发明名称 Field selection for pattern discovery
摘要 Fields are determined for pattern discovery in event data. Cardinality and repetitiveness statistics are determined for fields of event data. A set of the fields are selected based on the cardinality and repetitiveness for the fields. The fields may be included in a pattern discovery profile.
申请公布号 US9531755(B2) 申请公布日期 2016.12.27
申请号 US201214398003 申请日期 2012.05.30
申请人 HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP 发明人 Singla Anurag;Zhao Zhipeng
分类号 G06F17/30;H04L29/06;G06F21/55 主分类号 G06F17/30
代理机构 Mannava & Kang, P.C. 代理人 Mannava & Kang, P.C.
主权项 1. A method for determining fields for a pattern discovery profile, the method comprising: receiving, by a computing device comprising a hardware processor that implements machine readable instructions, a stream of event data; determining a threshold cardinality and a threshold repetitiveness for each of a plurality of fields of the event data, based on a global summary of the event data; determining cardinality and repetitiveness for each of the plurality of fields of the event data; selecting, by the computing device, a set of fields among the plurality of fields based on the determined cardinality, the determined repetitiveness, the determined threshold cardinality, and the determined threshold repetitiveness; including the set of fields in a pattern discovery profile; and detecting malicious activity in the event data using the pattern discovery profile, wherein selecting the set of fields comprises selecting a pattern identification field and a plurality of transaction fields based on the determined cardinality and repetitiveness, and wherein selecting the plurality of transaction fields comprises selecting, from the plurality of fields, a source field and a destination field having a combined cardinality and repetitiveness that satisfy the threshold cardinality and the threshold repetitiveness.
地址 Houston TX US