IP Library Granted Patent US 7,984,502
Granted Patent B2
US 7,984,502 · App. 12/243,838 · Granted Jul 19, 2011

Pattern discovery in a network system

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,984,502
App. No.
12/243,838
Granted
Jul 19, 2011
Kind
B2
Abstract

Patterns can be discovered in events collected by a network system. In one embodiment, the present invention includes collecting and storing events from a variety of monitor devices. In one embodiment, a subset of the stored events is provided to a manager as an event stream. In one embodiment, the present invention further includes the manager discovering one or more previously unknown event patterns in the event stream.

Claims (51)

1. A method for discovering an event pattern in an event stream, the event stream comprising a plurality of events, the method comprising:

using a processor to create a plurality of transactions based on a transaction parameter, wherein each transaction represents a subset of the plurality of events;

generating a transaction tree based on the plurality of transactions, wherein the transaction tree includes one root node and a plurality of non-root nodes, and

wherein each non-root node represents an event;

traversing a branch of the transaction tree starting at the root node, wherein the branch extends from the root node through a first non-root node to a second non-root node;

observing a drop in support from the first non-root node to the second non-root node, wherein a support of a non-root node represents a number of transactions that include the event represented by the non-root node; and

determining that the event pattern includes the event represented by the first non-root node and does not include the event represented by the second non-root node.

2. The method of claim 1 , wherein the plurality of events had been stored in an event database.

3. The method of claim 1 , wherein the transaction parameter comprises an interval of time, and wherein each transaction represents events that were received during the interval of time.

4. The method of claim 1 , wherein the transaction parameter comprises a value of an event field, and wherein each transaction represents events that include the value of the event field.

5. The method of claim 4 , wherein the event field comprises a source address.

6. The method of claim 4 , wherein the event field comprises a destination address.

7. The method of claim 1 , wherein the transaction parameter comprises a point in time, and wherein each transaction represents events that were received proximate to the point in time.

8. The method of claim 1 , wherein generating the transaction tree based on the plurality of transactions comprises generating the transaction tree based on a support of an event within the plurality of transactions.

9. The method of claim 1 , further comprising removing a field from each event in the plurality of events.

10. The method of claim 9 , wherein a value of the field is unique to each event.

11. The method of claim 1 , further comprising providing a user an option to convert the event pattern into an event correlation rule.

12. The method of claim 1 , further comprising creating an event correlation rule using the event pattern.

13. A method for generating a rule, comprising:

displaying a pattern discovery tool configured to enable a user to select a subset of previously stored events;

in response to the user selection:

using a processor to create a plurality of transactions based on a transaction parameter, wherein each transaction represents a subset of the selected events;

generating a transaction tree based on the plurality of transactions, wherein the transaction tree includes one root node and a plurality of non-root nodes, and wherein each non-root node represents an event;

traversing a branch of the transaction tree starting at the root node, wherein the branch extends from the root node through a first non-root node to a second non-root node;

observing a drop in support from the first non-root node to the second non-root node, wherein a support of a non-root node represents a number of transactions that include the event represented by the non-root node; and

determining that the event pattern includes the event represented by the first non-root node and does not include the event represented by the second non-root node;

displaying a rule generation tool configured to enable a user to perform an action; and

in response to the user action, converting the event pattern into a correlation rule.

14. The method of claim 13 , wherein the user action comprises a single mouse-click.

15. A system for discovering an event pattern in an event stream, the event stream comprising a plurality of events, the system comprising

creating a plurality of transactions based on a transaction parameter, wherein each transaction represents a subset of the plurality of events;

generating a transaction tree based on the plurality of transactions, wherein the transaction tree includes one root node and a plurality of non-root nodes, and wherein each non-root node represents an event;

traversing a branch of the transaction tree starting at the root node, wherein the branch extends from the root node through a first non-root node to a second non-root node;

observing a drop in support from the first non-root node to the second non-root node, wherein a support of a non-root node represents a number of transactions that include the event represented by the non-root node; and

determining that the event pattern includes the event represented by the first non-root node and does not include the event represented by the second non-root node.

16. The system of claim 15 , wherein the transaction parameter comprises an interval of time, and wherein each transaction represents events that were received during the interval of time.

17. The system of claim 15 , wherein the transaction parameter comprises a value of an event field, and wherein each transaction represents events that include the value of the event field.

18. The system of claim 15 , wherein the transaction parameter comprises a point in time, and wherein each transaction represents events that were received proximate to the point in time.

19. The system of claim 15 , wherein generating the transaction tree based on the plurality of transactions comprises generating the transaction tree based on a support of an event within the plurality of transactions.

20. The system of claim 15 , wherein the method further comprises removing a field from each event in the plurality of events.

21. The system of claim 15 , wherein the method further comprises displaying a user interface to provide a user a tool to convert the event pattern into an event correlation rule.

22. A non-transitory machine-readable storage medium having stored thereon data representing instructions that, when executed by a processor, cause the processor to perform operations comprising:

creating a plurality of transactions based on a transaction parameter, wherein each transaction represents a subset of a plurality of events;

generating a transaction tree based on the plurality of transactions, wherein the transaction tree includes one root node and a plurality of non-root nodes, and wherein each non-root node represents an event;

traversing a branch of the transaction tree starting at the root node, wherein the branch extends from the root node through a first non-root node to a second non-root node;

observing a drop in support from the first non-root node to the second non-root node, wherein a support of a non-root node represents a number of transactions that include the event represented by the non-root node; and

determining that the event pattern includes the event represented by the first non-root node and does not include the event represented by the second non-root node.

23. The non-transitory machine-readable storage medium of claim 22 , wherein generating the transaction tree based on the plurality of transactions comprises generating the transaction tree based on a support of an event within the plurality of transactions.

24. The non-transitory machine-readable storage medium of claim 22 , wherein the operations further comprise removing a field from each event in the plurality of events.

25. The non-transitory machine-readable storage medium of claim 22 , wherein the operations further comprise providing a user an option to convert the event pattern into an event correlation rule.

26. The non-transitory machine-readable storage medium of claim 22 , wherein the operations further comprise creating an event correlation rule using the event pattern.

Assignments (11)
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0577 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC)
Reel/Frame 063560/0001 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
CHANGE OF NAME Recorded Aug 8, 2019
From: ENTIT SOFTWARE LLC
To: MICRO FOCUS LLC
Reel/Frame 050004/0001 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ENTIT SOFTWARE LLC; ARCSIGHT, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0577 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 9, 2017
From: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
To: ENTIT SOFTWARE LLC
Reel/Frame 042746/0130 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 9, 2015
From: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 037079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 16, 2012
From: ARCSIGHT, LLC.
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 029308/0929 →
CERTIFICATE OF CONVERSION Recorded Nov 16, 2012
From: ARCSIGHT, INC.
To: ARCSIGHT, LLC.
Reel/Frame 029308/0908 →
MERGER Recorded Dec 23, 2010
From: PRIAM ACQUISITION CORPORATION
To: ARCSIGHT, INC.
Reel/Frame 025525/0172 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 5, 2008
From: SAURABH, KUMAR; TIDWELL, KENNY
To: ARCSIGHT, INC.
Reel/Frame 021789/0568 →