G06F11/3065

Storage System with Blockchain Based Features

An illustrative method includes a monitoring system obtaining event data describing an event within a distributed compute and storage system, generating an event block for the event based on the event data, and attaching the event block to an event blockchain associated with the distributed compute and storage system, the event blockchain being immutable and indicating one or more events within the distributed compute and storage system in a chronological order of the one or more events. The event blockchain is used to provide one or more features of a storage system.

Inferring security incidents from observational data

Methods, systems, and apparatuses are provided for inferring security incidents from observational data. For example, alerts generated with respect to a set of entities by a first alert generator are received, association scores are calculated for pairs of alerts, the alerts are formed into clusters based on the association scores, and a security incident model is formed based on the clusters. The security incident model may define sequences of alerts corresponding to security incidents. Furthermore, the security incident model may be used to determine a match between additional alerts and a sequence of alerts in the security incident model and identify the additional alerts as a security incident corresponding to the sequence of alerts in the security incident model.

Time-based element management in a computer system using temporal node trees

A method, apparatus, system, and computer program product for managing time-based elements. A computer system identifies the time-based elements, wherein the time-based elements have time units. The computer system arranges the nodes, representing the time-based elements, in a temporal node tree, wherein the nodes have the time units from corresponding time-based elements and a policy that defines scaling of the nodes based on the time units allocated to the nodes.

OPERATION LOGS ACQUIRING DEVICE, OPERATION LOGS ACQUIRING METHOD, AND OPERATION LOGS ACQUIRING PROGRAM

An operation log acquisition device (10), upon detecting an occurrence of an event, acquires an occurrence time of the event, an occurrence position of the event, and a captured image of an operation screen. Next, the operation log acquisition device (10) determines whether or not a matching area that the determination image matches is included in the acquired captured image, acquires the event occurrence area of the image if the captured image includes the matching area, acquires an operation image that is a captured image of the acquisition image area if the occurrence position of the event is included in the event occurrence area, and records operation type specifying information that corresponds to the determination image, the occurrence time of the event, and the operation image, in the storage unit (14) in association with each other as an operation log.

ANNOTATING A LOG BASED ON LOG DOCUMENTATION
20230093225 · 2023-03-23 ·

Embodiments of the invention are directed to annotating a log based on processing log documentation. Aspects include obtaining the log having a plurality of entries. Aspects also include creating a set of log entry templates by processing the log documentation associated with the log, wherein each log entry template includes one or more constants and one or more variables. Aspects further include annotating each of the plurality of entries based on the set of templates, wherein the annotating includes labeling each value of the one or more variables with a variable name.

Visualization of outliers in a highly-skewed distribution of telemetry data
11609704 · 2023-03-21 · ·

Systems and methods for enhancing the representation of outliers in a distribution of telemetry data of a monitored system are provided. According to one embodiment, telemetry data of the monitored system may be continuously collected. Frequency values representing a frequency of occurrence of corresponding telemetry data of the collected telemetry data may be generated by aggregating the collected telemetry data. As the vast majority of telemetry data is expected to represent a normal operating state of the system and relatively few, if any, of the telemetry data (e.g., outliers) will be indicative of one or more events of significance, the resulting distribution of the frequency values is highly skewed. In order to facilitate visualization of the distribution that accentuates the outliers, display characteristics may be calculated for the frequency values by applying a visualization model based on a weighted combination of multiple data transformations to each of the frequency values.

MEMORY DEVICE HEALTH EVALUATION AT A HOST DEVICE

Methods, systems, and devices for memory device health evaluation at a host device are described. The health evaluation relates to a host device that is associated with a memory device that monitors and reports health information, such as one or more parameters associated with a status of the memory device. The memory device may transmit the health information to the host device, which may perform one or more operations and may transmit the health information to a device of another entity of a system (e.g., ecosystem) including the host device. The host device may include one or more circuits for transmitting and processing the health information, such as a system health engine, a safety engine, a communication component, or a combination thereof. Based on a determination by the host device or information received from an external device, the host device may transmit a command to the memory device.

Medical device arrangement with a test module

A medical device arrangement (100) tests processing of data sets to be processed during operation of the medical device arrangement. The arrangement includes a data interface (110), analysis modules (120) and a test module (130). The analysis modules process a received medical data set (105). Each analysis module (122, 123, 124) forms a processing instance (390) for the medical data set or for the medical data set (125, 125′) already preprocessed by at least one other analysis module. The test module outputs a test data set (132) to one of the analysis modules during operation such that this analysis module processes the test data set in the same manner as the medical data set. The test module compares a correspondingly outputted, processed test data set (134) with a reference result (136) associated with the test data set and determines a test result (137) based on this comparison.

POWER MANAGEMENT FOR VIRTUALIZED COMPUTER SYSTEMS
20230131953 · 2023-04-27 ·

Aspects of the disclosure provide for mechanisms for memory protection of virtual machines in a computer system. A method of the disclosure includes: determining a plurality of host latency times for a plurality of processor power states of a processor of a host computer system; comparing, by a hypervisor executed on the host computer system, each of the host latency times to a target latency time associated with a virtual machine running on the host computer system; mapping the plurality of processor power states to a plurality of host power states in view of the comparison; and providing the host power states to the virtual machine.

Logging mechanism for memory system
11599403 · 2023-03-07 · ·

Techniques to more readily identify issues that arise in connection with memory systems and streamline the analysis process. A detailed activity log is generate with corresponding start and stop traffic events to facilitate identification of problems in memory devices. Each event registered in the log includes numerous items of information. The information facilitates identifying the origin of a particular problem including when and where it occurred, thus making failure analysis (FA) both easier and faster.