Response generation after distributed monitoring and evaluation of multiple devices
US-2017339178-A1 · Nov 23, 2017 · US
US10122747B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-10122747-B2 |
| Application number | US-201715660864-A |
| Country | US |
| Kind code | B2 |
| Filing date | Jul 26, 2017 |
| Priority date | Dec 6, 2013 |
| Publication date | Nov 6, 2018 |
| Grant date | Nov 6, 2018 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Data is collected from a set of devices according to a data collection policy. The data is associated with device configuration, device state, or device behavior. A norm is established using the collected data. A different data collection policy is established based on the norm. Data is collected from a particular device according to the different data collection policy. The norm is compared to the data collected from the particular device. If there is a deviation outside of a threshold deviation between the norm and the data collected from the particular device, a response is initiated.
Opening claim text (preview).
What is claimed is: 1. A method comprising: at a server, based on a first data collection policy, collecting observation data from a plurality of devices, the collected observation data including information associated with at least one of device configuration, device state, and device behavior; at the server, determining a normal pattern of activity occurring on the plurality of devices by processing the collected observation data, the normal pattern of activity being associated with at least one of the device configuration, the device state, and the device behavior of the plurality of devices; at the server, deriving a second data collection policy from the determined normal pattern of activity occurring on the plurality of devices, the second data collection policy being different from the first data collection policy; at the server, based on the derived second data collection policy, collecting first device data from a first device of the plurality of devices; at the server, comparing the normal pattern of activity occurring on the plurality of devices with a first pattern of activity occurring on the first device, the first pattern of activity being determined using the first device data; at the server, determining that a deviation between the normal pattern of activity and the first pattern of activity associated with the first device is outside of a threshold deviation; and upon the determination, generating alert information by the server, wherein the alert information when processed causes performance of a first action on the first device. 2. The method of claim 1 , wherein the action on the first device comprises: blocking the first device from accessing a service. 3. The method of claim 1 , wherein the action on the first device comprises: transmitting to the first device instructions to uninstall an application program on the first device. 4. The method of claim 1 , wherein the step of generating an alert further comprises: transmitting a message to an administrator. 5. The method of claim 1 , wherein the observation data collected comprises: a first set of observation data associated with an organization and collected from a first subset of the plurality of devices associated with the organization, and a second set of observation data collected from a second subset of the plurality of device not associated with the organization. 6. A method comprising: at a server, based on a first data collection policy, collecting observation data from a plurality of devices, the collected observation data including information associated with at least one of device configuration, device state, and device behavior; at the server, determining a normal pattern of activity occurring on the plurality of devices by processing the collected observation data, the normal pattern of activity being associated with at least one of the device configuration, the device state, and the device behavior of the plurality of devices; at the server, deriving a second data collection policy from the determined normal pattern of activity occurring on the plurality of devices, the second data collection policy being different from the first data collection policy; at the server, based on the derived second data collection policy, collecting first device data from a first device of the plurality of devices; at the server, comparing the normal pattern of activity occurring on the plurality of devices with a first pattern of activity occurring on the first device, the first pattern of activity being determined using the first device data; at the server, determining that a deviation between the normal pattern of activity and the first pattern of activity associated with the first device is outside of a threshold deviation; and upon the determination, generating alert information by the server, wherein the alert information when processed causes at least one of: the transmitting by the server of a message to an administrator; the blocking of the first device from accessing a service; and transmitting to the first device instructions to uninstall an application program on the first device. 7. The method of claim 6 , wherein the observation data collected comprises: a first set of observation data associated with an organization and collected from a first subset of the plurality of devices associated with the organization, and a second set of observation data collected from a second subset of the plurality of device not associated with the organization. 8. The method of claim 7 , wherein: the first device is associated with the organization; and the determining the normal pattern of activity occurring on the plurality of devices by processing the collected observation data comprises processing the collected observation data from the first subset of the plurality of devices and not processing the collected observation data from the second subset of the plurality of devices to determine the normal pattern of activity. 9. A method comprising: at a server, monitoring a plurality of devices for observation data based on a first data monitoring policy, the monitored observation data including information associated with at least one of device configuration, device state, and device behavior; at the server, establishing a normal pattern of activity occurring on the plurality of devices based on the monitored observation data, the normal pattern of activity being associated with at least one of the device configuration, the device state, and the device behavior of the plurality of devices; at the server, deriving a second data monitoring policy from the determined normal pattern of activity occurring on the plurality of devices, the second data monitoring policy being different from the first data monitoring policy; at the server, based on the derived second data monitoring policy, monitoring a first device of the plurality of devices for first device data; at the server, comparing the normal pattern of activity occurring on the plurality of devices with a first pattern of activity occurring on the first device, the first pattern of activity being determined by the monitored first device data; at the server, determining that the first pattern of activity associated with the first device of the plurality of devices is outside of a threshold deviation from the normal pattern of activity; and upon the determination, modifying the second data monitoring policy for monitoring of the first device by the server. 10. The method of claim 9 , wherein the step of modifying the second data monitoring policy comprises: increasing the monitoring of the first device. 11. The method of claim 9 , wherein the step of modifying the second data monitoring policy comprises: decreasing the monitoring of the first device. 12. The method of claim 9 , wherein the normal pattern of activity indicates that a first event occurs during a first context, and the step of determining that activity on the first device is outside the normal pattern of activity comprises: determining that the first event occurred on the first device during a second context, different from the first context. 13. The method of claim 9 , wherein the step of determining that the first pattern of activity on the first device is outside the normal pattern of activity comprises: receiving from the first device an indication that a shared library has been loaded on the first device from a memory card. 14. The method of claim 9 comprising: generating a model of characteristics for a specific application program on the plurality of device; and wherein the step of determining that the first patte
the attack involving the propagation of malware through the network, e.g. viruses, trojans or worms · CPC title
Threshold · CPC title
Error or fault reporting or storing · CPC title
Active monitoring, e.g. heartbeat, ping or trace-route · CPC title
using machine learning or artificial intelligence · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.