×

DETECTING SUSPICIOUS NETWORK ACTIVITY USING FLOW SAMPLING

  • US 20130036469A1
  • Filed: 08/03/2011
  • Published: 02/07/2013
  • Est. Priority Date: 08/03/2011
  • Status: Active Grant
First Claim
Patent Images

1. A method for network security, comprising:

  • receiving flow sampled network traffic from a plurality of network devices with a network monitoring computing device for network traffic among a plurality of computing devices;

    comparing source ports and destination ports in the flow sampled network traffic to a list of approved ports with the network monitoring computing device; and

    detecting suspicious network activity for flow sampled network traffic having a source port and a destination port exceptional to the list of approved ports with the network monitoring computing device.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×