×

NETWORK INTRUSION DETECTION VISUALIZATION

  • US 20110067106A1
  • Filed: 09/15/2009
  • Published: 03/17/2011
  • Est. Priority Date: 09/15/2009
  • Status: Active Grant
First Claim
Patent Images

1. A network monitoring and visualization system comprising:

  • a computer coupled to a network and adapted to receive data from the network, the computer including a computer readable medium having stored thereon software instructions for programming the computer to monitor the network and to provide a graphical visualization of monitored network activity, the software instructions, when executed by the computer, cause the computer to perform operations including;

    retrieving a plurality of minimum description length (MDL) models, each MDL model representing a different network activity behavior and each MDL model including a grammar having a plurality of motifs;

    receiving a network activity data sample corresponding to network activity;

    applying the grammar of each MDL model to the data sample to determine a measure of similarity between the data sample and the MDL model corresponding to the grammar being applied;

    characterizing the data sample based on the measure of similarity, including mapping a normalized difference value for each motif of a grammar to a generate a plurality of statistical features;

    generating a plurality of intelligent icons, each corresponding to one of the MDL models and each including a plurality of graphical representations corresponding to one of the statistical features representing the normalized difference value of a respective one of the motifs for that MDL model; and

    simultaneously displaying the intelligent icons on a display device coupled to the computer.

View all claims
  • 3 Assignments
Timeline View
Assignment View
    ×
    ×