The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.
The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.
Patent No.:
Date of Patent:
May. 12, 2026
Filed:
Oct. 30, 2023
Lacework, Inc., Mountain View, CA (US);
David Nellinger Adamson, Oakland, CA (US);
Christopher Hall, Baltimore, MD (US);
Njall Skarphedinsson, Redwood City, CA (US);
Pamela Bhattacharya, Redmond, WA (US);
Aditya Samalla, San Jose, CA (US);
Rui Zhang, Brooklyn, NY (US);
Jessica Liu, San Francisco, CA (US);
Marcos Garcia Marti, Montréal, CA;
Sowmya A. Karmali, Tustin, CA (US);
Yijou Chen, Cupertino, CA (US);
Fortinet, Inc., Sunnyvale, CA (US);
Abstract
A data platform monitors a compute environment by performing multi-stage heuristic analysis of event data representing a plurality of events occurring within the environment. The platform utilizes multiple event analyzers, each configured according to a distinct analysis heuristic, to evaluate different subsets of the event data and generate corresponding output signals. A higher-level event analyzer applies a further heuristic to the multiple output signals to generate a composite alert signal, indicating whether the combination of analyzed events collectively represents a security intrusion or other anomalous condition of sufficient severity to warrant alerting. Based on the composite alert signal, the platform performs an alert-based operation, such as generating a user-facing alert, initiating an automated mitigation, or updating a contextual model of system behavior. By combining the analytical outputs of heterogeneous heuristics, the disclosed architecture enhances the accuracy and contextual relevance of automated intrusion detection within complex computing environments.