×

Probabilistic alert correlation

  • US 20020059078A1
  • Filed: 08/31/2001
  • Published: 05/16/2002
  • Est. Priority Date: 09/01/2000
  • Status: Active Grant
First Claim
Patent Images

1. A method for organizing alerts into alert classes, both the alerts and alert classes having a plurality of features, the method comprising the steps of:

  • (a) receiving a new alert;

    (b) identifying a set of potentially similar features shared by the new alert and one or more existing alert classes;

    (c) updating a minimum similarity requirement for one or more features;

    (d) updating a similarity expectation for one or more features;

    (e) comparing the new alert with one or more alert classes, and either;

    (f1) associating the new alert with the existing alert class that the new alert most closely matches;

    or (f2) defining a new alert class that is associated with the new alert.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×