DATA VISUALIZATION IN SELF LEARNING NETWORKS
First Claim
1. A method, comprising:
- maintaining, by a first device in a network, raw traffic flow information for the network;
providing, by the first device, a compressed summary of the raw traffic flow information to a second device in the network, wherein the second device is configured to transform the compressed summary for presentation to a user interface;
detecting, by the first device, an anomalous traffic flow based on an analysis of the raw traffic flow information using a machine learning-based anomaly detector; and
providing, by the first device, at least a portion of the raw traffic flow information related to the anomalous traffic flow to the second device for presentation to the user interface.
1 Assignment
0 Petitions
Accused Products
Abstract
In one embodiment, a first device in a network maintains raw traffic flow information for the network. The first device provides a compressed summary of the raw traffic flow information to a second device in the network. The second device is configured to transform the compressed summary for presentation to a user interface. The first device detects an anomalous traffic flow based on an analysis of the raw traffic flow information using a machine learning-based anomaly detector. The first device provides at least a portion of the raw traffic flow information related to the anomalous traffic flow to the second device for presentation to the user interface.
36 Citations
20 Claims
-
1. A method, comprising:
-
maintaining, by a first device in a network, raw traffic flow information for the network; providing, by the first device, a compressed summary of the raw traffic flow information to a second device in the network, wherein the second device is configured to transform the compressed summary for presentation to a user interface; detecting, by the first device, an anomalous traffic flow based on an analysis of the raw traffic flow information using a machine learning-based anomaly detector; and providing, by the first device, at least a portion of the raw traffic flow information related to the anomalous traffic flow to the second device for presentation to the user interface. - View Dependent Claims (2, 3, 4, 5, 6, 7)
-
-
8. An apparatus, comprising:
-
one or more network interfaces to communicate with a network; a processor coupled to the network interfaces and adapted to execute one or more processes; and a memory configured to store a process executable by the processor, the process when executed configured to; receive a compressed summary of raw traffic flow information from one or more devices in the network; transform the compressed summary of raw traffic flow information for presentation to a user interface; provide the transformed summary of raw traffic flow information to the user interface; request at least a portion of the raw traffic flow information from the one or more devices, wherein the requested portion of the raw traffic flow information is related to an anomalous traffic flow detected by one of the one or more devices; and provide the requested at least a portion of the raw traffic flow information to the user interface. - View Dependent Claims (9, 10, 11, 12, 13)
-
-
14. An apparatus, comprising:
-
one or more network interfaces to communicate with a network; a processor coupled to the network interfaces and adapted to execute one or more processes; and a memory configured to store a process executable by the processor, the process when executed configured to; maintain raw traffic flow information for the network; provide a compressed summary of the raw traffic flow information to a device in the network, wherein the device is configured to transform the compressed summary for presentation to a user interface; detect an anomalous traffic flow based on an analysis of the raw traffic flow information using a machine learning-based anomaly detector; and provide at least a portion of the raw traffic flow information related to the anomalous traffic flow to the device for presentation to the user interface. - View Dependent Claims (15, 16, 17, 18, 19, 20)
-
Specification