IP Library Granted Patent US 8,600,996
Granted Patent B2
US 8,600,996 · App. 12/633,747 · Granted Dec 3, 2013

Use of inference techniques to facilitate categorization of system change information

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,600,996
App. No.
12/633,747
Granted
Dec 3, 2013
Kind
B2
Abstract

Methods, systems, and articles for receiving, by a monitor server, change data associated with a change captured on a target host, are described herein. In various embodiments, the target host may have provided the change data in response to detecting the change, and the change data may include one or more rules, settings, and/or parameters. Further, in some embodiments, the monitor server may analyze the change data in order to group the change data into clusters. Once the change data have been classified as clusters, a report may be generated providing classification or categorization and cluster information for the various changes. In various embodiments, the generating may comprise generating a report to the target host and/or to an administrative user.

Claims (51)

1. A method comprising:

receiving, by a computing device executing programming instructions for a monitor server, change data associated with a plurality of changes captured on a target host, the target host providing the change data in response to detecting the plurality of changes to target host data using one or more rules or collection policies to capture the changes, wherein the change data includes at least one or more of the following: rules, settings, or parameters;

analyzing, by the monitor server, the change data in order to group the change data into clusters;

classifying, by the monitor server, the clusters relating to at least one potential reason for the plurality of changes in order to categorize at least some of the clusters;

determining, by the monitor server, whether the change data violate one or more compliance policies;

generating, by the monitor server, one or more test results based at least on the results of the determining;

analyzing, by the monitor server, the one or more test results in order to group the one or more test results into test result clusters; and

classifying, by the monitor server, the test result clusters relating to at least one potential reason for the plurality of changes in order to categorize at least some of the test result clusters.

2. The method of claim 1 , wherein the classifying the clusters comprises inferring a categorization for at least some of the clusters based upon at least one known enterprise change.

3. The method of claim 1 , wherein the change data includes a rule that generated the change, the target host or node from which the change data was collected, a specific element name associated with the change, and element data associated with the change.

4. The method of claim 1 , further comprising generating a report, the report relating the categorization of the at least some of the clusters.

5. The method of claim 1 , wherein each compliance policy includes at least one or more of the following: a rule, a change name, one or more waivers from the policy, or an expression for evaluating element data of the change.

6. The method of claim 1 , further comprising filtering, by the monitor server, the received change data and conditionally performing the determining based on a result of the filtering.

7. The method of claim 1 , wherein the determining comprises evaluating an expression of at least one of the compliance policies against element data specified in the change data.

8. The method of claim 1 , further comprising generating a report, the report relating the categorization of the at least some of the test result clusters.

9. A monitor server residing on a computing device comprising:

a processor;

a change database for storing change data associated with a plurality of changes captured on a target host, the target host providing the change data to the monitor server in response to detecting the plurality of changes, wherein the change data includes at least one or more of the following: rules, settings, or parameters; and

one or more logic components communicatively coupled to the change database and to be operated by the processor to:

receive the change data;

store the change data in the change database;

analyze the change data in order to group the change data into clusters;

classify the clusters relating to at least one potential reason for the plurality of changes in order to categorize at least some of the clusters;

determine whether the change data violate one or more compliance policies;

generate one or more test results based at least on the results of the determining;

analyze the one or more test results in order to group the one or more test results into test result clusters; and

classify the test result clusters relating to at least one potential reason for the plurality of changes in order to categorize at least some of the test result clusters.

10. The monitor server of claim 9 , wherein the logic is further to:

classify the clusters relating to a potential reason for the plurality of changes by inferring a categorization for at least some of the clusters based upon at least one known enterprise change.

11. The monitor server of claim 9 , wherein the logic is further to:

generate a report, the report relating to the categorization of the at least some of the clusters.

12. The monitor server of claim 9 , wherein the compliance policies ensure that the target host is in compliance with one or more standards.

13. The monitor server of claim 9 , wherein the logic is further to:

filter the received change data and conditionally perform the determining based on a result of the filtering.

14. The monitor server of claim 9 , wherein the logic is further to:

evaluate an expression of at least one of the compliance policies against element data specified in the change data.

15. The monitor server of claim 9 , wherein the logic is further to:

generate a report, the report relating to the categorization of the at least some of the test result clusters.

16. An article of manufacture comprising:

a storage medium; and

a plurality of programming instructions stored on the storage medium and configured to program a computing device executing a monitor server to:

receive change data provided by a target host in response to detecting one or more changes captured on the target host, wherein the change data includes at least one or more of the following: rules, settings, or parameters;

analyze the change data in order to group the change data into clusters;

classify the clusters relating to at least one potential reason for the plurality of changes in order to categorize at least some of the clusters;

determine whether the change data violate one or more compliance policies;

generate one or more test results based at least on the results of the determining;

analyze the one or more test results in order to group the one or more test results into test result clusters; and

classify the test result clusters relating to at least one potential reason for the plurality of changes in order to categorize at least some of the test result clusters.

17. The article of manufacture of claim 16 , wherein the plurality of programming instructions is further configured to program the monitor server to:

classify the clusters relating to a potential reason for the plurality of changes by inferring a categorization for at least some of the clusters based upon at least one known enterprise change.

18. The article of manufacture of claim 16 , wherein the plurality of programming instructions are configured to generate a report based at least on the results of the classifying by the monitor server.

Assignments (14)
SECURITY INTEREST Recorded Jan 6, 2026
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.
To: ACQUIOM AGENCY SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 074233/0632 →
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 60306/0365 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: TRIPWIRE, INC.
Reel/Frame 074023/0235 →
TERMINATION AND RELEASE OF FIRST LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 60306/0555 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: TRIPWIRE, INC.
Reel/Frame 074023/0320 →
EXTENDED RCF FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: TRIPWIRE, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073663/0639 →
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 60306/0649 Recorded Nov 21, 2025
From: ACQUIOM AGENCY SERVICES LLC
To: TRIPWIRE, INC.
Reel/Frame 073663/0698 →
EXTENDED FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: TRIPWIRE, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073664/0124 →
NEW MONEY FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.; VERA SECURITY, INC.
To: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 073683/0534 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 14, 2025
From: GOLUB CAPITAL MARKETS LLC (AS EXISTING AGENT)
To: ACQUIOM AGENCY SERVICES LLC (AS SUCCESSOR COLLATERAL AGENT)
Reel/Frame 072471/0665 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jun 7, 2022
From: TRIPWIRE, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 060306/0365 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jun 7, 2022
From: TRIPWIRE, INC.
To: GOLUB CAPITAL MARKETS LLC, AS COLLATERAL AGENT
Reel/Frame 060306/0649 →
RELEASE OF SECURITY INTEREST Recorded Feb 2, 2015
From: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
To: TRIPWIRE, INC.; NCIRCLE NETWORK SECURITY INC.
Reel/Frame 034874/0150 →
SECURITY AGREEMENT Recorded Apr 2, 2013
From: TRIPWIRE, INC.; NCIRCLE NETWORK SECURITY, INC.
To: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 030132/0101 →
SECURITY AGREEMENT Recorded May 23, 2011
From: TRIPWIRE, INC.
To: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 026322/0580 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 8, 2009
From: GOOD, TOM; KIM, GENE; WHITLOCK, DAVID
To: TRIPWIRE, INC.
Reel/Frame 023623/0806 →