BEHAVIORAL BASELINING OF NETWORK SYSTEMS
First Claim
1. A method, comprising:
- instantiating, by at least one processor, a baseline, wherein the baseline comprises a set of assets, and a set of relationships including a first relationship;
associating a first event stream with the baseline, wherein the first event stream comprises events including a first event, and each event comprises attributes;
evaluating each event of the first event stream by performing evaluations corresponding to attributes in the set of relationships; and
detecting, by the at least one processor, based on the evaluating of the first event stream, a drift from the baseline, wherein the drift is based on a failure of at least one attribute value in the first event to match at least one attribute value of the first relationship.
4 Assignments
0 Petitions
Accused Products
Abstract
Systems and methods for behavioral baselining of network systems. In one embodiment, a method includes: storing, in an asset attribute database, information regarding assets, wherein each asset comprises at least one attribute; storing, in a relationship database, information regarding relationships, wherein each relationship comprises at least one attribute; selecting, from the asset attribute database, assets based on at least one attribute value; selecting, from the relationship database, one or more relationships based on at least one attribute value, the selected relationships including a first relationship; creating a baseline, wherein the baseline comprises the selected assets and the selected relationships; connecting a first event stream to the baseline, wherein the first event stream comprises a set of events, and each event comprises attributes; and detecting a drift from the baseline, wherein the drift is determined using the first event stream and is based on a failure of at least one attribute value in a first event of the first event stream to match at least one attribute value of the first relationship.
43 Citations
20 Claims
-
1. A method, comprising:
-
instantiating, by at least one processor, a baseline, wherein the baseline comprises a set of assets, and a set of relationships including a first relationship; associating a first event stream with the baseline, wherein the first event stream comprises events including a first event, and each event comprises attributes; evaluating each event of the first event stream by performing evaluations corresponding to attributes in the set of relationships; and detecting, by the at least one processor, based on the evaluating of the first event stream, a drift from the baseline, wherein the drift is based on a failure of at least one attribute value in the first event to match at least one attribute value of the first relationship. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11)
-
-
12. A system, comprising:
-
at least one database, at least one processor; and at least one memory in communication with the at least one processor and storing instructions that, when executed by the at least one processor, cause the system to; instantiate a baseline, wherein the baseline comprises a set of assets, and a set of relationships including a first relationship; associate a first event stream with the baseline, wherein the first event stream comprises events including a first event, and each event comprises attributes; evaluate each event of the first event stream by performing evaluations corresponding to attributes in the set of relationships; and detect, based on the evaluating of the first event stream, a drift from the baseline, wherein the drift is based on a failure of at least one attribute value in the first event to match at least one attribute value of the first relationship. - View Dependent Claims (13, 14, 15, 16, 17)
-
-
18. A non-transitory, computer-readable medium storing instructions that, when executed, cause a computing device to:
-
instantiate a baseline, wherein the baseline comprises a set of assets, and a set of relationships including a first relationship; associate a first event stream with the baseline, wherein the first event stream comprises events including a first event, and each event comprises attributes; evaluate each event of the first event stream by performing evaluations corresponding to attributes in the set of relationships; and detect, based on the evaluating of the first event stream, a drift from the baseline, wherein the drift is based on a failure of at least one attribute value in the first event to match at least one attribute value of the first relationship. - View Dependent Claims (19, 20)
-
Specification