IP Library › Granted Patent US 12,278,730
Granted Patent B2
US 12,278,730 · App. 18/338,462 · Granted Apr 15, 2025

Analyzing policies executed in a computer system

Inventors: Matthew Richard James Thornhill (London, GB); Keith Jeremy Posner (London, GB); David Jon Griffin (Reigate, GB)
Assignee: International Business Machines Corporation
H04L41/0894H04L41/0893
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,278,730
App. No.
18/338,462
Granted
Apr 15, 2025
Kind
B2
Abstract

There is provided a method, apparatus and computer program product for analysing policies executed in a computer system which comprises a plurality of entities. The system is operable to detect one or more policies within a set of policies that have executed a predetermined number of times within a time window; identify a plurality of co-occurring, and thereby related, policies based on the detecting; and group the identified co-occurring policies.

Claims (52)

1. A method for analysing policies executed in a computer system which comprises a plurality of entities, the system operable to emit a plurality of events providing status information for any of the entities in the system and wherein emitted events cause one or more policies to execute, the method comprising:

detecting one or more policies within a set of policies that have executed a predetermined number of times within a time window;

identifying a plurality of co-occurring, and thereby related, policies based on the detecting; and

grouping the identified co-occurring policies.

2. The method of claim 1 , wherein the time window is a rolling time window.

3. The method of claim 1 , comprising:

responsive to a policy executing, determining that the predetermined number has been met for a plurality of policies comprising the set.

4. The method of claim 1 , comprising:

presenting the one or more identified co-occurring policies to a user.

5. The method of claim 1 , comprising:

responsive to a user changing a policy of the set of policies, identifying a group that the changed policy is associated with; and

displaying suggestions to the user indicating that the user should consider changing one or more additional policies in the identified group.

6. The method of claim 1 , wherein the detecting comprises:

using an association rule mining algorithm to identify relationships between policies.

7. The method of claim 6 , wherein a support parameter determines one or more instances of co-occurrence required to identify a group of policies as related, and a confidence parameter determines a required similarity of the instances.

8. The method of claim 7 , wherein the support parameter and the confidence parameter are set empirically based on training data or using a default value.

9. The method of claim 5 , wherein event information about events emitted by the system is stored in a database, the method comprising:

responsive to one or more suggestions, making changes to one or more policies within one or more groups;

replaying, on-demand, one or more events stored in the database;

tracking one or more resulting policy executions; and

analysing the policy executions to produce updated policy grouping information.

10. An apparatus for analysing policies executed in a computer system which comprises a plurality of entities, the system operable to emit a plurality of events providing status information for any of the entities in the system and wherein emitted events cause one or more policies to execute, the apparatus comprising:

one or more processors;

a memory coupled to at least one of the processors; and

a set of computer program instructions stored in the memory and executed by at least one of the processors in order to perform a method comprising:

detecting one or more policies within a set of policies that have executed a predetermined number of times within a time window;

identifying a plurality of co-occurring, and thereby related, policies based on the detecting; and

grouping the identified co-occurring policies.

11. The apparatus of claim 10 , wherein the time window is a rolling time window.

12. The apparatus of claim 10 , wherein the method comprises:

presenting the one or more identified co-occurring policies to a user.

13. The apparatus of claim 10 , wherein the method comprises:

responsive to a user changing a policy of the set of policies, identifying a group that the changed policy is associated with; and

displaying suggestions to the user indicating that the user should consider changing one or more additional policies in the identified group.

14. The apparatus of claim 10 , wherein the detecting comprises using an association rule mining algorithm to identify relationships between policies, and wherein a support parameter determines one or more instances of co-occurrence required to identify a group of policies as related, and a confidence parameter determines a required similarity of the instances.

15. A computer program product for analysing policies executed in a computer system which comprises a plurality of entities, the system operable to emit a plurality of events providing status information for any of the entities in the system and wherein emitted events cause one or more policies to execute, the computer program product comprising:

a computer readable storage medium, comprising computer program code that, when executed by a computer performs a method comprising the steps of:

detecting one or more policies within a set of policies that have executed a predetermined number of times within a time window;

identifying a plurality of co-occurring, and thereby related, policies based on the detecting; and

grouping the identified co-occurring policies.

16. The computer program product of claim 15 , wherein the time window is a rolling time window.

17. The computer program product of claim 15 , wherein the method comprises:

presenting the one or more identified co-occurring policies to a user.

18. The computer program product of claim 15 , wherein the method comprises:

responsive to a user changing a policy of the set of policies, identifying a group that the changed policy is associated with; and

displaying suggestions to the user indicating that the user should consider changing one or more additional policies in the identified group.

19. The computer program product of claim 15 , wherein the detecting comprises using an association rule mining algorithm to identify relationships between policies, and wherein a support parameter determines one or more instances of co-occurrence required to identify a group of policies as related, and a confidence parameter determines a required similarity of the instances.

20. The computer program product of claim 18 , wherein event information about events emitted by the system is stored in a database, the method comprising:

responsive to one or more suggestions, making changes to one or more policies within one or more groups;

replaying, on-demand, one or more events stored in the database;

tracking one or more resulting policy executions; and

analysing the policy executions to produce updated policy grouping information.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 3, 2024
From: POSNER, KEITH JEREMY
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 066985/0897 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 21, 2023
From: THORNHILL, MATTHEW RICHARD JAMES; GRIFFIN, DAVID JON
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 064010/0610 →
Continuity (1)
Related Publication 20240430166A1 · Dec 26, 2024
References Cited (9)
US 11449379B2 · Gomes Pereira · 2022 [cited by applicant]
US 20090288135A1 · Chang · 2009 [cited by applicant]
US 20160315822A1 · Anderson · 2016 [cited by examiner]
US 20200120141A1 · Joseph · 2020 [cited by applicant]
US 20220129393A1 · Hodgson · 2022 [cited by applicant]
US 20220207241A1 · Bettencourt-Silva · 2022 [cited by examiner]
EP 2592513A2 · 2013 [cited by applicant]
WO WO2023229574A1 · 2022 [cited by examiner]
Disclosed Anonymously, “System and method to optimize multicloud resources and policy preparations,” IP.com, Aug. 2, 2020, 6 pages, IP.com No. IPCOM000263144D, Retrieved from the Internet: <URL: https://priorart.ip.com/… [cited by applicant]