Method and apparatus for rapid location of anomalies in IP traffic logs
First Claim
Patent Images
1. A method for identifying an anomaly, comprising:
- receiving at least one unit of data, where said at least one unit of data is associated with an event;
monitoring at least one object associated with said event;
ranking said at least one object on a rank list; and
identifying an anomaly in accordance with a movement of said at least one object within said rank list.
1 Assignment
0 Petitions
Accused Products
Abstract
An efficient method and apparatus for rapidly detecting anomalies from massive data streams is disclosed. In one embodiment, the method enables near real time detection of anomaly behavior in networks. The invention rapidly identifies the addresses that require further analysis and reduces the cost of monitoring, the cost of managing the security of the network as well as reduces the time needed to initiate mitigation steps.
-
Citations
20 Claims
-
1. A method for identifying an anomaly, comprising:
-
receiving at least one unit of data, where said at least one unit of data is associated with an event;
monitoring at least one object associated with said event;
ranking said at least one object on a rank list; and
identifying an anomaly in accordance with a movement of said at least one object within said rank list. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10)
-
-
11. A computer-readable medium having stored thereon a plurality of instructions, the plurality of instructions including instructions which, when executed by a processor, cause the processor to perform the steps of method for identifying an anomaly, comprising:
-
receiving at least one unit of data, where said at least one unit of data is associated with an event;
monitoring at least one object associated with said event;
ranking said at least one object on a rank list; and
identifying an anomaly in accordance with a movement of said at least one object within said rank list. - View Dependent Claims (12, 13, 14, 15, 16, 17, 18, 19)
-
-
20. An apparatus for identifying an anomaly, comprising:
-
means for receiving at least one unit of data, where said at least one unit of data is associated with an event;
means for monitoring at least one object associated with said event;
means for ranking said at least one object on a rank list; and
means for identifying an anomaly in accordance with a movement of said at least one object within said rank list.
-
Specification