IL253377A

System and method for monitoring a computer system using machine interpretable code

Abstract

This record has no abstract on file.

IL253377A, drawing sheet 1
Sheet 1 of 8

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

26 claims: 21 independent, 5 dependent

  1. 1
    A computer implemented method of monitoring a collector computer system, the collector computer system comprising one or more processors and memory storing an interpreter and compiled instructions for execution by the one or more processors, said method comprising:receiving machine interpretable code that is configured for interpretation by the interpreter, wherein the machine interpretable code is not directly executable by the one or more processors and the machine interpretable code includes: information identifying a first set of one or more monitoring targets within the collector computer system, a method for monitoring the first set of one or more monitoring targets, and predefined reporting criteria;interpreting the machine interpretable code with the interpreter to obtain the first set of one or more monitoring targets, the method for monitoring the first set of one or more monitoring targets, and the predefined reporting criteria;monitoring, using the one or more processors, at least a subset of the first set of one or more monitoring targets for candidate activity that satisfies the predefined reporting criteria by executing compiled instructions that correspond to the method for monitoring the first set of one or more monitoring targets;obtaining candidate event information that is associated with the candidate activity;and reporting the candidate event information to a computer system that is distinct from the collector computer system.
  2. 4
    The method of any of claims 1-3, wherein the predefined reporting criteria include types of information for reporting, the types of information including one or more of:a timestamp, one or more file names associated with the candidate activity, one or more process names associated with the candidate activity, one or more network connection points, WO 2016/112219 PCT/US2016/012533 one or more registry paths, one or more mutex objects, one or more library names, and one or more thread numbers and/or process numbers.
  3. 5
    The method of any of claims 1-4, wherein the receiving, the interpreting, the monitoring, and the obtaining are performed while the collector computer system is in a first state, the method further including:while the collector computer system is in a second state that is distinct from the first state: receiving machine executable code that is configured for execution by the one or more processors and that is not configured for interpretation by the interpreter, wherein the machine executable code includes information identifying a second set of one or more monitoring targets, and second predefined reporting criteria;monitoring using the one or more processors, the second set of the one or more monitoring targets for additional candidate activity that satisfies the second predefined reporting criteria by executing the machine executable code;obtaining additional candidate event information that is associated with the additional candidate activity;and reporting the additional candidate event information to the computer system that is distinct from the collector computer system.
  4. 6
    The method of any of claims 1-5, wherein the compiled instructions are stored within the collector computer system prior to receiving the machine interpretable code.
  5. 7
    The method of any of claims 1-5, wherein the compiled instructions are received by the collector computer system in conjunction with receiving the machine interpretable code.
  6. 8
    The method of any of claims 1-7, further comprising:subsequent to reporting the obtained information: receiving instructions to terminate the candidate activity;and terminating the candidate activity.
  7. 9
    The method of any of claims 1-8, wherein the interpreter is located within the kernel and interpretation of the machine interpretable code is performed without rebooting the collector computer system subsequent to receiving the machine interpretable code.
  8. 10
    A collector computer system, comprising:WO 2016/112219 PCT/US2016/012533 one or more processors;and memory storing one or more programs that include an interpreter and compiled instructions, the one or more programs, when executed by the one or more processors, cause the collector computer system to: receive machine interpretable code that is configured for interpretation by the interpreter, wherein the machine interpretable code is not directly executable by the one or more processors and the machine interpretable code includes: information identifying a first set of one or more monitoring targets within the collector computer system, a method for monitoring the first set of one or more monitoring targets, and predefined reporting criteria;interpret the machine interpretable code with the interpreter to obtain the first set of one or more monitoring targets, the method for monitoring the first set of one or more monitoring targets, and the predefined reporting criteria;monitor, using the one or more processors, at least a subset of the first set of one or more monitoring targets for candidate activity that satisfies the predefined reporting criteria by executing compiled instructions that correspond to the method for monitoring the first set of one or more monitoring targets;obtain candidate event information that is associated with the candidate activity;and report the candidate event information to a computer system that is distinct from the collector computer system.
  9. 11
    A non-transitory computer readable storage medium, storing one or more programs that include an interpreter and compiled instructions for execution by one or more processors of a collector computer system, the one or more programs including instructions for:receiving machine interpretable code that is configured for interpretation by the interpreter, wherein the machine interpretable code is not directly executable by the one or more processors and the machine interpretable code includes: information identifying a first set of one or more monitoring targets within the collector computer system, a method for monitoring the first set of one or more monitoring targets, and predefined reporting criteria;interpreting the machine interpretable code with the interpreter to obtain the first set of one or more monitoring targets, the method for monitoring the first set of one or more monitoring targets, and the predefined reporting criteria;monitoring, using the one or more processors, at least a subset of the first set of one or more monitoring targets for candidate activity that satisfies the predefined reporting criteria WO 2016/112219 PCT/US2016/012533 by executing compiled instructions that correspond to the method for monitoring the first set of one or more monitoring targets;obtaining candidate event information that is associated with the candidate activity;and reporting the candidate event information to a computer system that is distinct from the collector computer system.
  10. 12
    A collector computer system, comprising:one or more processors;and memory storing one or more programs that include an interpreter and compiled instructions, the one or more programs, when executed by the one or more processors, causing the collector computer system to perform any method of claims 1-9.
  11. 13
    A non-transitory computer readable storage medium, storing one or more programs that include an interpreter and compiled instructions for execution by one or more processors of a collector computer system, the one or more programs including instructions for performing any method of claims 1-9.
  12. 14
    A computer implemented method of monitoring a collector computer system by one or more controller computer system, at least a controller computer system comprising one or more processors and memory storing instructions for execution by the one or more processors, said method comprising:sending to the collector computer system machine interpretable code that is configured for interpretation by an interpreter stored within the collector computer system, wherein the machine interpretable code is not directly executable by one or more processors of the collector computer system and the machine interpretable code includes information identifying a first set of one or more monitoring targets within the collector computer system, a method for monitoring the first set of one or more monitoring targets by the collector computer system, and predefined reporting criteria;and, subsequent to sending to the collector computer system the machine interpretable code, receiving from the collector computer system candidate event information that is associated with a candidate activity with the first set of one or more monitoring targets.
  13. 18
    The method of any of claims 14-17, wherein the machine interpretable code is in a script language.
  14. 19
    The method of any of claims 14-18, wherein the first set of one or more monitoring targets include one or more of:one or more applications running on the collector computer system, one or more types of operations or services within the collector computer system, one or more regions of the memory, one or more registry entries, one or more network connection points, one or more mutex objects, and one or more memory operations.
  15. 20
    The method of any of claims 14-19, wherein the predefined reporting criteria include types of information for reporting, the types of information including one or more of:a timestamp, one or more file names associated with the candidate activity, one or more process names associated with the candidate activity, one or more network connection points, one or more registry paths, one or more mutex objects, one or more library names, and one or more thread numbers and/or process numbers.
  16. 21
    The method of any of claims 14-20, wherein the machine interpretable code is sent for the collector computer system operating in a first state, the method further including:for the collector computer system operating in a second state that is distinct from the first state: sending machine executable code that is configured for execution by the one or more processors of the collector computer system and that is not configured for interpretation by the interpreter, wherein the machine executable code includes information identifying a second set of one or more monitoring targets and second predefined reporting criteria;and, 33 WO 2016/112219 PCT/US2016/012533 subsequent to sending to the collector computer system the machine executable code, receiving additional candidate event information that is associated with the second set of one or more monitoring targets and that satisfies the second predefined reporting criteria.
  17. 22
    The method of any of claims 14-21, further comprising:subsequent to receiving the information, sending to the collector computer system instructions to terminate the candidate activity on the collector computer system.
  18. 23
    A controller computer system, comprising:one or more processors;and memory storing one or more programs, which, when executed by the one or more processors, cause the controller computer system to: send to the collector computer system machine interpretable code that is configured for interpretation by an interpreter stored within the collector computer system, wherein the machine interpretable code is not directly executable by one or more processors of the collector computer system and the machine interpretable code includes information identifying a first set of one or more monitoring targets within the collector computer system, a method for monitoring the first set of one or more monitoring targets by the collector computer system, and predefined reporting criteria;and, subsequent to sending to the collector computer system the machine interpretable code, receive from the collector computer system candidate event information that is associated with a candidate activity with the first set of one or more monitoring targets.
  19. 24
    A non-transitory computer readable storage medium, storing one or more programs execution by one or more processors of a controller computer system, the one or more programs including instructions for:sending to the collector computer system machine interpretable code that is configured for interpretation by an interpreter stored within the collector computer system, wherein the machine interpretable code is not directly executable by one or more processors of the collector computer system and the machine interpretable code includes information identifying a first set of one or more monitoring targets within the collector computer system, a method for monitoring the first set of one or more monitoring targets by the collector computer system, and predefined reporting criteria;and, WO 2016/112219 PCT/US2016/012533 subsequent to sending to the collector computer system the machine interpretable code, receiving from the collector computer system candidate event information that is associated with a candidate activity with the first set of one or more monitoring targets.
  20. 25
    A controller computer system, comprising:one or more processors;and memory storing one or more programs, which, when executed by the one or more processors, cause the controller computer system to perform any method of claims 14-22.
  21. 26
    A non-transitory computer readable storage medium, storing one or more programs execution by one or more processors of a controller computer system, the one or more programs including instructions for performing any method of claims 14-22.
Independent claims21