×

Distributed monitoring, evaluation, and response for multiple devices

  • US 9,753,796 B2
  • Filed: 12/06/2013
  • Issued: 09/05/2017
  • Est. Priority Date: 12/06/2013
  • Status: Active Grant
First Claim
Patent Images

1. A method comprising:

  • at a server, collecting observation data based on a first data collection policy from a plurality of devices, the collected observation data including information associated with device configuration, device state, and device behavior with regard to (1) an execution of an application on at least one of the plurality of devices and at least one of (2) a hardware or a firmware component on the at least one of the plurality of devices and (3) access to a network resource by the at least one of the plurality of devices;

    at the server, determining a normal pattern of activity occurring on the plurality of devices by processing the collected observation data, the normal pattern of activity being associated with at least one of the device configuration, the device state, and the device behavior of the plurality of devices;

    at the server, deriving a second data collection policy from the determined normal pattern of activity occurring on the plurality of devices, the second data collection policy being different than the first data collection policy;

    at the server, collecting first device data based on the derived second data collection policy from a first device of the plurality of devices;

    at the server comparing the normal pattern of activity occurring on the plurality of devices with a first pattern of activity occurring on the first device, the first pattern of activity being identified by the first device data;

    at the server determining that a deviation between the normal pattern of activity and the first pattern of activity associated with the first device is outside of a threshold deviation; and

    upon the determination, generating alert information by the server, wherein the alert information when processed causes performance of a first action on the first device.

View all claims
  • 7 Assignments
Timeline View
Assignment View
    ×
    ×