发明名称 | Amplitude-based anomaly detection | ||
摘要 | Systems and methods are disclosed herein for identifying an anomaly in a signal, where samples in the signal correspond to an amount of data flow in a network within a time interval, and an anomaly corresponds to at least one sample in the discrete signal having a likelihood value below a likelihood threshold. A historical probability distribution of the discrete signal is generated based on previously received samples. For each sample in a plurality of samples in the discrete signal, a likelihood is computed based at least in part on the historical probability distribution. A likelihood threshold is selected, and a set of consecutive samples is identified as an anomaly when each sample in the set has a computed likelihood below the likelihood threshold. | ||
申请公布号 | US8806313(B1) | 申请公布日期 | 2014.08.12 |
申请号 | US201213480084 | 申请日期 | 2012.05.24 |
申请人 | Google Inc. | 发明人 | Yu Kevin;Xie Yu;Zhang Xinyi |
分类号 | G06F11/00 | 主分类号 | G06F11/00 |
代理机构 | Foley & Lardner LLP | 代理人 | Lanza John D.;Foley & Lardner LLP |
主权项 | 1. A method for identifying an anomaly in a discrete signal, wherein an anomaly corresponds to at least one sample in the discrete signal having a likelihood value below a likelihood threshold, comprising: generating, by a processor, a historical probability distribution of the discrete signal based on previously received samples, wherein samples in the discrete signal correspond to amounts of data flow in a network within a time interval; computing, by the processor, a likelihood for each sample in a plurality of samples in the discrete signal based at least in part on the historical probability distribution; selecting, by the processor, a likelihood threshold; and identifying, by the processor, a set of consecutive samples as an anomaly, wherein each sample in the set has a computed likelihood below the likelihood threshold. | ||
地址 | Mountain View CA US |