×

Detection of anomalous events

  • US 9,361,463 B2
  • Filed: 12/11/2013
  • Issued: 06/07/2016
  • Est. Priority Date: 12/11/2013
  • Status: Active Grant
First Claim
Patent Images

1. A method comprising:

  • detecting anomalous events using a first anomaly detector positioned in parallel with a second anomaly detector, the detecting comprising;

    receiving a first log file including a first plurality of events from a first data source in the first anomaly detector including a first memory;

    receiving a second log file including a second plurality of events from a second data source that is a different type than the first data source in the second anomaly detector including a second memory;

    using the first log file, generating a first anomaly score, the generation being derived from an area associated with a probability density function of the first log file, wherein generating the first anomaly score includes using the formula Af(x)=−

    logbPf(f(X)≦

    f(x)) where b>

    1;

    using the second log file, generating a second anomaly score, the generation being derived from an area associated with a probability density function of the second log file; and

    comparing the first and second anomaly scores so as to compare anomalies from the first data source to the second data source, which are of different types.

View all claims
  • 4 Assignments
Timeline View
Assignment View
    ×
    ×