Vector-based anomaly detection
First Claim
1. A hybrid-fabric apparatus for detecting anomalous behavior of a network fabric comprising a plurality of network nodes, the hybrid-fabric apparatus comprising:
- a black box memory configured to at least store a plurality of behavior metrics; and
an anomaly agent coupled with the black box and configured to at least;
determine a baseline vector corresponding to nominal behavior of the network fabric, the baseline vector comprising at least two different behavior metrics that are correlated with each other;
disaggregate anomaly detection criteria into a plurality of anomaly criterion to be distributed among the plurality of network nodes, the anomaly detection criteria characterizing a variation from the baseline vector, and each of the plurality of anomaly criterion comprising a function of a measured vector of behavior metrics, the variation calculated based on a variation function applied to a vector of measured behavior metrics having elements corresponding to member elements of the baseline vector;
aggregate anomaly criterion statuses calculated by at least some of the plurality of network nodes to detect anomalous behavior, each anomaly criterion status being calculated by a network node as a function of the network node'"'"'s anomaly criterion and a measured vector of the at least two different behavior metrics; and
notify a manager of the anomalous behavior.
3 Assignments
0 Petitions
Accused Products
Abstract
A hybrid-fabric apparatus comprises a black box memory configured to store a plurality of behavior metrics and an anomaly agent coupled to the black box. The anomaly agent determines a baseline vector corresponding to nominal behavior of the fabric, wherein the baseline vector comprises at least two different behavior metrics that are correlated with each other. The anomaly agent disaggregates anomaly detection criteria into a plurality of anomaly criterion to be distributed among network nodes in the fabric, the anomaly detection criteria characterizing a variation from the baseline vector, and each of the plurality of anomaly criterion comprising a function of a measured vector of behavior metrics. The variation can be calculated based on a variation function applied to a vector of measured behavior metrics having elements corresponding to member elements of the baseline vector. Anomaly criterion statuses calculated by at least some of the plurality of network nodes are aggregated to detect anomalous behavior. Each anomaly criterion status can be calculated by a network node as a function of the network node'"'"'s anomaly criterion and a measured vector of the at least two different behavior metrics.
-
Citations
24 Claims
-
1. A hybrid-fabric apparatus for detecting anomalous behavior of a network fabric comprising a plurality of network nodes, the hybrid-fabric apparatus comprising:
-
a black box memory configured to at least store a plurality of behavior metrics; and an anomaly agent coupled with the black box and configured to at least; determine a baseline vector corresponding to nominal behavior of the network fabric, the baseline vector comprising at least two different behavior metrics that are correlated with each other; disaggregate anomaly detection criteria into a plurality of anomaly criterion to be distributed among the plurality of network nodes, the anomaly detection criteria characterizing a variation from the baseline vector, and each of the plurality of anomaly criterion comprising a function of a measured vector of behavior metrics, the variation calculated based on a variation function applied to a vector of measured behavior metrics having elements corresponding to member elements of the baseline vector; aggregate anomaly criterion statuses calculated by at least some of the plurality of network nodes to detect anomalous behavior, each anomaly criterion status being calculated by a network node as a function of the network node'"'"'s anomaly criterion and a measured vector of the at least two different behavior metrics; and notify a manager of the anomalous behavior. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13)
-
-
14. A network fabric system comprising:
-
a plurality of network nodes; and an anomaly agent coupled with the plurality of network nodes and configured to at least; determine a baseline vector corresponding to nominal behavior of the network fabric, the baseline vector comprising at least two different behavior metrics that are correlated with each other; disaggregate anomaly detection criteria into a plurality of anomaly criterion to be distributed among the plurality of network nodes, the anomaly detection criteria characterizing a variation from the baseline vector, and each of the plurality of anomaly criterion comprising a function of a measured vector of behavior metrics, the variation calculated based on a variation function applied to a vector of measured behavior metrics having elements corresponding to member elements of the baseline vector; aggregate anomaly criterion statuses calculated by at least some of the plurality of network nodes to detect anomalous behavior, each anomaly criterion status being calculated by a network node as a function of the network node'"'"'s anomaly criterion and a measured vector of the at least two different behavior metrics; and notify a manager of the anomalous behavior. - View Dependent Claims (15, 16, 17, 18, 19, 20, 21, 22, 23, 24)
-
Specification