The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Dec. 24, 2013

Filed:

Jun. 19, 2008
Applicants:

Marc Dacier, Mouans Sartoux, FR;

Klaus Julisch, Kilchberg, CH;

Inventors:

Marc Dacier, Mouans Sartoux, FR;

Klaus Julisch, Kilchberg, CH;

Attorneys:
Primary Examiner:
Assistant Examiner:
Int. Cl.
CPC ...
G06F 11/00 (2006.01); G06N 5/00 (2006.01); G06N 5/02 (2006.01);
U.S. Cl.
CPC ...
Abstract

A method and system is designed for processing alarms, that have been triggered by a monitoring system such as an intrusion detection system, a firewall, or a network management system, comprising the steps of entering the triggered alarms into an alarm log, evaluating similarity between alarms, grouping similar alarms into alarm clusters, summarizing alarm clusters by means of generalized alarms, counting the covered alarms for each generalized alarm and forwarding generalized alarms for further processing if the number of alarms covered satisfies a predetermined criterion. In the event of high rates of alarm messages, possibly containing many false alarms, a system administrator will therefore not be confronted with a flood of messages with little significance. Instead, only generalized alarms, more meaningful and smaller in number, are presented. The method can further comprise copying the alarm log to a cluster log and for each generalized alarm in the cluster log counting the number of covered alarms that are identical to the generalized alarm or more specific than the generalized alarm, and, if the number of covered alarms exceeds a predetermined minimum number, then terminating the loop. A heuristic is used to select an attribute of the alarms of the cluster log and for each alarm thereof the selected attribute is replaced by a more general attribute. A taxonomy on the attributes can be used to define the similarity between the alarms. The forwarded generalized alarm can furthermore be investigated in order to identify a root cause.


Find Patent Forward Citations

Loading…