Discovery and classification of enterprise assets via host characteristics
US-9830458-B2 · Nov 28, 2017 · US
US2017346674A1 · US · A1
| Field | Value |
|---|---|
| Publication number | US-2017346674-A1 |
| Application number | US-201715682314-A |
| Country | US |
| Kind code | A1 |
| Filing date | Aug 21, 2017 |
| Priority date | Aug 12, 2015 |
| Publication date | Nov 30, 2017 |
| Grant date | — |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Systems, apparatuses, and methods for automatic automated electronic computing and communication system event analysis and management are disclosed. Automatic automated electronic computing and communication system event analysis and management may include identifying an event, generating a computer readable representation of the electronic computing and communication system using automated topology enumeration, identifying an element of the electronic computing and communication system based on the representation, identifying a metric for the element, automatically investigating to determine a value for the metric, generating a remediation priority for the element based on a metric weight associated with the metric and a network layer value associated with a network layer associated with a network layer role associated with the element, and generating a graphical representation of the electronic computing and communication system indicating the remediation priority.
Opening claim text (preview).
What is claimed is: 1 . A method of analyzing events, the method comprising: receiving an indication of an event in an electronic computing and communication system comprising a plurality of elements; identifying an element of the plurality of elements of the electronic computing and communication system corresponding to the event, wherein the element is associated with a network layer role corresponding to a network layer; determining a value for a metric for the element of the electronic computing and communication system; based on the value being an abnormal value, generating a remediation priority for the element based at least in part on a metric weight associated with the metric; and remediating the event based at least in part on the remediation priority. 2 . The method of claim 1 , wherein receiving the indication of the event comprises receiving the indication via a message, a notification, or signal. 3 . The method of claim 1 , wherein the event affects one or more network communication layers. 4 . The method of claim 3 , wherein the one or more communication layers comprises a network layer event or a host layer event. 5 . The method of claim 1 , wherein the event corresponds to a failed or affected service. 6 . The method of claim 5 , wherein the failed or affected service comprises a data storage service, data manipulation service, presentation service, a communication service, e-mail service, printing service, network file system, directory services, file sharing service, instant messaging service, video telephony service, world wide web service, time service. 7 . The method of claim 5 comprising categorizing the metric based on the failed or affected service. 8 . The method of claim 1 , wherein the metric is identified based at least in part on historical data or a metric value stored in memory. 9 . The method of claim 1 comprising investigating the electronic computing and communication system in response to receiving the event to analyze the event using the metric. 10 . The method of claim 9 , wherein investigating the electronic computing and communication system comprises examining configuration changes in one or more of the plurality of elements. 11 . The method of claim 9 , wherein investigating the electronic computing and communication system comprises examining availability of the element. 12 . The method of claim 9 , wherein investigating the electronic computing and communication system comprises identifying performance of the element. 13 . The method of claim 9 , wherein investigating the electronic computing and communication system comprises identifying capacity usage of the element. 14 . The method of claim 1 comprising generating a computer-readable representation of the electronic computing and communication system using automated topology enumeration, wherein the computer-readable representation represents the plurality of elements of the electronic computing and communication system organized in a hierarchical plurality of network layers. 15 . Non-transitory, computer-readable, and tangible medium storing instructions thereon configured to cause one or more processors to: receive an indication of an incident occurring in an electronic computing and communication system, wherein the indication is generated at a network layer or a host layer; using an enumerated network topology, generate a list of network elements that are potentially affected by the event; collect a series of metrics for a plurality of categories for the list of network elements; flag possible issues for analysis; generate a remediation priority list of the list of network elements based at least in part on a metric weight associated with each of the metrics of the series of metrics; and remediating at least one of the network elements based at least in part on the remediation priority list. 16 . The non-transitory, computer-readable, and tangible medium of claim 15 , wherein the instructions are configured to cause the one or more processors to generate a computer-readable representation of the electronic computing and communication system using automated topology enumeration. 17 . The non-transitory, computer-readable, and tangible medium of claim 16 , wherein the representation represents the network elements organized in a hierarchical plurality of network layers. 18 . The non-transitory, computer-readable, and tangible medium of claim 16 , wherein the instructions are configured to cause the one or more processors are to generate the automated topology enumeration by: identifying a network layer role associated with each of the network elements; and identifying a network layer associated with each of the network elements based on the corresponding network layer role. 19 . The non-transitory, computer-readable, and tangible medium of claim 18 , wherein the instructions are configured to cause the one or more processors to identify the network layer role by: identifying information representing the network elements; and determining each corresponding network layer role by evaluating a configuration management database based on the information representing a respective network element of the network elements. 20 . The non-transitory, computer-readable, and tangible medium of claim 15 , wherein the instructions are configured to cause the one or more processors to identify network protocol information for each network element, wherein the instructions are configured to cause the one or more processors to identify network protocol information for a respective network element of the network elements that indicates a physical connection between the respective network element and another element of the electronic computing and communication system.
during program execution, e.g. stack integrity {; Preventing unwanted data erasure; Buffer overflow} · CPC title
using network fault recovery (ring fault isolation or reconfiguration in loop networks without recovery actions by a network management system H04L12/437) · CPC title
Assessing vulnerabilities and evaluating computer system security · CPC title
involving logical or physical relationship, e.g. grouping and hierarchies · CPC title
comprising specially adapted graphical user interfaces [GUI] · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.