×

Multi-tier aggregation for complex event correlation in streams

  • US 10,135,853 B2
  • Filed: 09/20/2016
  • Issued: 11/20/2018
  • Est. Priority Date: 09/20/2016
  • Status: Active Grant
First Claim
Patent Images

1. A method for detecting anomalous activity, the method comprising:

  • collecting data from a plurality of data sources, wherein each data source generates a data stream;

    harmonizing each data stream using a computer processor so that the harmonized data is in a common format;

    generating behavior models based on the harmonized data using the computer processor;

    analyzing the harmonized data at a first level using the behavior models and the computer processor to identify meta-events, wherein the meta-events represent anomalous behavior and analyzing the harmonized data at the first level identifies a meta-event based on a pre-defined set of anomalous activities;

    analyzing the meta-events at a second level using the computer processor to determine if an alert should be issued, wherein;

    the second level is a higher level of operation than the first level and encompasses the meta-events identified by analyzing the harmonized data at the first level, andanalyzing the meta-events at the second level includes determining whether an alert should be issued based on multiple meta-events; and

    when an alert should be issued, displaying the alert.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×