ANOMALY DETECTION METHODS FOR A COMPUTER NETWORK
First Claim
1. A method for detecting anomalous data in a data stream, comprising steps of:
- a) generating a baseline value corresponding to non-anomalous data in the data stream;
b) generating a first test value based on current data of the data stream;
c) adjusting the baseline value based on the first test value; and
d) triggering an anomaly alarm when the first test value varies from the baseline by at least a predetermined value.
0 Assignments
0 Petitions
Accused Products
Abstract
Methodologies and systems for detecting an anomaly in a flow of data or data stream are described herein. To detect an anomaly, an anomaly detection server may create a baseline based on historical or other known non-anomalous data within the data stream. The anomaly detection server then generates one or more test values based on current data in the data stream, and compares the test value(s) to the baseline to determine whether they vary by more than a predetermined amount. If the deviation exceeds the predetermined amount, an alarm is triggered. The anomaly detection server may continually adjust the baseline based on the current data in the data stream, and may renormalize the baseline periodically if desired or necessary.
106 Citations
20 Claims
-
1. A method for detecting anomalous data in a data stream, comprising steps of:
-
a) generating a baseline value corresponding to non-anomalous data in the data stream;
b) generating a first test value based on current data of the data stream;
c) adjusting the baseline value based on the first test value; and
d) triggering an anomaly alarm when the first test value varies from the baseline by at least a predetermined value. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11)
-
-
12. A computer-implemented method for detecting an anomaly in a data stream, comprising steps of:
-
a) initializing a baseline value based on known non-anomalous data;
b) comparing a test value to the baseline value;
c) updating the baseline value based on the test value;
d) triggering an alarm when the test value varies from the baseline value by at least a predetermined amount; and
e) iteratively repeating steps b)-d) at predetermined intervals. - View Dependent Claims (13, 14, 15, 16, 17, 18, 19, 20)
-
Specification