×

System and method for clustering host inventories

  • US 8,843,496 B2
  • Filed: 09/03/2013
  • Issued: 09/23/2014
  • Est. Priority Date: 09/12/2010
  • Status: Expired due to Fees
First Claim
Patent Images

1. One or more non-transitory media including code for execution that, when executed by a processor, is operable to:

  • obtain a plurality of host file inventories corresponding respectively to a plurality of hosts in a network environment, wherein each of the plurality of host file inventories includes one or more file identifiers, each of the file identifiers of a particular host file inventory representing a different executable file on one of the plurality of hosts corresponding to the particular host file inventory;

    calculate input data by transforming the plurality of host file inventories into a similarity matrix for the plurality of hosts, wherein for at least each unique pair of host file inventories of the plurality of host file inventories, the transforming includes;

    determining a normalized compression distance (NCD) between the unique pair of host file inventories;

    determining a numerical value representing a similarity distance between the unique pair of host file inventories, the numerical value being determined based on the NCD; and

    updating the similarity matrix to include the numerical value representing the similarity distance between the unique pair of host file inventories; and

    provide the input data to a clustering procedure to group the plurality of hosts into one or more clusters of hosts, wherein the one or more clusters of hosts are grouped using a predetermined similarity criteria.

View all claims
  • 9 Assignments
Timeline View
Assignment View
    ×
    ×