IP Library › Granted Patent US 12,284,214
Granted Patent B2
US 12,284,214 · App. 17/649,225 · Granted Apr 22, 2025

System and method for telemetry data based event occurrence analysis with rule engine

Inventors: Sanjay Kumar (Bangalore, IN); Manoj Paul (San Jose, CA); Rao Gattupalli (Los Gatos, CA)
Assignee: Virsec Systems, Inc.
H04L63/20H04L63/1416H04L67/02H04L67/30H04L67/5682
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,284,214
App. No.
17/649,225
Filed
Jan 28, 2022
Granted
Apr 22, 2025
Kind
B2
Examiner
KING, JOHN B
Art Unit
2498
USPC
726/1
Abstract

Embodiments determine event, e.g., performance degradation, security breach, etc., occurrence based on telemetry data. An embodiment receives telemetry data, e.g., data based on an HTTP transaction, and a rule associated with the telemetry data. The rule defines one or more filters for processing the telemetry data. In turn, a rule engine is modified in accordance with the received rule. The received telemetry data is processed with the modified rule engine to determine event occurrence.

Claims (54)

1. A computer-implemented method for determining event occurrence based on telemetry data, the method comprising:

receiving telemetry data, an indication of a rule for processing the received telemetry data, and the rule, the received rule defining one or more filters for the processing;

modifying a rule engine in accordance with the received rule by defining runtime state functionality of a finite state automaton, implemented by the rule engine, in accordance with the received rule; and

processing the received telemetry data with the modified rule engine to determine event occurrence.

2. The method of claim 1 wherein the telemetry data is based on at least one of: a Hypertext Transfer Protocol (HTTP) transaction and processing the HTTP transaction.

3. The method of claim 1 wherein the telemetry data is based on multiple HTTP transactions.

4. The method of claim 1 wherein the rule is constructed and defined in accordance with a grammar.

5. The method of claim 1 wherein the processing comprises:

identifying which of the one or more filters are activated in processing the received telemetry data; and

determining event occurrence based on the identified activated filters.

6. The method of claim 1 wherein the rule further defines at least one of:

output of a first filter utilized by a second filter;

an event profile comprising a group of filters or sequence of filters;

a feature comprising one or more event profiles; and

a namespace comprising one or more features.

7. The method of claim 6 wherein:

modifying the rule engine in accordance with the received rule comprises modifying the rule engine in accordance with the event profile; and

processing the received telemetry data with the rule engine modified in accordance with the event profile comprises determining event occurrence if the one or more filters are activated in accordance with the event profile.

8. The method of claim 6 wherein:

modifying the rule engine in accordance with the received rule comprises modifying the rule engine in accordance with the namespace and an event profile associated with the namespace; and

processing the received telemetry data with the rule engine modified in accordance with the namespace and the event profile associated with the namespace comprises determining event occurrence if the one or more filters are activated in accordance with the event profile associated with the namespace.

9. The method of claim 1 wherein the event is:

a performance degradation;

a security breach;

a hijacked session; or

a behavior defined by the rule.

10. The method of claim 1 wherein the processing determines event occurrence in real-time.

11. A system for determining event occurrence based on telemetry data, the system comprising:

a processor; and

a memory with computer code instructions stored thereon, the processor and the memory, with the computer code instructions, being configured to cause the system to:

receive telemetry data, an indication of a rule for processing the received telemetry data, and the rule, the received rule defining one or more filters for the processing;

modify a rule engine in accordance with the received rule by defining runtime state functionality of a finite state automaton, implemented by the rule engine, in accordance with the received rule; and

process the received telemetry data with the modified rule engine to determine event occurrence.

12. The system of claim 11 wherein the telemetry data is based on at least one of: a Hypertext Transfer Protocol (HTTP) transaction and processing the HTTP transaction.

13. The system of claim 11 wherein the rule is constructed and defined in accordance with a grammar.

14. The system of claim 11 wherein to process the received telemetry data with the modified rule engine, the processor and the memory, with the computer code instructions, are further configured to cause the system to:

identify which of the one or more filters are activated in processing the received telemetry data; and

determine event occurrence based on the identified activated filters.

15. The system of claim 11 wherein the rule further defines at least one of:

output of a first filter utilized by a second filter;

an event profile comprising a group of filters or sequence of filters;

a feature comprising one or more event profiles; and

a namespace comprising one or more features.

16. The system of claim 15 wherein:

to modify the rule engine in accordance with the received rule, the processor and the memory, with the computer code instructions, are further configured to cause the system to modify the rule engine in accordance with the event profile; and

to process the received telemetry data with the rule engine modified in accordance with the event profile, the processor and the memory, with the computer code instructions, are further configured to cause the system to determine event occurrence if the one or more filters are activated in accordance with the event profile.

17. The system of claim 15 wherein:

to modify the rule engine in accordance with the received rule, the processor and the memory, with the computer code instructions, are further configured to cause the system to modify the rule engine in accordance with the namespace and an event profile associated with the namespace; and

to process the received telemetry data with the rule engine modified in accordance with the namespace and the event profile associated with the namespace, the processor and the memory, with the computer code instructions, are further configured to cause the system to determine event occurrence if the one or more filters are activated in accordance with the event profile associated with the namespace.

18. A non-transitory computer program product for determining event occurrence, the computer program product executed by a server in communication across a network with one or more clients and comprising:

a computer readable medium, the computer readable medium comprising program instructions, which, when executed by a processor, causes the processor to:

receive telemetry data, an indication of a rule for processing the received telemetry data, and the rule, the received rule defining one or more filters for the processing;

modify a rule engine in accordance with the received rule by defining runtime state functionality of a finite state automaton, implemented by the rule engine, in accordance with the received rule; and

process the received telemetry data with the modified rule engine to determine event occurrence.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 31, 2022
From: KUMAR, SANJAY; GATTUPALLI, RAO
To: VIRSEC SYSTEMS, INC.
Reel/Frame 059460/0135 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 10, 2022
From: PAUL, MANOJ
To: VIRSEC SYSTEMS, INC.
Reel/Frame 059222/0912 →
Priority Claims (1)
IN 202141049540 · Oct 29, 2021 · national
Continuity (1)
Related Publication 20230138805A1 · May 4, 2023
References Cited (25)
US 5867651A · Dan · 1999 [cited by examiner]
US 7281018B1 · Begun · 2007 [cited by examiner]
US 8463925B1 · Nath · 2013 [cited by examiner]
US 8566444B1 · Yona · 2013 [cited by examiner]
US 8826443B1 · Raman · 2014 [cited by examiner]
US 10528725B2 · Samuel · 2020 [cited by examiner]
US 10922363B1 · Paiz · 2021 [cited by examiner]
US 11781883B1 · Dabell · 2023 [cited by examiner]
US 20040107360A1 · Herrmann · 2004 [cited by examiner]
US 20040205360A1 · Norton et al. · 2004 [cited by applicant]
US 20050268335A1 · Le · 2005 [cited by examiner]
US 20050273593A1 · Seminaro · 2005 [cited by examiner]
US 20080276316A1 · Roelker et al. · 2008 [cited by applicant]
US 20140123288A1 · Lee · 2014 [cited by examiner]
US 20190065755A1 · Hatsutori · 2019 [cited by examiner]
US 20200120107A1 · McGrew · 2020 [cited by examiner]
US 20200293916A1 · Li · 2020 [cited by examiner]
US 20200382529A1 · Higgins · 2020 [cited by examiner]
US 20200387597A1 · Karasev · 2020 [cited by examiner]
US 20210097168A1 · Patel · 2021 [cited by examiner]
US 20210367847A1 · Vasseur · 2021 [cited by examiner]
WO 2023102531A1 · 2023 [cited by applicant]
Sqreen, “Documenation”, retrieved at https://docs.sqreen.com/, Downloaded from Internet Apr. 29, 2022, 2 pages. [cited by applicant]
Sqreen, Protect, “Protect your app with Sqreen” retrieved at https://docs.sqreen.com/protection/introduction/Downloaded from Internet Apr. 29, 2022, 20 pages. [cited by applicant]
International Search Report and Written Opinion received for PCT Patent Application No. PCT/US2022/080826, mailed on Mar. 31, 2023, 11 pages. [cited by applicant]