Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

23 results about "Anomalous behavior" patented technology

Detecting anomalous behavior of nodes in a hierarchical cloud deployment

Detecting anomalous behavior of nodes in a hierarchical cloud deployment, including: gathering data describing a cloud deployment as a hierarchy of a plurality of nodes; presenting a graph depicting behavior at a particular hierarchical level of at least a subset of the plurality of nodes; and determining whether behavior associated with a particular node deviates from normal behavior based on a hierarchical portion of plurality of nodes including the particular node.
Owner:FORTINET INC

Systems, methods, and graphical user interfaces for detecting and explaining anomalous behavior in a deployed ai application

ActiveUS20250370908A1Error detection/correctionSoftware engineeringAnomalous behavior
A system, method, and computer-program product includes obtaining, via an application programming interface (API), a test object that includes application usage data of a deployed AI application for a target time span, executing, in real-time by one or more computer processors, one or more application behavior tests that assess an operational behavior of the deployed AI application, detecting, by the one or more computer processors, that a misbehavior occurred in the deployed AI application during the target time span and one or more deviant features contributing to the misbehavior in response to executing the one or more application behavior tests, and returning, by the one or more computer processors, the one or more deviant features contributing to the misbehavior to a subscribing entity associated with the deployed AI application.
Owner:DISTRIBUTIONAL INC

Detection of anomalous computing environment behavior using glucose

Detection of anomalous computing environment behavior using glucose is described. An anomaly detection system receives glucose measurements and event records during a first time period. Missing events that are missing from the event records during the first time period are identified by processing the glucose measurements using an event engine simulator. An anomaly detection model is generated based on the missing events during the first time period. Subsequently, the anomaly detection system receives additional glucose measurements and additional event records during a second time period. Missing events that are missing from the additional event records during the second time period are identified by processing the additional glucose measurements using the event engine simulator. Anomalous behavior is detected if the identified missing events that are missing from the event records during the second time period are outside a predicted range of missing events of the anomaly detection model.
Owner:DEXCOM INC

An abnormal behavior detection method, device, equipment and storage medium

The application relates to an abnormal behavior detection method, device and equipment and a storage medium. The method comprises the following steps: acquiring a process operation behavior sequence, dividing the process operation behavior sequence into a plurality of to-be-detected sequences, each to-be-detected sequence comprising a plurality of user process operation behaviors, and each user process operation behavior comprising a plurality of field information; performing feature extraction based on the attribute values of the plurality of field information of each process operation behavior in the to-be-detected sequence to obtain a feature vector corresponding to the to-be-detected sequence; performing abnormality detection on the feature vectors corresponding to the to-be-detected sequences, determining an abnormal feature vector as a feature vector detected as abnormal; determining the abnormality degrees of each dimension feature in the abnormal feature vector; determining the feature items existing in the abnormal feature vector based on the abnormality degrees of each dimension feature in the abnormal feature vector; and the application can improve the accuracy and efficiency of user abnormal behavior detection.
Owner:TENCENT TECHNOLOGY (SHENZHEN) CO LTD

System and method to determine anomalous behavior

ActiveUS12505638B2Image enhancementImage analysisPattern recognitionAnomalous behavior
The present disclosure relates to a system for determining anomalous behavior. The system comprises a processing device that is configured to generate first segmentation information and second segmentation information from the video feed, the first segmentation information corresponding to a first potential occupant and the second segmentation information corresponding to a second potential occupant. The processing device further configured to determine that the first segmentation information and the second segmentation information correspond to actual occupants based on the first segmentation information and the second segmentation information, and generate a first bounding box associated with the first segmentation information and a second bounding box associated with the second segmentation information. The processing device further configured to determine an intersection over union (IOU) region for the first bounding box and the second bounding box, identify anomalous behavior based on the IOU region, and generate one or more alerts identifying the anomalous behavior.
Owner:SENSORMATIC ELECTRONICS CORP

Detecting and mitigating system anomalies using knowledge graphs

ActiveUS12574397B2Securing communicationTheoretical computer scienceAnomalous behavior
Detecting and mitigating anomalous system behavior by providing a machine learning model comprising a knowledge graph depicting system entity relationships, and modeling behavioral correlations among system entities according to historical time-series data, receiving real-time time-series data for the system, detecting an anomalous system behavior in a system locale, according to the real-time time-series data, according to the machine learning model and multivariate sensor metrics, diagnosing the anomalous system behavior according to an upstream portion of the knowledge graph and a statistical behavior model for the system locale, and mitigating the anomalous behavior by deriving a recommended action according to the anomalous behavior and generating a work order to implement the recommended action.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Method and system for detecting anomalous behavior in stream data

A method and a system for detecting an anomalous sequence of events in stream data are provided. The method includes: receiving a first set of raw data; analyzing the first set of raw data in order to determine a first event sequence; applying a first Hidden Markov Model (HMM) to the first event sequence in order to generate a first output; and determining, based on the first output, whether the first event sequence is classifiable as being an anomalous event sequence. The HMM is trained by using known sequences of normal events and event sequences that are known to be anomalous.
Owner:JPMORGAN CHASE BANK NA

Device anomaly detection method and apparatus, storage medium, and program product

PendingCN122365227AAnomaly detectionAnomalous behavior
This application provides a method, apparatus, storage medium, and program product for detecting equipment anomalies, relating to the field of computer technology, and is used to improve the accuracy of equipment anomaly detection. The method includes: acquiring the current operating indicators and current behavioral characteristics of the device under test; determining the current load mode of the device under test based on the current operating indicators, and determining anomaly detection conditions matching the current load mode, the anomaly detection conditions being used to determine whether the operating indicators are abnormal; and, if the current operating indicators meet the anomaly detection conditions, determining anomaly risk information of the device under test based on the abnormal operating indicators in the current operating indicators and the abnormal behavioral characteristics in the current behavioral characteristics, the anomaly risk information being used to indicate whether the device under test is abnormal.
Owner:CHINA MOBILE COMM GRP CO LTD

Using Artificial Intelligence to Identify Anomalous Behavior in a Distributed Ledger

PendingUS20260019446A1Securing communicationAttackAnomalous behavior
Activity of a blockchain in a distributed ledger is monitored by an AI algorithm to identify anomalous behavior in the distributed ledger. The anomalous behavior of the distributed ledger can comprise one or more of: an anomalous consensus vote of the distributed ledger; an anomalous activity of a mempool of the distributed ledger; a denial-of-service attack on the mempool of the distributed ledger; an anomalous change of information stored in the blockchain of the distributed ledger; and an anomalous voting time for a node in the distributed ledger. Detection of these types of anomalous behavior can be used to prevent attacks on the blockchain, thus contributing to the overall integrity and security of the blockchain.
Owner:MICRO FOCUS LLC

Systems and methods budget-constrained sensor network design for distribution networks

A system provides the minimum number of sensors that will be needed to uniquely identify locations where anomalous behavior is sensed that can be deployed within the specified budget. The system applies an Integer Linear Programming formulation and a Maximum Set-Group Cover (MSGC) formulation. One implementation of the system is applied to detect contaminants in a water distribution system.
Owner:THE ARIZONA BOARD OF REGENTS ON BEHALF OF THE UNIV OF ARIZONA

Abnormal behavior detection method and device and electronic equipment

The embodiment of the invention discloses an abnormal behavior detection method and device and electronic equipment. The scheme comprises the following steps: acquiring to-be-detected behavior data of a target user, and acquiring a target behavior feature data set according to the to-be-detected behavior data; carrying out anomaly detection by adopting an isolation forest algorithm to obtain a first detection result, and carrying out anomaly detection by adopting a local anomaly factor algorithm to obtain a second detection result; obtaining an individual abnormal behavior detection result according to the first detection result and the second detection result; and performing anomaly detection by adopting a graph behavior analysis algorithm in response to that the individual abnormal behavior detection result is abnormal, and obtaining a group abnormal behavior detection result. According to the embodiment of the invention, the isolation forest algorithm, the local abnormal factor algorithm and the graph behavior analysis algorithm are effectively combined, double accurate detection of individual abnormal behaviors and group abnormal behaviors is realized through multi-level abnormal detection, and the accuracy, reliability and flexibility of an abnormal behavior detection process are improved.
Owner:CHINA MOBILE INTERNET CO LTD +1

Anomalous network behaviour identification

ActiveUS12676872B2SimulationAnomalous behavior
A computer implemented method of identifying anomalous behavior of a computer system in a set of intercommunicating computer systems can include monitoring communication between computer systems in the set to generate, for each of a first and second plurality of time periods, with a first and second duration respectively, a first and a second vector representation of each of the computer systems. First vector representations corresponding to different respective ones of the first plurality of time periods are compared to identify behavior of a target computer system at a first temporal resolution. Second vector representations corresponding to different respective ones of the second plurality of time periods are compared to identify behavior of the target computer system at a second temporal resolution. Based on the behavior at one or more of the first and second temporal resolutions, anomalous behavior of the target computer system is identified.
Owner:BRITISH TELECOM PLC

Federated abnormal process detection for kubernetes clusters

A baseline of behavior is received for a set of containers utilized by the Kubernetes manager from a cluster agent. The processes running on the set containers and network traffic generated by the set of containers, to identify anomalous behavior relative to the baseline. Subsequent to the container updates, and responsive to detecting the anomalous behavior exceeds a threshold for a specific container, anomalous data is sent to the cluster agent including an identification and version of the specific container and a description of abnormal behavior. The cluster agent determines a new rule is necessary to define the new behavior and distributes the new rule to the plurality of Kubernetes managers that are affected.
Owner:FORTINET INC

Abnormal behavior detection method and device, equipment, medium and program product

PendingCN121786337ANeural learning methodsSoftware engineeringAnomalous behavior
The invention provides an abnormal behavior detection method and device, equipment, a medium and a program product, and relates to the technical field of cloud computing, and the method comprises the steps: constructing an abnormal behavior feature data set based on a behavior template and sampling data, and obtaining a data consanguinity training set and user behavior attention model data based on the sampling data; based on the abnormal behavior feature data set, processing a data consanguinity training set and user behavior attention model data meeting a preset condition to construct an abnormal behavior information training set; performing feature processing on the abnormal behavior information training set and the baseline template knowledge base to obtain target feature data, inputting the target feature data into a large language model to generate an initial abnormal behavior baseline, and sending the initial abnormal behavior baseline to a data security agent for storage; and obtaining a target baseline passing through the data security intelligent experience certificate, and performing abnormal behavior detection based on the target baseline.
Owner:CHINA MOBILE GROUP JIANGSU +1

Method and system for automatically detecting anomalies in data

ActiveCN114270332BDatabase updatingHardware monitoringAnomalous behaviorTimestamping
A method and system for detecting anomalous transition point candidates in performance metadata. The method can be used in computer system performance monitoring. Anomalous candidates are identified that indicate a possible transition to or from an anomalous behavior pattern in a process that generated the performance metadata, e.g., by comparing z-scores on the left and right of various timestamps, and identifying anomalous candidates when the z-scores are significantly different. Anomalous candidates occur individually, not as endpoints of anomalous intervals. For at least one of the anomalous candidates, an explanatory predicate can be generated that indicates a human-readable explanation of the behavior of the process. A set of anomalies can then be filtered, e.g., by removing those that do not have explanatory predicates, or replacing a cluster of anomalies with the most relevant one.
Owner:HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD

An abnormal behavior detection method, device, equipment, medium and product

The application discloses a method, device, equipment, medium and product for detecting abnormal behavior, and applies to the field of data security. In the case that the first actual behavior is determined as an abnormal behavior, the first sliding window corresponding to the next second actual behavior is determined. Then, the second behavior sequence segment in the first sliding window is input into the pre-constructed reconstruction network for abnormal detection. In the case that the second behavior sequence segment is abnormal, the first sliding window is slid backward by one behavior on the historical behavior sequence, and the above reconstruction detection step is returned until the second behavior sequence segment is normal. Through the reconstruction network, the abnormal behavior existing after the first actual behavior is efficiently found out, the part actually existing the abnormality can be accurately positioned from the whole historical behavior sequence, and through the processing on the second behavior sequence segment, the rich context and semantic information are possessed, and the hidden abnormal behavior can be detected.
Owner:CHINA MOBILE INFORMATION TECHNOLOGY CO LTD +1

System and method for identifying anomalous behavior in electrical devices plugged into a smart socket

PendingUS20250389760A1Electric devicesElectrical testingElectrical devicesAnomalous behavior
Anomalous behavior of an appliance plugged into a smart socket may be identified. A baseline appliance profile is identified for the appliance plugged into the smart socket, based at least in part on the current and the voltage sampled at each of a plurality of sample times. An operational profile is identified based at least in part on the current and the voltage sampled during an operational time period. The operational profile of the appliance is compared to the baseline appliance profile, and an anomalous behavior in the operation of the appliance is detected and / or predicted based at least in part on the comparison of the operational profile of the appliance to the baseline appliance profile. Action may be taken in response to detecting and / or predicting the anomalous behavior in the operation of an appliance.
Owner:HONEYWELL INTERNATIONAL INC

Method of threat detection in a threat detection network and threat detection network

PendingUS20260129059A1Computer security arrangementsArtificial lifeAnomalous behaviorEngineering
A network node of a threat detection network, a backend server of a threat detection network, a threat detection network and a threat detection method in a threat detection network. The threat detection network comprises interconnected network nodes and a backend system, wherein at least part of the nodes comprise security agent modules which collect data related to the respective network node. The method comprises collecting and / or analyzing at the network node data related to a network node, generating at least one local behavior model at the network node related to the network node on the basis of the collected and / or analyzed data, sharing at least one generated local behavior model related to the network node with one or more other nodes and / or with the backend system, comparing user activity in a node to the generated local behavior model and / or a received behavior model, and alerting the backend and / or the other nodes, e.g. about anomalous behavior, if deviation from the generated local behavior model and / or the received behavior model is detected, and / or comparing at the backend system the anomalous data with other behavior models, e.g. with other behavior models in the same organization and / or behavior models of known malicious users, and sending from the backend system to the node results and / or data relating to the comparison.
Owner:F SECURE CORP

Root cause detection of anomalous behavior using network relationships and event correlation

ActiveUS12640978B2Mathematical modelsMachine learningTicketAnomalous behavior
A node detects an alert corresponding to an anomalous event during a time period. The alert is correlated with previously detected alerts occurring within the time period and a causal relationship associated with nodes in the networked computing environment. The node may then recursively identify a root cause of the anomalous event detected in the networked computing environment based on a set of correlated alerts. An incident ticket may then be sent to the node identified as the root cause of the anomalous event, and the node may notify other nodes in the network having a causal relationship with the node of the anomalous event.
Owner:STATE FARM MUTAL AUTOMOBILE INSURANCE COMPANY

System and method for detection of proxy server key performance indicators (KPI) deterioration, alerting and mitigation

A computing platform may train, using historical application programming interface (API) call information, an anomaly detection engine, to output, for a target system, a binary value indicating whether or not the target system is experiencing anomalous API call behavior, where the target system includes a proxy server. The computing platform may monitor the target system to collect API call information for the proxy server. The computing platform may input the API call information into the anomaly detection engine, which may output, based on the API call information, a binary value indicating whether the API call information. The computing platform may compare the binary value to a predetermined threshold value. Based on identifying that the selected binary value is less than the predetermined threshold value, the computing platform may label the target system as experiencing anomalous behavior. The computing platform may execute corrective actions to address the anomalous behavior.
Owner:BANK OF AMERICA CORP

Systems, methods, and graphical user interfaces for detecting and explaining anomalous behavior in a deployed AI application

A system, method, and computer-program product includes obtaining, via an application programming interface (API), a test object that includes application usage data of a deployed AI application for a target time span, executing, in real-time by one or more computer processors, one or more application behavior tests that assess an operational behavior of the deployed AI application, detecting, by the one or more computer processors, that a misbehavior occurred in the deployed AI application during the target time span and one or more deviant features contributing to the misbehavior in response to executing the one or more application behavior tests, and returning, by the one or more computer processors, the one or more deviant features contributing to the misbehavior to a subscribing entity associated with the deployed AI application.
Owner:DISTRIBUTIONAL INC