IP Library Granted Patent US 10,382,486
Granted Patent B2
US 10,382,486 · App. 13/631,611 · Granted Aug 13, 2019

Event integration frameworks

Inventor: Stephen Rivers (Crowthorne, GB)
Assignee: Tripwire, Inc.
H04L63/20G06F21/552G06F21/604
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,382,486
App. No.
13/631,611
Granted
Aug 13, 2019
Kind
B2
Abstract

Disclosed herein are representative embodiments of methods, apparatus, and systems for processing and managing information from a compliance and configuration control (“CCC”) tool and generating information for a security information and event management (“SIEM”) tool based on the information from the CCC tool. For example, in one exemplary embodiment, information from a CCC tool is transferred to a SIEM tool or logging tool by receiving the information from the CCC tool in a format that is not recognized by the SIEM tool or logging tool, and generating an output message in a message format that is recognized by the SIEM tool or logging tool. In particular embodiments, the message format is a customizable message format that is adaptable to multiple different SIEM tools or logging tools. In further embodiments, the data transferred to the SIEM tool comprises data indicative of compliance policy changes.

Claims (27)

1. A computer-implemented method, comprising:

by an event integration tool (“EIT”) implemented by computing hardware and configured to integrate information from a compliance and configuration control (“CCC”) tool with a security information and event management (“SIEM”) or logging tool, thereby providing a flexible output mechanism that allows a user or support engineer to customize the output from the CCC tool:

reading, by the EIT, output format configuration data defining a user-selected output format selected from multiple output formats;

inputting, by the EIT, first compliance data parsed from a compliance report generated by the CCC tool, the first compliance data indicating compliance results for one or more nodes in an information technology (“IT”) network relative to one or more compliance policies at a first time period;

determining, by the EIT, a compliance trend for the one or more nodes in the IT network by comparing the first compliance data to second compliance data from a previous compliance report, the second compliance data from the previous compliance report indicating the compliance status of the one or more nodes in the IT network at a second earlier time period that is previous to and different from the first time period; and

conditionally generating, by the EIT, an output message for the SIEM or logging tool according to the user-selected setting output format, the generating being performed only when (a) the compliance trend is less compliant in the compliance report for the first time period than indicated by the previous compliance report for the second earlier time period, and (b) the user-selected setting indicates a conditional reporting mode in which output messages are generated only if the compliance trend indicates that the one or more nodes are less compliant in the compliance report for the first time period than indicated by the previous compliance report for the second earlier time period.

2. The method of claim 1 , wherein the generating further comprises generating the output message in a message format adapted for the SIEM or logging tool.

3. The method of claim 1 , wherein the compliance results are provided by respective software agents that are running at the one or more nodes and that are configured to detect changes at the one or more nodes.

4. The method of claim 1 , wherein the compliance results comprise data identifying a name of a node that has changed and data identifying a name of a policy that detected the changed node.

5. One or more non-transitory computer-readable media storing computer-executable instructions which when executed by a computer cause the computer to perform a method for integrating information from a compliance and configuration control (“CCC”) tool with a security information and event management (“STEM”) or logging tool using an event integration tool that provides a flexible output mechanism allowing a user or support engineer to customize the output from the CCC tool, the method comprising:

reading output format configuration data defining a user-selected output format;

inputting compliance data parsed from a compliance report generated by the CCC tool, the compliance data indicating compliance results for one or more nodes in an information technology (“IT”) network relative to one or more compliance policies at a first time period;

determining a compliance trend for one or more nodes in the IT network by comparing the compliance data to compliance data from a previous compliance report, the compliance data from the previous compliance report indicating the compliance status of the one or more nodes in the IT network at a second earlier time period that is previous to and different from the first time period; and

conditionally generating an output message for the SIEM or logging tool according to the user-selected setting output format, the generating being performed only when (a) the compliance trend is less compliant in the compliance report for the first time period than indicated by the previous compliance report for the second earlier time period, and (b) the user-selected setting indicates a conditional reporting mode in which output messages are generated only if the compliance trend indicates that the one or more nodes are less compliant in the compliance report for the first time period than indicated by the previous compliance report for the second earlier time period.

6. The one or more non-transitory computer-readable media of claim 5 , wherein the generating further comprises generating the output message in a message format adapted for the STEM or logging tool.

7. The one or more non-transitory computer-readable media of claim 5 , wherein the compliance results are provided by respective software agents that are running at the one or more nodes and that are configured to detect changes at the one or more nodes.

8. The one or more non-transitory computer-readable media of claim 5 , wherein the compliance results comprise data identifying a name of a node that has changed and data identifying a name of a policy that detected the changed node.

9. A system, comprising:

one or more processors; and

one or more non-transitory computer-readable media storing computer-executable instructions which when executed by the one or more processors cause the one or more processors to perform a method for integrating information from a compliance and configuration control (“CCC”) tool with a security information and event management (“STEM”) or logging tool using an event integration tool that provides a flexible output mechanism allowing a user or support engineer to customize the output from the CCC tool, comprising:

reading output format configuration data defining a user-selected output format;

inputting compliance data parsed from a compliance report generated by the CCC tool, the compliance data indicating compliance results for one or more nodes in an information technology (“IT”) network relative to one or more compliance policies at a first time period;

determining a compliance trend for one or more nodes in the IT network by comparing the compliance data to compliance data from a previous compliance report, the compliance data from the previous compliance report indicating the compliance status of the one or more nodes in the IT network at a second earlier time period that is previous to and different from the first time period; and

conditionally generating an output message for the SIEM or logging tool according to the user-selected setting output format, the generating being performed only when (a) the compliance trend is less compliant in the compliance report for the first time period than indicated by the previous compliance report for the second earlier time period, and (b) the user-selected setting indicates a conditional reporting mode in which output messages are generated only if the compliance trend indicates that the one or more nodes are less compliant in the compliance report for the first time period than indicated by the previous compliance report for the second earlier time period.

10. The system of claim 9 , wherein the generating further comprises generating the output message in a message format adapted for the STEM or logging tool.

11. The system of claim 9 , wherein the compliance results are provided by respective software agents that are running at the one or more nodes and that are configured to detect changes at the one or more nodes.

12. The system of claim 9 , wherein the compliance results comprise data identifying a name of a node that has changed and data identifying a name of a policy that detected the changed node.

Assignments (13)
SECURITY INTEREST Recorded Jan 6, 2026
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.
To: ACQUIOM AGENCY SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 074233/0632 →
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 60306/0365 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: TRIPWIRE, INC.
Reel/Frame 074023/0235 →
TERMINATION AND RELEASE OF FIRST LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 60306/0555 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: TRIPWIRE, INC.
Reel/Frame 074023/0320 →
EXTENDED RCF FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: TRIPWIRE, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073663/0639 →
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 60306/0649 Recorded Nov 21, 2025
From: ACQUIOM AGENCY SERVICES LLC
To: TRIPWIRE, INC.
Reel/Frame 073663/0698 →
EXTENDED FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: TRIPWIRE, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073664/0124 →
NEW MONEY FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.; VERA SECURITY, INC.
To: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 073683/0534 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 14, 2025
From: GOLUB CAPITAL MARKETS LLC (AS EXISTING AGENT)
To: ACQUIOM AGENCY SERVICES LLC (AS SUCCESSOR COLLATERAL AGENT)
Reel/Frame 072471/0665 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jun 7, 2022
From: TRIPWIRE, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 060306/0365 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jun 7, 2022
From: TRIPWIRE, INC.
To: GOLUB CAPITAL MARKETS LLC, AS COLLATERAL AGENT
Reel/Frame 060306/0649 →
RELEASE OF SECURITY INTEREST Recorded Feb 2, 2015
From: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
To: TRIPWIRE, INC.; NCIRCLE NETWORK SECURITY INC.
Reel/Frame 034874/0150 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 11, 2014
From: RIVERS, STEPHEN
To: TRIPWIRE, INC.
Reel/Frame 034483/0448 →
SECURITY AGREEMENT Recorded Apr 2, 2013
From: TRIPWIRE, INC.; NCIRCLE NETWORK SECURITY, INC.
To: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 030132/0101 →
Continuity (1)
Related Publication 20140096181A1 · Apr 3, 2014
Cited By (1)
US 12,380,222