IP Library Granted Patent US 8,560,679
Granted Patent B2
US 8,560,679 · App. 13/031,079 · Granted Oct 15, 2013

Method and apparatus for exercising and debugging correlations for network system

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,560,679
App. No.
13/031,079
Granted
Oct 15, 2013
Kind
B2
Abstract

A selected time interval of previously stored events generated by a number of computer network devices are replayed and cross-correlated according to rules. Meta-events are generated when the events satisfy conditions associated with one or more of the rules. The rules used during replay may differ from prior rules used at a time when the events occurred within a computer network that included the computer network devices. In this way, new rules can be tested against true event data streams to determine whether or not the rules should be used in a live environment (i.e., the efficacy of the rules can be tested and/or debugged against actual event data).

Claims (40)

1. A method, comprising:

a first device, including a first hardware processor, receiving events, wherein one or more of the events originated in an event log that was generated by a computer network device;

the first device normalizing the events to a common event schema;

the first device transmitting the normalized events to a second device including a second hardware processor;

the second device receiving the normalized events and correlating the normalized events according to a first rule;

the first device storing the normalized events to a computer-readable storage device;

the first device retrieving one or more of the normalized events from the computer-readable storage device;

the first device transmitting the retrieved normalized events to the second device; and

the second device receiving the retrieved normalized events and correlating the retrieved normalized events according to a second rule, wherein the second rule differs from the first rule,

wherein the second rule is applied to live events reported by one or more computer network devices.

2. The method of claim 1 , further comprising displaying a meta-event.

3. The method of claim 2 , wherein the meta-event represents an instance for which various ones or more of the retrieved normalized events satisfy a condition associated with the second rule.

4. The method of claim 1 , wherein prior to being normalized, one or more of the events was gathered from one or more of routers, e-mail logs, anti-virus products, firewalls, network intrusion detection systems, access control servers, virtual private network systems, network device event logs, and network device Syslogs.

5. The method of claim 1 , wherein the first device stores a software agent that is associated with the computer network device.

6. The method of claim 1 , wherein the first device transmits the retrieved normalized events in response to user selection.

7. The method of claim 6 , wherein the user selection is made through a graphical user interface having elements defining modes of re-transmission.

8. The method of claim 7 , wherein the modes of re-transmission include “play”, “fast forward” and “reverse”.

9. The method of claim 6 , wherein the user selection indicates a time interval.

10. The method of claim 1 , wherein the transmission of the retrieved normalized events to the second device is performed faster than the initial transmission of the normalized events to the second device.

11. A system, comprising:

a first device comprising a first hardware processor configured to:

receive events, wherein one or more of the events originated in an event log that was generated by a computer network device;

normalize the events to a common event schema;

transmit the normalized events to a second device;

store the normalized events to a computer-readable storage device;

retrieve one or more of the normalized events from the computer-readable storage device; and

transmit the retrieved normalized events to the second device; and

the second device comprising a second hardware processor configured to:

receive the normalized events and correlate the normalized events according to a first rule; and

receive the retrieved normalized events and correlate the retrieved normalized events according to a second rule, wherein the second rule differs from the first rule,

wherein the second rule is applied to live events reported by one or more computer network devices.

12. The system of claim 11 , wherein the second hardware processor of the second device is further configured to display a meta-event.

13. The system of claim 12 , wherein the meta-event represents an instance for which various ones or more of the retrieved normalized events satisfy a condition associated with the second rule.

14. The system of claim 11 , wherein prior to being normalized, one or more of the events was gathered from one or more of routers, e-mail logs, anti-virus products, firewalls, network intrusion detection systems, access control servers, virtual private network systems, network device event logs, and network device Syslogs.

15. The system of claim 11 , wherein the first device stores a software agent that is associated with the computer network device.

16. The system of claim 11 , wherein the hardware processor of the first device is further configured to transmit the retrieved normalized events in response to user selection.

17. The system of claim 16 , wherein the user selection is made through a graphical user interface having elements defining modes of re-transmission.

18. The system of claim 17 , wherein the modes of re-transmission include “play”, “fast forward” and “reverse”.

19. The system of claim 16 , wherein the user selection indicates a time interval.

20. The system of claim 11 , wherein the transmission of the retrieved normalized events to the second device is performed faster than the initial transmission of the normalized events to the second device.

Assignments (8)
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0577 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC)
Reel/Frame 063560/0001 →
CHANGE OF NAME Recorded Aug 8, 2019
From: ENTIT SOFTWARE LLC
To: MICRO FOCUS LLC
Reel/Frame 050004/0001 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ENTIT SOFTWARE LLC; ARCSIGHT, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0577 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 9, 2017
From: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
To: ENTIT SOFTWARE LLC
Reel/Frame 042746/0130 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 16, 2012
From: ARCSIGHT, LLC.
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 029308/0929 →
CERTIFICATE OF CONVERSION Recorded Nov 16, 2012
From: ARCSIGHT, INC.
To: ARCSIGHT, LLC.
Reel/Frame 029308/0908 →