SYSTEMS AND METHODS FOR RULE-BASED ANOMALY DETECTION ON IP NETWORK FLOW
First Claim
1. A system comprising:
- a plurality of routers configured to route network traffic, each of the routers further configured to generate flow records pertain to the traffic flow through the respective router;
a flow collector in communication with the plurality of routers and receiving the flow records therefrom; and
a flow classifier configured to analyze the flow records from each of the plurality of routers and to identify an anomaly in traffic flow within the network.
1 Assignment
0 Petitions
Accused Products
Abstract
A system to detect anomalies in internet protocol (IP) flows uses a set of machine-learning (ML) rules that can be applied in real time at the IP flow level. A communication network has a large number of routers that can be equipped with flow monitoring capability. A flow collector collects flow data from the routers throughout the communication network and provides them to a flow classifier. At the same time, a limited number of locations in the network monitor data packets and generate alerts based on packet data properties. The packet alerts and the flow data are provided to a machine learning system that detects correlations between the packet-based alerts and the flow data to thereby generate a series of flow-level alerts. These rules are provided to the flow time classifier. Over time, the new packet alerts and flow data are used to provide updated rules generated by the machine learning system.
277 Citations
22 Claims
-
1. A system comprising:
-
a plurality of routers configured to route network traffic, each of the routers further configured to generate flow records pertain to the traffic flow through the respective router; a flow collector in communication with the plurality of routers and receiving the flow records therefrom; and a flow classifier configured to analyze the flow records from each of the plurality of routers and to identify an anomaly in traffic flow within the network. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12)
-
-
13. A system comprising:
-
network routing means having network interfaces for routing network traffic and for generating flow records pertain to the traffic flow therethrough; flow collector means for receiving the generated flow records; and flow classifier means for analyzing the flow records and identifying an anomaly in traffic flow within the network. - View Dependent Claims (14, 15, 16, 17)
-
-
18. A method comprising:
-
generating flow records at each of a plurality of network routing interfaces routing network; receiving the generated flow records from the plurality of network routing interfaces; and analyzing the flow records to thereby identify an anomaly in traffic flow within the network based on flow-level rules. - View Dependent Claims (19, 20, 21, 22)
-
Specification