DETERMINING A REPUTATION OF A NETWORK ENTITY
First Claim
Patent Images
1. A computer-implemented method, comprising:
- monitoring, by a network traffic monitoring system, network traffic data for a plurality of nodes of a network;
analyzing, by the network traffic monitoring system, the network traffic data to classify a type of traffic for each flow of a plurality of flows;
receiving, to the network traffic monitoring system from a requestor, a request for a reputation score associated with one or more nodes of the network;
identifying, by the network traffic monitoring system, the type of traffic for one or more flows associated with the one or more nodes;
determining, by the network monitoring system, the reputation score associated with the one or more nodes based on the type of traffic for the one or more flows associated with the one or more nodes; and
sending, by the network traffic monitoring system, the reputation score to the requestor.
1 Assignment
0 Petitions
Accused Products
Abstract
An example method can include monitoring a network to identify flows between nodes in the network. Once flows have been identified, the flows can be tagged and labelled according to the type of traffic they represent. If a flow represents malicious or otherwise undesirable traffic, it can be tagged accordingly. A request can then be made for a reputation score of an entity which can identify one or more nodes of the network.
-
Citations
20 Claims
-
1. A computer-implemented method, comprising:
-
monitoring, by a network traffic monitoring system, network traffic data for a plurality of nodes of a network; analyzing, by the network traffic monitoring system, the network traffic data to classify a type of traffic for each flow of a plurality of flows; receiving, to the network traffic monitoring system from a requestor, a request for a reputation score associated with one or more nodes of the network; identifying, by the network traffic monitoring system, the type of traffic for one or more flows associated with the one or more nodes; determining, by the network monitoring system, the reputation score associated with the one or more nodes based on the type of traffic for the one or more flows associated with the one or more nodes; and sending, by the network traffic monitoring system, the reputation score to the requestor. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9)
-
-
10. A non-transitory computer-readable medium having computer readable instructions that, when executed by a processor of a computer, cause the computer to:
-
monitor, by a network traffic monitoring system, network traffic data for a plurality of nodes of a network; analyze, by the network traffic monitoring system, the network traffic data to classify a type of traffic for each flow of a plurality of flows; receive, to the network traffic monitoring system from a requestor, a request for a reputation score associated with one or more nodes of the network; identify, by the network traffic monitoring system, the type of traffic for one or more flows associated with the one or more nodes; determine, by the network monitoring system, the reputation score associated with the one or more nodes based on the type of traffic for the one or more flows associated with the one or more nodes; and send, by the network traffic monitoring system, the reputation score to the requestor. - View Dependent Claims (11, 12, 13, 14, 15)
-
-
16. A system comprising:
-
a processor; memory including instructions that when executed by the processor, cause the system to; monitor, by a network traffic monitoring system, network traffic data for a plurality of nodes of a network; analyze, by the network traffic monitoring system, the network traffic data to classify a type of traffic for each flow of a plurality of flows; receive, to the network traffic monitoring system from a requestor, a request for a reputation score associated with one or more nodes of the network; identify, by the network traffic monitoring system, the type of traffic for one or more flows associated with the one or more nodes; determine, by the network monitoring system, the reputation score associated with the one or more nodes based on the type of traffic for the one or more flows associated with the one or more nodes; and send, by the network traffic monitoring system, the reputation score to the requestor. - View Dependent Claims (17, 18, 19, 20)
-
Specification