TEMPORAL GRAPH-BASED ANOMALY ANALYSIS AND CONTROL IN CYBER PHYSICAL SYSTEMS

    公开(公告)号:US20240354215A1

    公开(公告)日:2024-10-24

    申请号:US18594582

    申请日:2024-03-04

    IPC分类号: G06F11/34 G06F11/32

    CPC分类号: G06F11/3452 G06F11/327

    摘要: Systems and methods are provided for incident analysis in Cyber-Physical Systems (CPS) using a Temporal Graph-based Incident Analysis System (TGIAS) and/or Transition Based Categorical Anomaly Detection (TCAD). Dynamically gathered multimodal data from a distributed network of sensors across the CPS are preprocessed to identify abnormal sensor readings indicative of potential incidents, and a multi-layered incident timeline graph, representing abnormal sensor readings, relationships to specific CPS components, and temporal sequencing of events is constructed. Severity scores are calculated, and severity rankings are assigned to identified anomalies based on a composite index including impact on CPS operation, comparison with historical incident data, and predictive risk assessments. Probable root causes of incidents and pathways for anomaly propagation through the CPS are identified using causal interference and the incident timeline graph to detect underlying vulnerabilities and predict future system weaknesses. Recommended actions are generated and executed for incident resolution and system optimization.

    RENDERING A STACK TRACE VISUALIZATION DISPLAY

    公开(公告)号:US20240303173A1

    公开(公告)日:2024-09-12

    申请号:US18180970

    申请日:2023-03-09

    申请人: Salesforce, Inc.

    IPC分类号: G06F11/32 G06F11/30 G06F11/36

    摘要: A method and system for rendering a stack trace visualization display has been developed. A first stack trace associated with execution of an application during a time period is received from a central processing unit profiler. A first stack trace visualization display is rendered including a plurality of stack frames stacked in accordance with an order of ancestry based on the first stack trace. Rendering at least one stack frame involves rendering at a first location of the first stack trace visualization display, a stack frame rectangle for the at least one stack frame in accordance with the order of ancestry and rendering at a second location of the first stack trace visualization display, stack frame specific text for the at least one stack frame. The second location overlays the first location. Rendering of the stack frame rectangle is independent of the rendering of the stack frame specific text.

    Meta-data driven classifications of backup copies

    公开(公告)号:US12086034B2

    公开(公告)日:2024-09-10

    申请号:US17957332

    申请日:2022-09-30

    IPC分类号: G06F11/14 G06F11/32

    摘要: In general, one or more embodiments of the invention relates to systems and methods for performing a backup and later determining a level or percentage of corruption of the resulting backup set. By having a cyber-security module analyze the backup data periodically, corruption of backup data both caused by cyber-attacks or by hardware failures may be detected and characterized. By knowing how corrupted a particular corrupted backup data set is, an informed decision may be made with regards to purging the backup data set and/or using the backup data set or portion thereof in any further restorations. By making these determinations, a quick identification of possible ransomware attacks may be made, and additional degradation of a user's data may be avoided.

    APPARATUS AND METHOD FOR DETERMINING THE PERFORMANCE IMPACT OF CHANGES IN A COMPUTING SYSTEM

    公开(公告)号:US20240281355A1

    公开(公告)日:2024-08-22

    申请号:US18515991

    申请日:2023-11-21

    IPC分类号: G06F11/34 G06F11/30 G06F11/32

    摘要: A method for generating an output for performance impact assessment of a change includes determining changes associated with a first managed computer system where corresponding change records includes a respective change time-stamp, determining performance values for a performance metric for predetermined times and associating respective performance time-stamps, selecting one of the changes wherein the selected change has a change time-stamp, identifying first performance values with performance time-stamps that are prior in time to change time-stamp and associating them with a before-change category, identifying second performance values with performance time-stamps that are later in time relative to the change time-stamp and associating them with an after-change category, and generating an output with the first and second performance values (in a tabular or common timeline format) with the first performance values being distinguishable from the second performance values to thereby allow the user to determine before/after performance impact of the selected change.