IP Library Granted Patent US 9,576,243
Granted Patent B2
US 9,576,243 · App. 14/026,834 · Granted Feb 21, 2017

Advanced intelligence engine

Inventors: Chris Petersen (Boulder, CO); Phillip Villella (Boulder, CO); Brad Aisa (Lafayette, CO)
Assignee: LogRhythm, Inc.
G06N5/025H04L41/069H04L63/1425G06F21/552H04L43/04H04L43/16H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,576,243
App. No.
14/026,834
Granted
Feb 21, 2017
Kind
B2
Abstract

An advanced intelligence engine (AIE) for use in identifying what may be complex events or developments on one or more data platforms or networks from various types of structured or normalized data generated by one or more disparate data sources. The AIE may conduct one or more types of quantitative, correlative, behavioral and corroborative analyses to detect events from what may otherwise be considered unimportant or non-relevant information spanning one or more time periods. Events generated by the AIE may be passed to an event manager to determine whether further action is required such as reporting, remediation, and the like.

Claims (57)

1. A method for use in monitoring one or more platforms of one or more data systems, comprising:

receiving, at a processor, structured data generated by one or more platforms over at least one communications network;

first evaluating, by the processor engine using one of first and second rule blocks, at least some of the data;

first determining that a result of the first evaluating is a first of at least first and second outcomes, wherein the at least some of the data leading to the first outcome is identified by a time stamp that corresponds to a first time;

accessing, by the processor, a linking relationship object contained within at least one of the first and second rule blocks to determine a specified time period relative to the first time;

second evaluating, by the processor using the other of the first and second rule blocks, at least some of the data associated with one or more time stamps corresponding to a second time within the specified time period relative to the first time;

second determining, from the second evaluating, whether a result is one of at least first and second outcomes; and

analyzing the results of the first and second determining steps to determine an event of interest.

2. The method of claim 1 , wherein the specified relationship comprises the one or more second times occurring before the first time.

3. The method of claim 1 , wherein the specified relationship comprises the one or more second times occurring at the same time as or after the first time.

4. The method of claim 1 , wherein the first evaluating uses the second rule block and the second evaluating uses the first rule block.

5. The method of claim 1 , wherein the first evaluating uses the first rule block and the second evaluating uses the second rule block.

6. The method of claim 1 , wherein the second determining comprises second determining that the result is the first outcome, and wherein the method further comprises:

generating an event in response to the second determining comprising the first outcome.

7. The method of claim 1 , wherein the second determining comprises second determining that the result is the second outcome, and wherein the method further comprises after the second determining:

third evaluating, by the processor using the other of the first and second rule blocks, at least some of the data;

third determining that a result of the third evaluating is a first of at least first and second outcomes, wherein the at least some of the data leading to the first outcome is identified by a time stamp that corresponds to a third time;

fourth evaluating, by the processor using the one of the first and second rule block, at least some of the data associated with the time stamp corresponding to the first time having a specified relationship to the third time;

fourth determining, from the fourth evaluating, whether a result is one of at least first and second outcomes, wherein the results are analyzed to determine an event of interest.

8. The method of claim 7 , wherein the fourth determining comprises fourth determining that the result is the first outcome, and wherein the method further comprises:

generating an event in response to the fourth determining comprising the first outcome.

9. The method of claim 1 , wherein the first evaluating comprises making a determination about a content of one or more fields of the at least some of the data, wherein the second evaluating comprises making a determination about a content of one or more fields of the at least some of the data, and wherein a content of one of the fields in the first evaluating matches a content of one of the fields in the second evaluating.

10. The method of claim 9 , wherein the second evaluating comprises:

utilizing the matching content as a key into an index structure of the at least some of the data to determine if the result is one of the first and second outcomes.

11. A system for use in monitoring one or more platforms of one or more data systems, comprising:

a processor,

a memory connected to the processor and comprising a set of computer readable instructions that are executable by the processor to:

receive structured data generated by one or more platforms over at least one communications network;

evaluate at least some of the received data with a first rule block to obtain a first result;

determine that the first result is a first of at least first and second outcomes,

wherein the at least some of the received data leading to the first outcome is identified by a time stamp that corresponds to a first time;

access a linking relationship object to determine a specified time period relative to the first time;

evaluate, with a second rule block, at least some of the received data associated with one or more time stamps that correspond to one or more second times within the specified time period relative to the first time to obtain a second result;

determine that the second result is one of at least first and second outcomes; and

analyze the results to determine an event interest.

12. The system of claim 11 , wherein the specified relationship comprises the one or more second times occurring before the first time.

13. The system of claim 11 , wherein the specified relationship comprises the one or more second times occurring at the same time as or after the first time.

14. The system of claim 11 , wherein the set of computer readable instructions determines that the second result is the first outcome, and wherein the

set of computer readable instructions is executable by the processor to generate an event in response to the second rule block determining that the second result is the first outcome.

15. The system of claim 11 , wherein the set of computer readable instructions determines that the second result is the second outcome; and wherein the set of computer readable instructions is executable by the processor to:

evaluate at least some of the data to obtain a third result; and

determine that the third result is a first of at least first and second outcomes, wherein the at least some of the data leading to the first outcome is identified by a time stamp that corresponds to a third time;

evaluate at least some of the data associated with the time stamp corresponding to the first time having a specified relationship to the third time to obtain a fourth result; and

determine whether the fourth result is one of at least first and second outcomes, wherein the results are analyzed to determine an event of interest.

16. The system of claim 15 , wherein the set of computer readable instructions determines that the fourth result is the first outcome, and wherein the set of computer readable instructions is executable by processor to generate an event in response to the first rule block determining that the fourth result is the first outcome.

17. The system of claim 11 , wherein the set of computer readable instructions evaluates the at least some of the data by making a determination about a content of one or more fields of the at least some of the data, wherein the set of computer readable instructions evaluates by making a determination about a content of one or more fields of the at least some of the data, and wherein a content of one of the fields evaluated by the first rule module matches a content of one the fields evaluated by the second rule module.

18. The system of claim 17 , wherein the set of computer readable instructions evaluates by utilizing the matching content as a key into an index structure of the at least some of the data to determine if the second result is one of the first and second outcomes.

19. A method for use in monitoring one or more platforms of one or more data systems, comprising:

receiving, at a processor, structured data generated by one or more platforms over at least one communications network;

first evaluating, by the processor using one of first and second rule blocks, at least some of the data;

first determining that a result of the first evaluating is a first of at least first and second outcomes, wherein the at least some of the data leading to the first outcome is identified by a time stamp that corresponds to a first time;

second evaluating, by the processor using the other of the first and second rule blocks, at least some of the data associated with a second time stamp corresponding to a second time;

second determining, from the second evaluating, whether a result is one of at least first and second outcomes;

receiving, by an event manager, results of the first and second evaluating;

accessing, by the event manager, a linking relationship object that associates the first and second rule blocks to determine a specified time period;

ascertaining, by the event manager, whether the first and second times are within the specified time period; and

generating, by the event manager, an event in response to the ascertaining step.

Assignments (8)
SECURITY INTEREST Recorded Jul 3, 2024
From: LOGRHYTHM, INC.; EXABEAM, INC.
To: 26N DL SERVICING LP, AS THE COLLATERAL AGENT
Reel/Frame 068105/0797 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT R/F 049148/0537 Recorded Jul 3, 2024
From: TRUIST BANK SUCCESSOR BY MERGER TO SUNTRUST BANK
To: LOGRHYTHM, INC.
Reel/Frame 068105/0965 →
PATENT SECURITY AGREEMENT Recorded May 10, 2019
From: LOGRHYTHM, INC.
To: SUNTRUST BANK
Reel/Frame 049148/0537 →
TERMINATION AND RELEASE OF PATENT SECURITY AGREEMENT RECORDED AT REEL 046254, FRAME 0333 Recorded May 10, 2019
From: SILICON VALLEY BANK, AS COLLATERAL AGENT
To: LOGRHYTHM, INC.
Reel/Frame 049148/0430 →
SECURITY INTEREST Recorded Jul 2, 2018
From: LOGRHYTHM, INC.
To: SILICON VALLEY BANK
Reel/Frame 046254/0333 →
RELEASE OF SECURITY INTEREST Recorded Jul 2, 2018
From: SILICON VALLEY BANK
To: LOGRHYTHM, INC.
Reel/Frame 046252/0615 →
SECURITY AGREEMENT Recorded Aug 26, 2016
From: LOGRHYTHM, INC.
To: SILICON VALLEY BANK
Reel/Frame 039841/0322 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 13, 2013
From: PETERSEN, CHRIS; VILLELLA, PHILLIP; AISA, BRAD
To: LOGRHYTHM INC.
Reel/Frame 031205/0745 →
Continuity (3)
Continuation 13303526 · Nov 23, 2011
Provisional Application 61417114 · Nov 24, 2010
Related Publication 20140012796A1 · Jan 9, 2014