IP Library Granted Patent US 11,809,920
Granted Patent B2
US 11,809,920 · App. 17/327,663 · Granted Nov 7, 2023

Systems and methods for multi-event correlation

Inventor: John H. Lehmann (Charlton, MA)
Assignee: DIGITAL GUARDIAN LLC
G06F9/542G06F11/3017G06F11/3072H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,809,920
App. No.
17/327,663
Granted
Nov 7, 2023
Kind
B2
Abstract

Provided herein are systems and methods for multi-event correlation. Receiving a stream of events, each leaf rule engine may detect a plurality of events from the stream that matches a characteristic for the leaf rule engine. Each leaf rule engine may identify, from the plurality of events and within a time window, a group of events that satisfies a condition for the respective leaf rule engine. A root conditions engine may receive a stream of leaf events corresponding to the group of events identified by each leaf rule engine. The root conditions engine may identify, from the received stream of leaf events and within a root time window, a collection of events that satisfies a condition for the root conditions engine. A trigger may execute an action according to the collection of events identified within the root time window.

Claims (37)

1. A system for multi-event correlation, comprising:

one or more processors coupled with memory, configured to:

receive, for a leaf rule, a stream of events each corresponding to an activity of at least one of a user, a device, or a program;

detect, from the stream of events, a first plurality of events in accordance with a filter of the leaf rule;

identify, from the first plurality of events, a second plurality of events satisfying a condition within a time window of the leaf rule; and

provide the second plurality of events to a root rule to identify a third plurality of events with which to execute an action in accordance with a trigger.

2. The system of claim 1 , wherein the one or more processors is further configured to modify at least one of the filter, the condition, or the time window of the leaf rule based at least on an administrative specification.

3. The system of claim 1 , wherein the one or more processors is further configured to set at least one of the filter, the condition, or the time window of the leaf rule using a machine learning model.

4. The system of claim 1 , wherein the one or more processors is further configured to shift the time window to apply the conditions to the first plurality of events.

5. The system of claim 1 , wherein the filter of the leaf rule defines a characteristic of events identified to be at least one of a potential anomaly, a risk, or a threat to detect the first plurality of events.

6. The system of claim 1 , wherein the condition of the leaf rule defines at least one of a total number of events, a total number of devices, a total number of files, or a total number of bytes accumulated within the time window to identify the second plurality of events.

7. The system of claim 1 , wherein at least one of the filter, the condition, or the time window of the leaf rule differs from a corresponding filter, condition, or time window of another leaf rule.

8. A system for multi-event correlation, comprising:

one or more processors coupled with memory, configured to:

receive, for a root rule, a stream of events identified by a leaf rule, each event of the stream of events corresponding to an activity at least one of a user, a device, or a program;

determine, from the stream of events, a first plurality of events within a time window of the root rule;

identify, from the first plurality of events within the time window, a second plurality of events satisfying a condition of the root rule; and

provide, to a trigger, the second plurality of events with which to execute an action.

9. The system of claim 8 , wherein the one or more processors is further configured to modify at least one of the filter, the condition, or the time window of the root rule based at least on an administrative specification.

10. The system of claim 8 , wherein the one or more processors is further configured to set at least one of the filter, the condition, or the time window of the root rule using a machine learning model.

11. The system of claim 8 , wherein the one or more processors is further configured to aggregate the stream of events identified from a plurality of leaf rules, each of the plurality of leaf rules identifying a corresponding subset of events in accordance with a respective filter, time window, and condition.

12. The system of claim 8 , wherein the time window of the root rule differs from a time window of the leaf rule to determine the first plurality of events from the stream of events.

13. The system of claim 8 , wherein the condition of the root rule defines at least one of a total number of events, a total number of devices, a total number of files, or a total number of bytes accumulated within the time window to identify the second plurality of events.

14. The system of claim 8 , wherein the action executed by the trigger includes at least one of: an initiation of an alarm for a potential anomaly, a risk, or threat; or a provision of an instruction to pause or terminate execution of the program.

15. A method of correlating across multiple events, comprising:

receiving, by a computing system, for a leaf rule, a stream of events each corresponding to an activity of at least one of a user, a device, or a program;

detecting, by the computing system, from the stream of events, a first plurality of events in accordance with a filter of the leaf rule;

identifying, by the computing system, from the first plurality of events, a second plurality of events satisfying a condition within a time window of the leaf rule; and

providing, by the computing system, the second plurality of events to a root rule to identify a third plurality of events.

16. The method of claim 15 , further comprising:

determining, by the computing system, from the second plurality of events, the third plurality of events within a time window of the root rule;

identifying, by the computing system, from the third plurality of events within the time window of the root rule, a fourth plurality of events satisfying a condition of the root rule; and

provide, to a trigger, the fourth plurality of events with which to execute an action.

17. The method of claim 16 , further comprising aggregating, by the computing system, the second plurality of events identified from a plurality of leaf rules, each of the plurality of leaf rules identifying a corresponding subset of events in accordance with a respective filter, time window, and condition.

18. The method of claim 16 , wherein the action executed by the trigger includes at least one of: an initiation of an alarm for a potential anomaly, a risk, or threat; or a provision of an instruction to pause or terminate execution of the program.

19. The method of claim 15 , wherein the filter of the leaf rule defines a characteristic of events identified to be at least one of a potential anomaly, a risk, or a threat to detect the first plurality of events.

20. The method of claim 15 , wherein the condition of the leaf rule defines at least one of a total number of events, a total number of devices, a total number of files, or a total number of bytes accumulated within the time window to identify the second plurality of events.

Assignments (11)
SECURITY INTEREST Recorded Jan 6, 2026
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.
To: ACQUIOM AGENCY SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 074233/0632 →
TERMINATION AND RELEASE OF FIRST LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 58892/0766 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: DIGITAL GUARDIAN LLC
Reel/Frame 073783/0619 →
NEW MONEY FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.; VERA SECURITY, INC.
To: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 073683/0534 →
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 58892/0945 Recorded Nov 21, 2025
From: ACQUIOM AGENCY SERVICES LLC
To: DIGITAL GUARDIAN LLC
Reel/Frame 073663/0411 →
EXTENDED FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: DIGITAL GUARDIAN LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073663/0844 →
EXTENDED RCF FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: DIGITAL GUARDIAN LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073663/0050 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 14, 2025
From: GOLUB CAPITAL MARKETS LLC (AS EXISTING AGENT)
To: ACQUIOM AGENCY SERVICES LLC (AS SUCCESSOR COLLATERAL AGENT)
Reel/Frame 072471/0665 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 28, 2022
From: DIGITAL GUARDIAN, LLC
To: GOLUB CAPITAL MARKETS LLC, AS COLLATERAL AGENT
Reel/Frame 058892/0945 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 28, 2022
From: DIGITAL GUARDIAN, LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 058892/0766 →
CHANGE OF NAME Recorded Oct 11, 2021
From: DIGITAL GUARDIAN, INC.
To: DIGITAL GUARDIAN LLC
Reel/Frame 057773/0151 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 11, 2021
From: LEHMANN, JOHN H.
To: DIGITAL GUARDIAN, INC.
Reel/Frame 057753/0144 →
Continuity (2)
Continuation 16428122 · May 31, 2019
Related Publication 20210279117A1 · Sep 9, 2021