Anomaly detection method
First Claim
Patent Images
1. A computerized method, encoded on a computer-readable medium and executable on a computing device, of detecting anomalies in a data stream, the method comprising:
- (a) in an off-line process, using a tree structure comprising a suffix tree having suffixes representing certain patterns of interest which have an associated length to extract a grammar from a sample of normal behavior, the grammar having an associated set of rules;
(b) in a subsequent on-line process, checking the data stream against the rules of the grammar to detect deviations; and
(c) generating an alarm indication when a deviation is detected.
2 Assignments
0 Petitions
Accused Products
Abstract
A computerized method, encoded on a computer-readable medium, of detecting anomalies in an event stream. The method comprises at least two acts. In a first act, the method uses a tree structure to extract a grammar having an associated set of rules, from a sample of normal behavior. In a second act, the method checks an event stream against the rules of the grammar to detect anomalies.
44 Citations
8 Claims
-
1. A computerized method, encoded on a computer-readable medium and executable on a computing device, of detecting anomalies in a data stream, the method comprising:
-
(a) in an off-line process, using a tree structure comprising a suffix tree having suffixes representing certain patterns of interest which have an associated length to extract a grammar from a sample of normal behavior, the grammar having an associated set of rules;
(b) in a subsequent on-line process, checking the data stream against the rules of the grammar to detect deviations; and
(c) generating an alarm indication when a deviation is detected. - View Dependent Claims (2, 3, 4, 5, 6, 7)
-
-
8. A computerized method, encoded on a computer-readable medium executable on a computing device, of detecting anomalies in a data steam, the method comprising:
-
(a) in an off-line process, extracting a grammar from a sample of normal behavior, the grammar having an associated set of rules;
(b) in a subsequent on-line process, checking the data stream against the rules of the grammar to detect anomalies and generating an alarm indication when a data stream anomaly is detected; and
(c) using a rule-matching automaton to take a second pass over the sample in order to reduce the set of rules, for application in subsequent processes.
-
Specification