Method and system for advanced scenario based alert generation and processing
First Claim
1. A computer based method for generating alerts to a behavior as represented in data, the method comprising the steps of:
- receiving, on a periodic basis, data from at least one source;
transforming the data from a first format associated with the at least one source to data in a second format for subsequent analysis;
storing the data in the second format to a dataset;
retrieving an advanced scenario, wherein the advanced scenario defines a behavior of interest;
retrieving a portion of the dataset; and
applying the advanced scenario to the portion of the dataset to perform detection processing wherein the detection processing produces one or more matches wherein the matches are indicative of an instantiation of the advanced scenario in the portion of the dataset.
3 Assignments
0 Petitions
Accused Products
Abstract
A computer based method and system generates alerts based on the detection of an advanced scenario in a data set. The system and method may take data related to events and entities, transform the data, and apply advanced scenarios to the data to produce matches that reflect the occurrence of an advanced scenario and the behavior of interest. The advanced scenarios can be defined to cover specific product lines and services, lines of businesses, and combinations thereof. The advanced scenarios can be defined to be indicative of a behavior class, or a specific behavior which is part of a behavior class. Alerts produced by the system can be grouped, prioritized and routed such that the appropriate users are notified in a timely manner. The system and method can be applied to a variety of industries including financial and health care, and can detect both illicit and licit behaviors of interest.
156 Citations
77 Claims
-
1. A computer based method for generating alerts to a behavior as represented in data, the method comprising the steps of:
-
receiving, on a periodic basis, data from at least one source;
transforming the data from a first format associated with the at least one source to data in a second format for subsequent analysis;
storing the data in the second format to a dataset;
retrieving an advanced scenario, wherein the advanced scenario defines a behavior of interest;
retrieving a portion of the dataset; and
applying the advanced scenario to the portion of the dataset to perform detection processing wherein the detection processing produces one or more matches wherein the matches are indicative of an instantiation of the advanced scenario in the portion of the dataset. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16)
-
-
17. The method of claim 17, wherein the advanced scenario further includes parameterized logic.
-
18. A computer based method for generating alerts to a behavior as represented in data, the method comprising the steps of:
-
receiving, on a periodic basis, data from at least one source;
transforming the data from a first format associated with the at least one source to data in a second format for subsequent analysis;
storing the data in the second format to a dataset;
retrieving a behavior description, wherein the behavior description contains a plurality of conditions related to events and entities, the plurality of conditions related to events and entities being indicative of the specific behavior;
retrieving a portion of the dataset; and
performing detection processing, wherein the detection processing includes detection of relationships among events and entities in the portion of the dataset; and
generating a plurality of alerts, wherein the plurality of alerts is indicative of the specific behavior. - View Dependent Claims (19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29)
-
-
30. A computer based method for generating alerts to a behavior as represented in data, the method comprising the steps of:
-
receiving, on a periodic basis, data from at least one source;
transforming the data from a first format associated with the at least one source to data in a second format for subsequent analysis;
storing the data in the second format to a dataset;
receiving an advanced scenario, wherein the advanced scenario contains a plurality of events and entities related to a behavior description and reference to at least one algorithm for identifying the plurality of events and entities;
retrieving a portion of the dataset; and
performing detection processing, wherein the detection processing includes the detection of the plurality of events and entities in the portion of the dataset using the at least one algorithm; and
generating a plurality of alerts, wherein the plurality of alerts is indicative of the specific behavior. - View Dependent Claims (31, 32, 33, 34, 35, 36, 37, 38, 39, 40)
-
-
41. A computer program embodied on a computer-readable medium for generating alerts to a specific behavior as represented in data, the computer program comprising:
-
a code segment for receiving, on a periodic basis, data from at least one source;
a code segment for transforming the data from a first format associated with the at least one source to data in a second format for subsequent analysis;
a code segment for storing the data in the second format to a dataset;
a code segment for retrieving an advanced scenario, wherein the advanced scenario defines a behavior of interest;
a code segment for retrieving a portion of the dataset; and
a code segment for applying the advanced scenario to the portion of the dataset to perform detection processing wherein the detection processing produces one or more matches wherein the matches are indicative of an instantiation of the advanced scenario in the portion of the dataset. - View Dependent Claims (42, 43, 44, 45, 46, 47, 48, 49, 50, 51, 52, 53, 54, 55)
-
-
56. A computer program embodied on a computer-readable medium for generating alerts to a specific behavior as represented in data, the computer program comprising:
-
a code segment for receiving, on a periodic basis, data from at least one source;
a code segment for transforming the data from a first format associated with the at least one source to data in a second format for subsequent analysis;
a code segment for storing the data in the second format to a dataset;
a code segment for retrieving a behavior description, wherein the behavior description contains a plurality of conditions related to events and entities, the plurality of conditions related to events and entities being indicative of the specific behavior;
a code segment for retrieving a portion of the dataset; and
a code segment for performing detection processing, wherein the detection processing includes detection of relationships among events and entities in the portion of the dataset; and
a code segment for generating a plurality of alerts, wherein the plurality of alerts is indicative of the specific behavior. - View Dependent Claims (57, 58, 59, 60, 61, 62, 63, 64, 65, 66, 67)
-
-
68. A computer program embodied on a computer-readable medium for generating alerts to a specific behavior as represented in data, the computer program comprising:
-
a code segment for receiving, on a periodic basis, data from at least one source;
a code segment for transforming the data from a first format associated with the at least one source to data in a second format for subsequent analysis;
a code segment for storing the data in the second format to a dataset;
a code segment for receiving an advanced scenario, wherein the advanced scenario contains a plurality of events and entities related to a behavior description and reference to at least one algorithm for identifying the plurality of events and entities;
a code segment for retrieving a portion of the dataset; and
a code segment for performing detection processing, wherein the code segment for detection processing includes code for detection of the plurality of events and entities in the portion of the dataset using the at least one algorithm; and
a code segment for generating a plurality of alerts, wherein the plurality of alerts is indicative of the specific behavior. - View Dependent Claims (69, 70, 71, 72, 73, 74, 75, 76, 77)
-
Specification