摘要 |
<p>A method and apparatus for profiling a flow of event data packets. The method comprises the steps of: receiving data defining sub-periods which partition a base time period, creating a profile of recent behaviour for each sub-period, and allocating each event data packet to one of the sub-periods according to a time indication associated with the event data packet. The method and apparatus may be used in anomaly detection within data streams and, in particular, account fraud detection where the event data relates to account usage.</p> |