×

Personalization of alerts based on network monitoring

  • US 10,728,126 B2
  • Filed: 07/30/2018
  • Issued: 07/28/2020
  • Est. Priority Date: 02/08/2018
  • Status: Active Grant
First Claim
Patent Images

1. A method for monitoring network traffic using one or more network computers, wherein execution of instructions by the one or more network computers perform the method comprising:

  • instantiating a monitoring engine to perform actions, including;

    providing a device relation model based on one or more metrics and one or more types of communication protocols used in monitored network traffic associated with a plurality of entities in one or more networks; and

    instantiating an inference engine to perform actions including;

    associating each entity with an interest score based on the device relation model, wherein the one or more metrics and the one or more types of communication protocols are employed to weight one or more relationships between two or more entities, and wherein one or more portions of the one or more relationships having a weight that is a priority are included as one or more edges in the device relation model, and wherein one or more other portions of the relationships having a weight that is a non-priority are non-included as edges in the device relation model; and

    including one or more phantom edges in the device relation model based on one or more relationships between two or more other entities that indirectly communicate with each other; and

    instantiating an alert engine to perform actions, including;

    providing one or more alerts to the user from one or more alerts based on one or more ranked interest scores associated with the one or more entities based on the device relation model; and

    assigning one or more decay functions to the interest score associated with each entity, wherein the one or more decay functions are employed to decrease the interest score associated with an entity over time based on one or more of a lack of the user'"'"'s interaction with the entity or a lack of the user'"'"'s actions in response to one or more alerts regarding the entity, and wherein the one or more decay functions cause an increase or a decrease in an amount of the alerts associated with the entity that are provided to the user.

View all claims
  • 6 Assignments
Timeline View
Assignment View
    ×
    ×