The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Dec. 12, 2017

Filed:

Nov. 22, 2015
Applicant:

International Business Machines Corporation, Armonk, NY (US);

Inventors:

Ron Peleg, Tel-Aviv, IL;

Amir Ronen, Haifa, IL;

Tamer Salman, Haifa, IL;

Shmuel Regev, Tel-Aviv, IL;

Ehud Aharoni, Kfar Saba, IL;

Attorneys:
Primary Examiner:
Int. Cl.
CPC ...
G06F 21/52 (2013.01); G06F 21/55 (2013.01); G06F 21/56 (2013.01);
U.S. Cl.
CPC ...
G06F 21/52 (2013.01); G06F 21/554 (2013.01); G06F 21/566 (2013.01); G06F 2221/033 (2013.01);
Abstract

Detecting computer anomalies by determining probabilities of encountering call stack configurations at various depths, the call stacks being associated with software application instances on computers having the same operating system, where snapshots of the call stacks are recorded on the computers responsive to detecting predefined software application events, determining entropies of call stack configurations at various call stack depths using their associated probabilities, determining stack frame rarity scores of call stack configurations at various depths based on their associated stack frame entropies in accordance with a predefined rarity function, determining a call stack rarity score of any given call stack configuration as the maximum stack frame rarity score of the given configuration, and detecting an anomaly associated with any given one of the computers where any of the snapshots recorded on the given computer is of a call stack whose call stack rarity score meets a predefined anomaly condition.


Find Patent Forward Citations

Loading…