×

SYSTEM AND METHOD FOR DETECTION OF ABERRANT NETWORK BEHAVIOR BY CLIENTS OF A NETWORK ACCESS GATEWAY

  • US 20100191850A1
  • Filed: 04/01/2010
  • Published: 07/29/2010
  • Est. Priority Date: 03/10/2004
  • Status: Active Grant
First Claim
Patent Images

1. A system for detecting aberrant network, comprising:

  • a processor;

    a first network interface coupled to the processor, wherein the first network interface is coupled to one or more clients;

    a memory accessible by the processor;

    wherein the system is configured to;

    receive network communications at the first network interface, wherein each of the network communications is associated with a first client;

    determine if aberrant network behavior is occurring with respect to the first client wherein determining if the network behavior is aberrant comprises;

    analyzing the received network communications based upon one or more rules to determine if the network communications match any of the one or more rules, wherein the one or more rules are configured to identify particular network communications,if a network communication associated with the first client matches a first rule;

    updating a first set of statistical information associated with the first client, wherein the first set of statistical information is accumulated over a time period and is associated with at least the first rule of the one or more rules; and

    applying a set of conditions to the first set of statistical information, each of the set of conditions corresponding to aberrant network behavior and comprising a threshold to be applied to at least a portion of the statistical information.

View all claims
  • 8 Assignments
Timeline View
Assignment View
    ×
    ×