Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

5 results about "Anomalous behavior" patented technology

An abnormal behavior detection method, device, equipment and storage medium

The application relates to an abnormal behavior detection method, device and equipment and a storage medium. The method comprises the following steps: acquiring a process operation behavior sequence, dividing the process operation behavior sequence into a plurality of to-be-detected sequences, each to-be-detected sequence comprising a plurality of user process operation behaviors, and each user process operation behavior comprising a plurality of field information; performing feature extraction based on the attribute values of the plurality of field information of each process operation behavior in the to-be-detected sequence to obtain a feature vector corresponding to the to-be-detected sequence; performing abnormality detection on the feature vectors corresponding to the to-be-detected sequences, determining an abnormal feature vector as a feature vector detected as abnormal; determining the abnormality degrees of each dimension feature in the abnormal feature vector; determining the feature items existing in the abnormal feature vector based on the abnormality degrees of each dimension feature in the abnormal feature vector; and the application can improve the accuracy and efficiency of user abnormal behavior detection.
Owner:TENCENT TECHNOLOGY (SHENZHEN) CO LTD

Device anomaly detection method and apparatus, storage medium, and program product

PendingCN122365227AAnomaly detectionAnomalous behavior
This application provides a method, apparatus, storage medium, and program product for detecting equipment anomalies, relating to the field of computer technology, and is used to improve the accuracy of equipment anomaly detection. The method includes: acquiring the current operating indicators and current behavioral characteristics of the device under test; determining the current load mode of the device under test based on the current operating indicators, and determining anomaly detection conditions matching the current load mode, the anomaly detection conditions being used to determine whether the operating indicators are abnormal; and, if the current operating indicators meet the anomaly detection conditions, determining anomaly risk information of the device under test based on the abnormal operating indicators in the current operating indicators and the abnormal behavioral characteristics in the current behavioral characteristics, the anomaly risk information being used to indicate whether the device under test is abnormal.
Owner:CHINA MOBILE COMM GRP CO LTD

Anomalous network behaviour identification

ActiveUS12676872B2SimulationAnomalous behavior
A computer implemented method of identifying anomalous behavior of a computer system in a set of intercommunicating computer systems can include monitoring communication between computer systems in the set to generate, for each of a first and second plurality of time periods, with a first and second duration respectively, a first and a second vector representation of each of the computer systems. First vector representations corresponding to different respective ones of the first plurality of time periods are compared to identify behavior of a target computer system at a first temporal resolution. Second vector representations corresponding to different respective ones of the second plurality of time periods are compared to identify behavior of the target computer system at a second temporal resolution. Based on the behavior at one or more of the first and second temporal resolutions, anomalous behavior of the target computer system is identified.
Owner:BRITISH TELECOM PLC

Root cause detection of anomalous behavior using network relationships and event correlation

ActiveUS12640978B2Mathematical modelsMachine learningTicketAnomalous behavior
A node detects an alert corresponding to an anomalous event during a time period. The alert is correlated with previously detected alerts occurring within the time period and a causal relationship associated with nodes in the networked computing environment. The node may then recursively identify a root cause of the anomalous event detected in the networked computing environment based on a set of correlated alerts. An incident ticket may then be sent to the node identified as the root cause of the anomalous event, and the node may notify other nodes in the network having a causal relationship with the node of the anomalous event.
Owner:STATE FARM MUTAL AUTOMOBILE INSURANCE COMPANY