Tutorial: Formal Methods for Event Processing
Alexander Artikis, Γεώργιος Παλιούρας · Movebank · 2014
Organisations require techniques for automated transformation of the Big Data they collect into operational knowledge. This requirement may be addressed by employing event processing systems that detect activities/events of special significance within an organisation, given streams of low-level information that are difficult to be utilised by humans [4]. Systems for event processing and in particular event recognition (‘event pattern matching’) accept as input a stream of time-stamped, simple or low-level events. A low-level event is the result of applying a computational derivation process to some other event, such as an event coming from a sensor. Using low-level events as input, event processing systems identify composite or high-level events of interest — collections of events that satisfy some pattern. Consider, for example, the recognition of attacks on nodes of a computer network given the TCP/IP messages, the recognition of suspicious trader behaviour given the transactions in a financial market, and the recognition of whale songs given a symbolic representation of whale sounds. Numerous event processing systems have been proposed in the literature [3]. Systems with a logic-based representation of event structures, for example, have been attracting considerable attention. They exhibit a formal, declarative semantics, allowing for verification and a code maintenance, they have proven to be efficient and scalable, and they are supported by machine learning tools, minimising human effort in the system development. In this tutorial, we review formal event processing systems. High-level event ‘definitions’ impose temporal and, possibly, atemporal constraints on subevents, that is, low-level events or other high-level events. We will review a Chronicle Recognition System, the Event Calculus, ProbLog and Markov Logic Networks. The Chronicle Recognition System is a purely temporal reasoning system that allows for efficient event processing. It has been used in various domains, ranging from medical applications to computer network management. The Event Calculus allows for the representation of temporal, as well as atemporal constraints. Consequently, the Event Calculus may be used in applications requiring