IP Library Patent Application 19117332
Patent Application
App. No. 19/117,332

PROCESSING AND/OR GENERATING CYBERSECURITY TELEMETRY DATA

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
19/117,332
Abstract

A cybersecurity system comprises a mapping component in the form of program code compiled from a telemetry serialization schema, and a cybersecurity application in the form of program code compiled independently of the mapping component and the telemetry serialization schema, the program code embodying a plurality of telemetry functions. Each telemetry function is specific to a different data type, the cybersecurity application configured to provide to the mapping component a message topic for a telemetry message comprising a data field having a data type that is not known to the cybersecurity application. The mapping component is configured to determine the data type of the data field based on the message topic, and cause the cybersecurity application to apply, to the data field, the telemetry function associated with the data type of the data field.

Claims (35)

1 . A cybersecurity system comprising:

a data store comprising:

a mapping component corresponding to program code compiled from a telemetry serialization schema; and

a cybersecurity application corresponding to program code compiled independently of the mapping component and the telemetry serialization schema, the program code embodying a plurality of telemetry functions, wherein each telemetry function is specific to a different data type, the cybersecurity application configured to provide to the mapping component a message topic for a telemetry message comprising a data field having a data type that is not known to the cybersecurity application;

wherein the mapping component is configured to determine the data type of the data field based on the message topic, and cause the cybersecurity application to apply, to the data field, the telemetry function associated with the data type of the data field; and

a processor to execute the mapping component and the cybersecurity application.

2 . The cybersecurity system of claim 1 , wherein the cybersecurity application is configured to indicate the plurality of telemetry functions to the mapping component, and mapping component is configured to cause the cybersecurity application to apply the telemetry function to the data field via a call back to the telemetry function.

3 . The cybersecurity system of claim 1 , wherein the plurality of telemetry functions are stored as code portions in respective regions of processor memory, and indicated by the application providing respective references for identifying the respective regions of memory.

4 . The cybersecurity system of claim 1 , wherein the mapping component is configured to determine based on the message topic a field name of the data field and cause the application to apply the telemetry function to the field name.

5 . The cybersecurity system of claim 4 , wherein at least a first telemetry function of the plurality of telemetry functions is configured to match the field name of the data field to a field name contained in a configuration input to the cybersecurity application.

6 . The cybersecurity system of claim 5 , wherein the telemetry message is received by the cybersecurity application in serialized form, and the telemetry function is a telemetry processing function applied to a piece of telemetry data contained in the telemetry message.

7 . The cybersecurity system of claim 6 , wherein the mapping component is configured to extract a telemetry datum from the data field and cause the application to apply the telemetry processing function to the telemetry datum.

8 . The cybersecurity system of claim 7 , wherein the telemetry processing function is configured to match the field name of the data field to the field name contained in the configuration input, compare the telemetry datum to a pattern associated with the field name in the configuration input, and trigger a cybersecurity action responsive to a pattern match.

9 . The cybersecurity system of claim 1 , wherein the telemetry function is a telemetry generation function configured to return to the mapping component a piece of telemetry of its specific data type, and wherein the mapping component is configured to populate the data field with the piece of telemetry.

10 . The cybersecurity system of claim 1 , the data store further comprising:

a message queue;

an analysis component;

a telemetry database queryable by the analysis component;

a deserialization component configured to receive messages from the message queue and convert each message to a database record in the telemetry database; and

wherein the analysis component is configured to perform a cybersecurity analysis on data records contained in the telemetry database;

wherein the cybersecurity application and the mapping component operate directly on the message queue, without accessing the telemetry database.

11 . A method of processing cybersecurity telemetry data, the method comprising:

providing to a mapping component, by a cybersecurity application, a message topic for a telemetry message comprising a data field having a data type that is not known to the cybersecurity application, wherein cybersecurity application corresponds to program code compiled independently of the mapping component and a telemetry serialization schema, the program code embodying a plurality of telemetry functions, wherein each telemetry function is specific to a different data type, wherein the mapping component corresponds to program code compiled from a telemetry serialization schema; and

determining, by the mapping component, the data type of the data field based on the message topic, and causing the cybersecurity application to apply, to the data field, the telemetry function associated with the data type of the data field.

12 . The method of claim 11 , comprising:

automatically generating the program code of the mapping component based on the telemetry serialization schema, independently of the cybersecurity application.

13 . The method of claim 11 , wherein the telemetry message is received by the cybersecurity application in serialized form, and the telemetry function is a telemetry processing function applied to a piece of telemetry data contained in the telemetry message.

14 . The method of claim 11 , wherein the telemetry function is a telemetry generation function configured to return to the mapping component a piece of telemetry of its specific data type, and wherein the mapping component is configured to populate the data field with the piece of telemetry.

15 . One or more non-transitory media embodying computer-readable instruction configured so as, upon execution by one or more computer processors, to cause the one or more computer processors to implement a method comprising:

providing to a mapping component, by a cybersecurity application, a message topic for a telemetry message comprising a data field having a data type that is not known to the cybersecurity application, wherein cybersecurity application corresponds to program code compiled independently of the mapping component and a telemetry serialization schema, the program code embodying a plurality of telemetry functions, wherein each telemetry function is specific to a different data type, wherein the mapping component corresponds to program code compiled from a telemetry serialization schema; and

determining, by the mapping component, the data type of the data field based on the message topic, and causing the cybersecurity application to apply, to the data field, the telemetry function associated with the data type of the data field.

16 . The one or more non-transitory media of claim 15 , wherein the method further comprises:

automatically generating the program code of the mapping component based on the telemetry serialization schema, independently of the cybersecurity application.

17 . The one or more non-transitory media of claim 15 , wherein the telemetry message is received by the cybersecurity application in serialized form, and the telemetry function is a telemetry processing function applied to a piece of telemetry data contained in the telemetry message.

18 . The one or more non-transitory media of claim 15 , wherein the telemetry function is a telemetry generation function configured to return to the mapping component a piece of telemetry of its specific data type, and wherein the mapping component is configured to populate the data field with the piece of telemetry.

Assignments (1)
SECURITY INTEREST Recorded Dec 24, 2025
From: SENSEON TECH LTD
To: HSBC INNOVATION BANK LIMITED
Reel/Frame 073311/0164 →