IP Library Granted Patent US 9,792,169
Granted Patent B2
US 9,792,169 · App. 14/812,823 · Granted Oct 17, 2017

Managing alert profiles

Inventor: Jake Seigel (Halifax, CA)
Assignee: QUEST SOFTWARE INC.
G06F11/079G06F11/0751G06F11/0772G06F11/0787G06N99/005
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,792,169
App. No.
14/812,823
Granted
Oct 17, 2017
Kind
B2
Abstract

Systems and techniques for managing alert profiles, including creating the alert profiles and deactivating the alert profiles, are described. Auditing software executing on a central server may receive an event log from a software agent. The event log may identify activities associated with a network element in a computer system. The auditing software may include a classifier trained using machine learning. The auditing software may determine that the event log is indicative of an interesting activity, such as malicious activity. The auditing software may create an alert profile. The auditing software may assign a severity to the alert profile. The auditing software may determine whether the alert profile is relevant. The auditing software may deactivate the alert profile based on determining that the alert profile is not relevant.

Claims (74)

1. A computer-implemented method, comprising:

receiving, from a software agent, an event log identifying one or more activities associated with a network element;

determining, by a classifier trained using machine learning, that the event log is indicative of an interesting activity;

creating, by the classifier, an alert profile based at least partly on the event log;

determining, by the classifier, a severity of the alert profile based at least partly on the event log;

determining, by the classifier, a time interval associated with the alert profile;

determining a time period by multiplying the time interval by the severity of the alert profile;

associating, by the classifier, the time period with the alert profile; and

deactivating, by the classifier, the alert profile after the time period has expired.

2. The computer-implemented method of claim 1 , wherein the network element comprises at least one of:

a database hosting device;

a user computing device; or

a server device.

3. The computer-implemented method of claim 1 , further comprising:

determining that one or more conditions associated with the alert profile are satisfied; and

performing one or more actions associated with the alert profile.

4. The computer-implemented method of claim 3 , wherein the one or more actions include alerting a system administrator.

5. The computer-implemented method of claim 3 , wherein the one or more actions include preventing the network element from performing additional activities or preventing access to the network element.

6. The computer-implemented method of claim 1 , wherein deactivating, by the classifier, the alert profile after the time period has expired comprises:

determining, after the time period has expired, that the alert profile is not relevant based on one or more additional event logs; and

deactivating the alert profile based at least in part on determining that the alert profile is not relevant.

7. The computer-implemented method of claim 1 , wherein determining, by a classifier trained using machine learning, that the event log is indicative of an interesting activity comprises determining that the event log is indicative of at least one of:

a malicious activity; or

a utilization of a network resource satisfying a predetermined threshold.

8. One or more non-transitory computer-readable media storing instructions that include a classifier algorithm, the instructions executable by one or more processors to perform operations comprising:

receiving, from a software agent, an event log associated with a network element;

determining that the event log is indicative of an interesting activity;

creating an alert profile based at least partly on the event log;

determining a severity of the alert profile based at least partly on the event log;

determining a time interval associated with the alert profile;

determining a time period by multiplying the time interval by the severity of the alert profile;

associating the time period with the alert profile;

and

deactivating the alert profile based on determining that the time period has expired.

9. The one or more non-transitory computer-readable media of claim 8 , wherein determining that the event log is indicative of the interesting activity comprises:

determining that the event log is indicative of malicious activity.

10. The one or more non-transitory computer-readable media of claim 8 , wherein determining that the event log is indicative of the interesting activity comprises:

determining that the event log is indicative that a utilization of a network resource is at or above a predetermined threshold.

11. The one or more non-transitory computer-readable media of claim 8 , wherein determining that the event log is indicative of the interesting activity comprises:

determining that the event log is indicative that a utilization of a network resource is below a predetermined threshold.

12. The one or more non-transitory computer-readable media of claim 8 , further comprising:

receiving one or more additional event logs; and

determining that one or more conditions associated with the alert profile are satisfied based at least partly on the one or more additional event logs.

13. The one or more non-transitory computer-readable media of claim 8 , further comprising:

determining that one or more conditions associated with the alert profile are satisfied; and

performing one or more actions associated with the alert profile.

14. A server, comprising:

one or more processors; and

one or more non-transitory computer-readable media storing instructions comprising a classifier trained using machine learning, the instructions executable by the one or more processors to perform operations comprising:

receiving, from a software agent, a first event log identifying one or more events associated with a network element;

determining, by a classifier trained using machine learning, that the first event log is indicative of an interesting activity;

creating, by the classifier, an alert profile based at least partly on the first event log;

activating the alert profile;

receiving at least a second event log;

determining, by the classifier, that one or more conditions associated with the alert profile are satisfied based on the first event log and the second event log;

determining, by the classifier, a severity of the alert profile based at least partly on the first event log and the second event log;

determining, by the classifier, a time interval associated with the alert profile;

determining, by the classifier, a time period by multiplying the time interval by the severity of the alert profile;

associating, by the classifier, the time period with the alert profile;

performing one or more actions associated with the alert profile based on determining that the one or more conditions associated with the alert profile are satisfied; and

deactivating, by the classifier, the alert profile based on determining that the time period has expired.

15. The server of claim 14 , wherein determining that the first event log is indicative of an interesting activity comprises:

determining that the first event log is indicative of malicious activity.

16. The server of claim 14 , wherein the alert profile comprises the one or more conditions and the one or more actions.

17. The server of claim 14 , wherein performing the one or more actions associated with the alert profile comprises:

alerting a system administrator; and

blocking traffic to and from the network element.

18. The server of claim 14 , the operations further comprising:

determining a time period to activate the alert profile; and

associating the time period with the alert profile.

19. The server of claim 14 , further comprising:

determining that the interesting activity has not occurred for at least a predetermined amount of time.

20. The server of claim 14 , further comprising:

determining that an additional event log indicative of the interesting activity has not been received for at least a predetermined amount of time.

Assignments (27)
RELEASE OF SECURITY INTEREST Recorded Nov 19, 2025
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.
Reel/Frame 073606/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 18, 2025
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.
Reel/Frame 073613/0326 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0649 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0001 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059105/0479 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2022
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.; ONE IDENTITY LLC; ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
To: GOLDMAN SACHS BANK USA
Reel/Frame 058945/0778 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2022
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.; ONE IDENTITY LLC; ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 058952/0279 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059096/0683 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0486 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0347 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT R/F 040581/0850 Recorded May 22, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 046211/0735 →
CHANGE OF NAME Recorded Mar 21, 2018
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 045660/0755 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 16, 2018
From: DELL PRODUCTS L.P.
To: DELL SOFTWARE INC.
Reel/Frame 045355/0817 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 040587 FRAME: 0624. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 044811/0598 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 10, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040587/0624 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 9, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040581/0850 →
RELEASE OF SECURITY INTEREST Recorded Oct 31, 2016
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0467 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040039/0642) Recorded Oct 31, 2016
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0016 →
RELEASE OF REEL 036502 FRAME 0237 (TL) Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040028/0088 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040030/0187 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040039/0642 →
RELEASE OF REEL 036502 FRAME 0291 (NOTE) Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040027/0637 →
RELEASE OF REEL 036502 FRAME 0206 (ABL) Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040017/0204 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (ABL) Recorded Aug 27, 2015
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; WYSE TECHNOLOGY, L.L.C.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 036502/0206 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Aug 27, 2015
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 036502/0237 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (NOTES) Recorded Aug 27, 2015
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 036502/0291 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 31, 2015
From: SEIGEL, JAKE
To: DELL PRODUCTS L.P.
Reel/Frame 036230/0311 →
Continuity (1)
Related Publication 20170031741A1 · Feb 2, 2017