Data processing: artificial intelligence – Knowledge processing system
Reexamination Certificate
2005-05-03
2005-05-03
Knight, Anthony (Department: 2121)
Data processing: artificial intelligence
Knowledge processing system
C706S046000, C706S047000
Reexamination Certificate
active
06889218
ABSTRACT:
A computerized method, encoded on a computer-readable medium, of detecting anomalies in an event stream. The method comprises at least two acts. In a first act, the method uses a tree structure to extract a grammar having an associated set of rules, from a sample of normal behavior. In a second act, the method checks an event stream against the rules of the grammar to detect anomalies.
REFERENCES:
patent: 5440723 (1995-08-01), Arnold et al.
patent: 5699507 (1997-12-01), Goodnow et al.
patent: 5953006 (1999-09-01), Baker et al.
patent: 6401088 (2002-06-01), Jagadish et al.
patent: WO 9215954 (1992-09-01), None
McCreight, E., A Space-Economical Suffix Tree Construction Algorithm, Apr. 1976, ACM Press, vol. 23 Issue 2, p. 262-72.*
Rodeh, M. et al, Linear Algorithm for Data Compression via String Matching, Jan. 1981, ACM Press, vol. 28 Issue 1, p. 16-24.*
Wojciech, S., (Un)expected Behavior of Typical Suffix Trees, 1992, Society for Industrial and Applied Mathematics, p. 422-431.*
Teng et al., Security Audit Trail Analysis Using Inductively Generated Predictive Rules, 1990, IEEE Journal, p. 24.*
Apostolic A. et al., Structural Properties of the String Statistics Problem, Journal of Computer and Systems Sciences, vol. 31 No. 2, p. 394-411.*
Chen, K., An Inductive Engine for the Acquisition of Temporal Knowledge, Ph. D. Thesis, Dept. of CS at Univ. of Illinois at Urbana-Champaign, 1988.*
Vaccaro, H.S. and Liepins, G.E., Detection of Anomalous Computer Session Activity, 1989, IEEE Symp. On Res. in Sec. & Privacy, p. 280-89.*
Aho, A.V. and Corasick, M.J., Efficient String Matching: an aid to Bibliographic Search, Jun. 1975, Communications of the ACM, vol. 18 No. 6, p. 333-40.
Herzberg Louis P.
Holmes Michael B.
Knight Anthony
Scully Scott Murphy & Presser
LandOfFree
Anomaly detection method does not yet have a rating. At this time, there are no reviews or comments for this patent.
If you have personal experience with Anomaly detection method, we encourage you to share that experience with our LandOfFree.com community. Your opinion is very important and Anomaly detection method will most certainly appreciate the feedback.
Profile ID: LFUS-PAI-O-3384408