IP Library Granted Patent US 11,240,256
Granted Patent B2
US 11,240,256 · App. 15/420,417 · Granted Feb 1, 2022

Grouping alerts into bundles of alerts

Inventors: Tomasz Jaroslaw Bania (Mountain View, CA); William G. Horne (Lawrenceville, NJ); Renato Keshet (Haifa, IL); Pratyusa K. Manadhata (Piscataway, NJ); Manish Marwah (Palo Alto, CA); Brent James Miller (Raleigh, NC); Barak Raz (Tel Aviv, IL); Tomas Sander (New York, NY)
Assignee: Micro Focus LLC
H04L63/14H04L63/1416H04L63/1425H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,240,256
App. No.
15/420,417
Granted
Feb 1, 2022
Kind
B2
Abstract

In some examples, a plurality of alerts relating to issues in a computing arrangement are received, where the plurality of alerts generated based on events in the computing arrangement. A subset of the plurality of alerts is grouped into a bundle of alerts, the grouping being based on a criterion. The bundle of alerts is communicated to cause processing of the alerts in the bundle of alerts together.

Claims (38)

1. A non-transitory machine-readable storage medium storing instructions that upon execution cause a system to:

receive a plurality of alerts relating to issues in a computing arrangement, the plurality of alerts generated based on events in the computing arrangement;

group a subset of the plurality of alerts into a bundle of alerts, the grouping being based on a criterion, wherein grouping the subset of the plurality of alerts into the bundle of alerts based on the criterion comprises grouping the subset of the plurality of alerts according to a comparison of behavioral profiles of respective alerts of the plurality of alerts; and

trigger processing of the alerts in the bundle of alerts together to address the issues.

2. The non-transitory machine-readable storage medium of claim 1 , wherein the comparison of the behavioral profiles of respective alerts of the plurality of alerts comprises comparing profiles of a measure associated with the respective alerts of the plurality of alerts, wherein each profile of the measure includes a variation of values of the measure as a function of a variable.

3. The non-transitory machine-readable storage medium of claim 1 , wherein grouping the subset of the plurality of alerts into the bundle of alerts based on the criterion comprises grouping the subset of the plurality of alerts according to a comparison of criticalities of assets impacted by respective alerts of the plurality of alerts.

4. The non-transitory machine-readable storage medium of claim 3 , further comprising determining the criticalities of the assets impacted by the respective alerts of the plurality of alerts based upon a rule that specifies a criticality of a given asset responsive to a factor selected from among a role of an owner of the given asset or a type of data stored on the given asset.

5. The non-transitory machine-readable storage medium of claim 1 , wherein grouping the subset of the plurality of alerts into the bundle of alerts based on the criterion comprises grouping the subset of the plurality of alerts according to a comparison of analytics modules that generate respective alerts of the plurality of alerts, wherein the comparison of the analytics modules that generate respective alerts of the plurality of alerts comprises comparing rules or policies applied by the analytics modules to generate respective alerts.

6. The non-transitory machine-readable storage medium of claim 1 , wherein grouping the subset of the plurality of alerts into the bundle of alerts based on the criterion comprises grouping the subset of the plurality of alerts according to a comparison of indicators of compromise associated with respective alerts of the plurality of alerts, wherein each indicator of compromise includes an artifact indicating compromise of the computing arrangement.

7. The non-transitory machine-readable storage medium of claim 1 , wherein grouping the subset of the plurality of alerts into the bundle of alerts based on the criterion comprises grouping the subset of the plurality of alerts based on a determination that the subset of the plurality of alerts affect members of a predefined group.

8. The non-transitory machine-readable storage medium of claim 1 , wherein the criterion is selected from among similarity of events associated with respective alerts of the plurality of alerts, similarity of targets affected by respective alerts of the plurality of alerts, similarity sources of respective alerts of the plurality of alerts, similarity of attributes of users affected by or causing respective alerts of the plurality of alerts, similarity of features of features of respective alerts of the plurality of alerts, similarity of timings of respective alerts of the plurality of alerts, and similarity of analyst-defined tags of respective alerts of the plurality of alerts.

9. The non-transitory machine-readable storage medium of claim 1 , wherein the instructions upon execution cause the system to further:

identify related information for the bundle of alerts; and

communicate the identified related information for the bundle of alerts with the bundle of alerts to trigger processing of the alerts in the bundle of alerts together.

10. A system comprising:

a processor; and

a non-transitory storage medium storing instructions executable on the processor to:

receive event data relating to a plurality of events corresponding to operation of a computing arrangement;

generate a plurality of alerts in response to respective events of the plurality of events;

select, based on a similarity criterion, a subset of the plurality of alerts, and grouping the selected subset of the plurality of alerts into a bundle of alerts, wherein the selecting of the subset of the plurality of alerts that is included in the bundle of alerts is based on the similarity criterion comprising similarity of criticalities of assets impacted by the alerts of the plurality of alerts; and

trigger processing of the bundle of alerts to address respective issues in the computing arrangement.

11. The system of claim 10 , wherein the selecting of the subset of the plurality of alerts that are included in the bundle of alerts is based on the similarity criterion comprising: similarity of events associated with respective alerts of the plurality of alerts, similarity of behavioral profiles of respective alerts of the plurality of alerts, and similarity of analytics modules that generate respective alerts of the plurality of alerts.

12. The system of claim 10 , wherein the selecting of the subset of the plurality of alerts that are included in the bundle of alerts is based on the similarity criterion specifying that alerts affecting members of a predefined group are to be grouped.

13. A method of a system comprising a computer processor, comprising:

receiving a plurality of alerts relating to issues in a computing arrangement, the plurality of alerts generated based on events in the computing arrangement;

grouping a subset of the plurality of alerts into a bundle of alerts, the grouping being based on a grouping criterion that specifies grouping of alerts according to a comparison of behavioral profiles of respective alerts of the plurality of alerts, each behavioral profile of the behavioral profiles comprising a variation of values of a measure as a function of a variable;

identifying related information for the bundle of alerts based on a related information identification criterion;

communicating the bundle of alerts and the identified related information for the bundle of alerts; and

in response to the communicating of the bundle of alerts and the identified related information for the bundle of alerts, triggering processing of the alerts in the bundle of alerts together to address the issues.

14. The method of claim 13 , wherein the related information identification criterion is selected from among: a specification of an extent of historical data to search, a type of information to be returned, a feature used to determine similarity of alerts, a type of alert, a criticality of an alert, an asset affected by an alert, a category to which the bundle of alerts belong, and presence of an alert from a security tool.

15. The non-transitory machine-readable storage medium of claim 1 , wherein grouping the subset of the plurality of alerts into the bundle of alerts based on the criterion comprises:

grouping, into the bundle of alerts, a first alert generated responsive to a first set of events, and a second alert generated responsive to a second set of events, responsive to determining that the first set of events and the second set of events share greater than a threshold amount of common events.

16. The non-transitory machine-readable storage medium of claim 15 , wherein sharing greater than the threshold amount of common events is satisfied if:

the first set of events and the second set of events share greater than a threshold number of the common events, or

the first set of events and the second set of events share greater than a threshold percentage amount of the common events.

17. The non-transitory machine-readable storage medium of claim 2 , wherein the variable that the values of the measure are a function of comprises time or location.

18. The non-transitory machine-readable storage medium of claim 2 , wherein each behavioral profile of the behavioral profiles comprises variations of values of a plurality of measures as a function of the variable.

19. The system of claim 10 , wherein the selecting of the subset of the plurality of alerts that are included in the bundle of alerts is based on the similarity criterion that specifies grouping of alerts according to a comparison of behavioral profiles of respective alerts of the plurality of alerts, each behavioral profile of the behavioral profiles comprising a variation of values of a measure as a function of a variable.

Assignments (7)
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0577 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC)
Reel/Frame 063560/0001 →
CHANGE OF NAME Recorded Aug 8, 2019
From: ENTIT SOFTWARE LLC
To: MICRO FOCUS LLC
Reel/Frame 050004/0001 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ENTIT SOFTWARE LLC; ARCSIGHT, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0577 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 9, 2017
From: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
To: ENTIT SOFTWARE LLC
Reel/Frame 042746/0130 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 1, 2017
From: BANIA, TOMASZ JAROSLAW; HORNE, WILLIAM G.; KESHET, RENATO; MANADHATA, PRATYUSA K.; MARWAH, MANISH; MILLER, BRENT JAMES; RAZ, BARAK; SANDER, TOMAS
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 041142/0758 →
Continuity (1)
Related Publication 20180219875A1 · Aug 2, 2018
Cited By (2)
US 12,244,648 US 12,368,695