×

Method and system for confident anomaly detection in computer network traffic

  • US 10,542,024 B2
  • Filed: 12/11/2017
  • Issued: 01/21/2020
  • Est. Priority Date: 11/07/2011
  • Status: Active Grant
First Claim
Patent Images

1. A method for detecting and classifying network traffic anomalies, comprising:

  • receiving a packet of information related to network traffic;

    passing said packet to a plurality of network traffic analyzers, each network traffic analyzer capable of applying a corresponding one of a plurality of analytical algorithms to information contained in the packet;

    receiving results of analysis performed by the plurality of analyzers, each result corresponding to an event type;

    evaluating results of analysis performed by the plurality of analyzers as a collection by applying an exponentially decayed weight to each of the results, dependent upon event type, and calculating a cumulative confidence metric as a sum of the weights;

    determining if the result of evaluation signifies a network traffic anomaly by comparing the cumulative confidence metric to a threshold; and

    emitting an alert if the result of evaluation signifies a network traffic anomaly.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×