×

System and method to select and apply hypothetical mitigation parameters

  • US 10,708,294 B2
  • Filed: 01/19/2017
  • Issued: 07/07/2020
  • Est. Priority Date: 01/19/2017
  • Status: Active Grant
First Claim
Patent Images

1. A system to select mitigation parameters, the system comprising:

  • at least one packet intercept device coupled to a communication link in a computer network configured to make copies of packets of network traffic traversing in the computer network;

    a flow collector device coupled to the at least one packet intercept device configured to generate flows records associated with received network traffic packets captured by the at least one packet intercept device;

    a packet collector device coupled to the at least one packet intercept device configured to generate packet summaries associated with received network traffic packets captured by the at least one packet intercept device; and

    a network analytics system coupled to each of the flow collector device and the packet collector device, including;

    a memory configured to store instructions;

    a processor disposed in communication with the memory, wherein the processor upon execution of the instructions is configured to;

    provide a graphical user interface (GUI) that provides a plurality of interactive display elements that a user operates to select at least the following mitigation parameters;

         1) a filter definition for a filter to be applied;

         2) an attack traffic threshold value;

         3) a flow traffic threshold value; and

         4) a time window;

    define first user selected mitigation parameters for mitigation application whereby a user through interaction with the GUI selects each of

         1) a filter definition for a filter to be applied;

         2) an attack traffic threshold value;

         3) a flow traffic threshold value; and

         4) a time window;

    access a selected portion of stored network traffic for application of the first user selected mitigation parameters utilizing the generated flow records and packet summaries that corresponds to the user selected time window;

    apply the first user selected mitigation parameters to the selected portion of the stored network traffic; and

    output results of the applied first user selected mitigation parameters on the selected portion of the stored network traffic to be displayed on the GUI.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×