Invention Application
- Patent Title: DYNAMIC MONITORING, DETECTION OF EMERGING COMPUTER EVENTS
-
Application No.: PCT/US2020/023469Application Date: 2020-03-19
-
Publication No.: WO2020197897A1Publication Date: 2020-10-01
- Inventor: WILSON, Alexander James , NECKERMANN, Tom , VAN BRUGGEN, Simone
- Applicant: MICROSOFT TECHNOLOGY LICENSING, LLC
- Applicant Address: One Microsoft Way Redmond, Washington 98052-6399 US
- Assignee: MICROSOFT TECHNOLOGY LICENSING, LLC
- Current Assignee: MICROSOFT TECHNOLOGY LICENSING, LLC
- Current Assignee Address: One Microsoft Way Redmond, Washington 98052-6399 US
- Agency: MINHAS, Sandip S. et al.
- Priority: US16/367,152 20190327
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F21/55 ; H04L12/24
Abstract:
Technologies are provided for the monitoring, detection, and notification of emerging, related issues within a system, which may indicate a problem. Within a computing-security system, a sudden increase in the frequency of events associated with unauthorized logon attempts signal a real-time and ongoing security risk. A method monitors system-related events and generates a vector representation for each event based on event features. Clusters of related events are determined, and a state automaton is employed to determine a strength of temporal "bursty" activity for each cluster. Hypothesis testing is performed on each cluster to determine a likelihood that the cluster is a temporally emergent cluster. Clusters with a bursting likelihood above a threshold are determined to be an emergent cluster associated with an anomalous issue. A notification regarding the detected anomaly is provided. A remedial action addressing the anomaly is performed. Noisy clusters are filtered and aggregated based on their bursting likelihood and overlapping sub-spaces of the hyperspace.
Information query