IP Library Granted Patent US 10,936,380
Granted Patent B1
US 10,936,380 · App. 16/198,430 · Granted Mar 2, 2021

Systems and methods for filtering events

Inventor: Mikalaj Abramau (Minsk, BY)
Assignee: Stealthbits Technologies LLC
G06F9/542G06F9/543G06F16/1734
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,936,380
App. No.
16/198,430
Granted
Mar 2, 2021
Kind
B1
Abstract

A method is described. The method includes checking a raw event generated by a file system against a set of predicates conditions indicative of a high-level user operation. The method also includes filtering multiple raw events with a finite state machine (FSM) in response to determining that the raw event matches a predicate condition. The method further includes identifying a single high-level event for the high-level user operation based on the multiple raw events filtered by the FSM.

Claims (51)

1. A method, comprising:

checking a raw event generated by a file system against a set of predicate conditions indicative of a high-level user operation;

creating a finite state machine (FSM) in response to determining that the raw event matches a predicate condition;

filtering multiple raw events with the FSM, wherein the FSM changes states in response to a sequence in the multiple raw events associated with a high-level user operation, and wherein the multiple raw events comprise logs of operations implemented by the file system;

identifying a single high-level event for the high-level user operation based on the multiple raw events filtered by the FSM;

marking the FSM for deactivation;

deleting the FSM marked for deactivation; and

selecting a next active FSM.

2. The method of claim 1 , wherein the predicate condition comprises a certain combination of information that indicates a start of a sequence of raw events generated by the file system as part of the high-level user operation.

3. The method of claim 1 , wherein the FSM is associated with a file path of the raw event that matches the predicate condition.

4. The method of claim 1 , wherein the FSM identifies one type of high-level event.

5. The method of claim 1 , wherein the FSM has associated storage that holds the multiple raw events in an order in which the multiple raw events are received.

6. The method of claim 1 , wherein a final state of the FSM indicates the high-level event.

7. The method of claim 1 , further comprising:

emitting the single high-level event on a processing pipeline in response to identifying the single high-level event; and

discarding the multiple raw events from the processing pipeline.

8. A computing device, comprising:

a processor;

a memory in electronic communication with the processor; and

instructions stored in the memory, the instructions being executable to:

check a raw event generated by a file system against a set of predicate conditions indicative of a high-level user operation;

create a finite state machine (FSM) in response to determining that the raw event matches a predicate condition;

filter multiple raw events with the FSM, wherein the FSM changes states in response to a sequence in the multiple raw events associated with a high-level user operation, and wherein the multiple raw events comprise logs of operations implemented by the file system;

identify a single high-level event for the high-level user operation based on the multiple raw events filtered by the FSM;

mark the FSM for deactivation;

delete the FSM marked for deactivation; and

select a next active FSM.

9. The computing device of claim 8 , wherein the predicate condition comprises a certain combination of information that indicates a start of a sequence of raw events generated by the file system as part of the high-level user operation.

10. The computing device of claim 8 , wherein the FSM is associated with a file path of the raw event that matches the predicate condition.

11. The computing device of claim 8 , wherein the FSM identifies one type of high-level event.

12. The computing device of claim 8 , wherein the FSM has associated storage that holds the multiple raw events in an order in which the multiple raw events are received.

13. The computing device of claim 8 , wherein a final state of the FSM indicates the high-level event.

14. The computing device of claim 8 , further comprising instructions executable to:

emit the single high-level event on a processing pipeline in response to identifying the single high-level event; and

discard the multiple raw events from the processing pipeline.

15. A non-transitory, tangible computer-readable medium, comprising executable instructions for:

checking a raw event generated by a file system against a set of predicate conditions indicative of a high-level user operation;

creating a finite state machine (FSM) in response to determining that the raw event matches a predicate condition;

filtering multiple raw events with the FSM, wherein the FSM changes states in response to a sequence in the multiple raw events associated with a high-level user operation, and wherein the multiple raw events comprise logs of operations implemented by the file system;

identifying a single high-level event for the high-level user operation based on the multiple raw events filtered by the FSM;

marking the FSM for deactivation;

deleting the FSM marked for deactivation; and

selecting a next active FSM.

16. The computer-readable medium of claim 15 , wherein the predicate condition comprises a certain combination of information that indicates a start of a sequence of raw events generated by the file system as part of the high-level user operation.

17. The computer-readable medium of claim 15 , wherein the FSM is associated with a file path of the raw event that matches the predicate condition.

18. The computer-readable medium of claim 15 , wherein the FSM identifies one type of high-level event.

19. The computer-readable medium of claim 15 , wherein the FSM has associated storage that holds the multiple raw events in an order in which the multiple raw events are received.

20. The computer-readable medium of claim 15 , wherein a final state of the FSM indicates the high-level event.

21. The computer-readable medium of claim 15 , further comprising executable instructions for:

emitting the single high-level event on a processing pipeline in response to identifying the single high-level event; and

discarding the multiple raw events from the processing pipeline.

Assignments (5)
RELEASE OF SECURITY INTEREST Recorded Jul 7, 2022
From: TC LENDING, LLC, AS COLLATERAL AGENT
To: STEALTHBITS TECHNOLOGIES LLC (F/K/A STEALTHBITS TECHNOLOGIES II LLC)
Reel/Frame 060430/0798 →
SECURITY INTEREST Recorded Jun 9, 2022
From: NETWRIX CORPORATION; POLICYPAK SOFTWARE, LLC; STEALTHBITS TECHNOLOGIES LLC
To: GOLUB CAPITAL MARKETS LLC, AS COLLATERAL AGENT
Reel/Frame 060152/0855 →
MERGER AND CHANGE OF NAME Recorded Feb 25, 2021
From: STEALTHBITS TECHNOLOGIES, INC.; STEALTHBITS TECHNOLOGIES II LLC; STEALTHBITS TECHNOLOGIES II LLC
To: STEALTHBITS TECHNOLOGIES LLC
Reel/Frame 055416/0485 →
PATENT SECURITY AGREEMENT Recorded Dec 31, 2020
From: STEALTHBITS TECHNOLOGIES II LLC
To: TC LENDING, LLC, AS COLLATERAL AGENT
Reel/Frame 054884/0804 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 27, 2018
From: ABRAMAU, MIKALAJ
To: STEALTHBITS TECHNOLOGIES, INC.
Reel/Frame 047862/0556 →