发明名称 |
Graph structures for event matching |
摘要 |
A system for matching a system event to a rule is disclosed. The system includes a computer-readable data structure comprising a plurality of system event rules organizable as a partially ordered set. The system also includes a processor configured to analyze the computer-readable data structure to determine whether an event matches a description set of at least one rule from the plurality of system event rules. Methods and machine-readable mediums are also disclosed. |
申请公布号 |
US9413598(B2) |
申请公布日期 |
2016.08.09 |
申请号 |
US200912553040 |
申请日期 |
2009.09.02 |
申请人 |
International Business Machines Corporation |
发明人 |
Stakhanova Natalia;Ghorbani Ali-akbar;Bird William |
分类号 |
H04L29/06;H04L12/24;G06F21/55 |
主分类号 |
H04L29/06 |
代理机构 |
|
代理人 |
Lammes Francis;Walder, Jr. Stephen J.;Zarick Gail |
主权项 |
1. A system for matching a system event to a rule, the system comprising:
a computer-readable data structure comprising a plurality of system event rules organized as a graph having a plurality of nodes, at least one node corresponding to a field in a rule and having a weight value; a processor configured to analyze the computer-readable data structure to determine whether an event comprising at least one field matches a description set of at least one rule from the plurality of system event rules by:
for a node in the graph, comparing the field corresponding to the node to each field in the event;in the event of a match between the compared fields, adding the field to a list of matches; andsorting the list of matching fields according to the weight associated with each matching field. |
地址 |
Armonk NY US |