IP Library Granted Patent US 10,686,648
Granted Patent B2
US 10,686,648 · App. 16/236,551 · Granted Jun 16, 2020

System for decomposing clustering events from managed infrastructures

Inventor: Philip Tee (San Francisco, CA)
Assignee: Moogsoft Inc.
H04L41/046G06F16/951H04L41/0631H04L41/0654H04L41/0886H04L41/0893H04L41/12H04L41/142H04L41/145H04L41/22H04L43/067H04L43/0823H04L43/10H04L63/029H04L67/34H04L67/42
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,686,648
App. No.
16/236,551
Granted
Jun 16, 2020
Kind
B2
Abstract

An event clustering system includes a processor that generates reports. An extraction engine is in communication with an infrastructure. The extraction engine receives data from the infrastructure, produces events and populates a database with a dictionary of event or graph entropy. An alert engine receives the events and creates alerts mapped into a matrix, M. A signalizer engine includes one or more of an NMF engine, a k-means clustering engine and a topology proximity engine. The signalizer engine determines one or more common steps from events and produces clusters relating to the alerts and or events. One or more interactive displays provide a collaborative interface a coupled to the extraction and the signalizer engine for decomposing events from the infrastructure. A reporting engine generates a report from at least one of the clusters and the events that are retrieved from the collaborative interface with a source address for each event to assign a graph coordinate in the graph to the event with an optional subset of attributes being extracted for each event and turning that into a vector of the graph. In response to production of the clusters one or more physical changes in a managed infrastructure hardware is made, and in response.

Claims (27)

1. An event clustering system that generates reports, comprising:

a clustering system with one or more processors and one or more memories, and including:

an extraction engine in communication with an infrastructure, the extraction engine in operation receiving data from the infrastructure and produces events and populates a database with a dictionary of event or graph entropy; an alert engine that receives the events and creates alerts mapped into a matrix, M;

a signalizer engine that includes one or more of an NMF engine, a k-means clustering engine and a topology proximity engine, the signalizer engine determining one or more common steps from events and produces clusters relating to the alerts and or events;

one or more interactive displays that provide a collaborative interface a coupled to the extraction and the signalizer engine for decomposing events from the infrastructure;

a reporting engine configured to be coupled to the event clustering system, the reporting engine configured to generate a report from at least one of the clusters and the events that are retrieved from the collaborative interface a source address for each event to assign a graph coordinate in the graph to the event with an optional subset of attributes being extracted for each event and turning that into a vector of the graph; and

in response to production of the clusters one or more physical changes in a managed infrastructure hardware is made, where the hardware supports the flow and processing of information, and in response to production of the clusters security of the managed infrastructure is maintained.

2. The system of claim 1 , wherein security includes at least one of managed infrastructure: breach, intrusion or propagation.

3. The system of claim 1 , wherein security includes managed infrastructure:

access control, intrusion detection and threat propagation.

4. The system of claim 1 , wherein security includes authentication of a subject.

5. The system of claim 1 , wherein security includes authorization of a subject.

6. The system of claim 5 , wherein authorization specifies what a subject can do.

7. The system of claim 1 , wherein security includes audit.

8. The system of claim 1 , where security includes identification and authentication to ensure that only authorized subjects can access the managed infrastructure.

9. The system of claim 1 , wherein security includes access approval grants to the managed infrastructure by association of users with resources that they are allowed to access, based on an authorization policy.

10. The system of claim 1 , wherein the reporting engine generates reports from the clustered events and/or messages.

11. The system of claim 1 , wherein the report engine is coupled to a situation room of the event clustering system.

12. The system of claim 1 , wherein computer-executable instructions implement the reporting engine.

13. The system of claim 12 , wherein the instructions include a predefined procedure component, a metadata component, or layer, and an interface component.

14. The system of claim 1 , wherein the reporting engine generates a report from the clustered events and/or messages which can be retrieved from a situation room.

15. The system of claim 1 , wherein the reporting engine is in communication with one or more dashboards associated with a situation room and retrieves information therefrom in response to a request that is used to generate a report.

16. The system of claim 1 , wherein clustered events/messages are in a database.

17. The system of claim 1 , wherein queries regarding the clustered events/messages are answered through reports generated from structured query language (SQL) statements.

18. The system of claim 1 , wherein the reporting engine includes a metadata layer, an interface and a procedure component.

19. The system of claim 1 , wherein the clustered events/messages have several dimensions.

20. The system of claim 19 , wherein one of the dimensions is a procedure component.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 6, 2023
From: EMC CORPORATION
To: DELL PRODUCTS L.P.
Reel/Frame 065179/0980 →
MERGER Recorded Oct 4, 2023
From: MOOGSOFT INC.
To: EMC CORPORATION
Reel/Frame 065156/0805 →
RELEASE OF SECURITY INTEREST Recorded Aug 11, 2023
From: STIFEL BANK
To: MOOGSOFT INC.
Reel/Frame 064569/0391 →
SECURITY INTEREST Recorded Jan 23, 2022
From: MOOGSOFT INC.
To: STIFEL BANK
Reel/Frame 058734/0193 →
Continuity (17)
Continuation In Part 16140508 · Sep 24, 2018
Continuation In Part 16043168 · Jul 24, 2018
Continuation In Part 16041851 · Jul 23, 2018
Continuation In Part 16041792 · Jul 22, 2018
Continuation In Part 15811688 · Nov 14, 2017
Continuation In Part 15810297 · Nov 13, 2017
Continuation In Part 15596648 · May 16, 2017
Continuation In Part 15592689 · May 11, 2017
Continuation 14606946 · Jan 27, 2015
Provisional Application 62720207 · Aug 21, 2018
Provisional Application 62612438 · Dec 30, 2017
Provisional Application 62612435 · Dec 30, 2017
Provisional Application 62612437 · Dec 30, 2017
Provisional Application 62538941 · Jul 31, 2017
Provisional Application 62451321 · Jan 27, 2017
Provisional Application 62446088 · Jan 13, 2017
Related Publication 20190140887A1 · May 9, 2019