Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

449 results about "Event sequence" patented technology

Cloud mobile phone end-to-end performance tracking method and related equipment

The invention discloses a cloud mobile phone end-to-end performance tracking method and related equipment, and relates to the technical field of cloud computing, and the method comprises the steps: obtaining client touch event data and network event data, and generating a global unique identifier based on a preset Hash algorithm; obtaining server resource event data; performing timestamp calibration on the client touch event data and the server resource event data based on a hardware-level clock synchronization and software compensation algorithm to generate a synchronous timestamp; based on the synchronization timestamp, aligning the event sequences of the client and the server through a dynamic time warping algorithm to generate an aligned event sequence; performing causal probability calculation on the aligned event sequence based on a Bayesian network model, and determining a causal relationship weight between resource events; and performing root cause matching according to the causal relationship weight and a preset abnormal mode library, generating a root cause list with priority ranking, and triggering execution of a self-healing strategy.
Owner:启朔(深圳)科技有限公司

Abnormal behavior intelligent identification and pre-control disposal system for key places

The invention discloses a key place-oriented abnormal behavior intelligent identification and pre-processing system, which is characterized in that a preliminary abnormal event sequence is generated by collecting multi-modal environment data, the preliminary abnormal event sequence and a preset scene knowledge graph are subjected to semantic fusion to form composite abnormal event description information, and then a dynamic processing plan is generated based on large language model reasoning; the central scheduling agent is decomposed into a cooperative control instruction set to drive the video analysis agent, the broadcast grooming agent and the security and disinfection linkage agent to execute cooperative processing operation, situation evolution information is generated in a shared event canvas through environment feedback data, and dynamic optimization and adjustment of a processing strategy are achieved. According to the system, the whole process intelligence of the abnormal event from identification to disposal is realized, the semantic understanding ability of the system to a complex scene and the multi-agent collaborative response efficiency are improved, and the pertinence and the adaptive adjustment ability of a disposal plan are enhanced.
Owner:FUJIAN HENGFENG ANXIN TECH CO LTD

Artificial intelligence system for anomalous activity detection using static and dynamic covariates

A training data set which includes event sequences representing actions of respective users of an application, properties of the users, and dynamic attributes associated with events such as the elapsed time between successive events, is prepared. A machine learning model which provides probabilistic predictions of next events of input event sequences is trained using the training data set. A trained version of the model is stored.
Owner:AMAZON TECH INC

Intelligent factory management method and system based on industrial internet

The invention provides an intelligent factory management method and system based on the industrial internet, and the method comprises the steps: obtaining original data of a multi-source heterogeneous device, and generating a semantic event structure through preprocessing; the industrial event sequence is mapped into nodes, candidate edges are generated in combination with the physical topology connection relation of the equipment, and a target causal map is constructed; according to the target causal atlas, calculating a node risk score of each event node, and performing balance adjustment on the score by using a graph-level centrality value to generate a normalized node risk score of each event node; mapping the node risk scores to devices, and calculating a risk average value of each device; and converting a scoring matrix of the current task to all candidate devices into a scheduling strategy value, executing a scheduling strategy and collecting task execution feedback, and dynamically adjusting a target causal atlas and a node risk score according to the difference between an actual result and a predicted value to realize dual optimization of the target causal atlas and the scheduling strategy.
Owner:SHENZHEN JIANAN RUNXING SAFETY TECH CO LTD

Resource recommendation method, device and equipment based on small enterprise dynamic portraits and medium

The invention relates to a resource recommendation method and device based on a small enterprise dynamic portrait, equipment and a medium. According to the method, key events are extracted from enterprise multi-dimensional data and standardized to form an initial event sequence, importance scores are calculated based on frequency and weight, and a core event set is generated through self-adaptive filtering; according to the timestamps and the semantic features, calculating dependency strength among events, and constructing a causal event relation graph; learning event embedding and time sequence characteristics by using a graph neural network and a gating loop unit, and generating a dynamic portrait vector; analyzing a historical event influence weight through an attention mechanism to predict future demand distribution; the resource urgency degree and the matching degree are optimized in combination with enterprise capability constraints, and a prospective recommendation list is generated; and a closed loop is formed by predicting deviation to trigger incremental updating of the atlas and retraining the model. Finally, the dynamic capture of the development trajectory and the accurate pre-judgment of the resource demand are realized, and the recommendation timeliness and the service suitability are remarkably improved.
Owner:QIQIYING TECHNOLOGY CO LTD

Systems and methods for detecting malicious activity using a machine learning model tuned to a specific endpoint device

Disclosed herein are systems and method for detecting malicious activity using a tuned machine learning model. In one aspect, a method includes receiving a plurality of logs indicative of software behavior from a plurality of endpoint devices and generating a plurality of event sequences from the plurality of logs. The method includes training a global machine learning model using the plurality of event sequences to predict resultant events for a sequence of lead up events and classify whether the resultant events indicate malicious activity. The method includes, for each respective endpoint device of the plurality of endpoint devices, generating a testing dataset comprising a plurality of benign event sequences that occurred on the respective endpoint device. The method includes generating a tuned machine learning model for the respective endpoint device by retraining the global machine learning model using the testing dataset. The method includes executing the tuned machine learning model.
Owner:ACRONIS INT

Fault prediction method, fault prediction model training method, computing device, storage medium, and computer program product

The present disclosure provides a fault prediction method, a fault prediction model training method, a computing device, a storage medium, and a computer program product. The fault prediction method comprises: obtaining abnormal log data and unit attribute information of a service processing unit; determining an abnormal event sequence on the basis of the abnormal log data; and inputting the unit attribute information and the abnormal event sequence into a fault prediction model to obtain a fault prediction result of the service processing unit, wherein the fault prediction model is obtained by performing training on the basis of a positive sample, a first sample label corresponding to the positive sample, a negative sample, and a second sample label corresponding to the negative sample, the positive sample comprises a positive sample abnormal event sequence and sample unit attribute information, and the negative sample comprises a negative sample abnormal event sequence and sample unit attribute information. The training data of the fault prediction model is richer, so that the accuracy of prediction results of the fault prediction model during applications is improved.
Owner:CLOUD INTELLIGENCE ASSETS HOLDING (SINGAPORE) PTE LTD

Digraph-based power grid abnormal event identification method and device, terminal equipment and storage medium

The invention discloses a digraph-based power grid abnormal event identification method and device, terminal equipment and a storage medium, and the method comprises the steps: obtaining current power data and historical fault data in a to-be-detected region, and extracting entities, relationships and attributes from the current power data and historical fault data to construct an initial digraph; acquiring historical power data, and adjusting the weight of a directed edge in the initial directed graph to obtain an optimized directed graph and conditional probability distribution of each node; performing Monte Carlo random sampling on the optimized directed graph to generate a plurality of abnormal event sequences; and determining the actual node state of each node according to the current operation parameter, matching the node state feature of the actual node state with the event state feature of the abnormal event for each abnormal event sequence, determining a target abnormal event sequence, and further identifying the abnormal event occurring in the power grid. According to the invention, the abnormal event of the power grid can be identified.
Owner:POWER DISPATCHING CONTROL CENT OF GUANGDONG POWER GRID CO LTD

Depth time sequence prediction method and system based on event gating mechanism

The invention discloses a depth time sequence prediction method and system based on an event gating mechanism, and belongs to the technical field of artificial intelligence, and the method comprises the steps: obtaining time sequence data and corresponding event sequence data; mapping the time sequence data and the corresponding event sequence data to a low-dimensional potential vector space to obtain a time sequence feature representation and an event sequence feature representation; according to the time step sequence, inputting the time sequence feature representation and the event sequence feature representation into an improved recurrent neural network for processing to obtain a hidden state sequence; performing attention calculation based on the hidden state sequence to obtain final vector representation; and obtaining a prediction result according to the final vector representation. According to the invention, the prediction capability of the time sequence containing the non-periodic event interference can be improved.
Owner:PEKING UNIV

Event-driven sparse attention optimization method and system based on brain-like computing chip

The invention provides an event-driven sparse attention optimization method and system based on a brain-like computing chip, and belongs to the technical field of computers.The method comprises the steps that semantic analysis and feature extraction are conducted on input data and text information, and an input event sequence and a text event sequence are generated; calculating semantic relevancy between the input event sequence and the text event sequence, and generating an event importance evaluation matrix; calculating a sparseness parameter based on the complexity of the input data and the load of a brain-like calculation chip calculation node, and strengthening the sparseness parameter to obtain a target sparseness parameter; based on the target sparseness parameter and the event importance evaluation matrix, generating a sparse attention mask matrix; a sparse attention calculation task based on the sparse attention mask matrix is allocated to calculation nodes of the brain-like calculation chip for execution; and the output results of the calculation nodes are fused to generate a target output result. According to the invention, the accuracy and efficiency of the query result are improved.
Owner:CHINA TRANSPORT INFORMATION TECH GRP CO LTD

User behavior prediction via generative modeling of event sequences

PCT designated stage expiredWO2025144391A1Biological modelsCommerceLinguistic modelEvent data
Systems and methods for generating customizable models for predicting user behavior are provided. Such a method includes: obtaining first structured event data representative of first events performed by one or more users; training a generative language model using the first structured event data; obtaining second structured event data representative of one or more second events performed by a user; and predicting, at least in part by applying the second structured event data as an input to the trained generative language model, third structured event data representative of behavior associated with the user according to one or more customizable analytic outputs.
Owner:GOOGLE LLC

Natural language driven situation awareness control method and system based on task intention and medium

The invention discloses a natural language driven situation awareness control method and system based on task intention and a medium. Relates to the technical field of artificial intelligence and man-machine interaction. Generating a natural language template library and a task intention field table based on the three-table knowledge; constructing an interface-data double-mapping knowledge graph by taking three-table knowledge as a construction basis and taking a natural language template library and a task intention field table as retrieval rearrangement tools, and then performing semantic retrieval and anaphora resolution to generate structured intention data; on the premise of not depending on a fixed layout, a user instruction is analyzed into a task intention, stable anchoring of an interface object is achieved through semantic positioning, and the task intention is automatically compiled into a system API call or interface event sequence; and meanwhile, the availability and compliance of execution are guaranteed through a closed-loop mechanism of credible execution scoring and minimization clarification, so that the operation complexity is effectively reduced, and the response efficiency and intelligent interaction level of the situation awareness system are improved.
Owner:TIANFU JIANGXI LAB

Laboratory risk control method based on graph neural network

The invention discloses a laboratory risk control method based on a graph neural network, and the method comprises the following steps: S1, constructing a dynamically updated interaction event graph based on an interaction event sequence of laboratory equipment, personnel and environment; s2, dynamically updating the state space of each node according to the event preorder relation, and generating a synchronous node state sequence; s3, generating an early warning feature set of a node state change trend by adopting a graph convolution operation; s4, constructing an inter-node risk incidence matrix according to the early warning feature set, and generating an updated risk propagation path; s5, evaluating the probability of transition from the node state to the abnormal state, and generating a state risk prediction value; and S6, inputting a wolf pack optimization algorithm, and optimizing a parameter combination to obtain a laboratory risk prediction result. According to the invention, the real-time performance and accuracy of laboratory risk prediction are improved.
Owner:CORE GUIDE SOFTWARE (JIANGSU) CO LTD

Dual-network collaborative event sequence automatic testing method and device and storage medium

The invention provides a dual-network collaborative event sequence automatic testing method and device and a storage medium. The method comprises the following steps: generating a trigger identifier associated with a first pulse as a time reference; slave station logs are collected on the secondary backboard bus side, and communication messages are collected on the primary communication network side; correcting time offset and time drift of the primary communication network and the secondary backplane bus to generate a primary event sequence and a secondary event sequence; performing consistency comparison on the primary event sequence and the secondary event sequence under a unified time base to obtain a consistency comparison result; calculating an interval between adjacent events, comparing the interval with an expected interval to obtain a time scale precision checking result, and calculating an event resolution result; and calculating the time delay between the request and the response and counting the pairing rate to obtain a redundant pairing statistical result. According to the invention, end-to-end automatic testing, unified time base alignment, dual-network consistency verification, redundant request, response quantification and millisecond-level event resolution can be realized.
Owner:BEIJING HOLLYSYS TECHNOLOGY RESEARCH INSTITUTE CO LTD

Computer performance dynamic adjusting system and method based on user operation behaviors

The invention provides a computer performance dynamic adjusting system and method based on user operation behaviors, and relates to the technical field of computers. Comprising an event capture module, an operation semantic association module, a system resource optimization module and an adaptive correction module. The event capturing module obtains user operation data and generates an operation event sequence with a timestamp. The operation semantic association module is used for matching an operation event and an operation mode through a nonlinear time axis, and generating a resource demand vector in combination with a window focus and a process stack calling relationship. And the system resource optimization module selects a resource allocation scheme with the lowest power consumption on the basis of an ant colony algorithm under the condition that response time constraints are met, and reallocates resources. And the adaptive correction module adjusts the matching weight of the operation mode by comparing the deviation between the actual response time and the expected response time, and feeds back a corrected matching threshold. The system can dynamically adjust computer performance, improve response speed and reduce power consumption.
Owner:HEILONGJIANG COMM POLYTECHNIC

Network security operation and maintenance automatic analysis response system based on artificial intelligence

The invention relates to the technical field of network security, in particular to a network security operation and maintenance automatic analysis and response system based on artificial intelligence, which comprises an operation sensing module for acquiring a server state, extracting a security log, monitoring a network protocol and a transmission direction, identifying a performance bottleneck, sorting event data and generating a sensing summary sheet, the path offset identification module tracks a cross-domain path, identifies an abnormal path and generates an offset list; the behavior chain construction module sorts an event sequence and generates a behavior chain graph; the response processing module arranges processing steps, records a response process, generates an operation and maintenance execution sequence, synthesizes an output module to complete a process and generates an analysis result. According to the invention, by comparing the server resources with the historical reference, the abnormity is identified, and the event behavior basis is provided. And tracking cross-domain path lag and abnormity, and positioning threats. Arranging event data, and constructing an attack chain. The automatic response improves the speed and accuracy, shortens the response time, and enhances the attack handling capability.
Owner:HANGZHOU XIANGLIANG IOT TECHNOLOGY CO LTD

Workflow engine implementation method based on event traceability and decentralized monitoring

The invention relates to the technical field of informatization, in particular to a workflow engine implementation method based on event traceability and decentralized monitoring, which is based on the design of recording node operation and deducing a process state on the basis of an immutable event sequence, thoroughly relieves the constraint of traditional state table storage on dynamic adjustment, and improves the working efficiency. Operation such as node insertion, skipping or rollback can take effect in real time through runtime metadata reconstruction, meanwhile, a completely stored operation event chain naturally supports full-process audit tracing, and a log system does not need to be additionally developed; a power proportion algorithm decomposes distributed node decisions into three layers of logics of role allocation, predefined result verification and secondary monitoring triggering, cross-service consistency is guaranteed through a post weight adjustment and historical behavior voting dual mechanism, and an online voting mechanism dynamically calculates and processes human weights by using event logs, so that the decision accuracy is improved. Therefore, the technical bottlenecks of rigidity, redundancy and weak consistency of the traditional scheme are overcome.
Owner:CHONGQING ZHONGRAN DIGITAL TECH CO LTD

Feature-specific attention arrays for event sequence characterization

A method and related system for efficiently capturing relationships between event feature values in embeddings includes flattening an event sequence into a feature sequence including a first event prefix, a second event prefix, and a first set of feature values. The method includes generating an attention mask including first mask indicators to associate the first set of feature values with each other and second mask indicator to associate a first feature value of the first set of feature values with the second event prefix. The method includes providing the feature sequence and the attention mask to a self-attention neural network model to generate an embedding.
Owner:CAPITAL ONE SERVICES LLC

Log anomaly detection method and device, equipment, storage medium and program product

The invention relates to the technical field of computers, and provides a log anomaly detection method and device, equipment, a storage medium and a program product. The method comprises the steps of constructing a time sequence event graph based on a log event sequence; determining an adjacent matrix of each event graph snapshot and a node feature matrix of each event graph snapshot; inputting each event graph snapshot, each adjacent matrix and each node feature matrix into a dynamic graph model, and performing time sequence feature extraction and link prediction to obtain a predicted event graph snapshot; and judging whether the log event sequence is abnormal or not based on the predicted event graph snapshot. By means of the mode, efficient detection and positioning of the abnormal log can be achieved, the detection effect of the abnormal log is improved, and the detection requirement of an information system for log abnormity is met.
Owner:CHINA MOBILE M2M +1

Log association analysis method and system for network abnormal operation behavior

The invention relates to the technical field of log analysis, and discloses a log association analysis method and system for a network abnormal operation behavior, and the method comprises the steps: carrying out the normalized element analysis of a multi-source heterogeneous log of a target network environment, and obtaining a standardized event of the multi-source heterogeneous log; performing time sequence dependence mining on the standardized event to obtain a potential threat mode of the standardized event; performing active traversal matching on the standardized events to obtain a candidate associated event sequence of the standardized events; performing reverse deduction on a subsequent evolution stage of the target network environment to obtain a verification probe strategy of the subsequent evolution stage; applying the verification probe strategy to the target network environment, and performing data acquisition on the target network environment to obtain verification feedback data of the target network environment; performing threat degree evaluation on the candidate associated event sequence to obtain a research and judgment report of the target network environment; according to the invention, the efficiency of log association analysis of network abnormal operation behaviors can be improved.
Owner:GANSU ELECTRIC POWER TIANSHUI POWER SUPPLY

Block chain power abnormal data tracing method

The invention relates to the technical field of computers, in particular to a block chain power abnormal data tracing method. The method comprises the following steps: acquiring operation data and system logs of a power system, extracting model input, identifying exceptions and completing event source classification; for the abnormal generation differential change records, timestamps are extracted to construct chain records, and the chain records are serialized into traceable paths; performing cross-source alignment and sequence correction to form a consistent event sequence, classifying and sorting to obtain an event sequence structure, and verifying to generate a cross-system traceability path; and finally verifying a conclusion through a consensus mechanism, extracting a traceability report, and updating the anomaly detection model according to the traceability report. According to the method, the cross-source time sequence consistency and the evidence playback performance are improved, the conclusion credibility and the closed-loop iteration capability are enhanced, and the method is suitable for scenes such as data metering and equipment monitoring.
Owner:BEIJING FIBO XINDA TECHNOLOGY CO LTD

Technologies for performing attribute constrained queries for real-time event flow visualizations and analytics

A method for performing attribute constrained queries for event sequence visualization may include receiving an event sequence dataset including event sequences. The method further includes determining singleton events in the dataset, where each singleton event is associated with an attribute. The method also includes generating event pattern sets corresponding to different distinct singleton events and that maintain a fixed positional order for each event sequence. The event pattern sets include pattern occurrence data for each event sequence positioned according to the fixed positional order. The method also includes identifying the fixed positional order maintained by each event pattern set, and generating an attribute constraint search structure, such as a B-tree, B+tree, or table, that includes keys and pointer values. The method may also include searching the search structure to identify key values satisfying a received attribute constraint, and outputting the sequence identifiers corresponding to the identified key values.
Owner:GENESYS CLOUD SERVICES INC

Fault prediction method and apparatus, fault prediction model training method and apparatus, and computing device, computer storage medium and computer program product

Provided in the present disclosure are a fault prediction method and apparatus, a fault prediction model training method and apparatus, and a computing device, a computer storage medium and a computer program product. The fault prediction method is applied to a cloud computing system, wherein the cloud computing system comprises a service processing unit. The fault prediction method comprises: acquiring anomaly log data of a service processing unit and a log acquisition time of the anomaly log data; on the basis of the anomaly log data and the log acquisition time, determining an anomaly event sequence and an anomaly timestamp sequence; on the basis of a time interval threshold and anomaly occurrence times corresponding to anomaly events in the anomaly event sequence, grouping the anomaly events to obtain an anomaly group sequence; and on the basis of the anomaly event sequence, the anomaly timestamp sequence, and the anomaly group sequence, using a fault prediction model to obtain a fault prediction result of the service processing unit. Anomaly log data is analyzed from multiple dimensions, thereby improving the prediction accuracy of a fault prediction model, and improving the stability of a cloud computing system.
Owner:CLOUD INTELLIGENCE ASSETS HOLDING (SINGAPORE) PTE LTD

System fault mining method for log data

The invention provides a log data-oriented system fault mining method, which belongs to the technical field of information, and comprises the following steps: collecting original log data of a system, and preprocessing original system logs, including analysis, key information extraction, vectorization and generation of a structured log event sequence; processing the log event sequence by adopting a two-stage model fusing anomaly detection and mode clustering so as to distinguish accidental anomaly and a real fault mode; and for each candidate fault mode cluster, analyzing a time sequence causal relationship between internal events, and positioning a root cause event according to the causal flow score of the node. The method has the advantages that dependence on artificial experience is reduced through full-process automatic modeling and analysis; according to the method, log analysis, feature extraction, anomaly detection and root cause positioning are all automatically completed by adopting a preset algorithm process, and the detection effect is maintained through self-adjustment of the model, so that the flexibility and sustainability of fault mining are improved.
Owner:LUOHE POWER SUPPLY OF HENAN ELECTRIC POWER CORP

Micro-service processing system

The micro-service processing system provided by the embodiment of the invention comprises an event identification module which is used for defining a business domain event type and registering an event attribute structure; the event bus module constructs a distributed communication network containing a dual-channel message queue, and the event bus module implements partition routing according to event types; the event processing module is composed of an event producer and a consumer which are executed asynchronously, the event producer packages service actions into a standardized event data packet, and the consumer processes subscription events through a thread pool; the event storage module adopts a hierarchical log database for persistence of an event sequence and supports reestablishment of a service state according to a timestamp; and the security control module is used for implementing service authentication and event content encryption on a transmission layer. Through event bus dual-channel design, sender box transaction binding and hierarchical storage optimization, millisecond-level event processing delay is realized while the reliability of distributed transactions is ensured, and second-level state recovery can be realized based on a complete event log when a service fault occurs.
Owner:HUANENG ZHAOCAI DIGITAL TECHNOLOGY CO LTD +1

RPA mouse and keyboard control method and system for Wayland desktop

The invention belongs to the technical field of computer man-machine interaction and automatic control, and particularly relates to an RPA mouse and keyboard control method and system for a Wayland desktop. The method comprises the following steps: S1, creating and registering a virtual input device supporting mouse and keyboard functions in a user space by accessing a virtual input device interface provided by an operating system kernel; s2, current activity display output is detected, and screen resolution information is obtained; s3, the server program monitors a preset local Unix domain socket path for receiving a control instruction from the client; s4, the client sends a control request to the local Unix domain socket path in a structured format, and the server receives and analyzes the control request; s5, the server side maps the analyzed control request into a corresponding kernel input event sequence according to the operation type; meanwhile, by writing event data into the virtual input device, an input event is injected into the system so as to simulate a control operation on the graphic desktop.
Owner:浙江实在智能科技有限公司

Visual flow arrangement method for e-commerce marketing

The invention relates to the technical field of computer software, provides a visual flow arrangement method for e-commerce marketing, and aims to solve the problem of insufficient system processing performance and expansibility when an existing flow arrangement technology is applied to an e-commerce marketing scene. Generating and storing a state transition rule set; obtaining a user behavior event, obtaining a historical state transition event sequence according to the user behavior event, and then dynamically calculating a current user journey state; acquiring a corresponding state transition rule set, and performing matching query by taking the current user journey state and the user behavior event as input; if matching succeeds, a corresponding marketing action command is executed, and a new state transition event is generated and persisted to an event log so as to update a user journey state, so that efficient and accurate state-driven rule matching and automatic execution are realized, and the processing efficiency, expandability and state traceability of a system in a high-concurrency scene are improved.
Owner:GUANGZHOU SEVEN THINGS ARTIFICIAL INTELLIGENCE TECHNOLOGY CO LTD

Intelligent test generation method, system and equipment for H5 page and medium

PendingCN120578584AError detection/correctionBoundary testingHybrid testing
The invention discloses an intelligent test generation method, system and device for an H5 page and a medium, and the method specifically comprises the steps: collecting a user operation event sequence of the H5 page, and building an operation log stream with a timestamp through the user operation event sequence; collecting equipment fingerprint data and a network delay index, and performing space-time correlation coding on the equipment fingerprint data and the network delay index to generate an enhanced operation track data set; inputting the enhanced operation track data set into a pre-trained depth time sequence neural network to obtain an anomaly detection result; sending out safety early warning based on an abnormal detection result, extracting boundary condition features in the operation log stream, and automatically generating a boundary test case set; and fusing the boundary test case set with the user operation reproduction case, constructing a hybrid test suite, and triggering an automatic test assembly line through a CI / CD integrated interface. According to the method, the comprehensiveness, the accuracy and the efficiency of H5 page testing are remarkably improved, and the performance and the safety of the H5 page are effectively guaranteed.
Owner:广州三七极耀网络科技有限公司

Technologies for generating optimized event sequence indices for real-time event flow visualizations and analytics

A method for generating an inverted search index for event sequence visualization may include determining, from an event sequence dataset containing event sequences and events, event pair combinations based on identified unique singleton events. The method may further include establishing a positional ordering for each singleton event and each event pair combination and generating a respective event sequence set for each event sequence. The method may also include determining whether each unique singleton event and each event pair combination exists or does not exist within each event sequence, and populating, for each respective event sequence set and according to the positional ordering, data indicative of whether each unique singleton event and each event pair combination exists or does not exist within the event sequence for the respective event sequence set. The method may also include generating the inverted search index including each respective event sequence set for each event sequence.
Owner:GENESYS CLOUD SERVICES INC

Security event association aggregation and maliciousness analysis method

The invention belongs to the technical field of network security, and discloses a security event association aggregation and maliciousness analysis method. Preprocessing the security event log set to obtain a security event context sequence and an embedded vector thereof; obtaining an initial vector by the embedding vector of the security event context sequence through an encoder; the decoder calculates an attention vector and predicts event probability distribution according to the embedded vector and the initial vector decoded in the previous step; iteratively training until a termination condition is met, and calculating the total attention distribution of each event according to the obtained attention vector and the security event context sequence; an improved DBSCAN method is adopted, and a data set Z formed by total attention distribution of all events is clustered; and extracting a sample from each cluster, and performing event maliciousness analysis according to an LDA topic model. According to the method, the workload of further analysis can be effectively reduced, event sequences with similar context features are clustered, and the data complexity and calculation cost of subsequent analysis are reduced.
Owner:NORTHEASTERN UNIV CHINA +1