Systems and methods for detecting abnormal behavior of networked devices
US-8973133-B1 · Mar 3, 2015 · US
US9619376B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-9619376-B2 |
| Application number | US-201615248031-A |
| Country | US |
| Kind code | B2 |
| Filing date | Aug 26, 2016 |
| Priority date | Jan 23, 2013 |
| Publication date | Apr 11, 2017 |
| Grant date | Apr 11, 2017 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
A deviance monitoring module is provided for examining various parameters of an operating system for deviance from a baseline behavior at specified intervals. A range of acceptable deviance values from a baseline behavior is set for parameters of an operating system. The parameters of the operating system are then monitored at specified intervals for deviance from the baseline behavior. In response to detecting that the deviance exceeds a predetermined threshold, the method triggers diagnostic data gathering on the parameters of the operating system according to an embodiment.
Opening claim text (preview).
What is claimed is: 1. A computer program product, comprising: a non-transitory computer readable storage medium having computer readable program code stored thereon that, when executed, performs a method, the method comprising: setting, with a processing device, a range of acceptable deviance values from a baseline behavior for parameters of an operating system, wherein a user provides the range of acceptable deviance values from the baseline behavior for parameters of the operating system; monitoring the parameters at specified intervals for a deviance from the baseline behavior; determining whether the deviance falls within an exception list, wherein the exception list specifies an allowable amount of deviation of the monitored parameter values from the baseline behavior and allowable time values, wherein the allowable amount of time values include a set of time units and percentages of time units for which deviation is expected and wherein the exception list also specifies a list of programs associated with the monitored parameter values; triggering diagnostic data gathering on the parameters of the operating system in response to the deviance exceeding a predetermined threshold; notifying interested parties of the gathered diagnostic data; and wherein, in response to the deviance returning within a predetermined threshold within a specified amount of time specified in the exception list, the diagnostic data is logged and deleted after a predetermined period of time.
Dumping, i.e. gathering error/state information after a fault for later diagnosis · CPC title
where the computing system component is a software system · CPC title
for systems · CPC title
for test execution, e.g. scheduling of test suites · CPC title
the processing taking place on a specific hardware platform or in a specific software environment · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.