IP Library Granted Patent US 11,080,116
Granted Patent B2
US 11,080,116 · App. 16/232,110 · Granted Aug 3, 2021

Methods for decomposing events from managed infrastructures

Inventors: Philip Tee (San Francisco, CA); Robert Duncan Harper (London, GB); Charles Mike Silvey (San Francisco, CA)
Assignee: Moogsoft Inc.
G06F11/0709G06F3/0481G06F11/079G06F11/0751G06F11/0769G06F11/0778G06F11/30G06F16/358G06F21/552G06F21/577G06Q10/107H04L41/065H04L41/0631H04L41/0893H04L41/12H04L41/22H04L51/063H04L51/16H04L51/24G06Q10/00H04L41/046H04L43/0817
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,080,116
App. No.
16/232,110
Granted
Aug 3, 2021
Kind
B2
Abstract

A method is provided for communication with a managed infrastructure. Messages are received at an extraction engine from managed infrastructure that includes managed infrastructure physical hardware that supports the flow and processing of information. Events are produced that relate to the managed infrastructure. The events are converted into words and subsets used to group the events that relate to failures or errors in the managed infrastructure, including the managed infrastructure physical hardware. One or more common characteristics of events are determined. Clusters of events are produced relating to the failure or errors in the managed infrastructure. A source address is used for each event and a graph topology of the managed infrastructure to assign a graph coordinate to the event. Membership in a cluster indicates a common factor of the events that is a failure or an actionable problem in the physical hardware managed infrastructure directed to supporting the flow and processing of information. In response to production of the clusters one or more physical changes is made in a managed infrastructure hardware and security of the managed infrastructure is maintained.

Claims (25)

1. A method for communication with a managed infrastructure, comprising:

receiving messages at an extraction engine from managed infrastructure that includes managed infrastructure physical hardware that supports the flow and processing of information;

producing events that relate to the managed infrastructure and converting the events into words and subsets used to group the events that relate to failures or errors in the managed infrastructure, including the managed infrastructure physical hardware;

determining one or more common characteristics of events and producing clusters of events relating to the failure or errors in the managed infrastructure; using a source address for each event and a graph topology of the managed infrastructure to assign a graph coordinate to the event; where membership in a cluster indicates a common factor of the events that is a failure or an actionable problem in the physical hardware managed infrastructure; and

wherein in response to production of the clusters one or more physical changes in a managed infrastructure hardware is made, where the hardware supports the flow and processing of information, and in response to production of the clusters security of the managed infrastructure is maintained.

2. The method of claim 1 , wherein security includes at least one of managed infrastructure: breach, intrusion or propagation.

3. The method of claim 1 , wherein security includes managed infrastructure: access control, intrusion detection and threat propagation.

4. The method of claim 1 , wherein security includes authentication of a subject.

5. The method of claim 1 , wherein security includes authorization of a subject.

6. The method of claim 5 , wherein authorization specifies what a subject can do.

7. The method of claim 1 , wherein security includes audit.

8. The method of claim 1 , where security includes identification and authentication to ensure that only authorized subjects can access the managed infrastructure.

9. The method of claim 1 , wherein security includes access approval grants to the managed infrastructure by association of users with resources that they are allowed to access, based on an authorization policy.

10. The method of claim 1 , wherein the managed infrastructure is from a business organization.

11. The method of claim 1 , wherein the managed infrastructure includes, computers, network devices, appliances, mobile devices, text or numerical values from which those text or numerical values indicate a state of any hardware or software component of the managed infrastructure.

12. The method of claim 1 , wherein the managed infrastructure generates data that include attributes selected from at least one of, time, source a description of the event, textural or numerical values from which those text or numerical values indicate a state of any hardware or software component of the managed infrastructure.

13. The method of claim 1 , further comprising: a publication message bus.

14. The method of claim 1 , further comprising: a data bus web server coupled to one or more user interfaces.

15. The method of claim 1 , wherein a plurality of link access modules is in communication with a data bus.

16. The method of claim 1 , further comprising: a database.

17. The method of claim 1 , wherein the extraction engine reformats data from the events to create reformatted data.

18. The method of claim 17 , wherein the reformatted data is received at a system bus.

19. The method of claim 1 , wherein a dictionary is generated with the word and subtexts using Shannon Entropy, −1n(1/NGen) and normalizes the words and subtexts.

20. The method of claim 11 , wherein normalized words and subtexts are mapped from a common 0.0 to a non-common 1.0.

21. The method of claim 1 , further comprising: an entropy database that in operation normalizes entropy for events.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 6, 2023
From: EMC CORPORATION
To: DELL PRODUCTS L.P.
Reel/Frame 065179/0980 →
MERGER Recorded Oct 4, 2023
From: MOOGSOFT INC.
To: EMC CORPORATION
Reel/Frame 065156/0805 →
RELEASE OF SECURITY INTEREST Recorded Aug 11, 2023
From: STIFEL BANK
To: MOOGSOFT INC.
Reel/Frame 064569/0391 →
SECURITY INTEREST Recorded Jan 23, 2022
From: MOOGSOFT INC.
To: STIFEL BANK
Reel/Frame 058734/0193 →
Continuity (4)
Continuation In Part 15350950 · Nov 14, 2016
Continuation 14262890 · Apr 28, 2014
Provisional Application 61816867 · Apr 29, 2013
Related Publication 20190129783A1 · May 2, 2019