CPC H04L 63/1425 (2013.01) [G06N 20/00 (2019.01); H04L 63/1416 (2013.01)] | 20 Claims |
1. A method comprising,
generating a plurality of profiles for a first process for a plurality of hierarchical endpoint scopes, wherein the first process is executing on one or more endpoints indicated in the plurality of hierarchical endpoint scopes, wherein generating the plurality of profiles for the first process comprises, for each endpoint scope in the plurality of hierarchical endpoint scopes,
determining importance qualifiers for event data for the first process at the endpoint scope;
filtering the event data according to the importance qualifiers;
normalizing the filtered event data to generate normalized event data;
determining, for the first process, a plurality of classifiers for process activities of the first process that satisfy a criterion of normal activity for the first process at the endpoint scope, wherein the determination of the plurality of classifiers for process activities that satisfy the criterion of normal activity is based, at least in part, on statistics from the normalized event data for the first process at the endpoint scope; and
generating a profile with the plurality of classifiers and associating the profile with the endpoint scope.
|