IP Library Patent Application 18500143
Patent Application
App. No. 18/500,143

Inferred Events

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/500,143
Abstract

In one embodiment, a device includes a processor configured to generate a query to search for at least one event type in log data, provide the query to a data service to run against the log data, receive from the data service a result of running the query against the log data, and infer information from the result about a given family of event-types, the given family of event-types including the at least one event type, and a memory configured to store data used by the processor.

Claims (70)

1 . A device, comprising:

a processor configured to:

generate a query to search for at least one event type in log data;

provide the query to a data service to run against the log data;

receive from the data service a result of running the query against the log data; and

infer information from the result about a given family of event-types, the given family of event-types including the at least one event type; and

a memory configured to store data used by the processor.

2 . The device according to claim 1 , wherein:

the processor is configured to infer information from the result about a given event type in the given family of event-types; and

the result of running the query against the log data does not include events of the given event type.

3 . The device according to claim 1 , wherein the processor is configured to:

infer that the data service is not configured to receive events of the given family of event types or a given event type in the given family of event types responsively to the result indicating zero hits from running the query to search for the at least one event type against the log data; and

provide an alert indicating that the data service is not configured to receive the events of the given family of event types or a given event type in the given family of event types.

4 . The device according to claim 1 , wherein the processor being configured to:

receive a given rule from the data service, the given rule being configured to search for events of a given event type;

find the given family of event-types including the given event type; and

generate the query to search for the at least one event type included in the given family of event-types in the log data.

5 . The device according to claim 4 , wherein the processor is configured to:

infer that the given family of event-types or the given event type is not relevant to an operating environment responsively to the result indicating zero hits from running the query against the log data; and

provide an alert indicating that the given rule is irrelevant to the operating environment.

6 . The device according to claim 4 , wherein the processor is configured to infer that the data service is configured to receive events of the given event type responsively to the result indicating non-zero hits from running the query against the log data.

7 . The device according to claim 6 , wherein the processor is configured to provide an alert indicating that the data service or at least one log data source is configured correctly to provide log data for the given rule.

8 . The device according to claim 4 , wherein the data service is at least one of: a rule-based detection service; a rule-based security service; or a security information and event management (SIEM) service.

9 . The device according to claim 1 , wherein the processor is configured to:

generate the query to search for events in a time window, the result of running the query against the log data including multiple events;

identify event-types of the multiple events; and

infer which families of event-types are in an operating environment from the identified event-types.

10 . The device according to claim 1 , wherein the processor is configured to infer any one or more of the following from the families of event-types in the operating environment:

a configuration of log data sources feeding the data service;

which services are being used;

how the services are being used;

which cloud-based services are being used; or

which rules in the data service are redundant.

11 . The device according to claim 1 , wherein the processor is configured to:

identify log data sources of events in the given family of event-types; and

provide an indication about a value of the inference or perform an action based on the identified log data sources.

12 . A method, comprising:

generating a query to search for at least one event type in log data;

providing the query to a data service to run against the log data;

receiving from the data service a result of running the query against the log data; and

inferring information from the result about a given family of event-types, the given family of event-types including the at least one event type.

13 . The method according to claim 12 , wherein:

the inferring includes inferring information from the result about a given event type in the given family of event-types; and

the result of running the query against the log data does not include events of the given event type.

14 . The method according to claim 12 , wherein the inferring includes inferring that the data service is not configured to receive events of the given family of event types or a given event type in the given family of event types responsively to the result indicating zero hits from running the query to search for the at least one event type against the log data, the method further comprising providing an alert indicating that the data service is not configured to receive the events of the given family of event types or a given event type in the given family of event types.

15 . The method according to claim 12 , further comprising:

receiving a given rule from the data service, the given rule being configured to search for events of a given event type; and

finding the given family of event-types including the given event type, wherein the generating includes generating the query to search for the at least one event type included in the given family of event-types in the log data.

16 . The method according to claim 15 , wherein the inferring includes inferring that the given family of event-types or the given event type is not relevant to an operating environment responsively to the result indicating zero hits from running the query against the log data, the method further comprising providing an alert indicating that the given rule is irrelevant for the operating environment.

17 . The method according to claim 15 , wherein the inferring includes inferring that the data service is configured to receive events of the given event type responsively to the result indicating non-zero hits from running the query against the log data.

18 . The method according to claim 17 , further comprising providing an alert indicating that the data service or at least one log data source is configured correctly to provide log data for the given rule.

19 . The method according to claim 15 , wherein the data service is at least one of: a rule-based detection service; a rule-based security service; or a security information and event management (SIEM) service.

20 . The method according to claim 12 , wherein:

the generating includes generating the query to search for events in a time window, the result of running the query against the log data including multiple events;

the method further comprises identifying event-types of the multiple events; and

the inferring includes inferring which families of event-types are in an operating environment from the identified event-types.

21 . The method according to claim 20 , wherein the inferring includes inferring any one or more of the following from the families of event-types in the operating environment:

a configuration of log data sources feeding the data service;

which services are being used;

how the services are being used;

which cloud-based services are being used; or

which rules in the data service are redundant.

22 . The method according to claim 12 , further comprising:

identifying log data sources of events in the given family of event-types; and

providing an indication about a value of the inference or performing an action based on the identified log data sources.

23 . A software product, comprising a non-transient computer-readable medium in which program instructions are stored, which instructions, when read by a central processing unit (CPU), cause the CPU to:

generate a query to search for at least one event type in log data;

provide the query to a data service to run against the log data;

receive from the data service a result of running the query against the log data; and

infer information from the result about a given family of event-types, the given family of event-types including the at least one event type.

Assignments (2)
SECURITY INTEREST Recorded Feb 24, 2025
From: CARDINALOPS TLD.
To: BANK HAPOALIM B.M.
Reel/Frame 070311/0055 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 2, 2023
From: MANOR, YAIR; GELMAN, ALEX; HADAR, AMIHAI
To: CARDINALOPS LTD.
Reel/Frame 065430/0758 →