×

Automatic baselining of anomalous event activity in time series data

  • US 9,954,882 B2
  • Filed: 07/27/2016
  • Issued: 04/24/2018
  • Est. Priority Date: 11/30/2015
  • Status: Active Grant
First Claim
Patent Images

1. A computer-implemented method comprising:

  • determining a baseline pattern for one or more attributes of a computing system based, at least in part, on a first set of statistical thresholds determined for received values of the one or more attributes, wherein the received values correspond to one or more time periods, and on a second set of statistical thresholds determined for a first subset of values of the received values of the one or more attributes, wherein each value of the first subset exceeds the first set of statistical thresholds;

    monitoring additional values of the one or more attributes for anomalous activity, using the determined baseline pattern, wherein the monitored additional values correspond to one or more additional time periods, and wherein a start time of the one or more additional time periods is randomly determined, as part of an anti-gaming mechanism for preventing undetected malicious activity on the computing system, to prevent potential attackers of the computing system from utilizing knowledge of the first set of statistical thresholds, the second set of statistical thresholds, and/or the baseline pattern to avoid detection of malicious activity; and

    in response to identifying, based, at least in part, on the determined baseline pattern, anomalous values in the monitored additional values of the one or more attributes, sending an alert to a user of the computing system indicating that a potential intrusion in the computing system has occurred.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×