×

Detecting network anomalies by probabilistic modeling of argument strings with markov chains

  • US 10,063,576 B2
  • Filed: 12/29/2015
  • Issued: 08/28/2018
  • Est. Priority Date: 05/27/2008
  • Status: Active Grant
First Claim
Patent Images

1. A method for detecting network anomalies, the method comprising:

  • receiving, using a hardware processor, a communication protocol message having an argument string that is transmitted from a first processor to a second processor across a computer network;

    applying, using the hardware processor, a probabilistic model to the received communication protocol message to determine whether the communication protocol message is anomalous based on determining that at least one n-gram in the communication protocol message is anomalous, wherein the probabilistic model uses at least one Markov chain specified by one or more parameters to determine a probability that the argument string is anomalous based on n-grams in the argument string; and

    performing, using the hardware processor, a predetermined action in response to determining that the communication protocol message is anomalous.

View all claims
  • 0 Assignments
Timeline View
Assignment View
    ×
    ×