×

Anomaly detection using device relationship graphs

  • US 10,382,303 B2
  • Filed: 08/07/2017
  • Issued: 08/13/2019
  • Est. Priority Date: 07/11/2016
  • Status: Active Grant
First Claim
Patent Images

1. A method for monitoring network packets over a network, wherein one or more processors in a network computer execute instructions to perform actions, comprising:

  • instantiating a network monitoring application to perform actions, including;

    detecting one or more error signals from one or more agents that are included in a model that is comprised of a graph for two or more nodes and one or more edges, wherein each node represents an agent and each edge represents a relationship between two agents;

    employing network packets communicated by two or more agents that are unassociated with the model to identify these two agents as two or more new agents for the model that have one or more relationships with each other;

    updating the model with the two or more new agents and one or more phantom edges for the one or more relationships between the two or more new agents;

    employing the network packets associated with the one or more error signals to identify a plurality of anomalies that correspond to more than one agent in the model that is associated with a same error signal;

    employing the graph of the model to reduce an amount of the plurality of anomalies into one or more anomalies; and

    notifying a user of the one or more anomalies in the network.

View all claims
  • 6 Assignments
Timeline View
Assignment View
    ×
    ×