System event analyzer and outlier visualization
US-9794158-B2 · Oct 17, 2017 · US
US10885185B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-10885185-B2 |
| Application number | US-201816161564-A |
| Country | US |
| Kind code | B2 |
| Filing date | Oct 16, 2018 |
| Priority date | Oct 24, 2017 |
| Publication date | Jan 5, 2021 |
| Grant date | Jan 5, 2021 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
A computer-implemented method for implementing alert interpretation in enterprise security systems is presented. The computer-implemented method includes employing a plurality of sensors to monitor streaming data from a plurality of computing devices, generating alerts based on the monitored streaming data, automatically analyzing the alerts, in real-time, by using a graph-based alert interpretation engine employing process-star graph models, retrieving a cause of the alerts, an aftermath of the alerts, and baselines for the alert interpretation, and integrating the cause of the alerts, the aftermath of the alerts, and the baselines to output an alert interpretation graph to a user interface of a user device.
Opening claim text (preview).
What is claimed is: 1. A computer-implemented method executed on a processor for implementing alert interpretation in enterprise security systems, the method comprising: employing a plurality of sensors to monitor streaming data from a plurality of computing devices; generating alerts based on the monitored streaming data; automatically analyzing the alerts by using a graph-based alert interpretation engine employing process-star graph models; retrieving a cause of the alerts, an aftermath of the alerts, and baselines for the alert interpretation; and integrating the cause of the alerts, the aftermath of the alerts, and the baselines into an alert interpretation graph output to a user interface of a user device, wherein, when an alert is detected pertaining to a computing device of the plurality of computing devices, the graph-based alert interpretation engine matches the detected alert to a corresponding process-star graph and retrieves related entities; wherein the graph-based alert interpretation engine computes an abnormal score for each entity of the related entities; wherein the graph-based alert interpretation engine selects the entity with a highest score as an alert cause; wherein the graph-based alert interpretation engine retrieves historical normal activities as the baselines; wherein the graph-based alert interpretation engine traces following events on further incoming streaming data; wherein the alert cause can be determined based on entity seniority, entity stability, and entity similarity; and wherein the entity seniority is computed by ρ ( o ) = { t - t 0 T if t - t 0 < T 1 if t - t 0 ≥ T , the entity stability is computed by σ ( v ) = Count ( T stable ) Count ( T ) , and the entity similarity is computed by γ src ( o 1 , o 2 ) = dst ( o 1 ) ⋂ dst ( o 2 ) dst ( o 1 ) ⋃ dst ( o 2 ) and γ dst ( o 1 , o 2 ) = src ( o 1 )
involving logical or physical relationship, e.g. grouping and hierarchies · CPC title
comprising specially adapted graphical user interfaces [GUI] · CPC title
using statistical or mathematical methods · CPC title
Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities · CPC title
involving long-term monitoring or reporting · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.