Methods and apparatus for detecting anomalies in electronic data
First Claim
1. An apparatus to detect anomalies in electronic data, the apparatus comprising:
- a signature generator to generate a signature of context information for electronic transactions and to query a memorybase of previously received electronic transactions to identify a first entity associated with a subset of historical transactions that are associated with the signature, wherein the memorybase is an associative memorybase and includes a first application programming interface to serve queries for connections and a second application programming interface to serve queries for analogies;
a neighborhood generator to query the memorybase to generate a neighborhood for the first entity;
a target category identifier to determine a target category value for entities included in the neighborhood; and
an anomaly detector to determine a score for the first entity based on the target category value and to present an alert indicating that the first entity is anomalous based on the score.
1 Assignment
0 Petitions
Accused Products
Abstract
Methods and apparatus for detecting anomalies in electronic data are described. An example apparatus includes a signature generator to generate a signature of context information for electronic transactions and to query a memorybase of previously received electronic transactions to identify a first entity associated with a subset of historical transactions that are associated with the signature, a neighborhood generator to query the memorybase to generate a neighborhood for the first entity, a target category identifier to determine a target category value for entities included in the neighborhood, and an anomaly detector to determine a score for the first entity based on the target category value and to present an alert indicating that the first entity is anomalous based on the score.
18 Citations
23 Claims
-
1. An apparatus to detect anomalies in electronic data, the apparatus comprising:
-
a signature generator to generate a signature of context information for electronic transactions and to query a memorybase of previously received electronic transactions to identify a first entity associated with a subset of historical transactions that are associated with the signature, wherein the memorybase is an associative memorybase and includes a first application programming interface to serve queries for connections and a second application programming interface to serve queries for analogies; a neighborhood generator to query the memorybase to generate a neighborhood for the first entity; a target category identifier to determine a target category value for entities included in the neighborhood; and an anomaly detector to determine a score for the first entity based on the target category value and to present an alert indicating that the first entity is anomalous based on the score. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9)
-
-
10. A method to detect anomalies in electronic data, the method comprising:
-
generating a signature of context information for electronic transactions; querying a memorybase of previously received electronic transactions to identify a first entity associated with a subset of historical transactions that are associated with the signature, wherein the memorybase is an associative memorybase and includes a first application programming interface to serve queries for connections and a second application programming interface to serve queries for analogies; querying the memorybase to generate a neighborhood for the first entity; determining a target category value for entities included in the neighborhood; determining a score for the first entity based on the target category value; and presenting an alert indicating that the first entity is anomalous based on the score. - View Dependent Claims (11, 12, 13, 14, 15, 16, 17, 18)
-
-
19. A non-transitory machine readable storage medium comprising instructions that, when executed, cause a machine to at least:
-
generate a signature of context information for electronic transactions; query a memorybase of previously received electronic transactions to identify a first entity associated with a subset of historical transactions that are associated with the signature, wherein the memorybase is an associative memorybase and includes a first application programming interface to serve queries for connections and a second application programming interface to serve queries for analogies; query the memorybase to generate a neighborhood for the first entity; determine a target category value for entities included in the neighborhood; determine a score for the first entity based on the target category value; and present an alert indicating that the first entity is anomalous based on the score. - View Dependent Claims (20, 21, 22, 23)
-
Specification