×

Anomaly detection method

  • US 6,889,218 B1
  • Filed: 05/15/2000
  • Issued: 05/03/2005
  • Est. Priority Date: 05/17/1999
  • Status: Expired due to Fees
First Claim
Patent Images

1. A computerized method, encoded on a computer-readable medium and executable on a computing device, of detecting anomalies in a data stream, the method comprising:

  • (a) in an off-line process, using a tree structure comprising a suffix tree having suffixes representing certain patterns of interest which have an associated length to extract a grammar from a sample of normal behavior, the grammar having an associated set of rules;

    (b) in a subsequent on-line process, checking the data stream against the rules of the grammar to detect deviations; and

    (c) generating an alarm indication when a deviation is detected.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×