Stackable aggregation for connection based anomaly detection
First Claim
Patent Images
1. A system, comprising:
- a plurality of collector devices that are disposed to collect statistical information on packets sent between nodes on a network;
a stackable aggregator device that receives network data from the plurality of collector devices, the aggregator device producing a connection table that maps each node on the network to a record that stores information about traffic to or from the node, the stackable aggregator comprising;
a manager blade, a database blade, and two or more, analyzer blades.
21 Assignments
0 Petitions
Accused Products
Abstract
A system includes a plurality of collector devices that are disposed to collect statistical information on packets that are sent between nodes on a network. The system also includes a stackable aggregator that receives network data from the plurality of collector devices, and which produces a connection table that maps each node on the network to a record that stores information about traffic to or from the node. The stackable aggregator includes a manager blade, a database blade, and two or more, analyzer blades.
193 Citations
20 Claims
-
1. A system, comprising:
-
a plurality of collector devices that are disposed to collect statistical information on packets sent between nodes on a network;
a stackable aggregator device that receives network data from the plurality of collector devices, the aggregator device producing a connection table that maps each node on the network to a record that stores information about traffic to or from the node, the stackable aggregator comprising;
a manager blade, a database blade, and two or more, analyzer blades. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13)
-
-
14. A method, comprises:
-
collecting statistical information on packets that are sent between nodes on a network;
dispatching statistical information to one of two or more analyzer blades to produce a connection table that maps each node on the network to a record that stores information about traffic to or from the node. - View Dependent Claims (15, 16)
-
-
17. A computer program product residing on a computer readable medium, comprising instructions for causing a computer to:
-
receive network data from a plurality of collector devices that collect statistical information on packets that are sent between nodes on a network; and
dispatch received network data from a plurality of collector devices to a specific one of the two or more analyzer blades to produce multiple connection tables each table storing a portion of the collect statistical information on packets sent on the network to a record. - View Dependent Claims (18, 19, 20)
-
Specification