×

Apparatus method and medium for detecting payload anomaly using n-gram distribution of normal data

  • US 20050281291A1
  • Filed: 11/12/2004
  • Published: 12/22/2005
  • Est. Priority Date: 11/12/2003
  • Status: Active Grant
First Claim
Patent Images

1. A method of detecting anomalous payloads transmitted through a network, comprising the steps of:

  • receiving at least one payload within the network;

    determining a length for data contained in the at least one payload;

    generating a statistical distribution of data contained in the at least one payload received within the network;

    comparing at least one portion of the generated statistical distribution to a corresponding portion of a selected model distribution representative of normal payloads transmitted through the network;

    wherein the selected model distribution has a predetermined length range that encompasses the length for data contained in the at least one payload; and

    identifying whether the at least one payload is an anomalous payload based, at least in part, on differences detected between the at least one portion of the statistical distribution for the at least one payload and the corresponding portion of the model distribution.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×