System, method and apparatus for enterprise policy management
    1.
    发明授权
    System, method and apparatus for enterprise policy management 失效
    企业政策管理制度,方法和手段

    公开(公告)号:US08417678B2

    公开(公告)日:2013-04-09

    申请号:US12572160

    申请日:2009-10-01

    IPC分类号: G06F7/00

    CPC分类号: G06F17/30221 G06F17/30082

    摘要: Disclosed are systems, methods and apparatuses for managing objects (files and directories) in network file systems according to policies. Each policy may have one or more rules, each of which ties a condition to an action. Each condition can be expressed in terms of metadata harvested across file systems and stored in a metadata repository. The actions are user-programmable. Users can apply and/or enforce a policy by manipulating the metadata stored in the metadata repository. For example, suppose a policy prohibits storing MP3 files in corporate storage, a user can specify a rule that ties the condition “no MP3 files in volumes A-Z” to an action “delete MP3 files from volumes A-Z.” A file management application may apply a filter to the metadata repository to produce metadata records having values that meet the specified condition and take the corresponding action on managed objects associated with those metadata records.

    摘要翻译: 公开了根据策略管理网络文件系统中的对象(文件和目录)的系统,方法和装置。 每个策略可能具有一个或多个规则,每个规则将条件与操作相关联。 每个条件都可以通过文件系统收集的元数据来表示,并存储在元数据存储库中。 这些操作是用户可编程的。 用户可以通过操纵元数据存储库中存储的元数据来应用和/或实施策略。 例如,假设政策禁止在公司存储中存储MP3文件,用户可以指定将卷A-Z中的MP3文件与卷A-Z中的动作删除MP3文件的条件相关联的规则。 文件管理应用程序可以将过滤器应用于元数据存储库以产生具有满足指定条件的值的元数据记录,并对与这些元数据记录相关联的被管理对象采取相应的操作。

    System, method and apparatus for enterprise policy management
    2.
    发明授权
    System, method and apparatus for enterprise policy management 有权
    企业政策管理制度,方法和手段

    公开(公告)号:US07805449B1

    公开(公告)日:2010-09-28

    申请号:US11262282

    申请日:2005-10-28

    IPC分类号: G06F7/00 G06F17/30

    CPC分类号: G06F17/30091

    摘要: Disclosed are systems, methods and apparatuses for managing objects in an enterprise environment according to policies. According to the invention, each policy rule ties a condition that conceptually lives in a repository to an appropriate action(s). Since each condition can be expressed in terms of metadata, policies can be applied and enforced over managed objects (files and directories) by allowing users to program appropriate corresponding action(s) via manipulating metadata stored in a metadata repository, e.g., a policy could prohibit storing MP3 files in corporate storage. In one embodiment, a user can specify a policy rule that ties the condition “no MP3 files in volumes A-Z” to an action “delete MP3 files from volumes A-Z” via a Web-based user interface. A harvester is disclosed for harvesting metadata across file systems.

    摘要翻译: 公开了根据策略在企业环境中管理对象的系统,方法和装置。 根据本发明,每个策略规则将概念上存在于存储库中的条件与适当的动作联系起来。 由于每个条件都可以用元数据表示,所以可以通过允许用户通过操纵元数据存储库中存储的元数据来编程适当的相应动作,从而可以对被管理对象(文件和目录)应用和实施策略,例如策略 禁止在公司存储中存储MP3文件。 在一个实施例中,用户可以指定将条目“卷A-Z中的MP3文件”与通过基于Web的用户界面从卷A-Z中删除MP3文件的动作相关联的策略规则。 披露收割机用于在文件系统上采集元数据。

    System and method for a desktop agent for use in managing file systems
    3.
    发明授权
    System and method for a desktop agent for use in managing file systems 失效
    用于管理文件系统的桌面代理的系统和方法

    公开(公告)号:US08510331B1

    公开(公告)日:2013-08-13

    申请号:US12840804

    申请日:2010-07-21

    IPC分类号: G06F7/00 G06F17/30

    CPC分类号: G06F17/30091 G06F17/30082

    摘要: Embodiments of desktop agents for use in file management are disclosed. Specifically, in certain embodiments a set of desktop computers within a particular networked environment where it is desired to install these desktop agents may be determined. Desktop agents may then be installed on these desktops. A desktop agent on a particular desktop computer may register with an appliance such as that described above and be given an objective including one or more tasks. For each of the tasks provided, the desktop agent may return a list of files which can be collected based on the classification(s) associated with that task. Specific files to collect may then be selected from the list of files such that these specific files may be sent from the desktop computer to the appliance by the desktop agent and stored.

    摘要翻译: 公开了用于文件管理的桌面代理的实施例。 具体地,在某些实施例中,可以确定在期望安装这些桌面代理的特定联网环境中的一组台式计算机。 然后可以在这些桌面上安装桌面代理。 特定台式计算机上的桌面代理可以向诸如上述的设备注册,并给出包括一个或多个任务的目标。 对于提供的每个任务,桌面代理可以根据与该任务相关联的分类返回可以收集的文件列表。 然后可以从文件列表中选择要收集的特定文件,使得这些特定文件可以由桌面计算机从桌面计算机发送到设备并存储。

    System and method for access controls
    4.
    发明授权
    System and method for access controls 失效
    用于访问控制的系统和方法

    公开(公告)号:US08463815B1

    公开(公告)日:2013-06-11

    申请号:US12269222

    申请日:2008-11-12

    申请人: Keith Zoellner

    发明人: Keith Zoellner

    IPC分类号: G06F17/30

    摘要: Systems and methods for controlling access to objects within a file system utilizing data associated with those objects are disclosed. More specifically, in one embodiment access controls pertaining to a user may be specified in terms of tags which may be associated with an object, and a user's access to objects may be controlled based upon these tags. These tags may reflect the content of the object, or a grouping, category or another type of classification of the object and may be determined through the processing of the object. In particular, in one embodiment, metadata associated with an object may be classified and associated with classification tags associated with those classifications. A user's access to objects may then be specified through a set of classification tags, where the user may access objects associated with those classification tags.

    摘要翻译: 公开了利用与这些对象相关联的数据来控制对文件系统内的对象的访问的系统和方法。 更具体地,在一个实施例中,可以根据可能与对象相关联的标签来指定与用户相关的访问控制,并且可以基于这些标签来控制用户对对象的访问。 这些标签可以反映对象的内容,或对象的分组,类别或其他类型的分类,并且可以通过对象的处理来确定。 特别地,在一个实施例中,与对象相关联的元数据可以被分类并与与这些分类相关联的分类标签相关联。 然后可以通过一组分类标签来指定用户对对象的访问,其中用户可以访问与这些分类标签相关联的对象。

    METHOD AND APPARATUS FOR HARVESTING FILE SYSTEM METADATA
    5.
    发明申请
    METHOD AND APPARATUS FOR HARVESTING FILE SYSTEM METADATA 失效
    用于收集文件系统元数据的方法和装置

    公开(公告)号:US20100088317A1

    公开(公告)日:2010-04-08

    申请号:US12572116

    申请日:2009-10-01

    IPC分类号: G06F17/30

    CPC分类号: G06F17/30094 G06F17/30144

    摘要: A harvester is disclosed for harvesting metadata of managed objects (files and directories) across file systems which are generally not interoperable in an enterprise environment. Harvested metadata may include 1) file system attributes such as size, owner, recency; 2) content-specific attributes such as the presence or absence of various keywords (or combinations of keywords) within documents as well as concepts comprised of natural language entities; 3) synthetic attributes such as mathematical checksums or hashes of file contents; and 4) high-level semantic attributes that serve to classify and categorize files and documents. The classification itself can trigger an action in compliance with a policy rule. Harvested metadata are stored in a metadata repository to facilitate the automated or semi-automated application of policies.

    摘要翻译: 披露收割机用于在企业环境中通常不能互操作的文件系统上收集托管对象(文件和目录)的元数据。 收获的元数据可能包括1)文件系统属性,如大小,所有者,新近度; 2)内容特定的属性,例如文档中各种关键字(或关键字的组合)的存在或不存在以及由自然语言实体组成的概念; 3)合成属性,如数学校验和或文件内容的散列; 和4)用于对文件和文档进行分类和分类的高级语义属性。 分类本身可以触发符合策略规则的操作。 收获的元数据存储在元数据存储库中,以便于自动或半自动应用策略。

    SYSTEM AND METHOD FOR CLASSIFYING OBJECTS
    6.
    发明申请
    SYSTEM AND METHOD FOR CLASSIFYING OBJECTS 有权
    用于分类对象的系统和方法

    公开(公告)号:US20100042625A1

    公开(公告)日:2010-02-18

    申请号:US12603367

    申请日:2009-10-21

    IPC分类号: G06F17/30

    摘要: Embodiments of a classification pipeline disclosed herein have the ability to both collect data as it occurs and dynamically redact it, allowing ongoing statistics to be gathered and maintained while simultaneously constraining the total amount of storage capacity that must be dedicated to such a purpose. Various types of information can be extracted from or obtained on the object through the classification pipeline. In one embodiment, the classification pipeline comprises a plurality of layers implemented as a set of services available to network clients through a Web interface or an Applications Programming Interface (API). Each client can subscribe to one or more layers of the classification pipeline at their leisure and tailor their classification pipeline configuration through the interface. The classification pipeline can be configured to collaborate with other software to provide a consistent snapshot of the state of a network environment based on data collected at the time.

    摘要翻译: 本文公开的分类流程的实施例具有在数据发生时收集数据的能力,并且动态地对其进行修改,从而允许收集和维护正在进行的统计信息,同时限制必须专用于此目的的总存储容量。 可以通过分类管道从物体中提取或获取各种类型的信息。 在一个实施例中,分类流水线包括通过Web接口或应用编程接口(API)来实现为可用于网络客户端的一组服务的多个层。 每个客户端可以随意订阅分层管道的一层或多层,并通过接口定制其分类流水线配置。 分类流水线可以配置为与其他软件协作,以便根据当时收集的数据提供网络环境状态的一致性快照。

    Classifying objects
    7.
    发明授权
    Classifying objects 有权
    分类对象

    公开(公告)号:US09122750B2

    公开(公告)日:2015-09-01

    申请号:US12603367

    申请日:2009-10-21

    IPC分类号: G06F17/30

    摘要: Embodiments of a classification pipeline disclosed herein have the ability to both collect data as it occurs and dynamically redact it, allowing ongoing statistics to be gathered and maintained while simultaneously constraining the total amount of storage capacity that must be dedicated to such a purpose. Various types of information can be extracted from or obtained on the object through the classification pipeline. In one embodiment, the classification pipeline comprises a plurality of layers implemented as a set of services available to network clients through a Web interface or an Applications Programming Interface (API). Each client can subscribe to one or more layers of the classification pipeline at their leisure and tailor their classification pipeline configuration through the interface. The classification pipeline can be configured to collaborate with other software to provide a consistent snapshot of the state of a network environment based on data collected at the time.

    摘要翻译: 本文公开的分类流程的实施例具有在数据发生时收集数据的能力,并且动态地对其进行修改,从而允许收集和维护正在进行的统计信息,同时限制必须专用于此目的的总存储容量。 可以通过分类管道从物体中提取或获取各种类型的信息。 在一个实施例中,分类流水线包括通过Web接口或应用编程接口(API)来实现为可用于网络客户端的一组服务的多个层。 每个客户端可以随意订阅分层管道的一层或多层,并通过接口定制其分类流水线配置。 分类流水线可以配置为与其他软件协作,以便根据当时收集的数据提供网络环境状态的一致性快照。

    Harvesting file system metsdata
    8.
    发明授权
    Harvesting file system metsdata 失效
    收获文件系统metsdata

    公开(公告)号:US08612404B2

    公开(公告)日:2013-12-17

    申请号:US12572116

    申请日:2009-10-01

    IPC分类号: G06F17/30

    CPC分类号: G06F17/30094 G06F17/30144

    摘要: A harvester is disclosed for harvesting metadata of managed objects (files and directories) across file systems which are generally not interoperable in an enterprise environment. Harvested metadata may include 1) file system attributes such as size, owner, recency; 2) content-specific attributes such as the presence or absence of various keywords (or combinations of keywords) within documents as well as concepts comprised of natural language entities; 3) synthetic attributes such as mathematical checksums or hashes of file contents; and 4) high-level semantic attributes that serve to classify and categorize files and documents. The classification itself can trigger an action in compliance with a policy rule. Harvested metadata are stored in a metadata repository to facilitate the automated or semi-automated application of policies.

    摘要翻译: 披露收割机用于在企业环境中通常不能互操作的文件系统上收集托管对象(文件和目录)的元数据。 收获的元数据可能包括1)文件系统属性,如大小,所有者,新近度; 2)内容特定的属性,例如文档中各种关键字(或关键字的组合)的存在或不存在以及由自然语言实体组成的概念; 3)合成属性,如数学校验和或文件内容的散列; 和4)用于对文件和文档进行分类和分类的高级语义属性。 分类本身可以触发符合策略规则的操作。 收获的元数据存储在元数据存储库中,以便于自动或半自动应用策略。

    Browser-based system and method for defining and manipulating expressions
    9.
    发明授权
    Browser-based system and method for defining and manipulating expressions 有权
    基于浏览器的系统和方法,用于定义和操作表达式

    公开(公告)号:US07865873B1

    公开(公告)日:2011-01-04

    申请号:US11645205

    申请日:2006-12-22

    IPC分类号: G06F9/44 G06F3/00

    摘要: Embodiments of the invention provide methods and systems for defining classes of objects which entails defining and manipulating expressions. A two-tiered classification editor operates to enable a user to define and manipulate expression in real time through a browser-based user interface. The first tier comprises a group editor for enabling a user to define groups. The second tier comprises an expression editor for enabling a user to define and manipulate an expression comprising a set of groups and one or more relationships between the groups. Each group may comprise a set of conditions, each of which may be based on a possible attribute of an object. Via the expression editor, a user can drag and drop to create and modify these expressions on-the-fly. When a user is done manipulating an expression on the second tier, the user is returned to the first tier, which may present the expression as modified.

    摘要翻译: 本发明的实施例提供用于定义需要定义和操纵表达的对象类的方法和系统。 一个双层分类编辑器用于使用户能够通过基于浏览器的用户界面实时定义和操作表达式。 第一层包括用于使用户定义组的组编辑器。 第二层包括表达式编辑器,用于使用户能够定义和操纵包括一组组和表达组之间的一个或多个关系的表达式。 每个组可以包括一组条件,每个条件可以基于对象的可能属性。 通过表达式编辑器,用户可以拖放来即时创建和修改这些表达式。 当用户完成操作第二层上的表达式时,用户返回到第一层,这可以将表达式呈现为修改。

    SYSTEM, METHOD AND APPARATUS FOR ENTERPRISE POLICY MANAGEMENT
    10.
    发明申请
    SYSTEM, METHOD AND APPARATUS FOR ENTERPRISE POLICY MANAGEMENT 失效
    企业政策管理系统,方法与设备

    公开(公告)号:US20100145917A1

    公开(公告)日:2010-06-10

    申请号:US12572160

    申请日:2009-10-01

    IPC分类号: G06F17/30 G06F15/16 G06F17/00

    CPC分类号: G06F17/30221 G06F17/30082

    摘要: Disclosed are systems, methods and apparatuses for managing objects (files and directories) in network file systems according to policies. Each policy may have one or more rules, each of which ties a condition to an action. Each condition can be expressed in terms of metadata harvested across file systems and stored in a metadata repository. The actions are user-programmable. Users can apply and/or enforce a policy by manipulating the metadata stored in the metadata repository. For example, suppose a policy prohibits storing MP3 files in corporate storage, a user can specify a rule that ties the condition “no MP3 files in volumes A-Z” to an action “delete MP3 files from volumes A-Z.” A file management application may apply a filter to the metadata repository to produce metadata records having values that meet the specified condition and take the corresponding action on managed objects associated with those metadata records.

    摘要翻译: 公开了根据策略管理网络文件系统中的对象(文件和目录)的系统,方法和装置。 每个策略可能具有一个或多个规则,每个规则将条件与操作相关联。 每个条件都可以通过文件系统收集的元数据来表示,并存储在元数据存储库中。 这些操作是用户可编程的。 用户可以通过操纵元数据存储库中存储的元数据来应用和/或实施策略。 例如,假设政策禁止在公司存储中存储MP3文件,则用户可以指定将条目“没有MP3文件在AZ中”与“AZ”中的MP3文件相关联的规则。文件管理应用程序可以应用 到元数据存储库的过滤器,以产生具有符合指定条件的值的元数据记录,并对与这些元数据记录相关联的被管理对象采取相应的操作。