IP Library Granted Patent US 10,264,022
Granted Patent B2
US 10,264,022 · App. 15/017,243 · Granted Apr 16, 2019

Information technology governance and controls methods and apparatuses

Inventors: Robert DiFalco (Portland, OR); Kenneth L. Keeler (Lake Oswego, OR); Robert L. Warmack (West Linn, OR)
Assignee: Tripwire, Inc.
H04L63/20G06F17/30088G06Q10/00G06Q10/0637H04L63/102
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,264,022
App. No.
15/017,243
Granted
Apr 16, 2019
Kind
B2
Abstract

Embodiments of the present invention provide methods and systems for automated change audit of an enterprise's IT infrastructure, including independent detection of changes, reconciliation of detected changes and independent reporting, to effectuate a triad of controls on managing changes within the IT infrastructure, preventive controls, detective controls and corrective controls.

Claims (22)

1. A method for performing preventative, detective, and corrective control of an information technology (IT) infrastructure, comprising:

detecting a change of state in at least one of a plurality of data processing devices in the information technology (IT) infrastructure, wherein the detecting is performed by comparing a baseline state for the at least one of the plurality of data processing devices to a current state of the at least one of the plurality of data processing devices and wherein the detecting is performed without knowledge of a source of the change of state;

performing an enrichment operation by correlating the detected change of state to one or more events identified in a separate event or audit log, and supplementing the detected change of state with the correlated one or more events;

after the detecting, reconciling the detected change of state as an authorized and planned change of state by determining whether the change of state is associated with a work ticket or maintenance window for the at least one of the plurality of data processing devices; and

if the detected change of state is not an authorized and planned change of state, generating a notification to a system administrator reporting the detected change of state.

2. The method of claim 1 , further comprising, if the change of state is an authorized and planned change of state, updating the baseline state for the at least one of a plurality of data processing devices to the current state.

3. The method of claim 1 , wherein the reconciling further comprises determining whether the detected change of state is conforming to a regulatory or security standard.

4. The method of claim 3 , wherein the reconciling further comprises changing the baseline state for the at least one data processing device only if the detected change of state is conforming to the regulatory or security standard.

5. The method of claim 3 , wherein the reconciling further comprises determining at least one of a level of severity or non-conformance for the detected change of state, if the detected change of state is not conforming.

6. The method of claim 1 , further comprising memorializing a detected change of state of the at least one of a plurality of data processing device by logging one or events in an event log.

7. The method of claim 1 , wherein the method further comprises generating a change report for changes detected in the information technology (IT) infrastructure, including the change at the data processing node, the change report including one or more of an identification of one or more of a number of changes detected, dates of the changes detected, times of the changes detected, operators associated with the changes detected, or permissions related to the operators associated with the changes detected.

8. One or more nom-transitory computer medium storing computer-executable instructions which when executed by a computer cause the computer to perform a method, the method comprising:

detecting a change of state in at least one of a plurality of data processing devices the information technology (IT) infrastructure, wherein the detecting is performed by comparing a baseline state for the at least one of the plurality of data processing devices to a current state of the at least one of the plurality of data processing devices and wherein the detecting is performed without knowledge of a source of the change of state;

performing an enrichment operation by correlating the detected change of state to one or more events identified in a separate event or audit log, and supplementing the detected change of state with the correlated one or more events;

after the detecting, reconciling the detected change of state as an authorized and planned change of state by determining whether the change of state is associated with a work ticket or maintenance window for the at least one of the plurality of data processing devices; and

if the detected change of state is not an authorized and planned change of state, generating a notification to a system administrator reporting the detected change of state.

9. The one or more non-transitory computer medium of claim 8 , wherein the method further comprises, if the change of state is an authorized and planned change of state, updating the baseline state for the at least one of a plurality of data processing devices to the current state.

10. The one or more non-transitory computer medium of claim 8 , wherein the reconciling further comprises determining whether the detected change of state is conforming to a regulatory or security standard.

11. The one or more non-transitory computer medium of claim 10 , wherein the reconciling further comprises changing the baseline state for the at least one data processing device only if the detected change of state is conforming to the regulatory or security standard.

12. The one or more non-transitory computer medium of claim 10 , wherein the reconciling further comprises determining at least one of a level of severity or non-conformance for the detected change of state, if the detected change of state is not conforming.

13. The one or more non-transitory computer medium of claim 8 , the method further comprising memorializing a detected change of state of the at least one of a plurality of data processing device by logging one or events in an event log.

14. The one or more non-transitory computer medium of claim 8 , wherein the method further comprises generating a change report for changes detected in the information technology (IT) infrastructure, including the change at the data processing node, the change report including one or more of an identification of one or more of a number of changes detected, dates of the changes detected, times of the changes detected, operators associated with the changes detected, or permissions related to the operators associated with the changes detected.

Assignments (11)
SECURITY INTEREST Recorded Jan 6, 2026
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.
To: ACQUIOM AGENCY SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 074233/0632 →
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 60306/0365 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: TRIPWIRE, INC.
Reel/Frame 074023/0235 →
TERMINATION AND RELEASE OF FIRST LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 60306/0555 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: TRIPWIRE, INC.
Reel/Frame 074023/0320 →
EXTENDED RCF FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: TRIPWIRE, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073663/0639 →
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 60306/0649 Recorded Nov 21, 2025
From: ACQUIOM AGENCY SERVICES LLC
To: TRIPWIRE, INC.
Reel/Frame 073663/0698 →
EXTENDED FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: TRIPWIRE, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073664/0124 →
NEW MONEY FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.; VERA SECURITY, INC.
To: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 073683/0534 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 14, 2025
From: GOLUB CAPITAL MARKETS LLC (AS EXISTING AGENT)
To: ACQUIOM AGENCY SERVICES LLC (AS SUCCESSOR COLLATERAL AGENT)
Reel/Frame 072471/0665 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jun 7, 2022
From: TRIPWIRE, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 060306/0365 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jun 7, 2022
From: TRIPWIRE, INC.
To: GOLUB CAPITAL MARKETS LLC, AS COLLATERAL AGENT
Reel/Frame 060306/0649 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 2, 2018
From: DIFALCO, ROBERT A.; KEELER, KENNETH L.; WARMACK, ROBERT L.
To: TRIPWIRE, INC.
Reel/Frame 047391/0101 →
Continuity (4)
Continuation 13465935 · May 7, 2012
Continuation 11463580 · Aug 9, 2006
Provisional Application 60706938 · Aug 9, 2005
Related Publication 20160234254A1 · Aug 11, 2016