IP Library Granted Patent US 8,595,837
Granted Patent B2
US 8,595,837 · App. 13/220,377 · Granted Nov 26, 2013

Security event management apparatus, systems, and methods

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,595,837
App. No.
13/220,377
Granted
Nov 26, 2013
Kind
B2
Abstract

Apparatus, systems, and methods may operate to receive multiple security event data streams from a plurality of hardware processing nodes, the multiple security event data streams comprising multiple security events. Additional operations may include extracting multiple security events from multiple security event data streams, and classifying the extracted multiple security events to form domain-specific, categorized data streams. A hierarchy of statistical data streams may then be generated from the domain-specific, categorized data streams. Additional apparatus, systems, and methods are disclosed.

Claims (37)

1. A system, comprising:

an interface to receive multiple security event data streams from a plurality of hardware processing nodes, the multiple security event data streams comprising multiple security events;

a hierarchical classifier module coupled to a memory to store classification algorithms to operate on the multiple security events to provide a tree of domain-specific, categorized data streams according to arbitrary categories that are created using at least one of external knowledge or inbuilt intelligence, the arbitrary categories being dimensions;

and

at least one processor to generate a hierarchy of statistical data streams from the dimensions, the statistical data streams being linked to a plurality of paths within the tree, the paths corresponding to different levels of classification.

2. The system of claim 1 , further comprising:

a graphical user interface (GUI) executed by a client node to receive the statistical data streams.

3. The system of claim 1 , wherein the hardware processing nodes comprise at least one of server nodes, client nodes, or storage nodes.

4. The system of claim 1 , wherein the at least one processor is housed together with at least one of the hardware processing nodes.

5. The system of claim 1 , wherein the hierarchical classifier module further comprises:

a contextual asset classifier having an output coupled to an input of an activity classifier.

6. A processor-implemented method to execute on one or more processors that perform the method, comprising:

receiving multiple security event data streams from a plurality of hardware processing nodes, the multiple security event data streams comprising multiple security events;

classifying the multiple security events to form a tree of domain-specific, categorized data streams according to arbitrary categories that are created using at least one of external knowledge or inbuilt intelligence, the arbitrary categories being dimensions; and

generating a hierarchy of statistical data streams from the dimensions, including linking the statistical data streams to a plurality of paths within the tree, the paths corresponding to different levels of classification.

7. The method of claim 6 , wherein the receiving further comprises:

receiving at least one of the security event data streams in response to accessing a log file stored on one of the hardware processing nodes.

8. The method of claim 6 , wherein the classifying further comprises:

classifying the multiple security events according to vulnerability categories associate with sources of the security event data streams.

9. The method of claim 6 , wherein the classifying further comprises:

classifying the multiple security events using a sequential hierarchy of classifier functions, wherein output from a first level of the classifier functions in the hierarchy provides input to a second level of the classifier functions in the hierarchy.

10. The method of claim 6 , further comprising:

receiving some of the multiple security event data streams while generating the hierarchy of the statistical data streams as part of a continuous reception and generation process.

11. The method of claim 6 , wherein the statistical data streams comprise multiple dimensions.

12. A processor-implemented method to execute on one or more processors that perform the method, comprising:

extracting multiple security events from multiple security event data streams;

classifying the extracted multiple security events to form a tree of domain-specific, categorized data streams according to arbitrary categories that are created using at least one of external knowledge or inbuilt intelligence, the arbitrary categories being dimensions; and

generating a hierarchy of statistical data streams from the dimensions, including linking the statistical data streams to a plurality of paths within the tree, the paths corresponding to different levels of classification.

13. The method of claim 12 , further comprising:

transmitting at least some of the statistical data streams to a network interface in a client node coupled to a display.

14. The method of claim 12 , wherein using external knowledge the comprises:

accessing a database stored on a non-transitory storage medium; and

receiving information as external knowledge from the database to provide context-aware classification of the extracted multiple security events.

15. The method of claim 12 , wherein the classifying uses a combination of classifier functions comprising a tree of multilevel, hierarchical classifiers.

16. The method of claim 12 , wherein the generating comprises:

generating the statistical data streams to include at least one of a volume-based stream or a frequency-based stream.

17. The method of claim 12 , wherein at least one of the extracting, the classifying, or the generating are accomplished using input/output aggregation pipelines.

Assignments (12)
RELEASE OF SECURITY INTEREST REEL/FRAME 035656/0251 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: BORLAND SOFTWARE CORPORATION; ATTACHMATE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.)
Reel/Frame 062623/0009 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
CORRECTIVE ASSIGNMENT TO CORRECT THE TO CORRECT TYPO IN APPLICATION NUMBER 10708121 WHICH SHOULD BE 10708021 PREVIOUSLY RECORDED ON REEL 042388 FRAME 0386. ASSIGNOR(S) HEREBY CONFIRMS THE NOTICE OF SUCCESSION OF AGENCY. Recorded Jul 26, 2018
From: BANK OF AMERICA, N.A., AS PRIOR AGENT
To: JPMORGAN CHASE BANK, N.A., AS SUCCESSOR AGENT
Reel/Frame 048793/0832 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
NOTICE OF SUCCESSION OF AGENCY Recorded May 2, 2017
From: BANK OF AMERICA, N.A., AS PRIOR AGENT
To: JPMORGAN CHASE BANK, N.A., AS SUCCESSOR AGENT
Reel/Frame 042388/0386 →
CHANGE OF NAME Recorded Sep 13, 2016
From: NOVELL, INC.
To: MICRO FOCUS SOFTWARE INC.
Reel/Frame 040020/0703 →
SECURITY INTEREST Recorded May 13, 2015
From: MICRO FOCUS (US), INC.; BORLAND SOFTWARE CORPORATION; ATTACHMATE CORPORATION; NETIQ CORPORATION; NOVELL, INC.
To: BANK OF AMERICA, N.A.
Reel/Frame 035656/0251 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 18, 2012
From: ANTONY, JOHN MELVIN; APOSTOLESCU, PAUL; SRINIVASAN, PATTABIRAMAN; ADUSUMILLI, PRATHAP
To: NOVELL, INC.
Reel/Frame 029025/0109 →
RELEASE OF SECURITY INTEREST IN PATENTS FIRST LIEN (RELEASES RF 026270/0001 AND 027289/0727) Recorded May 22, 2012
From: CREDIT SUISSE AG, AS COLLATERAL AGENT
To: NOVELL, INC.
Reel/Frame 028252/0077 →
RELEASE OF SECURITY IN PATENTS SECOND LIEN (RELEASES RF 026275/0018 AND 027290/0983) Recorded May 22, 2012
From: CREDIT SUISSE AG, AS COLLATERAL AGENT
To: NOVELL, INC.
Reel/Frame 028252/0154 →
GRANT OF PATENT SECURITY INTEREST Recorded Nov 29, 2011
From: NOVELL, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 027289/0727 →
GRANT OF PATENT SECURITY INTEREST (SECOND LIEN) Recorded Nov 29, 2011
From: NOVELL, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 027290/0983 →