×

Selective flow inspection based on endpoint behavior and random sampling

  • US 20150256431A1
  • Filed: 03/07/2014
  • Published: 09/10/2015
  • Est. Priority Date: 03/07/2014
  • Status: Abandoned Application
First Claim
Patent Images

1. A computer-implemented method comprising:

  • determining an initiator of network traffic;

    at each of multiple instants of time, collecting usage data for network traffic associated with the initiator;

    storing historical usage data based on updates from usage data for the network traffic over time;

    determining whether current usage data are within an expected distribution with respect to the historical usage data by comparing the current usage data to the historical usage data of the initiator;

    selecting an inspection threshold for traffic flows from the initiator based upon the comparison between the current usage data and the historical usage data; and

    determining a proportion of traffic flows associated with the initiator to be inspected based on the inspection threshold.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×