×

Presentation of correlated events as situation classes

  • US 7,278,160 B2
  • Filed: 08/16/2001
  • Issued: 10/02/2007
  • Est. Priority Date: 08/16/2001
  • Status: Active Grant
First Claim
Patent Images

1. A method in a data processing system for reporting security situations, comprising the steps of:

  • logging events by storing event attributes as an event set, wherein each event set includes a source attribute, a target attribute and an event category attribute;

    classifying events as groups by aggregating events with at least one attribute within the event set as an identical value;

    calculating severity levels for the groups, wherein a severity level for a group is a function of a number of events comprising the group and values of common elements in the group;

    reporting a group from the groups to a user as a situation, if a severity level of the group exceeds a threshold value; and

    aggregating a subset of the groups into a combined group.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×