×

Behavioral baselining of network systems

  • US 10,666,673 B2
  • Filed: 08/02/2017
  • Issued: 05/26/2020
  • Est. Priority Date: 02/27/2017
  • Status: Active Grant
First Claim
Patent Images

1. A method, comprising:

  • instantiating, by at least one processor, a baseline, wherein the baseline comprises a set of assets, and a set of relationships including a first relationship;

    associating a first event stream with the baseline, wherein the first event stream comprises a sequence of events, the events include a first event at a first time and a second event at a second time, and each event comprises a source or destination attribute;

    performing an evaluation to create a range of addresses, the addresses based on values for source or destination addresses collected from the first event stream;

    evaluating each event of the first event stream by performing evaluations corresponding to attributes in the set of relationships, the evaluating comprising determining whether a value of a source or destination address in the first event is within the range of addresses; and

    detecting, by the at least one processor, based on the evaluating of the first event stream, a drift from the baseline, wherein the drift is based on a failure of at least one attribute value in the first event to match at least one attribute value of the first relationship.

View all claims
  • 4 Assignments
Timeline View
Assignment View
    ×
    ×