IP Library Granted Patent US 11,330,001
Granted Patent B2
US 11,330,001 · App. 16/527,981 · Granted May 10, 2022

Platform for the extraction of operational technology data to drive risk management applications

Inventor: Steven G. Schlarman (Shawnee, KS)
Assignee: EMC IP Holding Company LLC
H04L63/1416H04L63/0421H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,330,001
App. No.
16/527,981
Granted
May 10, 2022
Kind
B2
Abstract

A method in one embodiment includes receiving usage data from a first operational management system, the first operational management system utilizing a plurality of assets of an information technology infrastructure. The method also includes identifying, based at least in part on the received usage data, one or more asset relationships between at least two assets of the plurality of assets, and one or more user-asset relationships between one or more users and one or more of the plurality of assets. In the method, one or more parameters of a plurality of parameters are applied to the identified asset and user-asset relationships to determine one or more designations associated with the identified asset and user-asset relationships. The one or more designations are transmitted to a second operational management system to trigger a risk management workflow based at least in part on the one or more designations.

Claims (44)

1. An apparatus comprising:

at least one processing platform comprising a plurality of processing devices;

said at least one processing platform:

receiving usage data from a first operational management system, the first operational management system utilizing a plurality of assets of an information technology infrastructure;

identifying, based at least in part on the received usage data, one or more asset relationships between at least two assets of the plurality of assets, and one or more user-asset relationships between one or more users and one or more of the plurality of assets;

applying one or more parameters of a plurality of parameters to the identified asset and user-asset relationships to determine one or more designations associated with the identified asset and user-asset relationships; and

transmitting the one or more designations to a second operational management system to trigger a risk management workflow based at least in part on the one or more designations;

wherein, in applying the one or more parameters, said at least one processing platform identifies a volume of communications for a given asset of at least one of a given asset relationship and a given user-asset relationship;

wherein the one or more parameters comprises a rule that if the identified volume of communications exceeds a threshold volume, then the given asset is designated as a high priority asset for the risk management workflow; and

wherein the given asset is dynamically identifiable as a component of at least one of the given asset relationship and the given user-asset relationship based at least in part on the usage data comprising one or more of packet activity data, source data and destination data.

2. The apparatus of claim 1 wherein the one or more designations comprise a characterization of one or more risks associated with the identified asset and user-asset relationships.

3. The apparatus of claim 1 wherein the usage data comprises at least one of network traffic data, identification data for the plurality of assets, and asset communication log data.

4. The apparatus of claim 1 wherein the usage data comprises metadata corresponding to communications between the at least two assets associated with the identified one or more asset relationships.

5. The apparatus of claim 1 wherein said at least one processing platform further determines a frequency of communication between entities of the given asset relationship, and between entities of the given user-asset relationship.

6. The apparatus of claim 1 wherein said at least one processing platform further identifies a location where one or more of the plurality of assets is hosted.

7. The apparatus of claim 1 wherein said at least one processing platform further determines whether the given user-asset relationship comprises one of an enterprise relationship and a dedicated function relationship based at least in part on at least one of a number of users associated with the given user-asset relationship and a category of users associated with the given user-asset relationship.

8. The apparatus of claim 1 wherein said at least one processing platform further maintains a catalog associating the plurality of assets with one or more asset types.

9. The apparatus of claim 1 wherein, in applying the one or more parameters, said at least one processing platform identifies a category of users associated with the given user-asset relationship.

10. The apparatus of claim 1 wherein the volume of communications comprises one or more periods of relatively high communication volume relative to other periods of relatively low communication volume.

11. The apparatus of claim 1 wherein, in applying the one or more parameters, said at least one processing platform determines whether the given asset of the plurality of assets comprises at least one of personally identifiable information and electronic protected health information.

12. The apparatus of claim 1 wherein, in applying the one or more parameters, said at least one processing platform compares a number of users accessing the given asset of the plurality of assets with a threshold number of users to determine whether a relatively high number of users are accessing the given asset.

13. The apparatus of claim 1 wherein the one or more parameters comprise an asset utilization threshold.

14. The apparatus of claim 1 wherein said at least one processing platform further determines at least one of a type of data, a volume of the data and a growth rate of the data associated with the given asset of the plurality of assets.

15. The apparatus of claim 1 wherein the risk management workflow comprises prioritizing risk management based at least in part on at least one of time and location associated with use of the given asset of the plurality of assets.

16. A method comprising:

receiving usage data from a first operational management system, the first operational management system utilizing a plurality of assets of an information technology infrastructure;

identifying, based at least in part on the received usage data, one or more asset relationships between at least two assets of the plurality of assets, and one or more user-asset relationships between one or more users and one or more of the plurality of assets;

applying one or more parameters of a plurality of parameters to the identified asset and user-asset relationships to determine one or more designations associated with the identified asset and user-asset relationships; and

transmitting the one or more designations to a second operational management system to trigger a risk management workflow based at least in part on the one or more designations;

wherein applying the one or more parameters comprises identifying a volume of communications for a given asset of at least one of a given asset relationship and a given user-asset relationship;

wherein the one or more parameters comprises a rule that if the identified volume of communications exceeds a threshold volume, then the given asset is designated as a high priority asset for the risk management workflow;

wherein the given asset is dynamically identifiable as a component of at least one of the given asset relationship and the given user-asset relationship based at least in part on the usage data comprising one or more of packet activity data, source data and destination data; and

wherein the method is performed by at least one processing platform comprising at least one processing device comprising a processor coupled to a memory.

17. The method of claim 16 wherein the one or more designations comprise a characterization of one or more risks associated with the identified asset and user-asset relationships.

18. The method of claim 16 wherein the volume of communications comprises one or more periods of relatively high communication volume relative to other periods of relatively low communication volume.

19. A computer program product comprising a non-transitory processor-readable storage medium having stored therein program code of one or more software programs, wherein the program code when executed by at least one processing platform causes said at least one processing platform:

to receive usage data from a first operational management system, the first operational management system utilizing a plurality of assets of an information technology infrastructure;

to identify, based at least in part on the received usage data, one or more asset relationships between at least two assets of the plurality of assets, and one or more user-asset relationships between one or more users and one or more of the plurality of assets;

to apply one or more parameters of a plurality of parameters to the identified asset and user-asset relationships to determine one or more designations associated with the identified asset and user-asset relationships; and

to transmit the one or more designations to a second operational management system to trigger a risk management workflow based at least in part on the one or more designations;

wherein, in applying the one or more parameters, the program code causes said at least one processing platform to identify a volume of communications for a given asset of at least one of a given asset relationship and a given user-asset relationship;

wherein the one or more parameters comprises a rule that if the identified volume of communications exceeds a threshold volume, then the given asset is designated as a high priority asset for the risk management workflow; and

wherein the given asset is dynamically identifiable as a component of at least one of the given asset relationship and the given user-asset relationship based at least in part on the usage data comprising one or more of packet activity data, source data and destination data.

20. The computer program product according to claim 19 , wherein the one or more designations comprise a characterization of one or more risks associated with the identified asset and user-asset relationships.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053311/0169) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060438/0742 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (050724/0571) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060436/0088 →
RELEASE OF SECURITY INTEREST AT REEL 050406 FRAME 421 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 058213/0825 →
SECURITY INTEREST Recorded Jun 5, 2020
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 053311/0169 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Oct 15, 2019
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 050724/0571 →
SECURITY AGREEMENT Recorded Sep 17, 2019
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 050406/0421 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 31, 2019
From: SCHLARMAN, STEVEN G.
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 049921/0120 →