CPC G06F 16/24575 (2019.01) [G06F 16/2365 (2019.01); G06F 16/24544 (2019.01); G06F 16/2456 (2019.01); G06F 16/248 (2019.01); G06F 16/9535 (2019.01); G06Q 20/4016 (2013.01); G06Q 40/12 (2013.12); H04L 63/1416 (2013.01); H04L 63/1425 (2013.01); H04L 63/20 (2013.01); H04L 2463/102 (2013.01)] | 17 Claims |
1. A computing system comprising:
a database storing first data;
a computer processor; and
a computer readable storage medium storing program instructions configured for execution by the computer processor in order to cause the computing system to:
select a behavior outlier rule;
cluster a portion of the first data into a first cluster based on a statistical measure;
apply the behavior outlier rule to the first cluster to identify a first outlier and a second outlier;
generate a first alert for the first outlier and a second alert for the second outlier;
receive an indication of one or more user actions taken with respect to at least one of the first alert or the second alert;
in response to receiving the indication of one or more user actions taken with respect to the at least one of the first alert or the second alert:
identify a percentage of outliers of the first cluster that are actioned; and
determine that the percentage is different from a threshold; and
in response to determining that the percentage is different from the threshold, modify the behavior outlier rule based on the one or more user actions such that a modified behavior outlier rule is applied to future clusters.
|