IP Library › Granted Patent US 12,634,303
Granted Patent B2
US 12,634,303 · App. 18/390,178 · Granted May 19, 2026

Proactive suspicious activity monitoring for a software application framework

Inventors: Benjamin Walther (Mountain View, CA); Brianna Malcolmson (San Francisco, CA)
Assignees: ATLASSIAN PTY, LTD.; ATLASSIAN US, INC.
H04L63/1416G06F21/552G06F2221/2101
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,634,303
App. No.
18/390,178
Granted
May 19, 2026
Kind
B2
Abstract

Various embodiments of the present invention provide methods, apparatuses, systems, computing devices, and/or the like that are configured to enable effective and efficient monitoring of software application frameworks. For example, certain embodiments of the present invention provide methods, apparatuses, systems, computing devices, and/or the like that are configured to perform software application framework monitoring using an interactive software application platform monitoring dashboard comprises a set of user interfaces (e.g., an alert feed user interface, an alert monitoring user interface, and/or the like) that enable an end user to hierarchically view event monitoring metadata fields associated with each recorded suspicious activity alert of one or more recorded suspicious activity alerts of the software application platform, provide user-selected alert validity indicators for each recorded suspicious activity alert of the recorded suspicious activity alerts, and/or generate a suspicious activity monitoring workflow for each recorded suspicious activity alert of the recorded suspicious activity alerts.

Claims (41)

1 . An apparatus for performing proactive suspicious activity monitoring for a software application framework, the apparatus comprising at least one processor and at least one memory including program code, the at least one memory and the program code configured to, with the at least one processor, cause the apparatus to at least:

receive, at the apparatus, user interaction with an interactive software application platform monitoring dashboard, the user interaction indicating a user request to view an alert feed user interface;

transmit a request to a software monitoring data management system to obtain alert feed user interface data for rendering the alert feed user interface;

render the alert feed user interface to the interactive software application platform monitoring dashboard based on the alert feed user interface data, wherein the alert feed user interface data is received from the software monitoring data management system;

provide indication of a user-selected suspicious activity alert to the software monitoring data management system, wherein the indication of a user-selected suspicious activity alert is generated based on user interaction data with the alert feed user interface, and wherein the user interaction data describes user selection of a recorded suspicious activity alert that is displayed by the alert feed user interface;

render an alert monitoring user interface to the interactive software application platform monitoring dashboard based on alert monitoring user interface data, wherein the alert monitoring user interface is associated with the user-selected suspicious activity alert, and wherein the alert monitoring user interface data is received from the software monitoring data management system in response to providing the indication of the user-selected suspicious activity alert to the software monitoring data management system;

identify a user-selected validity indicator for the user-selected suspicious activity alert based on the user interaction data; and

transmit the user-selected validity indicator for the user-selected suspicious activity alert to the software monitoring data management system in response to identifying the user-selected validity indicator.

2 . The apparatus of claim 1 , wherein the alert feed user interface data is generated by the software monitoring data management system.

3 . The apparatus of claim 1 , wherein the request to obtain the alert feed user interface data for rendering the alert feed user interface is transmitted by the apparatus to a frontend unit of the software monitoring data management system.

4 . The apparatus of claim 1 , wherein the alert monitoring user interface is configured to display one or more event monitoring metadata fields associated with the user-selected suspicious activity alert and enable user selection of a user-selected alert validity indicator for the user-selected suspicious activity alert.

5 . The apparatus of claim 4 , wherein the one or more event monitoring metadata fields associated with the user-selected suspicious activity alert that are displayed comprise a top-level subset of event monitoring metadata fields associated with the user-selected suspicious activity alert.

6 . The apparatus of claim 4 , wherein the one or more event monitoring metadata fields associated with the user-selected suspicious activity alert that are displayed comprise a bottom-level subset of event monitoring metadata fields associated with the user-selected suspicious activity alert.

7 . The apparatus of claim 1 , wherein the user-selected suspicious activity alert is generated when an underlying recorded activity event that is associated with the user-selected suspicious activity alert is classified as being a security-critical alert by one or more proactive suspicious activity monitoring predictive data analysis models, wherein the security-critical alert is determined based on a noted event monitoring metadata field describing an inferred suspicious activity likelihood weight for a platform activity pattern that is associated with a recorded activity pattern exceeds a suspicious activity likelihood weight threshold value.

8 . A computer-implemented method for performing proactive suspicious activity monitoring for a software application framework, the computer-implemented method comprising:

receiving user interaction with an interactive software application platform monitoring dashboard, the user interaction indicating a user request to view an alert feed user interface;

transmitting a request to a software monitoring data management system to obtain alert feed user interface data for rendering the alert feed user interface;

rendering the alert feed user interface to the interactive software application platform monitoring dashboard based on the alert feed user interface data, wherein the alert feed user interface data is received from the software monitoring data management system;

providing, indication of a user-selected suspicious activity alert to the software monitoring data management system, wherein the indication of a user-selected suspicious activity alert is generated based on user interaction data with the alert feed user interface, and wherein the user interaction data describes user selection of a recorded suspicious activity alert that is displayed by the alert feed user interface;

rendering an alert monitoring user interface to the interactive software application platform monitoring dashboard based on alert monitoring user interface data, wherein the alert monitoring user interface is associated with the user-selected suspicious activity alert, and wherein the alert monitoring user interface data is received from the software monitoring data management system in response to providing the indication of the user-selected suspicious activity alert to the software monitoring data management system;

identifying a user-selected validity indicator for the user-selected suspicious activity alert based on the user interaction data; and

transmitting the user-selected validity indicator for the user-selected suspicious activity alert to the software monitoring data management system in response to identifying the user-selected validity indicator.

9 . The computer-implemented method of claim 8 , wherein the alert feed user interface data is generated by the software monitoring data management system.

10 . The computer-implemented method of claim 8 , wherein the request to obtain the alert feed user interface data for rendering the alert feed user interface is transmitted to a frontend unit of the software monitoring data management system.

11 . The computer-implemented method of claim 8 , wherein the alert monitoring user interface is configured to display one or more event monitoring metadata fields associated with the user-selected suspicious activity alert and enable user selection of a user-selected alert validity indicator for the user-selected suspicious activity alert.

12 . The computer-implemented method of claim 11 , wherein the one or more event monitoring metadata fields associated with the user-selected suspicious activity alert that are displayed comprise a top-level subset of event monitoring metadata fields associated with the user-selected suspicious activity alert.

13 . The computer-implemented method of claim 11 , wherein the one or more event monitoring metadata fields associated with the user-selected suspicious activity alert that are displayed comprise a bottom-level subset of event monitoring metadata fields associated with the user-selected suspicious activity alert.

14 . The computer-implemented method of claim 8 , wherein the user-selected suspicious activity alert is generated when an underlying recorded activity event that is associated with the user-selected suspicious activity alert is classified as being a security-critical alert by one or more proactive suspicious activity monitoring predictive data analysis models, wherein the security-critical alert is determined based on a noted event monitoring metadata field describing an inferred suspicious activity likelihood weight for a platform activity pattern that is associated with a recorded activity pattern exceeds a suspicious activity likelihood weight threshold value.

15 . A computer program product for performing proactive suspicious activity monitoring for a software application framework, the computer program product comprising at least one non-transitory computer-readable storage medium having computer-readable program code portions stored therein, the computer-readable program code portions configured to:

receive user interaction with an interactive software application platform monitoring dashboard, the user interaction indicating a user request to view an alert feed user interface;

transmit a request to a software monitoring data management system to obtain alert feed user interface data for rendering the alert feed user interface;

render the alert feed user interface to the interactive software application platform monitoring dashboard based on the alert feed user interface data, wherein the alert feed user interface data is received from the software monitoring data management system;

provide indication of a user-selected suspicious activity alert to the software monitoring data management system, wherein the indication of a user-selected suspicious activity alert is generated based on user interaction data with the alert feed user interface, and wherein the user interaction data describes user selection of a recorded suspicious activity alert that is displayed by the alert feed user interface;

render an alert monitoring user interface to the interactive software application platform monitoring dashboard based on alert monitoring user interface data, wherein the alert monitoring user interface is associated with the user-selected suspicious activity alert, and wherein the alert monitoring user interface data is received from the software monitoring data management system in response to providing the indication of the user-selected suspicious activity alert to the software monitoring data management system;

identify a user-selected validity indicator for the user-selected suspicious activity alert based on the user interaction data; and

transmit the user-selected validity indicator for the user-selected suspicious activity alert to the software monitoring data management system in response to identifying the user-selected validity indicator.

16 . The computer program product of claim 15 , wherein the alert feed user interface data is generated by the software monitoring data management system.

17 . The computer program product of claim 15 , wherein the request to obtain the alert feed user interface data for rendering the alert feed user interface is transmitted to a frontend unit of the software monitoring data management system.

18 . The computer program product of claim 15 , wherein the alert monitoring user interface is configured to display one or more event monitoring metadata fields associated with the user-selected suspicious activity alert and enable user selection of a user-selected alert validity indicator for the user-selected suspicious activity alert.

19 . The computer program product of claim 18 , wherein the one or more event monitoring metadata fields associated with the user-selected suspicious activity alert that are displayed comprise a top-level subset of event monitoring metadata fields associated with the user-selected suspicious activity alert.

20 . The computer program product of claim 18 , wherein the one or more event monitoring metadata fields associated with the user-selected suspicious activity alert that are displayed comprise a bottom-level subset of event monitoring metadata fields associated with the user-selected suspicious activity alert.

Assignments (3)
CHANGE OF NAME Recorded Feb 4, 2026
From: ATLASSIAN, INC.
To: ATLASSIAN US, INC.
Reel/Frame 074602/0145 →
CHANGE OF NAME Recorded Dec 19, 2025
From: ATLASSIAN, INC.
To: ATLASSIAN US, INC.
Reel/Frame 073970/0027 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 7, 2024
From: WALTHER, BENJAMIN; MALCOLMSON, BRIANNA
To: ATLASSIAN PTY LTD.; ATLASSIAN, INC.
Reel/Frame 066680/0253 →
Continuity (3)
Continuation 17932767 · Sep 16, 2022
Continuation 17490930 · Sep 30, 2021
Related Publication 20240244063A1 · Jul 18, 2024
References Cited (17)
US 10397258B2 · Luo · 2019 [cited by examiner]
US 10904289B2 · Tsironis · 2021 [cited by examiner]
US 11153333B1 · HΘrmoni · 2021 [cited by examiner]
US 20120240185A1 · Kapoor · 2012 [cited by examiner]
US 20140067734A1 · Hawkins · 2014 [cited by examiner]
US 20180068219A1 · Turner · 2018 [cited by examiner]
US 20180173579A1 · Potlapally · 2018 [cited by examiner]
US 20180309822A1 · Baradaran · 2018 [cited by examiner]
US 20200259852A1 · Wolff · 2020 [cited by examiner]
US 20200285737A1 · Kraus · 2020 [cited by examiner]
US 20210029137A1 · Wright · 2021 [cited by examiner]
US 20210092141A1 · Gamble · 2021 [cited by examiner]
US 20210182388A1 · Myneni · 2021 [cited by examiner]
US 20210250369A1 · Åvist · 2021 [cited by examiner]
US 20210360015A1 · Mammadli · 2021 [cited by examiner]
U.S. Appl. No. 17/932,767, filed Sep. 16, 2022, U.S. Pat. No. 11,895,130, Issued. [cited by applicant]
U.S. Appl. No. 17/490,930, filed Sep. 30, 2021, U.S. Pat. No. 11,483,322, Issued. [cited by applicant]