IP Library Granted Patent US 9,280,741
Granted Patent B2
US 9,280,741 · App. 13/874,522 · Granted Mar 8, 2016

Automated alerting rules recommendation and selection

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,280,741
App. No.
13/874,522
Granted
Mar 8, 2016
Kind
B2
Abstract

An improved technique involves a device monitoring system providing alerting rules for a particular computing environment automatically based on existing alerting rules sets for other computing environments. Along these lines, when an IT professional monitors a computing environment through the device monitoring system, the device monitoring system stores alerting rules sets for that computing environment in a database. In storing rules sets and other information about that and other computing environments, the device monitoring system acquires intelligence from a wealth of data concerning how other IT professionals react to configuration changes in their computing environments. In this way, the device monitoring system then suggests alerting rules for a particular computing environment whose alerting rules are found to be suboptimal based on performance data from the particular computing environment.

Claims (97)

1. In a device monitoring system constructed and arranged to communicate alerts, via a set of alerting rules, in response to changes within a computing environment, a method of providing alerting rules for a particular computing environment, the method comprising:

storing multiple alerting rule sets in a rule set database, the multiple alerting rule sets providing sets of alerts when applied to configuration data of existing computing environments;

selecting particular alerting rules among the multiple alerting rule sets stored in the rule set database, the particular alerting rules providing particular alerts when applied to configuration data of an existing computing environment; and

providing the particular alerting rules to the particular computing environment,

wherein each existing computing environment is managed by an expert user, each expert user receiving alerts from the device monitoring system in response to configuration changes within the existing computing environment managed by that expert user according to an alerting rule set stored in the rule set database,

wherein each alerting rule of the multiple alerting rule sets includes (i) a configuration change identifier identifying a configuration change in an existing computing environment and (ii) a respective alert indicator indicating whether an alert is to be issued in response to the configuration change identified by the configuration change identifier,

wherein selecting the particular alerting rules includes:

performing a comparison operation between the existing computing environments and the particular computing environment, the comparison operation producing a comparison result indicative of whether the existing computing environments are similar to the particular computing environment; and

picking, as the particular alerting rules, rules from the multiple alerting rule sets based on the comparison result.

2. A method as in claim 1 ,

wherein performing the comparison operation includes:

deriving, from the existing computing environments, groups of similar computing environments, each group of similar computing environment including computing environments having similar characteristics according to a similarity metric, each group of similar computing environments having a common alerting rule set, the particular alerting rule set being selected according to which group of similar computing environments the new computing environment is most similar according to the similarity metric.

3. A method as in claim 1 ,

wherein each existing computing environment has an expected configuration, an alerting rule set for that existing computing environment including rules for alerting when configuration data of that existing computing environment differs from the expected configuration; and

wherein performing the comparison operation includes:

comparing the expected configuration of the new computing environment to the expected configuration of at least one existing computing environment.

4. A method as in claim 3 ,

wherein the expected configuration of the existing computing environment includes values of a set of configuration parameters, each alerting rule of the alerting rule set including a constraint on a value of at least one configuration parameter of the set of configuration parameters; and

wherein performing the comparison operation further includes:

assigning a weight to each alerting rule of the alerting rule set to form a set of weights, the weight being indicative of a level of importance of the imposition of that alerting rule to the existing computing environment.

5. A method as in claim 4 ,

wherein the existing computing environment includes an activity log, the activity log including entries corresponding to an action taken by a user of the existing computing environment in response to a change in the configuration of the existing computing environment; and

wherein assigning the weight to that alerting rule of the alerting rule set includes:

inputting the values of the set of configuration parameters into a machine learning system, the machine learning system being configured to output a set of weights for the alerting rules of the alerting rules set based on a historical trend of the entries of the activity log.

6. A method as in claim 5 ,

wherein the machine learning system employs a supervised learning technique in which output of the machine learning system depends on a set of training data which includes entries from the activity log; and

wherein assigning the weight to that alerting rule of the alerting rule set further includes:

inputting the entries from the activity log of the existing computing environment into the machine learning system.

7. A method as in claim 5 ,

wherein assigning the weight to that alerting rule of the alerting rule set further includes:

receiving feedback from an existing computing environment in response to the existing computing environment reacting to an alert, and

inputting the feedback into the machine learning system.

8. A method as in claim 5 ,

wherein assigning the weight to that alerting rule of the alerting rule set further includes:

monitoring the reaction of an-expert user to receiving an alert according to the alerting rule set for the computing environment managed by that expert user, and

inputting the monitored reaction of the expert user into the machine learning system.

9. A method as in claim 1 , further comprising:

verifying whether other computing environments may benefit from the particular alerting rule set;

sending the particular alerting rules to another computing environment when the particular alerting rule set benefits that computing environment; and

not sending the particular alerting rules to that computing environment when the particular alerting rule set does not benefit that computing environment.

10. A device monitoring system constructed and arranged to provide alerting rules for a particular computing environment for communicating alerts, via a set of alerting rules, in response to a changes within a computing environment, the device monitoring system comprising:

a network interface;

memory; and

a controller including controlling circuitry, the controlling circuitry being constructed and arranged to:

store multiple alerting rule sets in a rule set database, the multiple alerting rule sets providing sets of alerts when applied to configuration data of existing computing environments;

select particular alerting rules among the multiple alerting rule sets stored in the rule set database, the particular alerting rules providing particular alerts when applied to configuration data of an existing computing environment; and

provide the particular alerting rules to the particular computing environment;

wherein each existing computing environment is managed by an expert user, each expert user receiving alerts from the device monitoring system in response to configuration changes within the existing computing environment managed by that expert user according to an alerting rule set stored in the rule set database,

wherein each alerting rule of the multiple alerting rule sets includes (i) a configuration change identifier identifying a configuration change in an existing computing environment and (ii) a respective alert indicator indicating whether an alert is to be issued in response to the configuration change identified by the configuration change identifier,

wherein selecting the particular alerting rules includes:

performing a comparison operation between the existing computing environments and the particular computing environment, the comparison operation producing a comparison result indicative of whether the existing computing environments are similar to the particular computing environment; and

picking, as the particular alerting rules, rules from the multiple alerting rule sets based on the comparison result.

11. A device monitoring system as in claim 10 ,

wherein performing the comparison operation includes:

deriving, from the existing computing environments, groups of similar computing environments, each group of similar computing environment including computing environments having similar characteristics according to a similarity metric, each group of similar computing environments having a common alerting rule set, the particular alerting rule set being selected according to which group of similar computing environments the new computing environment is most similar according to the similarity metric.

12. A device monitoring system as in claim 10 ,

wherein each existing computing environment has an expected configuration, an alerting rule set for that existing computing environment including rules for alerting when configuration data of that existing computing environment differs from the expected configuration; and

wherein performing the comparison operation includes:

comparing the expected configuration of the new computing environment to the expected configuration of at least one existing computing environment.

13. A device monitoring system as in claim 12 ,

wherein the expected configuration of the existing computing environment includes values of a set of configuration parameters, each alerting rule of the alerting rule set including a constraint on a value of at least one configuration parameter of the set of configuration parameters; and

wherein performing the comparison operation further includes:

assigning a weight to each alerting rule of the alerting rule set to form a set of weights, the weight being indicative of a level of importance of the imposition of that alerting rule to the existing computing environment.

14. A device monitoring system as in claim 13 ,

wherein the existing computing environment includes an activity log, the activity log including entries corresponding to an action taken by a user of the existing computing environment in response to a change in the configuration of the existing computing environment; and

wherein assigning the weight to that alerting rule of the alerting rule set includes:

inputting the values of the set of configuration parameters into a machine learning system, the machine learning system being configured to output a set of weights for the alerting rules of the alerting rules set based on a historical trend of the entries of the activity log.

15. A device monitoring system as in claim 14 ,

wherein the machine learning system employs a supervised learning technique in which output of the machine learning system depends on a set of training data which includes entries from the activity log; and

wherein assigning the weight to that alerting rule of the alerting rule set further includes:

inputting the entries from the activity log of the existing computing environment into the machine learning system.

16. A device monitoring system as in claim 14 ,

wherein assigning the weight to that alerting rule of the alerting rule set further includes:

receiving feedback from an existing computing environment in response to the existing computing environment reacting to an alert, and

inputting the feedback into the machine learning system.

17. A device monitoring system as in claim 14 ,

wherein assigning the weight to that alerting rule of the alerting rule set further includes:

monitoring the reaction of an-expert user to receiving an alert according to the alerting rule set for the computing environment managed by that expert user, and

inputting the monitored reaction of the expert user into the machine learning system.

18. A computer program product having a non-transitory, computer-readable storage medium which, in a device monitoring system constructed and arranged to communicate alerts, via a set of alerting rules, in response to changes within a computing environment, stores code for providing alerting rules for a particular computing environment, the code including instructions which, when executed by a computer, causes the computer to:

store multiple alerting rule sets in a rule set database, the multiple alerting rule sets providing sets of alerts when applied to configuration data of existing computing environments;

select particular alerting rules among the multiple alerting rule sets stored in the rule set database, the particular alerting rules providing particular alerts when applied to configuration data of an existing computing environment; and

provide the particular alerting rules to the particular computing environment,

wherein each existing computing environment is managed by an expert user, each expert user receiving alerts from the device monitoring system in response to configuration changes within the existing computing environment managed by that expert user according to an alerting rule set stored in the rule set database,

wherein each alerting rule of the multiple alerting rule sets includes (i) a configuration change identifier identifying a configuration change in an existing computing environment and (ii) a respective alert indicator indicating whether an alert is to be issued in response to the configuration change identified by the configuration change identifier,

wherein selecting the particular alerting rules includes:

performing a comparison operation between the existing computing environments and the particular computing environment, the comparison operation producing a comparison result indicative of whether the existing computing environments are similar to the particular computing environment; and

picking, as the particular alerting rules, rules from the multiple alerting rule sets based on the comparison result.

19. A method as in claim 2 , wherein each of the existing computing environments includes a set of electronic devices;

wherein the configuration data of each of the existing computing environments specifies an operating system run by the set of electronic devices of that existing computing environment; and

wherein deriving the groups of similar computing environments includes:

assigning a numerical score to each existing computing environment based on the operating system specified by the configuration data of that existing computing environment;

producing, as a value of the similarity metric, a difference between the numerical score assigned to an existing computing environment and a numerical score assigned to the particular computing environment.

20. A method as in claim 1 , further comprising, prior to selecting the particular alerting rules:

receiving data indicating an occurrence of a security incident within the particular computing environment; and

in response to receipt of the data, initiating the selection of the particular alerting rules, the particular alerting rules being selected so as to prevent another occurrence of the security incident.

21. A method as in claim 1 , wherein the configuration change identified by the configuration change identifier of each alerting rule is one of a set of configuration changes, the set of configuration changes including (i) installation of new software on a device within the particular computing environment, (ii) change in internet security configuration of a device within the particular computing environment, and (iii) addition of a new device within the particular computing environment.

Assignments (11)
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 053667/0169, REEL/FRAME 060450/0171, REEL/FRAME 063341/0051) Recorded Mar 15, 2024
From: BARCLAYS BANK PLC, AS COLLATERAL AGENT
To: GOTO GROUP, INC. (F/K/A LOGMEIN, INC.)
Reel/Frame 066800/0145 →
SECURITY INTEREST Recorded Feb 16, 2024
From: GOTO COMMUNICATIONS, INC.; GOTO GROUP, INC.; LASTPASS US LP
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION, AS THE NOTES COLLATERAL AGENT
Reel/Frame 066614/0355 →
SECURITY INTEREST Recorded Feb 16, 2024
From: GOTO COMMUNICATIONS, INC.,; GOTO GROUP, INC., A; LASTPASS US LP,
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION, AS THE NOTES COLLATERAL AGENT
Reel/Frame 066614/0402 →
SECURITY INTEREST Recorded Feb 7, 2024
From: GOTO GROUP, INC.,; GOTO COMMUNICATIONS, INC.; LASTPASS US LP
To: BARCLAYS BANK PLC, AS COLLATERAL AGENT
Reel/Frame 066508/0443 →
CHANGE OF NAME Recorded Apr 8, 2022
From: LOGMEIN, INC.
To: GOTO GROUP, INC.
Reel/Frame 059644/0090 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS (SECOND LIEN) Recorded Feb 16, 2021
From: BARCLAYS BANK PLC, AS COLLATERAL AGENT
To: LOGMEIN, INC.
Reel/Frame 055306/0200 →
NOTES LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: LOGMEIN, INC.
To: U.S. BANK NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 053667/0032 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: LOGMEIN, INC.
To: BARCLAYS BANK PLC, AS COLLATERAL AGENT
Reel/Frame 053667/0079 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: LOGMEIN, INC.
To: BARCLAYS BANK PLC, AS COLLATERAL AGENT
Reel/Frame 053667/0169 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 041588/0143 Recorded Aug 31, 2020
From: JPMORGAN CHASE BANK, N.A.
To: LOGMEIN, INC.; GETGO, INC.
Reel/Frame 053650/0978 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 4, 2019
From: GETGO, INC.
To: LOGMEIN, INC.
Reel/Frame 049843/0833 →