IP Library Granted Patent US 9,391,863
Granted Patent B2
US 9,391,863 · App. 14/271,264 · Granted Jul 12, 2016

Server resource management, analysis, and intrusion negotiation

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,391,863
App. No.
14/271,264
Granted
Jul 12, 2016
Kind
B2
Abstract

A console host and intrusion negation system (CHAINS) includes a host component and a console component. The host component monitors resources at a server. Resources that are becoming overloaded can be throttled back. Reports relating to resource usage may be transmitted to the console component. At the console component, resource reports from multiple host components may be viewed and managed.

Claims (35)

1. A method comprising:

monitoring a plurality of resources associated with a network server, the plurality of resources including a communication interface of the network server and a processor of the network server, wherein monitoring the plurality of resources includes determining a number of open network connections using the communication interface of the network server;

comparing activity levels of the plurality of resources to predetermined threshold activity levels; and

reducing usage of one of the plurality of resources when the activity level associated with the one of the plurality of resources increases above the predetermined threshold activity level associated therewith, wherein reducing usage of the one of the plurality of resources includes:

reducing the number of open network connections to obtain a first number of open network connections by closing open network connections based on a priority of the open network connections, shutting down an open but inactive network connection, and refusing to open new network connections;

comparing the first number of open network connections with a number of open network connections threshold; and

in the event that the first number of open network connections is greater than or equal to the number of open network connections threshold, randomly close an open network connection.

2. The method of claim 1 , wherein monitoring the plurality of resources includes determining usage of the processor of the network server, and wherein reducing usage of the one of the plurality of resources includes reducing a load on the processor by shutting down an inactive process and/or shutting down lower priority processes.

3. The method of claim 1 , wherein the plurality of resources includes a storage device associated with the network server, and wherein monitoring the plurality of resources includes determining usage of the storage device associated with the network server.

4. The method of claim 1 , wherein the plurality of resources includes a storage device associated with the network server, wherein monitoring the plurality of resources includes determining usage of the storage device associated with the network server, and wherein reducing usage of the one of the plurality of resources includes redirecting future disk write commands to a monitor and/or compressing log files.

5. The method of claim 1 , wherein the plurality of resources includes a memory associated with the network server, and wherein monitoring the plurality of resources includes determining usage of the memory associated with the network server.

6. The method of claim 1 , wherein the plurality of resources includes a memory associated with the network server, wherein monitoring the plurality of resources includes determining usage of the memory associated with the network server, and wherein reducing usage of the one of the plurality of resources includes reducing the usage of the memory by shutting down inactive processes.

7. The method of claim 1 , further comprising alerting a user when the activity level associated with the one of the plurality of resources increases above the predetermined threshold activity level.

8. The method of claim 1 , further comprising alerting a user when the activity level associated with the one of the plurality of resources increases above the predetermined threshold activity level, wherein alerting the user includes transmitting an alert to a remote computer.

9. The method of claim 1 , wherein the predetermined threshold activity levels are received from a remote computer.

10. The method of claim 1 , wherein the reducing of the number of open network connections to obtain a first number of open network connections comprises:

performing the closing of the open network connections based on the priority of the open network connection before the shutting down of the open but inactive network connection.

11. A system comprising:

a communication interface of a network server;

a processor of the network server; and

a host component executed on the processor for:

monitoring a plurality of resources associated with the network server, the plurality of resources including the communication interface of the network server and the processor of the network server, wherein monitoring the plurality of resources includes determining a number of open network connections using the communication interface of the network server;

comparing activity levels of the plurality of resources to predetermined threshold activity levels; and

reducing usage of one of the plurality of resources when the activity level associated with the one of the plurality of resources increases above the predetermined threshold activity level associated therewith, wherein reducing usage of the one of the plurality of resources includes:

reducing the number of open network connections to obtain a first number of open network connections by closing open network connections based on a priority of the open network connections, shutting down an open but inactive network connection, and refusing to open new network connections;

comparing the first number of open network connections with a number of open network connections threshold; and

in the event that the first number of open network connections is greater than or equal to the number of open network connections threshold, randomly close an open network connection.

12. The system recited in claim 11 , wherein monitoring the plurality of resources includes determining usage of the processor of the network server, and wherein reducing usage of the one of the plurality of resources includes reducing a load on the processor by shutting down an inactive process and/or shutting down lower priority processes.

13. The system recited in claim 11 , further comprising a storage device associated with the network server, wherein the plurality of resources includes the storage device associated with the network server, and wherein monitoring the plurality of resources includes determining usage of the storage device associated with the network server.

14. The system recited in claim 11 , further comprising a storage device associated with the network server, wherein the plurality of resources includes the storage device associated with the network server, wherein monitoring the plurality of resources includes determining usage of the storage device associated with the network server, and wherein reducing usage of the one of the plurality of resources includes redirecting future disk write commands to a monitor and/or compressing log files.

15. The system recited in claim 11 , further comprising a memory associated with the network server, wherein the plurality of resources includes the memory associated with the network server, and wherein monitoring the plurality of resources includes determining usage of the memory associated with the network server.

16. The system recited in claim 11 , further comprising a memory associated with the network server, wherein the plurality of resources includes the memory associated with the network server, wherein monitoring the plurality of resources includes determining usage of the memory associated with the network server, and wherein reducing usage of the one of the plurality of resources includes reducing the usage of the memory by shutting down inactive processes.

17. The system recited in claim 11 , further comprising the host component executed on the processor for alerting a user when the activity level associated with the one of the plurality of resources increases above the predetermined threshold activity level.

18. The system recited in claim 11 , further comprising the host component executed on the processor for alerting a user when the activity level associated with the one of the plurality of resources increases above the predetermined threshold activity level, wherein alerting the user includes transmitting an alert to a remote computer.

19. The system recited in claim 11 , wherein the predetermined threshold activity levels are received from a remote computer.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 19, 2014
From: SAMPLE, CHAR
To: FEDERAL NETWORK SYSTEMS, LLC
Reel/Frame 033567/0033 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 19, 2014
From: FEDERAL NETWORK SYSTEMS, LLC
To: VERIZON PATENT AND LICENSING INC.
Reel/Frame 033567/0049 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 19, 2014
From: VERIZON PATENT AND LICENSING INC.
To: HOME RUN PATENTS LLC
Reel/Frame 033567/0062 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 18, 2014
From: HOME RUN PATENTS LLC
To: PALO ALTO NETWORKS, INC.
Reel/Frame 033556/0655 →