IP Library Granted Patent US 11,188,655
Granted Patent B2
US 11,188,655 · App. 15/588,391 · Granted Nov 30, 2021

Scanning information technology (IT) components for compliance

Inventor: Sachin Johar (Karnataka, IN)
Assignee: Micro Focus LLC
G06F21/577G06F21/552G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,188,655
App. No.
15/588,391
Granted
Nov 30, 2021
Kind
B2
Abstract

Examples disclosed herein relate to scanning an IT component for compliance. In an example, events related to an IT component and past compliance scans performed on the IT component may be analyzed. Based on an analysis of the events related to the IT component and the past compliance scans performed on the IT component, a determination may be made whether a compliance scan is to be performed on the IT component.

Claims (56)

1. A method performed by a system comprising a hardware processor, comprising:

analyzing event data of events related to information technology (IT) components;

identifying, based on the event data, compliance rules for the IT components;

generating, based on the identifying of compliance rules for the IT components, a compliance policy that comprises the compliance rules;

analyzing past compliance scans performed on the IT components according to the generated compliance policy;

determining whether a compliance scan is to be performed on the IT components according to the generated compliance policy, based on the analyzing of the past compliance scans,

wherein real time events including the generated compliance policy are weighted more than previous events including the past compliance scans when determining whether a compliance scan is to be performed on the IT components; and

in response to determining that the compliance scan is to be performed on the IT components according to the generated compliance policy:

determining a time period for initiating the compliance scan on the IT components according to the generated compliance policy, wherein the determining the time period is based on use of a predictive algorithm to recommend the time period, and

initiating, at the determined time period, scanning of the IT components according to the generated compliance policy,

wherein the compliance rules are based on validation on the IT components and

wherein the event data includes events executed on the IT components.

2. The method of claim 1 , wherein the IT components are part of a data center.

3. The method of claim 1 , wherein the IT components are part of a cloud.

4. The method of claim 1 , wherein the analyzing of the past compliance scans uses a machine learning algorithm, and wherein the determining of the time period based on the use of the predictive algorithm is further based on the analyzing of the past compliance scans using the machine learning algorithm.

5. The method of claim 1 , wherein the time period determined based on the use of the predictive algorithm is different from a scheduled time period.

6. The method of claim 1 , wherein the compliance rules included in the compliance policy comprise a rule governing a specified order of execution of activities.

7. The method of claim 1 , wherein the compliance rules included in the compliance policy comprise a rule governing a characteristic of a password.

8. The method according to claim 1 , wherein the event data is captured in a log file by the IT components.

9. The method according to claim 1 , wherein the compliance policy is dynamically generated based on the compliance rules.

10. A system comprising:

a processor; and

a non-transitory storage medium storing instructions executable on the processor to:

analyze events generated on information technology (IT) components to identify compliance rules for the IT components;

generate, based on the identifying of the compliance rules, a compliance policy comprising the compliance rules;

analyze previous compliance scans performed on the IT components according to the generated compliance policy; and

determine whether the IT components are to be scanned for compliance with the generated compliance policy, based on the analysis of the previous compliance scans performed on the IT components according to the generated compliance policy,

wherein real time events including the generated compliance policy are weighted more than previous events including the previous compliance scans when determining whether the IT components are to be scanned for compliance; and

in response to determine that the IT components are to be scanned according to the generated compliance policy:

determine a time period for performing the scanning of the IT components, wherein determination of the time period is based on use of a predictive algorithm to recommend the time period, and

initiate, at the determined time period, a scan of the IT components according to the generated compliance policy,

wherein the compliance rules are based on validation on the IT components and

wherein the events generated on IT components include events executed on the IT components.

11. The system of claim 10 , wherein the instructions are executable on the processor to determine a priority for performing the scanning of the IT components.

12. The system of claim 10 , wherein the analysis of the previous compliance scans performed on the IT components according to the generated compliance policy uses a machine learning algorithm, and wherein the determination of the time period based on the use of the predictive algorithm is further based on the analysis of the previous compliance scans performed on the IT components according to the generated compliance policy using the machine learning algorithm.

13. The system of claim 10 , wherein the analysis of the previous compliance scans performed on the IT components according to the generated compliance policy is based on a machine learning algorithm, and wherein the determining of the time period based on the use of the predictive algorithm is further based on the analysis of the past compliance scans performed on the IT components according to the generated compliance policy using the machine learning algorithm.

14. The system of claim 10 , wherein the time period determined based on the use of the predictive algorithm is different from a scheduled time period.

15. The system of claim 10 , wherein the compliance rules included in the compliance policy comprise a rule governing a specified order of execution of activities.

16. The system of claim 10 , wherein the compliance rules included in the compliance policy comprise a rule governing a characteristic of a password.

17. A non-transitory machine-readable storage medium comprising instructions that upon execution cause a system to:

analyze event data of events of a plurality of information technology (IT) components;

identify, based on the event data, compliance rules for the plurality of IT components;

identify, based on the compliance rules, a compliance policy that comprises the compliance rules;

analyze previous compliance scans performed on the plurality of IT components according to the identified compliance policy;

based on the analysis of the previous compliance scans performed on the plurality of IT components according to the identified compliance policy, determine whether a compliance scan is to be performed on the plurality of IT components according to the identified compliance policy,

wherein real time events including the identified compliance policy are weighted more than previous events including the previous compliance scans when determining whether a compliance scan is to be performed on the plurality of IT components; and

in response to determining that the compliance scan is to be performed on the plurality of IT components according to the identified compliance policy:

determine a time period to initiate the compliance scan on the plurality of IT components according to the identified compliance policy and based on the analysis of the previous compliance scans performed on the plurality of IT components according to the identified compliance policy and use of a predictive algorithm to recommend the time period, and

initiate the compliance scan on the plurality of IT components at the determined time period, to cause scanning of the plurality of IT components according to the identified compliance policy,

wherein the compliance rules are based on validation on the IT components and

wherein the event data includes events executed on the IT components.

18. The non-transitory machine-readable storage medium of claim 17 , wherein the plurality of IT components are part of a cloud system.

19. The non-transitory machine-readable storage medium of claim 17 , wherein the analysis of the previous compliance scans performed on the plurality of IT components according to the identified compliance policy is based on a machine learning algorithm.

20. The non-transitory machine-readable storage medium of claim 17 , wherein the time period determined based on the use of the predictive algorithm is different from a scheduled time period.

21. The non-transitory machine-readable storage medium of claim 17 , wherein the compliance rules included in the compliance policy comprise a rule governing a specified order of execution of activities.

22. The non-transitory machine-readable storage medium of claim 17 , wherein the compliance rules included in the compliance policy comprise a rule governing a characteristic of a password.

Assignments (6)
RELEASE OF SECURITY INTEREST REEL/FRAME 059610/0338 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC
Reel/Frame 062626/0134 →
SECURITY AGREEMENT Recorded Apr 5, 2022
From: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC)
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 059610/0338 →
SECURITY AGREEMENT Recorded Apr 5, 2022
From: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC)
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 059610/0380 →
CHANGE OF NAME Recorded Aug 8, 2019
From: ENTIT SOFTWARE LLC
To: MICRO FOCUS LLC
Reel/Frame 050004/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 5, 2018
From: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
To: ENTIT SOFTWARE LLC
Reel/Frame 048261/0084 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 5, 2017
From: JOHAR, SACHIN
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 042260/0333 →
Priority Claims (1)
IN 201641017163 · May 18, 2016 · national
Continuity (1)
Related Publication 20170337379A1 · Nov 23, 2017