Method, computer program element and system for processing alarms triggered by a monitoring system
First Claim
1. A method for processing alarms that have been triggered by a monitoring system, in a subsequent system of a type employing a model representing normal alarm behavior of the monitoring system, the method comprising the steps of:
- a) counting a number of alarms that have been triggered, and a number of alarms that have been filtered by the model, within at least one time-interval;
b) calculating a ratio between the number of alarms that have been filtered, and the number of alarms that have been triggered; and
c) updating the model in response to the ratio reaching a threshold value.
1 Assignment
0 Petitions
Accused Products
Abstract
A method and system is proposed that allow to process alarms, that have been triggered by a monitoring system, by means of a model representing the normal alarm behavior of the monitoring system. The number of alarms, that have been triggered, and the number of alarms, that have been filtered by means of the model, are counted. Then the ratio between the number of alarms, that have been filtered, and the number of alarms, that have been triggered, is calculated; and the update of the model is started whenever the ratio has reached a first or a second threshold value. Thus in order to efficiently achieve an optimal over-all performance, an update of the model is always performed, whenever a decline in the model'"'"'s performance is detected. In a preferred embodiment, alarms that have been triggered, are grouped depending on source address information contained therein. Groups of alarms, that display diverse behavior, are flagged and forwarded for closer investigation in order to identify suspicious source systems.
61 Citations
11 Claims
-
1. A method for processing alarms that have been triggered by a monitoring system, in a subsequent system of a type employing a model representing normal alarm behavior of the monitoring system, the method comprising the steps of:
-
a) counting a number of alarms that have been triggered, and a number of alarms that have been filtered by the model, within at least one time-interval;
b) calculating a ratio between the number of alarms that have been filtered, and the number of alarms that have been triggered; and
c) updating the model in response to the ratio reaching a threshold value. - View Dependent Claims (2, 3, 4, 10)
-
-
5. A method for processing alarms, that have been triggered by a monitoring system, the method comprising the steps of:
-
a) grouping alarms, that have been triggered, according to source address information, b) detecting groups of alarms that display diverse behavior and c) forwarding detected groups of alarms for further processing. - View Dependent Claims (6, 7, 8, 9, 11)
-
Specification