Patent classifications
G06F11/3072
SYSTEM AND METHOD TO REPLAY SUSPICIOUS ACTIVITY DETECTION PIPELINE IN RISK NETWORKS
A computer-implemented system, platform, computer program product, tool, and/or method for re-running alert reports that includes: identifying an alert report to be rerun; collecting information on the alert report; gathering information on the configuration of a data analytics pipeline that generated the alert report; gathering data used to generate the alert report; recreating a regenerated data analytics pipeline based upon the information gathered on the configuration of the data analytics pipeline that generated the alert report; running the regenerated data analytics pipeline using the gathered data to create a rerun alert report; and optionally comparing the rerun to the original run including optionally generating a visual display of the results including in an aspect creating a side-by-side comparison of the tasks.
ANALYSIS INFORMATION MANAGEMENT METHOD AND ANALYSIS INFORMATION MANAGEMENT SYSTEM
One mode of the analysis information management method according to the present invention is a method for managing information related to an analysis by an analyzing device, using a computer or computers, including the steps of: collecting, as comprehensive log information, work-log information related to a use of the analyzing device; calculating the number of executions of each of types of work including a manual analysis operation and a batch analysis operation, using at least a portion of the comprehensive log information collected in the step of collecting; presenting, to a user, information of the number of executions of each type of work obtained in the step of calculating; receiving, from the user, an input of one or more types of work selected from the types of work; and presenting, to the user, the work-log information concerning the one or more types of work received from the user.
Systems and method for flexible access of a regulated system
A method to provide flexible access to an internal data of an regulated system, the method comprising receiving, by a data access component of the regulated system, a loadable configuration file defining a set of triggering events and a set of memory, determining the occurrence of a single triggering event, accessing at least a subset of memory that contain the internal data of the avionics system to retrieve data associated with the one or more memory of the set of memory, and outputting the retrieved data to a receiving component.
System for Performing an Autonomous Widget Operation
A system, method, and computer-readable medium are disclosed for performing a data center monitoring and management operation. The data center monitoring and management operation includes: monitoring data center assets within a data center; identifying an issue within the data center, the issue being associated with an operational situation associated with a particular component of the data center; determining whether data associated with the issue corresponds to predefined conditional criteria; and, triggering an autonomous widget operation in response to a determination of the data associated with the issue corresponding to the predefined conditional criteria, the autonomous widget operation executing a particular autonomous widget.
System and method for partition-scoped snapshot creation in a distributed data computing environment
A system and method for partitioned snapshot creation of caches in a distributed data grid is provided. The system and method enables a snapshot to be created in a running system without quiescing a cache service. Moreover for each particular partition, execution of read/write requests are not blocked during the period that a snapshot creation task is being performed for the particular partition. The cache service thread continues to execute read requests for all partitions with write requests for the partition under snapshot experiencing delayed response. The system and method reduces the period of time for which partitions are unavailable during a snapshot process and increases the availability of cache services provided by a distributed data grid compared to prior snapshot systems.
DIAGNOSTIC DATA COLLECTION FOR KUBERNETES
Techniques are disclosed for capturing diagnostics data in a distributed computing environment comprising a plurality of computing devices executing a plurality of Kubernetes pods. A worker node is configured with a staging area for storing temporary diagnostics data. An agent is configured to upload the temporary diagnostics data. Each container in the worker node is assigned a directory in the staging area for writing the container's temporary diagnostics data. When a container in the worker node has written a temporary diagnostics data file to the container's directory in the staging area, the temporary diagnostics data file is uploaded to the persistent storage.
Method and system for clustering darknet traffic streams with word embeddings
A system for analyzing and clustering darknet traffic streams with word embeddings, comprising a data processing module which collects packets that are sent to non-existing IP addresses that belong to darknet's taps (blackholes) that are deployed over the internet: a port embedding module for performing port sequence embeddings by using a word embedding algorithm on the port sequences extracted from the data processing module while transforming the port sequences into a meaningful numerical feature vectors: a clustering module for performing temporal clustering of the feature vectors over time; and an alert logic and visualization module visualizes the data and provides alerts regarding a cluster that an analyst classified as malicious in the past.
Elastic buffer in a memory sub-system for debugging information
A processing device in a memory system determines to send system state information associated with the memory device to a host system and identifies a subset of a plurality of event entries from a staging buffer based on one or more filtering factors, the plurality of event entries corresponding to events associated with the memory device. The processing device further sends the subset of the plurality of event entries as the system state information to the host system over a communication pipe having limited bandwidth.
EVENT VISUALIZATION FOR ASSET CONDITION MONITORING
Systems and methods for asset management are provided. Event data characterizing events experienced by assets distributed among different sites of a fleet is maintained. The event data includes an asset location within an asset hierarchy of the fleet and an event parameter corresponding to the event. A graphical user interface (GUI) is generated that displays a first window including a hierarchical list of assets organized according to their position within the asset hierarchy. When the GUI receives a selection of a level within the hierarchical list, events associated with the selected level can be identified. Identified events can be classified based upon their event data as a unique event having a single occurrence or a repeat event having multiple occurrences. In response to receipt of the selection, the GUI is updated to display a second window listing single entries for respective unique events and single entries for respective repeat events.
MANAGEMENT ACTION PREDICTIONS
In some examples, a method includes monitoring device management actions. In some examples, the method includes predicting whether a proposed operation will trigger a device management action based on triggers and the device management actions. In some examples, the method may include generating a message in response to predicting that the proposed operation will trigger the device management action.