IP Library Granted Patent US 8,104,087
Granted Patent B2
US 8,104,087 · App. 11/970,650 · Granted Jan 24, 2012

Systems and methods for automated data anomaly correction in a computer network

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,104,087
App. No.
11/970,650
Granted
Jan 24, 2012
Kind
B2
Abstract

Systems and methods for correcting an anomaly in a target computer that is part of a network of computers. An anomaly is detected in data stored on a target computer and it is determined what corrective data is needed to correct the anomaly. A donor computer with the corrective data is located and requested to provide the corrective data to the target computer. The corrective data is used to correct the anomaly on the target computer and the target computer may acknowledge receipt of the corrective data. In one embodiment, an arbitrator component receives the requests for the corrective data, passes the requests to potential donor computers, and receives the acknowledgements from the target computers.

Claims (52)

1. A method for correcting an anomaly in a target computer that is part of a network of computers, the method comprising:

determining first corrective data needed to correct the anomaly in the target computer, wherein the target computer is part of the network of computers, the target computer comprising an agent component that is configured to detect the anomaly, wherein the anomaly is identified by:

receiving respective snapshots from computers in the network of computers including the target computer, wherein one of the snapshots includes the data having the anomaly;

creating an adaptive reference model based at least in part on the respective snapshots, wherein the adaptive reference model is operable to identify statistically significant patterns among the respective snapshots; and

comparing at least one of the respective snapshots to the adaptive reference model;

sending, using the agent component in the target computer, a request for the first corrective data;

locating a donor computer among the plurality of computers in the network, wherein the donor computer includes the first corrective data that is needed to correct the anomaly and wherein the donor computer comprises a same agent component as the target computer;

receiving the first corrective data at the target computer from the donor computer;

correcting the anomaly in the data stored on the target computer using the first corrective data;

receiving, at the target computer a request for second corrective data, wherein the request for second corrective data is sent from the donor computer; and

sending, using the agent component in the target computer, the second corrective data for use by the donor computer, such that the target computer acts as a donor computer for purposes of the second corrective data.

2. The method of claim 1 , wherein the anomaly comprises a missing file, missing data, or a missing portion of a file or missing data.

3. The method of claim 1 , wherein the anomaly comprises a missing registry key.

4. The method of claim 1 , wherein the anomaly comprises a corrupted file or corrupted data.

5. The method of claim 1 , wherein the anomaly comprises a corrupted registry key.

6. The method of claim 1 , further comprising:

sending a request from the target computer to an arbitrator, the request being for the first corrective data.

7. The method of claim 6 , further comprising:

sending a donation request from the arbitrator to the donor computer, the donation request being for the first corrective data.

8. The method of claim 7 , further comprising:

receiving at the arbitrator a donation request failure message from the donor computer when the donor computer is not able to provide the first corrective data.

9. The method of claim 1 , wherein the step of locating the donor computer comprises determining a physical location of the donor computer.

10. The method of claim 1 , further comprising deleting data from the target computer.

11. A system for correcting an anomaly in data stored on a computer, comprising:

a target computer, which is among a plurality of computers in a network of computers, having detected the anomaly in data stored therein, the target computer comprising an agent component that is configured to detect the anomaly and to send a request for a first asset;

an arbitrator configured to receive the request for the first asset from the target computer, the first asset being sufficient to correct the anomaly once loaded on the target computer;

at least one donor computer that receives a donation request from the arbitrator and in response thereto supplies the requested first asset to the target computer, the at least one donor computer comprising a same agent component as the target computer,

wherein the arbitrator is configured to receive from the agent component on the at least one donor computer a request for another asset, and wherein the agent component on the target computer is configured to receive a donation request from the arbitrator and in response thereto supply the another asset to the at least one donor computer; and

an analytics module that is configured to detect and identify the anomaly in data stored on the target computer, the analytics module is configured to:

receive respective snapshots from the plurality of computers including the target computer, wherein at least one of the snapshots includes the data having the anomaly;

create an adaptive reference model based at least in part on the snapshots, wherein the adaptive reference model is operable to identify statistically significant patterns in the snapshots;

compare the at least one of the snapshots to the adaptive reference model; and

identify the anomaly and the target computer based on the comparison.

12. The system of claim 11 , wherein the arbitrator is configured to send multiple respective donation requests to multiple donor computers.

13. The system of claim 11 , wherein the target computer is configured to acknowledge receipt of the first asset.

14. The system of claim 11 , wherein the arbitrator is configured to send a second donation request to a second donor computer when a first donation request to a first donor computer has resulted in a failure.

15. The system of claim 11 , wherein the agent component on the donor computer is in communication with at least the arbitrator.

16. The system of claim 15 , wherein the agent component on the target computer is operable to communicate with the agent component on the at least one donor computer.

17. The system of claim 11 , wherein the anomaly comprises at least one of a missing file, a missing portion of a file, a missing registry key, a corrupted file, or a corrupted registry key.

18. An automated method of curing an anomaly in a computer that is part of a network of computers, comprising:

receiving an asset request from a target computer, the asset request being for corrective content that is to replace or augment data on the target computer and thereby cure the anomaly in selected data stored on the target computer, the target computer comprising an agent component that is configured to detect the anomaly, wherein the anomaly is identified by:

receiving respective snapshots from computers in the network of computers including the target computer, wherein one of the snapshots includes the data having the anomaly;

creating an adaptive reference model based at least in part on the respective snapshots, wherein the adaptive reference model is operable to identify statistically significant patterns among the respective snapshots; and

comparing at least one of the respective snapshots to the adaptive reference model;

transforming the asset request into a donation request and sending the donation request to at least one donor computer, the at least one donor computer comprising a same agent component as the target computer;

receiving from the target computer an indication that the asset has been received from the donor computer;

receiving a second asset request from the at least one donor computer, the second asset request being for second corrective content that is to replace or augment data on the at least one donor computer;

transforming the second asset request into a second donation request and sending the second donation request to the target computer; and

receiving from the at least one donor computer an indication that the second asset has been received from the target computer.

19. The method of claim 18 , further comprising receiving from an Analytics component an identification of the at least one donor computer.

20. The method of claim 18 , further comprising sending multiple donation requests to multiple donor computers.

21. The method of claim 20 , further comprising keeping track of pending donation requests.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 19, 2021
From: TRIUMFANT, INC.; NEHEMIAH SECURITY, INC.
To: RPX CORPORATION
Reel/Frame 054957/0894 →
PATENT SECURITY AGREEMENT Recorded Oct 23, 2020
From: RPX CLEARINGHOUSE LLC; RPX CORPORATION
To: BARINGS FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 054198/0029 →
PATENT SECURITY AGREEMENT Recorded Oct 23, 2020
From: RPX CLEARINGHOUSE LLC; RPX CORPORATION
To: BARINGS FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 054244/0566 →