Method and apparatus for detecting irregularities on a device
US-9767278-B2 · Sep 19, 2017 · US
US10346744B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-10346744-B2 |
| Application number | US-201313850725-A |
| Country | US |
| Kind code | B2 |
| Filing date | Mar 26, 2013 |
| Priority date | Mar 29, 2012 |
| Publication date | Jul 9, 2019 |
| Grant date | Jul 9, 2019 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
The field of the disclosure relates generally to a method and system for analyzing behavior of a computer infrastructure and the displaying the behavior of the computer infrastructure in a graphical manner. The system comprises an analytical engine connected to agents running on devices in the computer infrastructure and analyzing continuous data and asynchronous data.
Opening claim text (preview).
The invention claimed is: 1. A system for analysing a behaviour of a computer infrastructure, the system comprising: at least one agent associated with at least one device of the computer infrastructure for monitoring and collecting continuous data on the at least one device and for collecting asynchronous data on the at least one device when changes happen on the at least one device, wherein the asynchronous data includes at least log file data and the continuous data comprises computing resource data regarding the at least one device, the at least one agent forwarding the continuous data and the asynchronous data to a management system; the management system comprising at least one database storing the continuous data and the asynchronous data including associated time stamps, wherein the continuous data on the at least one device is stored in the at least one database only if a certain threshold value is reached, the management system aggregating the continuous data and the asynchronous data from a plurality of devices that include the at least one device; and an analytics engine configured to: analyse relationships between the continuous data and the asynchronous data; detect a behaviour type of the at least one device of the computer infrastructure based on the analysis; recognise recurrent patterns between the continuous data and the asynchronous data to further detect the behaviour type; transfer to a display, an indication of at least one detection of the detected behaviour type as graphic elements, wherein at least one of the graphic elements is linked to the continuous data and the asynchronous data collected by the at least one agent associated with the at least one device, and wherein the graphic elements have different colours or shapes in relation to a degree of impact of the behaviour on the computer infrastructure, further wherein at least a portion of the graphic elements are selectable and open related types of system parameters and the log file data of the continuous data and the asynchronous data within the computer infrastructure; determine or simulate probabilities of at least a portion of streams of the log file data of the at least one device of the computer infrastructure; and provide a forecast of possible future performance of the at least one device of the computer infrastructure based on the determination or simulation. 2. The system according to claim 1 , the analytics engine being further for adapting the display to indicate the degree of impact on the computer infrastructure of the behaviour type. 3. The system according to claim 1 , wherein the continuous data and the asynchronous data is related to a data operation in an application at the at least one device. 4. The system according to claim 1 , the continuous data and the asynchronous data being indicative of running processes on the at least one device. 5. The system according to claim 1 , wherein the analytics engine is adapted to diagnose an abnormal one of the behaviour type by analysing at least one of a sequence of the at least log file data, temporal parameters of the at least log file data, and the relationships between one or more of the asynchronous data and the continuous data. 6. The system according to claim 1 , wherein different ones of graphic elements on the display are linked to different ones of the behaviour types. 7. The system according to claim 6 , wherein the different ones of the graphic elements are selectable for opening information panels relating to the linked ones of the behaviour types. 8. The system according to claim 1 , wherein the analytics engine is adapted to group the behaviour types and the grouping is represented by a grouping of graphic elements on the display. 9. The system according to claim 1 , wherein the analytics engine is a self-learning system. 10. The system according to claim 1 , wherein the computer infrastructure is adapted to connect with a data source transferring business and financial data to the computer infrastructure via an interface. 11. The system according to claim 1 , wherein the analytics engine is adapted to recognise recurrent patterns by comparing historical data and current data stored in the at least one database. 12. A method for analysing a behaviour of a computer infrastructure, the method comprising: monitoring and collecting, by least one agent, continuous data on at least one device and collecting asynchronous data on the at least one device when changes happen on the at least one device, wherein the asynchronous data includes at least log file data and the continuous data comprises computing resource data regarding the at least one device, the at least one agent forwarding the continuous data and the asynchronous data to a management system; storing, in at least one database, the continuous data and the asynchronous data including associated time stamps, wherein the continuous data on the at least one device is stored in the at least one database only if a certain threshold value is reached, the management system aggregating the continuous data and the asynchronous data from a plurality of devices that include the at least one device; analyzing relationships between the continuous data and the asynchronous data; detecting a behaviour type of the at least one device of the computer infrastructure based on the analysis; recognizing recurrent patterns between the continuous data and asynchronous data to further detect the behaviour type; transferring to a display, an indication of at least one detection of the detected behaviour type as graphic elements, wherein at least one of the graphic elements is linked to the continuous data and the asynchronous data collected by the at least one agent associated with the at least one device, and wherein the graphic elements have different colours or shapes in relation to a degree of impact of the behaviour on the computer infrastructure, further wherein at least a portion of the graphic elements are selectable and open related types of system parameters and the log file data of the continuous data and the asynchronous data within the computer infrastructure; determining or simulating probabilities of at least a portion of streams of the log file data of the at least one device of the computer infrastructure; and providing a forecast of possible future performance of the at least one device of the computer infrastructure based on the determination or simulation. 13. The method according to claim 12 , further comprising adapting the display to indicate the degree of impact on the computer infrastructure of the behaviour type. 14. The method according to claim 12 , wherein the continuous data and the asynchronous data are related to a data operation in an application at the at least one device. 15. The method according to claim 12 , wherein the continuous data and the asynchronous data are indicative of running processes on the at least one device. 16. The method according to claim 12 , further comprising diagnosing an abnormal one of the behaviour type by analysing at least one of a sequence of the at least log file data, temporal parameters of the at least log file data, and the relationships between one or more of the asynchronous data and the continuous data. 17. The method according to claim 12 , wherein different ones of graphic elements on the display are linked to different ones of the behaviour types. 18. The method according to claim 17 , wherein the different ones of the graphic elements are selectable for opening information panels relating to t
Data logging (G06F11/14, G06F11/2205 take precedence) · CPC title
Monitoring arrangements for monitoring the status of the computing system or of the computing system component, e.g. monitoring if the computing system is on, off, available, not available (error or fault processing without redundancy G06F11/0703; error detection or correction by redundancy in data representation G06F11/08; error detection or correction of the data by redundancy in operations G06F11/14; error detection or correction by redundancy in hardware G06F11/16) · CPC title
for systems · CPC title
for performance assessment · CPC title
Computer systems status display (G06F11/327 takes precedence) · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.