×

Vector-based anomaly detection

  • US 10,542,027 B2
  • Filed: 01/15/2019
  • Issued: 01/21/2020
  • Est. Priority Date: 11/18/2010
  • Status: Active Grant
First Claim
Patent Images

1. A hybrid-fabric apparatus for detecting anomalous behavior of a network fabric comprising a plurality of network nodes, the hybrid-fabric apparatus comprising:

  • at least one memory configured to at least store a plurality of behavior metrics;

    at least one processor coupled to the at least one memory; and

    software code configured to use the at least one processor, access the at least one memory, and cause the apparatus to at least;

    disaggregate a set of anomaly detection criteria into a plurality of anomaly criterion to be distributed among the plurality of network nodes, the set of anomaly detection criteria characterizing a variation from a baseline vector corresponding to nominal traffic flow through the network fabric, and the plurality of anomaly criterion comprising a function of a measured vector of behavior metrics comprising a threshold;

    aggregate anomaly criterion statuses calculated by at least some of the plurality of network nodes to detect anomalous behavior, each anomaly criterion status being calculated with respect to a network node as a function of the network node'"'"'s anomaly criterion and the measured behavior vector of behavior metrics; and

    initiate a notification regarding the anomalous behavior.

View all claims
  • 4 Assignments
Timeline View
Assignment View
    ×
    ×