×

SYSTEM AND METHOD FOR REAL-TIME DETECTION OF ANOMALIES IN DATABASE USAGE

  • US 20150355957A1
  • Filed: 06/05/2015
  • Published: 12/10/2015
  • Est. Priority Date: 06/09/2014
  • Status: Active Grant
First Claim
Patent Images

1. A method for real-time detection of anomalies comprising:

  • receiving a plurality of heterogeneous data streams, wherein the heterogeneous data streams are received from at least two of a group consisting of agents located at databases, agents located at applications, audit programs located at user workstations, and sensors located in, or at access points to, a network;

    correlating the heterogeneous data streams, wherein the correlation identifies corresponding events in different ones of the heterogeneous data streams;

    identifying patterns of events across the correlated heterogeneous data streams;

    building a model of normalcy from the identified pattern of events, wherein the model of normalcy is stored in an analysis database;

    creating rules that determine how and whether anomalies are detected, how a detected anomaly is treated and characterized, and what reaction to employ upon detection of the anomaly;

    receiving a plurality of additional heterogeneous data streams from the at least two of a group consisting of the agents, audit programs, and sensors;

    applying, using an analysis engine, the model of normalcy and rules to the additional heterogeneous data streams and analyzing data from the additional heterogeneous data streams against the model of normalcy and rules;

    detecting an anomaly in real-time by determining whether an anomalous event is present, by the application of the rules and whether events, in relation to other events within the additional heterogeneous data streams, fit or do not fit the model of normalcy;

    determining at least one characteristic of the detected anomaly; and

    issuing an alert upon detection of the anomaly, wherein a type of alert is determined based on the at least one determined characteristic of the detected anomaly.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×