The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Nov. 23, 2021

Filed:

Oct. 17, 2019
Applicant:

Vmware, Inc., Palo Alto, CA (US);

Inventors:

Ashot Nshan Harutyunyan, Yerevan, AM;

Arnak Poghosyan, Yerevan, AM;

Nicholas Kushmerick, Yerevan, AM;

Naira Movses Grigoryan, Yerevan, AM;

Assignee:

VMware, Inc., Palo Alto, CA (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
G06F 21/55 (2013.01); G06F 11/30 (2006.01); G06F 9/54 (2006.01); H04L 12/24 (2006.01); H04L 12/26 (2006.01);
U.S. Cl.
CPC ...
G06F 11/3072 (2013.01); G06F 9/542 (2013.01); G06F 11/3006 (2013.01); G06F 21/552 (2013.01); H04L 41/0681 (2013.01); H04L 41/0622 (2013.01); H04L 41/145 (2013.01); H04L 43/067 (2013.01);
Abstract

Automated methods and systems to determine a baseline event-type distribution of an event source and use the baseline event type distribution to detect changes in the behavior of the event source are described. In one implementation, blocks of event messages generated by the event source are collected and an event-type distribution is computed for each of block of event messages. Candidate baseline event-type distributions are determined from the event-type distributions. The candidate baseline event-type distribution has the largest entropy of the event-type distributions. A normal discrepancy radius of the event-type distributions is computed from the baseline event-type distribution and the event-type distributions. A block of run-time event messages generated by the event source is collected. A run-time event-type distribution is computed from the block of run-time event messages. When the run-time event-type distribution is outside the normal discrepancy radius, an alert is generated indicating abnormal behavior of the event source.


Find Patent Forward Citations

Loading…