IP Library › Granted Patent US 10,482,242
Granted Patent B2
US 10,482,242 · App. 15/215,474 · Granted Nov 19, 2019

System and method for performing event inquiries in a network

Inventors: Christian L. Hunt (Chapel Hill, NC); Thomas R. Gissel (Apex, NC); Aaron Tarter (Chapel Hill, NC); Daniel Floyd (Raleigh, NC); Benjamin Hobbs (Vacaville, CA)
Assignee: TANIUM INC.
G06F21/554G06F21/552G06F21/577H04L41/0813H04L41/0893H04L41/12H04L43/10H04L63/1408H04L63/1425H04L63/1441H04L67/141G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,482,242
App. No.
15/215,474
Granted
Nov 19, 2019
Kind
B2
Abstract

A respective node in a linear communication orbit receives an instruction packet through the linear communication orbit, where the instruction packet has been propagated from a starting node to the respective node through one or more upstream nodes along the linear communication orbit, and the instruction packet includes an instruction for establishing a direct duplex connection between the respective node and a respective server. In response to receiving the instruction packet, the respective node sends an outbound connection request to the respective server to establish the direct duplex connection. The respective node then uploads local data to the respective server through the direct duplex connection (e.g., in response to one or more queries, instructions, and requests received from the respective server through the direct duplex connection), where the respective server performs analysis on the local data received from the respective node through the direct duplex connection.

Claims (63)

1. A method of monitoring a network comprising a collection of machines that forms a linear communication orbit, the method comprising:

at a respective machine in the linear communication orbit:

receiving from a respective server, external to the linear communication orbit, an instruction packet via the linear communication orbit, wherein the instruction packet has been propagated to the respective machine through one or more upstream machines of the respective machine along the linear communication orbit, and wherein the instruction packet includes an instruction for establishing a direct duplex connection between the respective machine and the respective server;

in response to receiving the instruction packet through the linear communication orbit, sending an outbound connection request to the respective server to establish the direct duplex connection between the respective machine and the respective server in accordance with a respective network connection protocol; and

uploading local data to the respective server through the direct duplex connection, wherein the respective server is configured to perform analysis on the local data received from the respective machine through the direct duplex connection.

2. The method of claim 1 , including:

prior to uploading the local data to the respective server, receiving a request for the local data from the respective server through the direct duplex connection.

3. The method of claim 2 , wherein the request for the local data includes a request to capture a snapshot of the local database of event history.

4. The method of claim 1 , including:

maintaining a local database of event history at the respective machine, wherein the event history includes historical local values for a plurality of indicator items that are relevant to events of interest in the network.

5. The method of claim 4 , wherein the instruction packet has been propagated from a starting machine to the respective machine along the linear communication orbit, further including:

receiving a query from the respective server through the linear communication orbit, wherein the respective server injects the query into the network via the starting machine of the linear communication orbit; and

in response to receiving the query:

generating a local answer based on the historical local values stored in the local database at the respective machine; and

sending the local answer to the starting machine through the linear communication orbit, wherein the starting machine responds to the respective server based at least in part on the local answer collected from the respective machine.

6. The method of claim 5 , wherein the starting machine receives respective local answers from a plurality of machines in the linear communication orbit and sends an integrated response to the respective server based on the respective local answers collected from the plurality of machines in the linear communication orbit.

7. The method of claim 1 , including:

receiving, from the respective server and through the direct duplex connection, a request for event artifacts associated with an event of interest; and

in response to the request for event artifacts, sending relevant event artifact data for the event of interest to the respective server through the direct duplex connection.

8. The method of claim 1 , wherein the direct duplex connection is a secure Web Socket connection.

9. The method of claim 1 , wherein the respective server is separated from the network by a firewall.

10. A respective machine in a collection of machines that forms a linear communication orbit, the respective machine comprising:

one or more processors; and

memory storing instructions that, when executed by the one or more processors, cause the processors to perform operations including:

receiving from a respective server, external to the linear communication orbit, an instruction packet via the linear communication orbit, wherein the instruction packet has been propagated to the respective machine through one or more upstream machines of the respective machine along the linear communication orbit, and wherein the instruction packet includes an instruction for establishing a direct duplex connection between the respective machine and the respective server;

in response to receiving the instruction packet through the linear communication orbit, sending an outbound connection request to the respective server to establish the direct duplex connection between the respective machine and the respective server in accordance with a respective network connection protocol; and

uploading local data to the respective server through the direct duplex connection, wherein the respective server is configured to perform analysis on the local data received from the respective machine through the direct duplex connection.

11. The respective machine of claim 10 , wherein the operations further include:

prior to uploading the local data to the respective server, receiving a request for the local data from the respective server through the direct duplex connection.

12. The respective machine of claim 11 , wherein the request for the local data includes a request to capture a snapshot of the local database of event history.

13. The respective machine of claim 10 , wherein the operations further include:

maintaining a local database of event history at the respective machine, wherein the event history includes historical local values for a plurality of indicator items that are relevant to events of interest in the network.

14. The respective machine of claim 13 , wherein the instruction packet has been propagated from a starting machine to the respective machine along the linear communication orbit, and the operations further include:

receiving a query from the respective server through the linear communication orbit, wherein the respective server injects the query into the network via the starting machine of the linear communication orbit; and

in response to receiving the query:

generating a local answer based on the historical local values stored in the local database at the respective machine; and

sending the local answer to the starting machine through the linear communication orbit, wherein the starting machine responds to the respective server based at least in part on the local answer collected from the respective machine.

15. The respective machine of claim 14 , wherein the starting machine receives respective local answers from a plurality of machines in the linear communication orbit and sends an integrated response to the respective server based on the respective local answers collected from the plurality of machines in the linear communication orbit.

16. The respective machine of claim 15 , wherein the operations further include:

receiving, from the respective server and through the direct duplex connection, a request for event artifacts associated with an event of interest; and

in response to the request for event artifacts, sending relevant event artifact data for the event of interest to the respective server through the direct duplex connection.

17. The respective machine of claim 10 , wherein the direct duplex connection is a secure WebSocket connection.

18. The respective machine of claim 10 , wherein the respective server is separated from the network by a firewall.

19. A non-transitory computer-readable medium storing instructions that, when executed by one or more processors on a respective machine in a collection of machines that forms a linear communication orbit, cause the processors to perform operations comprising:

receiving from a respective server, external to the linear communication orbit, an instruction packet via the linear communication orbit, wherein the instruction packet has been propagated to the respective machine through one or more upstream machines of the respective machine along the linear communication orbit, and wherein the instruction packet includes an instruction for establishing a direct duplex connection between the respective machine and the respective server;

in response to receiving the instruction packet through the linear communication orbit, sending an outbound connection request to the respective server to establish the direct duplex connection between the respective machine and the respective server in accordance with a respective network connection protocol; and

uploading local data to the respective server through the direct duplex connection, wherein the respective server is configured to perform analysis on the local data received from the respective machine through the direct duplex connection.

20. The non-transitory computer-readable medium of claim 19 , wherein the operations further include:

prior to uploading the local data to the respective server, receiving a request for the local data from the respective server through the direct duplex connection.

21. The non-transitory computer-readable medium of claim 20 , wherein the request for the local data includes a request to capture a snapshot of the local database of event history.

22. The non-transitory computer-readable medium of claim 19 , wherein the operations include:

maintaining a local database of event history at the respective machine, wherein the event history includes historical local values for a plurality of indicator items that are relevant to events of interest in the network.

23. The non-transitory computer-readable medium of claim 22 , wherein the instruction packet has been propagated from a starting machine to the respective machine along the linear communication orbit, and the operations include:

receiving a query from the respective server through the linear communication orbit, wherein the respective server injects the query into the network via the starting machine of the linear communication orbit; and

in response to receiving the query:

generating a local answer based on the historical local values stored in the local database at the respective machine; and

sending the local answer to the starting machine through the linear communication orbit, wherein the starting machine responds to the respective server based at least in part on the local answer collected from the respective machine.

24. The non-transitory computer-readable medium of claim 23 , wherein the starting machine receives respective local answers from a plurality of machines in the linear communication orbit and sends an integrated response to the respective server based on the respective local answers collected from the plurality of machines in the linear communication orbit.

25. The non-transitory computer-readable medium of claim 19 , wherein the operations include:

receiving, from the respective server and through the direct duplex connection, a request for event artifacts associated with an event of interest; and

in response to the request for event artifacts, sending relevant event artifact data for the event of interest to the respective server through the direct duplex connection.

26. The non-transitory computer-readable medium of claim 19 , wherein the direct duplex connection is a secure WebSocket connection.

27. The non-transitory computer-readable medium of claim 19 , wherein the respective server is separated from the network by a firewall.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 13, 2016
From: HUNT, CHRISTIAN L.; GISSEL, THOMAS R.; TARTER, AARON; FLOYD, DANIEL; HOBBS, BENJAMIN
To: TANIUM INC.
Reel/Frame 039426/0959 →
Continuity (3)
Provisional Application 62333768 · May 9, 2016
Provisional Application 62305482 · Mar 8, 2016
Related Publication 20170264588A1 · Sep 14, 2017
Cited By (15)
US 12,204,652 US 12,229,032 US 12,229,276 US 12,231,457 US 12,231,467 US 12,284,204 US 12,309,239 US 12,316,486 US 12,346,451 US 12,373,566 US 12,406,068 US 12,556,623 US 12,632,357 US 12,717,931 US 12,719,916