CPC H04L 63/1433 (2013.01) [H04L 63/1425 (2013.01); G06F 18/2411 (2023.01); G06Q 50/01 (2013.01)] | 20 Claims |
1. A method comprising:
receiving, by a processor, a plurality of events associated with a plurality of resources;
computing, in real-time, statistical representations for each resource associated with at least one of the plurality;
generating a reference window comprising a first portion of the plurality of events and a current window comprising a second portion of the plurality of events;
training an anomaly detector on the reference window using the statistical representations of resources in the first portion of the plurality of events;
evaluating, by the trained anomaly detector, the current window using the statistical representations of resources in the second portion of the plurality of events to identify a set of anomalous resources;
identifying a set of anomalous events associated with the set of anomalous resources; and
causing display, on a computing device, of an interface comprising the set of anomalous resources and the set of anomalous events.
|