首页> 外国专利> Methods and systems to detect anomalies in computer system behavior based on log-file sampling

Methods and systems to detect anomalies in computer system behavior based on log-file sampling

机译:基于日志文件采样的计算机系统行为异常检测方法和系统

摘要

Methods and systems that detect computer system anomalies based on log file sampling are described. Computers systems generate log files that record various types of operating system and software run events in event messages. For each computer system, a sample of event messages are collected in a first time interval and a sample of event messages are collected in a recent second time interval. Methods calculate a difference between the event messages collected in the first and second time intervals. When the difference is greater than a threshold, an alert is generated. The process of repeatedly collecting a sample of event messages in a recent time interval, calculating a difference between the event messages collected in the recent and previous time intervals, comparing the difference to the threshold, and generating an alert when the threshold is violated may be executed for each computer system of a cluster of computer systems.
机译:描述了基于日志文件采样检测计算机系统异常的方法和系统。计算机系统生成日志文件,该日志文件在事件消息中记录各种类型的操作系统和软件运行事件。对于每个计算机系统,在第一时间间隔中收集事件消息的样本,并在最近的第二时间间隔中收集事件消息的样本。方法计算在第一时间间隔和第二时间间隔中收集的事件消息之间的差异。当差异大于阈值时,将生成警报。可能需要重复以下过程:在最近的时间间隔中重复收集事件消息的样本,计算在最近和先前的时间间隔中收集的事件消息之间的差异,将差异与阈值进行比较,并在违反阈值时生成警报为一组计算机系统中的每个计算机系统执行。

著录项

  • 公开/公告号US10116675B2

    专利类型

  • 公开/公告日2018-10-30

    原文格式PDF

  • 申请/专利权人 VMWARE INC.;

    申请/专利号US201514963100

  • 申请日2015-12-08

  • 分类号G06F21;H04L29/06;H04L12/26;G06N7;

  • 国家 US

  • 入库时间 2022-08-21 13:05:05

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号