×

Monitoring events in a computer network

  • US 7,750,910 B2
  • Filed: 10/31/2007
  • Issued: 07/06/2010
  • Est. Priority Date: 03/12/2003
  • Status: Expired due to Fees
First Claim
Patent Images

1. An article of manufacture comprising a tangible computer readable medium having computer readable code means embodied therein for causing monitoring network activities, the computer readable program code means in said article of manufacture, when executed by a computer, cause the computer to effect monitoring network activities as a time-ordered sequence of events in a computer network, each event having attributes triggered by an intrusion-detection system, each event being characterized by a given set of attributes called dimensions, each event forming an n-dimensional space, the step of monitoring comprising:

  • said computer network triggering said events, each event being provided with attribute values allocated to a given set of attributes of said each event, each attribute having a particular attribute value,simultaneously monitoring each particular attribute value of various event attributes from said given set of attributes versus the arrival time of said each event,providing an event display with a cross plot having x and y coordinate axes, the x-axis presenting a time period and the y-axis presenting an attribute value range, and visualizing data along said x and y coordinate axes, said axes being attribute axes,determining a primary attribute of said each event, said primary attribute being selected from the given set of attributes, each said primary attribute of said each event to be presented with a corresponding attribute value on the y-axis of the cross plot,allocating a first display label to the events indicating the attribute value of the primary attribute of each event, providing a pattern algorithm to detect whether an arrived event is part of the given pattern on the basis of a comparison of the attributes allocated to the given pattern and of the attributes assigned to the arrived event, providing a mapping algorithm to map any attribute value of an attribute selected from the given set of attributes onto the y-axis of the cross plot,allocating a second display label to said each event indicating the attribute values of the attributes being uncovered as part of the given pattern,plotting all events that arrived within the time period and including an attribute value allocated to the primary attribute into the cross plot with the first display label indicating the primary attribute, the position of the first display label of said each event in the cross plot being determined on the basis of the attribute value of the primary attribute of the event and its arrival time,plotting all events that arrived within the time period and being detected by means of the pattern algorithm as part of the given pattern into the cross plot with the second display label indicating the given pattern, the position of the second display label of said each event in the cross plot being determined by the mapping algorithm on the basis of the attribute value of the attribute of the event being uncovered as part of the given pattern and its arrival time, anddisplaying a secondary attribute of said each event together with the primary attribute on said display.

View all claims
  • 0 Assignments
Timeline View
Assignment View
    ×
    ×