IP Library Granted Patent US 11,431,792
Granted Patent B2
US 11,431,792 · App. 15/420,420 · Granted Aug 30, 2022

Determining contextual information for alerts

Inventors: Manish Marwah (Palo Alto, CA); Renato Keshet (Haifa, IL); Barak Raz (Tel Aviv, IL); Brent James Miller (Raleigh, NC)
Assignee: Micro Focus LLC
H04L67/104H04L63/1408H04L12/4641
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,431,792
App. No.
15/420,420
Granted
Aug 30, 2022
Kind
B2
Abstract

In some examples, an alert relating to an issue in a computing arrangement is received. Contextual information is determined for the alert, the determined contextual information comprising spatial and temporal distributions of previous instances of the alert or similar alerts. The contextual information is communicated for use in addressing the issue in the computing arrangement.

Claims (38)

1. A non-transitory machine-readable storage medium storing instructions that upon execution cause a system to:

receive a first alert relating to an issue in a computing arrangement;

determine a second alert that is similar to the first alert, based on comparing a property of the second alert to a property of the first alert by applying a distance function that calculates a similarity value based on a difference between the property of the second alert and the property of the first alert;

determine contextual information for the first alert, the determined contextual information comprising spatial and temporal distributions of previous instances of the second alert that is similar to the first alert;

communicate, to a remediation engine, the contextual information for use in addressing the issue in the computing arrangement; and

perform, by the remediation engine, a remediation action that resolves the issue.

2. The non-transitory machine-readable storage medium of claim 1 , wherein the spatial distribution of the previous instances of the second alert comprises a distribution of the previous instances of the second alert across different physical or virtual locations.

3. The non-transitory machine-readable storage medium of claim 1 , wherein the temporal distribution of the previous instances of the second alert comprises a distribution of the previous instances of the second alert across different time instances.

4. The non-transitory machine-readable storage medium of claim 1 , wherein the contextual information further comprises information temporally correlating the first alert and the second alert.

5. The non-transitory machine-readable storage medium of claim 1 , wherein the contextual information further comprises a spatial distribution of instances of the second alert within a current time window.

6. The non-transitory machine-readable storage medium of claim 1 , wherein the contextual information further comprises attributes associated with the second alert, the attributes selected from among a user that the second alert relates to, a machine involved in the second alert, a network address involved in the second alert, a network port involved in the second alert, a domain name involved in the second alert, a protocol involved in the second alert, a program involved in the second alert, and an amount of transferred data that triggered the second alert.

7. The non-transitory machine-readable storage medium of claim 6 , wherein the contextual information comprises a difference between a value of a given attribute in a first time window and a value of the given attribute in a second time window.

8. The non-transitory machine-readable storage medium of claim 1 , wherein the contextual information comprises a peer group of users, machines, or programs that share a feature.

9. The non-transitory machine-readable storage medium of claim 1 , wherein the contextual information comprises information regarding past investigations for resolving the second alert.

10. The non-transitory machine-readable storage medium of claim 1 , wherein the property of the first alert and the property of the second alert are selected from among an alert source, an alert type, events of an alert, and tasks performed in response to an alert.

11. A method of a computing system comprising a processor, the method comprising:

receiving a first alert relating to an issue in a computing arrangement;

determining a second alert that is similar to the first alert, based on comparing a property of the second alert to a property of the first alert by applying a distance function that calculates a similarity value based on a difference between the property of the second alert and the property of the first alert;

determining contextual information for the first alert, the determined contextual information comprising a distribution of instances of the first alert and the second alert in historical event data, and a distribution of instances of the first alert and the second alert in event data in a current time window;

communicating, over a network to a remediation engine, the contextual information for use in addressing the issue in the computing arrangement; and

performing, by the remediation engine, a remediation action that resolves the issue.

12. The method of claim 11 , wherein the contextual information further comprises a statistic of values of an attribute in the historical event data and a statistic of values of the attribute in the current time window.

13. The method of claim 11 , wherein the contextual information further comprises information of past investigations to resolve the issue in the computing arrangement.

14. The method of claim 11 , wherein the first alert involves an entity, and wherein the contextual information further comprises information of past investigations performed with respect to the entity.

15. The method of claim 11 , wherein the contextual information further comprises information temporally correlating the first alert and the second alert.

16. A computing system comprising:

a processor; and

a non-transitory storage medium storing instructions executable on the processor to:

receive a first alert relating to an issue in a computing arrangement;

determine a second alert that is similar to the first alert, based on comparing a property of the second alert to a property of the first alert by applying a distance function that calculates a similarity value based on a difference between the property of the second alert and the property of the first alert;

determine contextual information for the first alert, the determined contextual information comprising distributions of previous instances of the second alert that is similar to the first alert, and information of past investigations to resolve the issue;

communicate, to a remediation engine, the contextual information for use in addressing the issue in the computing arrangement; and

perform, by the remediation engine, a remediation action that resolves the issue.

17. The computing system of claim 16 , wherein the distributions of previous instances of the second alert comprise a spatial distribution of the previous instances of the second alert across different virtual networks.

18. The non-transitory machine-readable storage medium of claim 1 , wherein the determined contextual information further comprises spatial and temporal distributions of previous instances of the first alert, and wherein the instructions upon execution cause the system to:

communicate, to the remediation engine, the contextual information comprising the spatial and temporal distributions of previous instances of the first alert for use in addressing the issue in the computing arrangement.

19. The computing system of claim 16 , wherein the contextual information further comprises information temporally correlating the first alert and the second alert.

20. The computing system of claim 16 , wherein the determined contextual information further comprises a spatial distribution of instances of the second alert within a current time window.

Assignments (7)
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0577 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC)
Reel/Frame 063560/0001 →
CHANGE OF NAME Recorded Aug 8, 2019
From: ENTIT SOFTWARE LLC
To: MICRO FOCUS LLC
Reel/Frame 050004/0001 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ENTIT SOFTWARE LLC; ARCSIGHT, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0577 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 9, 2017
From: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
To: ENTIT SOFTWARE LLC
Reel/Frame 042746/0130 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 1, 2017
From: MARWAH, MANISH; KESHET, RENATO; RAZ, BARAK; MILLER, BRENT JAMES
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 041144/0253 →
Continuity (1)
Related Publication 20180219876A1 · Aug 2, 2018