×

Event detection

  • US 6,347,374 B1
  • Filed: 06/05/1998
  • Issued: 02/12/2002
  • Est. Priority Date: 06/05/1998
  • Status: Expired due to Term
First Claim
Patent Images

1. A system for event detection comprising:

  • a collector operable to collect raw audit data comprising raw audit data records, the collector being at a first audit source having a first type of operating system;

    a database;

    an inserter, in communication with the database, operable to insert Virtual Records into the database, including both a first type of Virtual Record generated in response to a raw audit data record, and a second type of Virtual Record generated in response to a detected audit event;

    a parser, in communication with the collector and the inserter, operable to convert raw audit data records in the raw audit data into Virtual Records of the first type, wherein the Virtual Records of the first type are generated in a normalized format, the normalized format having a plurality of data fields, each data field corresponding to a different category of data associated with a potential audit event, the parser converting the raw audit data records into Virtual Records of the first type by parsing the raw audit data records to identify the different categories of data for storage within the data fields; and

    a detector, in communication with the parser and the inserter, operable to detect audit events in response to analyzing data arranged according to the normalized format in the Virtual Records of the first type, the detector operable to generate the second type of Virtual Record in the event one of the audit events is detected, the detector further operable to detect audit events in response to analyzing data arranged according to the normalized format in additional Virtual Records of the first type, the additional Virtual Records being converted from additional raw audit data records collected at a second audit source, the second audit source having a second type of operating system.

View all claims
  • 5 Assignments
Timeline View
Assignment View
    ×
    ×