×

STATISTICAL METHOD AND SYSTEM FOR NETWORK ANOMALY DETECTION

  • US 20080250497A1
  • Filed: 03/31/2008
  • Published: 10/09/2008
  • Est. Priority Date: 03/30/2007
  • Status: Active Grant
First Claim
Patent Images

1. A method for determining an Internet protocol (IP) network status comprising the steps of:

  • monitoring an IP communications network, said IP communications network comprising a plurality of associated computer systems, said monitoring step further comprising the steps of;

    evaluating logged data communicated on said IP communications network as said logged data is logged; and

    detecting at least one data communications event from said logged data to be a potentially anomalous event by nominating said at least one data communications event and performing a time series generation associated with the communication of said at least one data communications event on said IP communications network;

    discovering said potentially anomalous data event to be an anomalous event by forming a percentiled data set from said logged data and comparing said at least one data communications event to a threshold level associated with said percentiled data set; and

    generating an alert signal in association with said monitoring step if said anomalous event differs from said percentiled data set by a level at least equal to said threshold level.

View all claims
  • 3 Assignments
Timeline View
Assignment View
    ×
    ×