IP Library › Patent Application 11148472
Patent Application
App. No. 11/148,472

Runtime thresholds for behavior detection

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
11/148,472
Abstract

A computer based method and system for detecting behaviors from patterns of data where sets of thresholds and ranges used within detection scenarios can be created and applied while the system is in active operation. Data is received from at least one source, and an application environment is determined. A scenario including one or more parameterized patterns indicative of one or more behaviors is retrieved. One or more sets of parameters applicable to the one or more parameterized patterns are also retrieved. A parameter set is selected based on the application environment, and a dataset including a portion of the received data, one or more events, and one or more entities is formed. Detection processing is then performed by detecting one or more matches between the dataset and the parameterized patterns using the selected parameter set.

Claims (54)

1 . A computer based method for detecting a behavior, the method comprising:

receiving data from at least one source;

determining an application environment corresponding to the data;

retrieving a scenario, wherein the scenario comprises one or more parameterized patterns indicative of one or more behaviors;

retrieving one or more parameter sets applicable to the one or more parameterized patterns, wherein each parameter set comprises one or more parameters;

selecting one of the one or more parameter sets based on the application environment;

forming a dataset, wherein the dataset includes a portion of the received data, one or more events and one or more entities; and

detecting one or more matches between the dataset and the one or more parameterized patterns with the selected parameter set.

2 . The method of claim 1 wherein detecting one or more matches comprises:

performing sequence matching to identify sequences in the one or more events; and

relating those sequences to the one or more entities in the dataset.

3 . The method of claim 1 wherein detecting one or more matches comprises one or more of the following:

performing link analysis to establish connections between a plurality of entities and events in the dataset;

performing rule-based analysis to identify one or more entities and one or more events in the dataset based on rules specifying parameters and thresholds; and

performing outlier detection analysis to identify at least one event and at least one entity outside of a defined range.

4 . The method of claim 1 , further comprising:

generating one or more alerts based on the existence of one or more matches.

5 . The method of claim 1 , further comprising:

generating one or more reports based on the existence of one or more matches.

6 . A computer readable medium embodying program instructions for detecting a behavior, the computer readable medium comprising instructions for:

receiving data from at least one source;

determining an application environment corresponding to the data;

retrieving a scenario, wherein the scenario comprises one or more parameterized patterns indicative of one or more behaviors;

retrieving one or more parameter sets applicable to the one or more parameterized patterns, wherein each parameter set comprises one or more parameters;

selecting one of the one or more parameter sets based on the application environment;

forming a dataset, wherein the dataset includes a portion of the received data, one or more events and one or more entities; and

detecting one or more matches between the dataset and the one or more parameterized patterns with the selected parameter set.

7 . The computer readable medium of claim 6 wherein the detecting one or more matches comprises instructions for one or more of the following:

performing sequence matching to identify sequences in the one or more events in the dataset and relating those sequences to the one or more entities in the dataset;

performing link analysis to establish connections between a plurality of entities and events in the dataset;

performing rule-based analysis to identify one or more entities and one or more events in the dataset based on rules specifying parameters and thresholds; and

performing outlier detection analysis to identify at least one event and at least one entity outside of a defined range.

8 . The computer readable medium of claim 6 , further comprising instructions for:

generating one or more alerts based on the existence of one or more matches.

9 . The computer readable medium of claim 6 , further comprising instructions for:

generating one or more reports based on the existence of one or more matches.

10 . The computer readable medium of claim 6 wherein the medium comprises one or more of magnetic data storage disks, magnetic tape, alterable electronic read-only memory, non-alterable electronic read-only memory, electronic random-access memory, flash memory, optical storage devices, wired communication links, wired transmission media, wired propagated signal media, wireless communication links, wireless transmission media, and wireless propagated signal media.

11 . A system for detecting a behavior, the system comprising:

a processor having circuitry to execute instructions;

a communications interface, in communication with the processor, for receiving data from at least one source;

a memory, in communication with the processor, for storing instructions for:

determining an application environment corresponding to the data;

retrieving a scenario, wherein the scenario comprises one or more parameterized patterns indicative of one or more behaviors;

retrieving one or more parameter sets applicable to the one or more parameterized patterns, wherein each parameter set comprises one or more parameters;

selecting one of the one or more parameter sets based on the application environment;

forming a dataset, wherein the dataset includes a portion of the received data, one or more events and one or more entities; and

detecting one or more matches between the dataset and the one or more parameterized patterns with the selected parameter set.

12 . A method for configuring parameter sets for detection scenarios, the method comprising:

retrieving a base parameter set comprising one or more parameters for use in a detection scenario and a default value for each parameter;

generating one or more derived parameter sets, wherein each derived parameter set includes at least one parameter from the base parameter set;

setting at least one parameter in each derived parameter set to a value different than the default value for the corresponding parameter in the base parameter set; and

specifying, for each derived parameter set, an application environment to which the derived parameter set applies.

13 . The method of claim 12 wherein at least one parameter applies to a pattern defined in the detection scenario.

14 . The method of claim 12 wherein at least one parameter applies to a dataset defined in the detection scenario.

Assignments (3)
RELEASE OF SECURITY INTEREST Recorded Sep 6, 2006
From: COMERICA BANK
To: MANTAS, INC.
Reel/Frame 018211/0932 →
SECURITY AGREEMENT Recorded May 9, 2006
From: MANTAS, INC.
To: COMERICA BANK
Reel/Frame 017592/0740 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 9, 2005
From: BERK, MITCHELL F.; SALMON, SETH P.; AGGARWAL, VINEET K.
To: MANTAS, INC.
Reel/Frame 016680/0159 →