IP Library Granted Patent US 9,910,874
Granted Patent B1
US 9,910,874 · App. 13/930,074 · Granted Mar 6, 2018

Scalable alerter for security information and event management

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,910,874
App. No.
13/930,074
Granted
Mar 6, 2018
Kind
B1
Abstract

A methodology and related system operable to store a plurality of complex event processing (CEP) rules, the CEP rules being based on a plurality of events that are to be monitored. The CEP rules are pre-processed by, e.g., generating and storing a de-duplicated list of events from the plurality of events that are to be monitored. A received event from a received event stream is compared to events in the de-duplicated list of events and when a match between the received event (e.g., an event instance) and any one of the events in the de-duplicated list of events is detected, the received event (the event instance) is stored in an input repository. The plurality of CEP rules are then applied to the received event in the input repository, and any other previously stored events in the input repository.

Claims (50)

1. A method comprising:

storing a plurality of complex event processing (CEP) rules, the CEP rules being based on a plurality of events that are to be monitored;

pre-processing the CEP rules by generating and storing a de-duplicated list of events from the plurality of events that are to be monitored, resulting in a separately stored de-duplicated list of events;

comparing a received event from a received event stream to events in the separately stored de-duplicated list of events and when a match between the received event and any one of the events in the separately stored de-duplicated list of events is detected, storing the received event in an input repository; and

applying the plurality of CEP rules to the received event in the input repository;

wherein pre-processing the CEP rules comprises:

identifying, in each of the plurality of CEP rules, one or more events to be detected in the received event stream that contribute to satisfaction of that CEP rule; and

generating the de-duplicated list of events to be detected from the received event stream based on the identified events in each of the plurality of CEP rules.

2. The method of claim 1 , wherein the received event from the received event stream comprises a log received from a network-connected device.

3. The method of claim 2 , wherein the log is received from at least one of a server, a router, a switch, an operating system, a database, an application and a firewall.

4. The method of claim 1 , wherein comparing comprises performing pattern matching between the received event from the received event stream and events in the separately stored de-duplicated list of events.

5. The method of claim 1 , further comprising comparing a plurality of received events from a plurality of received event streams to each of the events in the separately stored de-duplicated list of events.

6. The method of claim 1 , further comprising updating a state machine based on a result of applying the plurality of CEP rules to the received event in the input repository.

7. The method of claim 6 , updating the state machine by at least one of:

iterating through each instantiated rule in the state machine; and

iterating through the input repository.

8. The method of claim 6 , wherein the state machine is implemented as a relational database.

9. The method of claim 1 , wherein the method is performed with a security information and event management (SIEM) system.

10. A system, comprising:

a memory;

a network interface unit; and

a processing unit operatively in communication with the memory and the network interface,

wherein the processing unit is configured:

to store a plurality of complex event processing (CEP) rules, the CEP rules being based on a plurality of events that are to be monitored;

to pre-process the CEP rules by generating and storing a de-duplicated list of events from the plurality of events that are to be monitored, resulting in a separately stored de-duplicated list of events;

to compare a received event from a received event stream to events in the separately-stored de-duplicated list of events and when a match between the received event and any one of the events in the separately stored de-duplicated list of events is detected, store the received event in an input repository; and

to apply the plurality of CEP rules to the received event in the input repository;

wherein the processing unit is configured to pre-process the CEP rules by:

identifying, in each of the plurality of CEP rules, one or more events to be detected in the received event stream that contribute to satisfaction of that CEP rule; and

generating the de-duplicated list of events to be detected from the received event stream based on the identified events in each of the plurality of CEP rules.

11. The system of claim 10 , wherein the received event from the received event stream comprises a log received from a network-connected device.

12. The system of claim 11 , wherein the log is received from at least one of a server, a router, a switch, an operating system, a database, an application and a firewall.

13. The system of claim 10 , wherein the processing unit is configured to perform pattern matching between the received event from the received event stream and events in the separately stored de-duplicated list of events.

14. The system of claim 10 , wherein the processing unit is further configured to compare a plurality of received events from a plurality of received event streams to each of the events in the separately stored de-duplicated list of events.

15. The system of claim 10 , wherein the processing unit is further configured to update a state machine in the memory based on a result of applying the plurality of CEP rules to the received event in the input repository.

16. The system of claim 15 , wherein the processing unit is further configured to update the state machine by at least one of:

iterating through each instantiated rules in the state machine; and

iterating through the input repository.

17. The system of claim 15 , wherein the state machine is implemented as a relational database.

18. The system of claim 10 , wherein the system is operational with a security information and event management (SIEM) system.

19. A method comprising:

storing a plurality of complex event processing (CEP) rules, the CEP rules being based on a plurality of events that are to be monitored;

pre-processing the CEP rules by generating and storing a de-duplicated list of events from the plurality of events that are to be monitored, resulting in a separately stored de-duplicated list of events;

receiving a stream of events;

comparing individual received events in the stream of events to events in the separately stored de-duplicated list of events and, when a match between a given received event in the stream of events matches any one of the events in the separately stored de-duplicated list of events is detected, storing the given received event in an input repository, wherein each such stored given received event includes a timestamp; and

applying the plurality of CEP rules to the events stored in the input repository based on respective timestamps thereof;

wherein pre-processing the CEP rules comprises:

identifying, in each of the plurality of CEP rules, one or more events to be detected in the received event stream that contribute to satisfaction of that CEP rule; and

generating the de-duplicated list of events to be detected from the received event stream based on the identified events in each of the plurality of CEP rules.

20. The method of claim 19 , further comprising sorting the events stored in the input repository to obtain sorted events, and applying the plurality of CEP rules to the sorted events.

Assignments (7)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (046366/0014) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060450/0306 →
RELEASE OF SECURITY INTEREST AT REEL 046286 FRAME 0653 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 058298/0093 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Jun 1, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 046366/0014 →
PATENT SECURITY AGREEMENT (CREDIT) Recorded Jun 1, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046286/0653 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 28, 2013
From: JAMAIL, JOHN M.; REICH, DANIEL B.; STOECKER, PAUL W.
To: EMC CORPORATION
Reel/Frame 030708/0690 →