SYSTEMS AND METHODS FOR EVALUATION OF EVENTS BASED ON A REFERENCE BASELINE ACCORDING TO TEMPORAL POSITION IN A SEQUENCE OF EVENTS
First Claim
Patent Images
1. A method for evaluation of events, the method comprising:
- generating, by a computing device, a user-specific reference baseline comprising a set of temporally-ordered sequences of events;
receiving an event of a sequence of events in a current session;
determining whether the event at least partially matches the reference baseline using an attribute of the event and based on a temporal position of the event within the sequence of events in the current session; and
analyzing a condition of a rule based on the determination of whether the event least partially matches the reference baseline.
12 Assignments
0 Petitions
Accused Products
Abstract
Systems and methods for evaluation of events are provided. A user-specific reference baseline comprising a set of temporally-ordered sequences of events. An event of a sequence of events in a current session is received. A determination is made as to whether the event at least partially matches the reference baseline using an attribute of the event and a temporal position of the event within the sequence of events in the current session.
60 Citations
15 Claims
-
1. A method for evaluation of events, the method comprising:
-
generating, by a computing device, a user-specific reference baseline comprising a set of temporally-ordered sequences of events; receiving an event of a sequence of events in a current session; determining whether the event at least partially matches the reference baseline using an attribute of the event and based on a temporal position of the event within the sequence of events in the current session; and analyzing a condition of a rule based on the determination of whether the event least partially matches the reference baseline. - View Dependent Claims (2, 3, 4, 7, 8)
-
- 5. The method of claim, wherein at least one sequence in the set of temporally-ordered sequences of events is flagged as being either normal user behavior or anomalous user behavior.
-
9. A system for evaluation of events, the system comprising:
-
a processor; and a memory coupled to the processor, the memory configured to store a data list including a plurality of user-specific reference baselines; wherein the processor is configured to; generate a first user-specific reference baseline of the plurality of user-specific reference baselines, the first user-specific reference baseline comprising a set of temporally-ordered sequences of events; receive an event of a sequence of events in a current session; determine whether the event at least partially matches the reference baseline using an attribute of the event and based on a temporal position of the event within the sequence of events in the current session; analyze a condition of a rule based on the determination of whether the event at least partially matches the reference baseline; and generate a correlation event. - View Dependent Claims (10, 11, 12, 13)
-
-
14. A non-transitory computer-readable medium storing a plurality of instructions to control a data processor to evaluate events, the plurality of instructions comprising instructions that cause the data processor to:
-
generate a first user-specific reference baseline of the plurality of user-specific reference baselines, the first reference baseline comprising a set of temporally-ordered sequences of transactional events, wherein each event is a part of a financial transaction; receive a transactional event of a sequence of transactional events in a current session; determine whether the transactional event at least partially matches the reference baseline using an attribute of the transactional event and based on a temporal position of the transactional event within the sequence of transactional events in the current session; analyze a condition of a rule based on the determination of whether the transactional event at least partially matches the reference baseline; and correlate the transactional event with a security-related event. - View Dependent Claims (15)
-
Specification