Invention Grant
- Patent Title: Detecting and responding to an anomaly in an event log
-
Application No.: US16522005Application Date: 2019-07-25
-
Publication No.: US11237897B2Publication Date: 2022-02-01
- Inventor: Aankur Bhatia , Chadwick M. Baatz , Gary I. Givental , Thomas Wallace , Srinivas B. Tummalapenta
- Applicant: International Business Machines Corporation
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agent Stephen J. Walder, Jr.; Jeffrey S. LaBaw
- Main IPC: G06F11/00
- IPC: G06F11/00 ; G06F11/07 ; G06N20/00 ; G06K9/62

Abstract:
A method identifies and prioritizes anomalies in received monitoring logs from an endpoint log source. One or more processors identify anomalies in the monitoring logs by applying a plurality of disparate types of anomaly detection algorithms to the monitoring logs, and then determine a likelihood that the identified anomalies are anomalous based on outputs of the plurality of disparate types of anomaly detection algorithms. The processor(s) then prioritize the monitoring logs based on the likelihood that the identified anomalies are actually anomalous, and send prioritized monitoring logs that exceed a priority level to a security information and event management system (SIEM).
Public/Granted literature
- US20210026722A1 DETECTING AND RESPONDING TO AN ANOMALY IN AN EVENT LOG Public/Granted day:2021-01-28
Information query