METHOD OF DETECTING ANOMALIES IN A COMMUNICATION SYSTEM USING NUMERICAL PACKET FEATURES
1 Assignment
0 Petitions
Accused Products
Abstract
A method of detecting anomalies in a communication system, includes: providing a first packet flow portion and a second packet flow portion; extracting samples of a numerical feature associated with a traffic status of the first and second packet flow portions; computing from said extracted samples a first statistical dispersion quantity and a second statistical dispersion quantity of the numerical feature associated with the first and second packet flow portions, respectively; computing from the dispersion quantities a variation quantity representing a dispersion change from the first packet flow portion to the second packet flow portion; comparing the variation quantity with a comparison value; and detecting an anomaly in the system in response to said comparison.
-
Citations
50 Claims
-
1-25. -25. (canceled)
-
26. A method of detecting anomalies in a communication system, comprising:
-
providing a first packet flow portion and a second packet flow portion; extracting samples of a numerical feature associated with a traffic status of the first and second packet flow portions; computing from said extracted samples a first statistical dispersion quantity and a second statistical dispersion quantity of the numerical feature associated with the first and second packet flow portions, respectively; computing from said dispersion quantities a variation quantity representing a dispersion change from the first packet flow portion to the second packet flow portion; comparing the variation quantity with a comparison value; and detecting an anomaly in the system in response to said comparison. - View Dependent Claims (27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37, 38, 39, 40, 41, 42, 43, 44, 45, 46, 50)
-
-
47. An apparatus capable of detecting anomalies in a packet switched communication system, comprising:
-
a collection module capable of storing samples of a numerical packet feature associated with traffic status of a first packet flow portion and a second packet flow portion; a computing module capable of being arranged so as to; compute from said samples a first statistical dispersion quantity and a second statistical dispersion quantity of the numerical feature associated with the first and second packet flow portions, respectively; and compute from said dispersion quantities a variation quantity representing a dispersion change from the first packet flow portion to the second packet flow portion; and a detection module arranged so as to; compare the variation quantity with a comparison value; and detect an anomaly in the system in response to said comparison. - View Dependent Claims (48, 49)
-
Specification