Please download the dossier by clicking on the dossier button x
×

Vector-based anomaly detection

  • US 10,218,732 B2
  • Filed: 04/06/2017
  • Issued: 02/26/2019
  • Est. Priority Date: 11/18/2010
  • Status: Active Grant
First Claim
Patent Images

1. A hybrid-fabric apparatus for detecting anomalous behavior of a network fabric comprising a plurality of network nodes, the hybrid-fabric apparatus comprising:

  • a black box memory configured to at least store a plurality of behavior metrics; and

    an anomaly agent coupled with the black box and configured to at least;

    determine a baseline vector corresponding to nominal behavior of the network fabric, the baseline vector comprising at least two different behavior metrics that are correlated with each other;

    disaggregate anomaly detection criteria into a plurality of anomaly criterion to be distributed among the plurality of network nodes, the anomaly detection criteria characterizing a variation from the baseline vector, and each of the plurality of anomaly criterion comprising a function of a measured vector of behavior metrics, the variation calculated based on a variation function applied to a vector of measured behavior metrics having elements corresponding to member elements of the baseline vector;

    aggregate anomaly criterion statuses calculated by at least some of the plurality of network nodes to detect anomalous behavior, each anomaly criterion status being calculated by a network node as a function of the network node'"'"'s anomaly criterion and a measured vector of the at least two different behavior metrics; and

    notify a manager of the anomalous behavior.

View all claims
  • 3 Assignments
Timeline View
Assignment View
    ×
    ×