×

Impact Scoring and Reducing False Positives

  • US 20100027432A1
  • Filed: 11/06/2008
  • Published: 02/04/2010
  • Est. Priority Date: 07/31/2008
  • Status: Active Grant
First Claim
Patent Images

1. A computer program product residing on a computer readable medium for anomaly detection, the computer program product comprising instructions for causing a processor to:

  • detect a spike or dip in at least one network traffic characteristic;

    determine a change in overall observed network traffic for the at least one network traffic characteristic at the time of the detected spike or dip in the at least one network traffic characteristic by;

    comparing the network traffic for the at least one network traffic characteristic at a time period of a predetermined length of time prior to the time of the detected spike or dip in the at least one network traffic characteristic to the overall observed network traffic for the at least one network traffic characteristic at the time of the detected spike or dip in the at least one network traffic characteristic;

    determine changes in the observed network traffic for the at least one network traffic characteristic for a plurality of individual network entities at the time of the detected spike or dip in the at least one network traffic characteristic by;

    comparing the network traffic for the at least one network traffic characteristic for each of the individual network entities at the time period of the predetermined length of time prior to the time of the detected spike or dip in network traffic for the at least one network traffic characteristic to the network traffic for the at least one network traffic characteristic for each of the individual network entities at the time of the detected spike or dip in the at least one network traffic characteristic; and

    produce impact scores for the plurality of individual network entities by calculating a ratio of the change in the network traffic for the network entity to the change in the overall observed network traffic for the at least one network traffic characteristic.

View all claims
  • 22 Assignments
Timeline View
Assignment View
    ×
    ×