring profiles that are usable to detect abnormal behavior of a member or members of the described group.

11. A system for adaptively monitoring a computer network, the system comprising:

a plurality of associated network components and a plurality of terminals connected thereto, the pluralities of network components and terminals configured to run a plurality of application programs at least one of which is configured to perform one or more user initiated activities, the execution of each activity generating a data stream;

a first detecting section that detects opcodes in one or more data streams resulting from the execution of the one or more activities multiple times, each opcode indicating that a unique operation of a specific user driven activity has been executed by an application;

a storage section that provides one or more activity signatures each usable to detect that a specific activity has been performed;

a second detecting section that detects, using the one or more activity signatures, one or more baselined attributes of one or more user initiated activities of the two or more of the network components and/or terminals;

a measuring section that measures, after the detecting, one or more of the same baselined attributes of the two or more network components and/or terminals, each baselined attribute defined by its own signature that may extend beyond an associated activity signature;

a logic section that groups network components and/or terminals into a plurality of subsets thereof based on (i) the measured attribute values and (ii) the identifying characteristics so as to yield group descriptions, each group description describing a group of the network components and/or terminals whose members share related characteristics in the measured baselined attribute values, the yielded descriptions being monitoring profiles; and

a monitoring section that used the monitoring profiles as identifiable groups of network components and/or terminals to detect abnormal behavior of a member or members of the yielded groups by comparing the measured baselined values against expected baselined values in real time.

12. The method of claim 9 , wherein the activity signatures are a series of opcodes each indicating that a unique operation of a specific user driven activity has been executed by an application.

Assignments (17)
RELEASE OF SECURITY INTEREST Recorded Aug 11, 2023
From: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC; RIVERBED HOLDINGS, INC.
Reel/Frame 064673/0739 →
CHANGE OF NAME Recorded Feb 10, 2022
From: RIVERBED TECHNOLOGY, INC.
To: RIVERBED TECHNOLOGY LLC
Reel/Frame 059009/0906 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS U.S. COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0169 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0046 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0108 →
SECURITY INTEREST Recorded Dec 10, 2021
From: RIVERBED TECHNOLOGY LLC (FORMERLY RIVERBED TECHNOLOGY, INC.); ATERNITY LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS U.S. COLLATERAL AGENT
Reel/Frame 058486/0216 →
PATENT SECURITY AGREEMENT Recorded Oct 27, 2021
From: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 057943/0386 →
PATENT SECURITY AGREEMENT SUPPLEMENT - FIRST LIEN Recorded Oct 14, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 057810/0502 →
PATENT SECURITY AGREEMENT SUPPLEMENT - SECOND LIEN Recorded Oct 14, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 057810/0559 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORED AT REEL 056397, FRAME 0750 Recorded Oct 13, 2021
From: MACQUARIE CAPITAL FUNDING LLC
To: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 057983/0356 →
SECURITY INTEREST Recorded May 26, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: MACQUARIE CAPITAL FUNDING LLC
Reel/Frame 056397/0750 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 30, 2020
From: RIVERBED TECHNOLOGY, INC.
To: ATERNITY LLC
Reel/Frame 054778/0540 →
PATENT SECURITY AGREEMENT Recorded Jul 10, 2019
From: RIVERBED TECHNOLOGY, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 049720/0808 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN INTELLECTUAL PROPERTY RECORDED AT REEL 037470/FRAME 0528 Recorded Sep 14, 2017
From: KREOS CAPITAL V (EXPERT FUND) L.P.
To: ATERNITY INFORMATION SYSTEMS LTD.
Reel/Frame 043865/0070 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 23, 2017
From: ATERNITY INFORMATION SYSTEMS LTD.
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 041361/0892 →
SECURITY INTEREST Recorded Jan 13, 2016
From: ATERNITY INFORMATION SYSTEMS LTD.
To: KREOS CAPITAL V (EXPERT FUND) L.P.
Reel/Frame 037470/0528 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 22, 2005
From: RIDEL, LENNY; LAHAV, SHLOMO; RUBINSHTEIN, MIKI; FREYDIN, BORIS; SCHOCHAT, EDEN; KAPON, ORIT KISLEV
To: ATERNITY INFORMATION SYSTEMS LTD.
Reel/Frame 017413/0376 →