Scalable automated detection of functional behavior
US10642676B2 · kind B2 · utility
Assignee
Inventors
Key dates
| Filing date | May 11, 2017 |
| Grant date | May 5, 2020 |
| Priority date | — |
| Expiry date | Mar 19, 2038 |
Classification
- Technology area (CPC G)Physics
- CPC primaryG06F11/0778
- WIPO fieldComputer technology
- WIPO sectorElectrical engineering
Abstract
A behavior detection system has access to a collection of behavior definitions that each describe a functional behavior of a system. Each behavior definition includes multiple basic operations, each of which includes an identifier and one or more parameters. The behavior definition also includes, explicitly or inherently, a basic operation combination definition that describes a sequence or other manner in which the basic operations are combined. The behavior detection system analyzes events in an event log for the system and determines whether the events in the event log satisfy any of the behavior definitions. An appropriate responsive action is taken in response to detecting that the events in the event log satisfy a behavior definition. The collection of behavior definitions is scalable, allowing behavior definitions to be added or deleted, and allowing basic operations in a behavior definition to be changed (e.g., adding, removing, and/or modifying basic operation parameters).
Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.