PARAMETER ADJUSTMENT FOR PATTERN DISCOVERY
First Claim
Patent Images
1. A method for determining parameters for pattern discovery in event data, the method comprising:
- selecting an initial set of parameters for pattern discovery, wherein the parameters specify conditions for identifying a pattern in the event data;
executing, by a processor, a pattern discovery run on the event data based on the initial set of parameters; and
adjusting a parameter of the initial set of parameters based on an output of the pattern discovery run.
12 Assignments
0 Petitions
Accused Products
Abstract
Pattern discovery performed on event data may include selecting an initial set of parameters for the pattern discovery. The parameters may specify conditions for identifying a pattern in the event data. A pattern discovery run is executed on the event data based on the initial set of parameters, and a parameter may be adjusted based on the output of the pattern discovery run.
32 Citations
15 Claims
-
1. A method for determining parameters for pattern discovery in event data, the method comprising:
-
selecting an initial set of parameters for pattern discovery, wherein the parameters specify conditions for identifying a pattern in the event data; executing, by a processor, a pattern discovery run on the event data based on the initial set of parameters; and adjusting a parameter of the initial set of parameters based on an output of the pattern discovery run. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10)
-
-
11. A network security event processing system comprising:
-
data storage storing event data describing activities for devices connected to a network; a pattern identifier engine, executed by a processor, to execute a pattern discovery run to detect patterns in the event data based on an initial set of parameters associated with conditions for identifying the patterns; and a parameter tuning module to adjust a parameter from the initial set based on an output of the pattern discovery run. - View Dependent Claims (12, 13, 14)
-
-
15. A non-transitory computer readable medium including machine readable instructions that when executed by a processor cause the processor to:
-
select an initial set of parameters for pattern discovery, wherein the parameters specify conditions for identifying a pattern in the event data; execute a pattern discovery run on the event data based on the initial set of parameters; and adjust a parameter of the initial set of parameters based on a number of patterns identified in the pattern discovery run or based on whether the pattern discovery run failed to complete execution.
-
Specification