×

Parameter adjustment for pattern discovery

  • US 10,027,686 B2
  • Filed: 05/30/2012
  • Issued: 07/17/2018
  • Est. Priority Date: 05/30/2012
  • Status: Active Grant
First Claim
Patent Images

1. A method comprising:

  • receiving event data collected by agents from sources over a communication network, the sources comprising network security devices;

    providing a set of parameters to a pattern identifier engine, wherein the set of parameters specify conditions for identifying patterns in the event data;

    executing, by the pattern identifier engine executed on a hardware processor of a manager system, a pattern discovery comprising identifying, by the pattern identifier engine, the patterns in the event data if the event data satisfies the conditions specified by the set of parameters;

    determining whether the pattern discovery failed to complete within a predetermined period of time;

    in response to determining that the pattern discovery failed to complete within the predetermined period of time, iteratively performing further pattern discovery until a criterion is satisfied by;

    adjusting a parameter of the set of parameters to reduce use of system resources of the manager system for a subsequent pattern discovery run, the adjusting producing a respective adjusted set of parameters;

    providing the respective adjusted set of parameters to the pattern identifier engine and executing, by the pattern identifier engine, the subsequent pattern discovery run to identify patterns in the event data if the event data satisfies conditions specified by the respective adjusted set of parameters; and

    executing an action in response to the identified patterns produced by the further pattern discovery, the action comprising one or more of mitigating an attack and displaying the event data for analysis by a network administrator.

View all claims
  • 12 Assignments
Timeline View
Assignment View
    ×
    ×