IP Library Patent Application 12755912
Patent Application
App. No. 12/755,912

Distributed data search, audit and analytics

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
12/755,912
Abstract

A system that comprises of a set of components that interact together to achieve large-scale distributed data auditing, searching, and analytics. Traditional systems require auditing data to be captured and centralized for analytics, which leads to scaling and bottleneck issues (both on network and processing side). Unlike these systems, the system described herein leverages the combination of distributed storage and intelligence, along with centralized policy intelligence and coordination, to allow for large-scale data auditing that scales. This architecture allows for data auditing in “billions” of events, unlike traditional architectures that struggled in the realm of “millions” of events.

Claims (15)

1 . A distributed system associated with an enterprise computing environment in which data servers are being monitored for insider attacks, the distributed system comprising:

a set of client appliances distributed across the enterprise computing environment, wherein each client appliance is associated with a subset of the data servers being monitored for insider attacks;

a set of one or more server appliances, wherein each server appliance is associated with one or more client appliances of the set of client appliances; and

a control routine executed by a processor for receiving and executing a query across one or more server appliances, which query, in turn, is executed by each server appliance against the client appliances and their associated data servers, and, in response, returns a consolidated audit result.

2 . The distributed system as described in claim 1 further including a management console through which an authorized user creates centralized policy and configuration commands, and to view data auditing results and reports.

3 . The distributed system as described in claim 1 wherein the management console is used to formulate the query.

4 . The distributed system as described in claim 1 wherein the server appliance collects and processes per client appliance query results.

5 . The distributed system as described in claim 4 wherein the server appliance processes the per client the per client appliance query results by converting event date and times to a time zone associated with the server appliance.

6 . The distributed system as described in claim 4 wherein the server appliance processes the per client appliance query results by applying a range argument.

7 . The distributed system as described in claim 4 wherein the server appliance aggregates and displays per client appliance query results in a specified format.

8 . The distributed system as described in claim 1 wherein a client appliance comprises:

at least one or more processors:

code executing on a given processor for generating a display interface through which an authorized entity using a given policy specification language specifies an insider attack;

code executing on a given processor that determines whether a trusted user's given data access to an enterprise resource is indicative of the insider attack; and

code executing on a given processor and responsive to the insider attack for taking a given mitigation action.

Assignments (11)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 26, 2021
From: SOFTWARE LABS CAMPUS UNLIMITED COMPANY
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 056396/0942 →
CORRECTIVE ASSIGNMENT TO CORRECT THE 4 ERRONEOUSLY LISTED PATENTS ON SCHEDULE A. PREVIOUSLY RECORDED AT REEL: 053452 FRAME: 0580. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT . Recorded Jan 29, 2021
From: IBM TECHNOLOGY CORPORATION
To: SOFTWARE LABS CAMPUS UNLIMITED COMPANY
Reel/Frame 055171/0693 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 11, 2020
From: IBM TECHNOLOGY CORPORATION
To: SOFTWARE LABS CAMPUS UNLIMITED COMPANY
Reel/Frame 053452/0580 →
NUNC PRO TUNC ASSIGNMENT Recorded Dec 17, 2018
From: IBM ATLANTIC C.V.
To: IBM TECHNOLOGY CORPORATION
Reel/Frame 047795/0001 →
NUNC PRO TUNC ASSIGNMENT Recorded Dec 17, 2018
From: IBM INTERNATIONAL GROUP B.V.
To: IBM INTERNATIONAL C.V.
Reel/Frame 047794/0779 →
NUNC PRO TUNC ASSIGNMENT Recorded Dec 17, 2018
From: IBM INTERNATIONAL C.V.
To: IBM ATLANTIC C.V.
Reel/Frame 047794/0927 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 27, 2012
From: NETEZZA CORPORATION
To: IBM INTERNATIONAL GROUP B.V.
Reel/Frame 029035/0193 →
REQUEST FOR CORRECTED NOTICE OF RECORDATION TO REMOVE PATENT NO. 7.415,729 PREVIOUSLY INCORRECTLY LISTED ON ELECTRONICALLY FILED RECORDATION COVERSHEET, RECORDED 12/23/2011 AT REEL 027439, FRAMES 0867-0870-COPIES ATTACHED Recorded Jan 19, 2012
From: TIZOR SYSTEMS, INC.
To: NETEZZA CORPORATION
Reel/Frame 027614/0356 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2011
From: TIZOR SYSTEMS, INC.
To: NETEZZA CORPORATION
Reel/Frame 027439/0867 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 15, 2011
From: TIZOR SYSTEMS, INC.
To: NETEZZA CORPORATION
Reel/Frame 027232/0417 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 10, 2011
From: MOGHE, PRATYUSH
To: TIZOR SYSTEMS, INC.
Reel/Frame 027206/0675 →