Method for monitoring abnormal behavior in a computer system
First Claim
Patent Images
1. A computer monitoring system comprising:
- a manager computer; and
a plurality of agent computers coupled to the manager computer over a network,wherein said manager computer, in response to an abnormal state occurring on one of said plurality of agents computers;
presumes a first cause of said abnormal state;
requests said plurality of agent computers to collect logs to prove said presumed first cause;
receives said collected log from each of said plurality of agent computers;
compares said collected logs with each other;
presumes a second cause which caused the first cause; and
requests said plurality of agent computers to collect logs to prove said presumed second cause; and
wherein each of said plurality of agent computers;
collects a log to prove said presumed first cause in response to a request from said manager computer;
sends said collected log to said manager computer, andcollects a log to prove said presumed second cause in response to a request from said manager computer.
0 Assignments
0 Petitions
Accused Products
Abstract
The present invention relates to a method for monitoring a computer system in which one manager computer is connected to a plurality of agent computers over a network. The manager computer sends information on the types of log to be collected to the plurality of agent computers. In response, the plurality of agent computers collect the specified types of log. Then, the plurality of agent computers send the collected logs to the manager computer. Thus, the plurality of agent computers are able to collect the types of log specified by the manager computer.
31 Citations
19 Claims
-
1. A computer monitoring system comprising:
-
a manager computer; and a plurality of agent computers coupled to the manager computer over a network, wherein said manager computer, in response to an abnormal state occurring on one of said plurality of agents computers; presumes a first cause of said abnormal state; requests said plurality of agent computers to collect logs to prove said presumed first cause; receives said collected log from each of said plurality of agent computers; compares said collected logs with each other; presumes a second cause which caused the first cause; and requests said plurality of agent computers to collect logs to prove said presumed second cause; and wherein each of said plurality of agent computers; collects a log to prove said presumed first cause in response to a request from said manager computer; sends said collected log to said manager computer, and collects a log to prove said presumed second cause in response to a request from said manager computer. - View Dependent Claims (2)
-
-
3. A computer monitoring system comprising:
-
a manager computer; and (n+1) agent computers coupled to said manager computer over a network, wherein said manager computer; divides a collected log into n pieces of log information; generates appendage information which recovers said log based on pieces of log information less than n; distributes said n pieces of information and said appendage information to said (n+1) agent computers, respectively; and
wherein each of said (n+1) agent computers encrypts and memorizes respective one of said distributed log information and said appendage information.
-
-
4. A computer monitoring system comprising:
-
a manager computer; and a plurality of computers coupled to said manager computer over a network, wherein said manager computer monitors logs collected from said plurality of computers to be managed and detects suspicious behavior by comparing said logs or checking inconsistency of said logs, wherein said manager computer; displays icons of said computers to be managed on the monitor screen of said manager computer; and changes an alarm sound or a color on said monitor screen according to a degree of suspicion for said computers to be managed performing suspicious behavior or a range of a display section showing possibility of existence of said computers to be managed performing suspicious behavior. - View Dependent Claims (5, 6, 7, 8, 9)
-
-
10. An apparatus for monitoring a computer system in which a manager computer and a plurality of agent computers are connected over a network, comprising:
-
a software portion configured, in response to an abnormal state occurring on one of said plurality of agent computers, to presume on said manager computer a first cause of said abnormal state; a software portion configured to send a request from said manager computer to said plurality of agent computers, said request requesting to collect logs to prove said presumed first cause; a software portion configured to collect a log to prove said presumed first cause on each of said plurality of agent computers; a software portion configured to send said collected log from each of said plurality of agent computers to said manager computer; a software portion configured to compare on said manager computer said collected logs with each other to presume, as a result of comparison thereof, a second cause which caused the first cause; and a software portion configured to send a request from said manager computer to said plurality of agent computers, said request requesting to collect logs to prove said presumed second cause. - View Dependent Claims (11)
-
-
12. An apparatus for monitoring a computer system in which a manager computer and (n+1) agent computers are connected over a network, comprising:
-
a software portion configured to divide a log collected on said manager computer into n pieces of log information; on said manager computer, a software portion configured to generate appendage information that recovers said log based on pieces of log information less than n; a software portion configured to distribute said n pieces of information and said appendage information to said (n+1) agent computers, respectively; and on each of said (n+1) agent computers, a software portion configured to encrypt and to memorize respective one of said distributed log information and said appendage information.
-
-
13. An apparatus for monitoring a computer system in which a plurality of computers to be managed and a manager computer are connected to a network, comprising:
-
a software portion configured to monitor, by said manager, logs collected from said plurality of computers to be managed; and a software portion configured to detect, by said manager computer, suspicious behavior by comparing said logs or checking inconsistency of said logs, wherein said manager computer comprises; a software portion configured to display icons of said computers to be managed on a monitor screen; and a software portion configured to chance an alarm sound or a color on said monitor screen according to a degree of suspicion for a computer performing suspicious behavior or a range of a display section showing possibility of existence of a computer performing suspicious behavior. - View Dependent Claims (14, 15, 16, 17, 18, 19)
-
Specification