IP Library Granted Patent US 11,016,826
Granted Patent B2
US 11,016,826 · App. 16/428,122 · Granted May 25, 2021

Systems and methods for multi-event correlation

Inventor: John H. Lehmann (Charlton, MA)
Assignee: Digital Guardian LLC
G06F9/542G06F11/3017G06F11/3072H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,016,826
App. No.
16/428,122
Granted
May 25, 2021
Kind
B2
Abstract

Provided herein are systems and methods for multi-event correlation. Receiving a stream of events, each leaf rule engine may detect a plurality of events from the stream that matches a characteristic for the leaf rule engine. Each leaf rule engine may identify, from the plurality of events and within a time window, a group of events that satisfies a condition for the respective leaf rule engine. A root conditions engine may receive a stream of leaf events corresponding to the group of events identified by each leaf rule engine. The root conditions engine may identify, from the received stream of leaf events and within a root time window, a collection of events that satisfies a condition for the root conditions engine. A trigger may execute an action according to the collection of events identified within the root time window.

Claims (32)

1. A system for multi-event correlation, the system comprising:

a plurality of leaf rule engines executing on at least one server having one or more hardware processors, and configured to receive a stream of events each corresponding to an activity of at least one of a user, device or program, each leaf rule engine configured to:

detect, from the stream of events, a plurality of events matching a characteristic predefined for the respective leaf rule engine; and

identify, from the plurality of events and within a respective time window, a group of events that satisfies at least one condition for the respective leaf rule engine;

a root conditions engine executing on the at least one server and configured to:

receive a stream of leaf events corresponding to the identified group of events from each of the plurality of leaf rule engines; and

identify, from the received stream of leaf events and within a root time window, a collection of events that satisfies at least one condition predefined for the root conditions engine; and

a trigger executing on the at least one server and configured to execute an action according to the collection of events identified within the root time window.

2. The system of claim 1 , wherein each event of the stream of events is described by a timestamp and at least one field.

3. The system of claim 1 , wherein each leaf rule engine is configured to store the detected plurality of events within the respective time window.

4. The system of claim 1 , wherein the respective time window of each leaf engine is different from the root time window.

5. The system of claim 1 , wherein a characteristic predefined for a first leaf rule engine of the plurality of leaf rule engines comprises a characteristic of events identified to be a potential anomaly, risk or threat.

6. The system of claim 1 , wherein a condition of a first leaf rule engine of the plurality of leaf rule engines pertains to at least one of: a total number of events, devices, files or bytes accumulated within a respective time window.

7. The system of claim 6 , wherein the total number of events, devices, files or bytes corresponds to the total number of distinct events, devices, files or bytes accumulated within the respective time window.

8. The system of claim 6 , wherein the respective time window is adjustable forward or backward in time.

9. The system of claim 1 , wherein a first leaf rule engine of the plurality of leaf rule engines is configured to update a condition for the first leaf rule engine.

10. The system of claim 1 , wherein the trigger is configured to initiate an alarm for a potential anomaly, risk or threat according to the event identified within the root time window.

11. A method for multi-event correlation, the method comprising:

detecting, by each leaf rule engine of a plurality of leaf rule engines receiving a stream of events, a plurality of events from the stream of events that matches a characteristic predefined for the respective leaf rule engine;

identifying, by each leaf rule engine of the plurality of leaf rule engines, from the plurality of events and within a respective time window, a group of events that satisfies at least one condition for the respective leaf rule engine;

receiving, by a root conditions engine, a stream of leaf events corresponding to the group of events identified by each leaf rule engine of the plurality of leaf rule engines;

identifying, by the root conditions engine, from the received stream of leaf events and within a root time window, a collection of events that satisfies at least one condition predefined for the root conditions engine; and

executing, by a trigger, an action according to the collection of events identified within the root time window.

12. The method of claim 11 , wherein each event of the stream of events is described by a timestamp and at least one field.

13. The method of claim 11 , wherein each leaf rule engine is configured to store the detected plurality of events within the respective time window.

14. The method of claim 11 , wherein the respective time window of each leaf engine is different from the root time window.

15. The method of claim 11 , wherein a characteristic predefined for a first leaf rule engine of the plurality of leaf rule engines comprises a characteristic of events identified to be a potential anomaly, risk or threat.

16. The method of claim 11 , wherein a condition of a first leaf rule engine of the plurality of leaf rule engines pertains to at least one of: a total number of events, devices, files or bytes accumulated within a respective time window.

17. The method of claim 16 , wherein the total number of events, devices, files or bytes corresponds to the total number of distinct events, devices, files or bytes accumulated within the respective time window.

18. The method of claim 16 , wherein the respective time window is adjustable forward or backward in time.

19. The method of claim 11 , further comprising adjusting, by a first leaf rule engine of the plurality of leaf rule engines, a condition for the first leaf rule engine.

20. The method of claim 11 , further comprising initiating, by the trigger, an alarm for a potential anomaly, risk or threat, according to the event identified within the root time window.

Assignments (13)
SECURITY INTEREST Recorded Jan 6, 2026
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.
To: ACQUIOM AGENCY SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 074233/0632 →
TERMINATION AND RELEASE OF FIRST LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 58892/0766 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: DIGITAL GUARDIAN LLC
Reel/Frame 073783/0619 →
NEW MONEY FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.; VERA SECURITY, INC.
To: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 073683/0534 →
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 58892/0945 Recorded Nov 21, 2025
From: ACQUIOM AGENCY SERVICES LLC
To: DIGITAL GUARDIAN LLC
Reel/Frame 073663/0411 →
EXTENDED FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: DIGITAL GUARDIAN LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073663/0844 →
EXTENDED RCF FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: DIGITAL GUARDIAN LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073663/0050 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 14, 2025
From: GOLUB CAPITAL MARKETS LLC (AS EXISTING AGENT)
To: ACQUIOM AGENCY SERVICES LLC (AS SUCCESSOR COLLATERAL AGENT)
Reel/Frame 072471/0665 →
RELEASE OF SECURITY INTEREST Recorded May 3, 2022
From: GOLUB CAPITAL LLC
To: DIGITAL GUARDIAN LLC
Reel/Frame 059802/0303 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 28, 2022
From: DIGITAL GUARDIAN, LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 058892/0766 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 28, 2022
From: DIGITAL GUARDIAN, LLC
To: GOLUB CAPITAL MARKETS LLC, AS COLLATERAL AGENT
Reel/Frame 058892/0945 →
CHANGE OF NAME Recorded Apr 21, 2021
From: DIGITAL GUARDIAN, INC.
To: DIGITAL GUARDIAN LLC
Reel/Frame 055998/0068 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 20, 2021
From: LEHMANN, JOHN H.
To: DIGITAL GUARDIAN, INC.
Reel/Frame 055975/0968 →
SECOND AMENDED AND RESTATED INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2021
From: DIGITAL GUARDIAN LLC
To: GOLUB CAPITAL LLC, AS ADMINISTRATIVE AGENT
Reel/Frame 055207/0012 →
Continuity (1)
Related Publication 20200379823A1 · Dec 3, 2020