IP Library Granted Patent US 12,423,150
Granted Patent B1
US 12,423,150 · App. 19/068,551 · Granted Sep 23, 2025

Method of handling a failure in a task pipeline between a source of alerts and a security incident and event management (SIEM) system

Inventors: Alec R. Kerr (Tuscaloosa, AL); Joseph Edmonds (Ellicott City, MD)
Assignee: MORGAN STANLEY SERVICES GROUP INC.
G06F9/5027G06F21/554
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,423,150
App. No.
19/068,551
Granted
Sep 23, 2025
Kind
B1
Abstract

A method of handling a failure in a pipeline between a source of alerts and a Security Incident & Event Management (SIEM) platform involves: deserializing data from at least one error state object in an error log; transferring the deserialized data to an offline environment; reconstituting at least some tasks of the pipeline, including the failed task, using contents of the error log and contents from a task log; re-running the at least some tasks of the pipeline; identifying a cause of the failed task; based upon the cause of the failed task, transferring at least one of a modified task or replacement task for use in the pipeline; instantiating a new version of the pipeline incorporating the at least one of the modified task or the replacement task; and re-executing the new version of the pipeline to process alerts and provide the processed alerts to the SIEM platform.

Claims (18)

1. A method of handling a failure in a task pipeline executed in a system comprising a case creation platform having at least one processor, non-transient storage, the pipeline and an error log containing at least one error state object resulting from a non-skippable failed task, wherein the case creation platform is functionally between a source of alerts and a Security Incident & Event Management (SIEM) platform, the method comprising:

deserializing data from the at least one error state object in the error log;

transferring the deserialized data to an offline environment comprising at least one processor and non-transient storage;

reconstituting at least some tasks of the pipeline, including the failed task, in the offline environment using contents of the error log and contents from a task log associated with the pipeline; wherein the reconstituting further comprises using a local output task in place of a sink task of the pipeline;

re-running the at least some tasks of the pipeline in the offline environment;

identifying a cause of the failed task based upon the re-running;

based upon the cause of the failed task, transferring at least one of a modified task or replacement task to the system for use in the pipeline;

instantiating a new version of the pipeline in the system incorporating the at least one of the modified task or the replacement task; and

re-executing the new version of the pipeline to process alerts and provide the processed alerts to the SIEM platform.

2. The method of claim 1 , wherein the reconstituting at least some tasks of the pipeline comprises: re-instantiating all tasks of the pipeline.

3. The method of claim 1 , wherein the reconstituting further comprises: using a local input task in place of a source task of the pipeline.

4. The method of claim 1 , wherein the re-running of the at least some tasks of the pipeline in the offline environment comprises: running an entirety of the pipeline using specific alert data originally sourced by the source task from the error log.

5. The method of claim 1 , wherein the re-running of the at least some tasks of the pipeline in the offline environment comprises: running a portion of the pipeline beginning from an input to the a specific task where the failure occurred.

6. The method of claim 1 , wherein the re-running the at least some tasks of the pipeline in the offline environment further comprises: re-running using a copy of input data received from the task log.

7. The method of claim 1 , wherein the re-running the at least some tasks of the pipeline in the offline environment further comprises: re-running using alternative data as input data.

8. The method of claim 7 wherein the alternative data comprises data newly gathered by a source task of the pipeline.

9. The method of claim 8 wherein the alternative data comprises data obtained using a parameter different from an original parameter.

10. The method of claim 9 wherein the parameter includes different time constraints.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 3, 2025
From: KERR, ALEC R; EDMONDS, JOSEPH
To: MORGAN STANLEY SERVICES GROUP INC.
Reel/Frame 070383/0219 →
Continuity (2)
Continuation 18951880 · Nov 19, 2024
Continuation 18794248 · Aug 5, 2024
References Cited (42)
US 8782784B1 · Bruskin · 2014 [cited by applicant]
US 8874550B1 · Soubramanien · 2014 [cited by examiner]
US 8904531B1 · Saklikar · 2014 [cited by applicant]
US 9064210B1 · Hart · 2015 [cited by applicant]
US 9069930B1 · Hart · 2015 [cited by applicant]
US 9282114B1 · Dotan · 2016 [cited by applicant]
US 10049220B1 · Hatsutori et al. · 2018 [cited by applicant]
US 10333948B2 · Rostamabadi · 2019 [cited by applicant]
US 10698767B1 · De Kadt · 2020 [cited by examiner]
US 10873614B2 · Kolan · 2020 [cited by examiner]
US 11106562B2 · Su · 2021 [cited by examiner]
US 11403136B1 · Willson · 2022 [cited by applicant]
US 11431817B2 · Kolan · 2022 [cited by examiner]
US 11818156B1 · Parikh et al. · 2023 [cited by applicant]
US 12190161B1 · Kerr · 2025 [cited by examiner]
US 12271757B1 · Kerr · 2025 [cited by examiner]
US 20060053334A1 · Ingen · 2006 [cited by examiner]
US 20140090068A1 · Guarnieri · 2014 [cited by applicant]
US 20150163242A1 · Laidlaw et al. · 2015 [cited by applicant]
US 20160019091A1 · Leber · 2016 [cited by examiner]
US 20180167402A1 · Scheidler et al. · 2018 [cited by applicant]
US 20180288126A1 · Smart · 2018 [cited by applicant]
US 20190303228A1 · Kowta · 2019 [cited by examiner]
US 20190356679A1 · Sites · 2019 [cited by applicant]
US 20200186569A1 · Milazzo · 2020 [cited by applicant]
US 20210110032A1 · Yip · 2021 [cited by applicant]
US 20210352136A1 · Dojka et al. · 2021 [cited by applicant]
US 20220114252A1 · Syed et al. · 2022 [cited by applicant]
US 20220342707A1 · Alagna et al. · 2022 [cited by applicant]
US 20220343181A1 · Thomas · 2022 [cited by applicant]
US 20220345479A1 · Markonis et al. · 2022 [cited by applicant]
US 20220368696A1 · Karpovsky · 2022 [cited by applicant]
US 20240080337A1 · Matefi · 2024 [cited by applicant]
US 20240089293A1 · Singla · 2024 [cited by applicant]
US 20240152371A1 · He · 2024 [cited by examiner]
US 20240192974A1 · Gadupudi · 2024 [cited by examiner]
US 20240256421A1 · Alexander · 2024 [cited by applicant]
US 20240394311A1 · Dash · 2024 [cited by examiner]
Lu et al.; “Log-based Abnormal Task Detection and Root Cause Analysis for Spark”; 2017 IEEE International Conference on Web Services (ICWS); DOI 10.1109/ICWS.2017.135; (Lu_2017.pdf; pp. 389-396) (Year: 2017). [cited by examiner]
Bhatt et al.; “The Operational Role of Security Information and Event Management Systems”; HP lab; Oct. 2014; IEEE; (Bhatt_2014.pdf; pp. 35-41) (Year: 2014). [cited by applicant]
Gonzalez et al.; “New Types of Alert Correlation for Security Information and Event Management Systems”; IEEE (Gonzalez_2016. pdf; pp. 1-7) (Year: 2016). [cited by applicant]
Granadillo et al.; “Security Information and Event Management (SIEM): Analysis, Trends, and Usage in Critical Infrastructures”; Sensors 2021, 21, 4759. https://doi.org/10.3390/s21144759 (Granadillo_2021.pdf; pp. 1-28) (… [cited by applicant]
Cited By (1)
US 12,596,814