IP Library Granted Patent US 10,320,845
Granted Patent B2
US 10,320,845 · App. 15/206,632 · Granted Jun 11, 2019

Recommended security action feature sets

Inventors: Sourabh Satish (Fremont, CA); Oliver Friedrichs (Woodside, CA); Atif Mahadik (Fremont, CA); Govind Salinas (Sunnyvale, CA); Ryan Russell (El Cerrito, CA)
Assignee: Splunk Inc.
H04L63/20G06F21/00G06F21/577
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,320,845
App. No.
15/206,632
Granted
Jun 11, 2019
Kind
B2
Abstract

Systems, methods, and software described herein provide for identifying recommended feature sets for new security applications. In one example, a method of providing recommended feature sets for a new security application includes identifying a request for the new security application, and determining a classification for the new security application. The method further provides identifying related applications to the new security application based on the classification, and identifying a feature set for the new security application based on features provided in the related applications.

Claims (48)

1. A method comprising:

identifying a request to generate a new security application;

determining a classification for the new security application based on security responsibilities of the new security application;

identifying related applications with the same classification;

identifying features implemented in the related applications; and

identifying a recommended feature set comprising one or more features for the new security application, wherein the recommended feature set is identified based on the features implemented in the related applications, wherein each feature in the feature set is associated with a unified command to implement the feature in the related applications that have the feature, and wherein the unified command is translated by each application that has the feature into operations associated with the application.

2. The method of claim 1 wherein determining the classification for the new security application comprises:

generating a user interface to receive the classification for the new security application; and

receiving the classification from a developer for the new security application via the user interface.

3. The method of claim 1 wherein the new security application comprises one of a firewall, an antivirus application, a ticketing application, or a backup application.

4. The method of claim 1 wherein the features comprise security actions to be taken against security threats of a computing network.

5. The method of claim 1 further comprising:

maintaining at least one data structure, the data structure associating applications with available features; and

wherein identifying the features implemented in the related applications comprises identifying the features implemented in the related applications based on the at least one data structure.

6. The method of claim 1 wherein the unified command comprises a command in a unified syntax for an administrator of a computing network.

7. The method of claim 1 wherein the related applications comprise applications to provide security operations on different computing system hardware or software configurations.

8. A computing apparatus comprising:

one or more non-transitory computer readable storage media;

a processing system operatively coupled with the one or more non-transitory computer readable storage media; and

program instructions stored on the one or more non-transitory computer readable storage media that, when executed by the processing system, direct the processing system to at least:

identify a request to generate a new security application;

determine a classification for the new security application based on security responsibilities of the new security application;

identify related applications with the same classification;

identify features implemented in the related applications; and

identify a recommended feature set comprising one or more features for the new security application, wherein the recommended feature set is identified based on the features implemented in the related applications, wherein each feature in the feature set is associated with a unified command to implement the feature in the related applications that have the feature, and wherein the unified command is translated by each application that has the feature into operations associated with the application.

9. The computing apparatus of claim 8 wherein the program instructions to determine the classification for the new security application direct the processing system to generate a user interface to receive the classification for the new security application and receive the classification from a developer via the user interface.

10. The computing apparatus of claim 8 wherein the new security application comprises one of a firewall, an antivirus application, a ticketing application, or a backup application.

11. The computing apparatus of claim 8 wherein the features comprise security actions to be taken against security threats of a computing network.

12. The computing apparatus of claim 8 :

wherein the program instructions further direct the processing system to maintain at least one data structure, the data structure associating applications with available features; and

wherein identifying the features implemented in the related applications comprises identifying the features implemented in the related applications based on the at least one data structure.

13. The computing apparatus of claim 8 wherein the unified command comprises a command in a unified syntax for an administrator of a computing network.

14. The computing apparatus of claim 8 wherein the related applications comprise applications to provide security operations on different computing system hardware or software configurations.

15. An apparatus comprising:

one or more non-transitory computer readable storage media;

program instructions stored on the one or more non-transitory computer readable storage media that, when executed by a processing system, direct the processing system to at least:

identify a request to generate a new security application;

determine a classification for the new security application based on security responsibilities of the new security application;

identify related applications with the same classification;

identify features implemented in the related applications; and

identify a recommended feature set comprising one or more features for the new security application, wherein the recommended feature set is identified based on the features implemented in the related applications, wherein each feature in the feature set is associated with a unified command to implement the feature in the related applications that have the feature, and wherein the unified command is translated by each application that has the feature into operations associated with the application.

16. The apparatus of claim 15 wherein the program instructions to determine the classification for the new security application direct the processing system to generate a user interface to receive the classification for the new security application and receive the classification from a developer via the user interface.

17. The apparatus of claim 15 wherein the new security application comprises one of a firewall, an antivirus application, a ticketing application, or a backup application.

18. The apparatus of claim 15 wherein the features comprise security actions to be taken against security threats of a computing network.

19. The apparatus of claim 15 :

wherein the program instructions further direct the processing system to maintain at least one data structure, the data structure associating applications with available features; and

wherein identifying the features implemented in the related applications comprises identifying the features implemented in the related applications based on the at least one data structure.

20. The apparatus of claim 15 wherein the program instructions to determine the classification for the new security application direct the processing system to receive the classification for the new security application from a developer of the new security application.

Assignments (4)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 1, 2018
From: PHANTOM CYBER CORPORATION
To: SPLUNK INC.
Reel/Frame 045686/0215 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 12, 2016
From: SATISH, SOURABH; FRIEDRICHS, OLIVER; MAHADIK, ATIF; SALINAS, GOVIND; RUSSELL, RYAN
To: PHANTOM CYBER CORP.
Reel/Frame 039698/0609 →
Continuity (2)
Provisional Application 62190356 · Jul 9, 2015
Related Publication 20170013019A1 · Jan 12, 2017