Flow logging for connection-based anomaly detection
First Claim
1. A method, comprising:
- collecting flow records from a plurality of flow collector devices that are disposed to collect flow information on a network;
determining whether a pair of flow records has the same source and destination flow identifiers and was received within a predefined time period to eliminate duplicate flow records received from the flow collectors; and
storing remaining, non duplicated flow records received from the plurality of flow collector devices.
21 Assignments
0 Petitions
Accused Products
Abstract
A plurality of flow collector devices is disposed to collect flow information on a network. Duplicate flow records received from the flow collectors are eliminated by determining whether a pair of flow records has the same, source and destination flow identifiers and were received within a predefined time-period. Non-duplicated flow records received from the plurality of flow collector devices are stored and used to produces a connection table that maps each node on the network to a record that stores information about traffic to or from the node from non-duplicated flow records. The connection table stores statistical information of packets on the network based on a time-slice basis.
-
Citations
21 Claims
-
1. A method, comprising:
-
collecting flow records from a plurality of flow collector devices that are disposed to collect flow information on a network;
determining whether a pair of flow records has the same source and destination flow identifiers and was received within a predefined time period to eliminate duplicate flow records received from the flow collectors; and
storing remaining, non duplicated flow records received from the plurality of flow collector devices. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11)
-
-
12. A system comprises:
-
a computing device including a computer readable medium storing a computer program that includes instructions to cause the computing device to;
collect flow records from a plurality of flow collector devices that are disposed to collect flow information on a network;
determine whether a pair of flow records has the same whether a pair of flow records have the same source and destination flow identifiers and whether the records were received within a predefined time period to eliminate duplicate flow records received from the flow collectors;
store remaining, non duplicated flow records received data from the plurality of collector devices. - View Dependent Claims (13, 14, 15, 16)
-
-
17. A computer readable medium storing a computer program that includes instructions to cause a computing device to:
-
collect flow records from a plurality of flow collector devices that are disposed to collect flow information on a network;
determine whether a pair of flow records has the same source and destination flow identifiers and whether the records were received within a predefined time period to eliminate duplicate flow records received from the flow collectors;
store remaining, non duplicated flow records received data from the plurality of collector devices. - View Dependent Claims (18, 19, 20, 21)
-
Specification