IP Library Patent Application 18896486
Patent Application
App. No. 18/896,486

ADVANCED INTELLIGENCE ENGINE

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/896,486
Abstract

An advanced intelligence engine (AIE) for use in identifying what may be complex events or developments on one or more data platforms or networks from various types of structured or normalized data generated by one or more disparate data sources. The AIE may conduct one or more types of quantitative, correlative, behavioral and corroborative analyses to detect events from what may otherwise be considered unimportant or non-relevant information spanning one or more time periods. Events generated by the AIE may be passed to an event manager to determine whether further action is required such as reporting, remediation, and the like.

Claims (31)

1 - 16 . (canceled)

17 . A method for use in monitoring one or more platforms of one or more data systems, comprising:

first evaluating, by a processor using a first rule block, structured data received from one or more platforms over at least one communications network; wherein the first rule block is configured to fire when a predetermined first threshold number of a quantitative value of a first field has been reached;

dynamically adjusting the first threshold number upwardly or downwardly based on first historical results;

first determining, from the first evaluating, that a result is one of at least first and second outcomes;

accessing, by the processor, a linking relationship object in the first rule block to identify a data field in the structured data;

extracting, by the processor, a content of the data field from the structured data;

second evaluating, by the processor using a second rule block, structured data associated with the extracted content received from the one or more platforms;

second determining, from the second evaluating, whether a result is one of at least first and second outcomes; and

analyzing the results of the first and second determining to determine an event of interest.

18 . The method of claim 17 , wherein the second rule block is configured to fire when a predetermined second threshold number of a quantitative value of a second field has been reached.

19 . The method of claim 18 , further comprising:

dynamically adjusting the second threshold number upwardly or downwardly based on second historical results.

20 . The method of claim 17 , wherein the first field is a log count.

21 . The method of claim 17 , wherein the first field is bytes transferred.

22 . The method of claim 17 , wherein the second field is a period of time.

23 . A non-transitory, computer-readable storage medium, storing program instructions that when executed on one or more computers cause the one or more computers to perform:

first evaluating, using a first rule block, structured data received from one or more platforms over at least one communications network; wherein the first rule block is configured to fire when a predetermined first threshold number of a quantitative value of a first field has been reached;

dynamically adjusting the first threshold number upwardly or downwardly based on historical results;

first determining, from the first evaluating, that a result is one of at least first and second outcomes;

accessing a linking relationship object in the first rule block to identify a data field in the structured data;

extracting a content of the data field from the structured data;

second evaluating, using a second rule block, structured data associated with the extracted content received from the one or more platforms;

second determining, from the second evaluating, whether a result is one of at least first and second outcomes; and

analyzing the results of the first and second determining to determine an event of interest.

24 . The non-transitory, computer-readable storage medium of claim 23 , wherein the second rule block is configured to fire when a predetermined second threshold number of a quantitative value of a second field has been reached.

25 . The non-transitory, computer-readable storage medium of claim 24 , further storing program instructions that when executed on one or more computers cause the one or more computers to perform:

dynamically adjusting the second threshold number upwardly or downwardly based on second historical results.

26 . The non-transitory, computer-readable storage medium of claim 23 , wherein the first field is a log count.

27 . The non-transitory, computer-readable storage medium of claim 23 , wherein the first field is bytes transferred.

28 . The non-transitory, computer-readable storage medium of claim 23 , wherein the second field is a period of time.