EDGE-BASED DETECTION OF NEW AND UNEXPECTED FLOWS
First Claim
Patent Images
1. A method comprising:
- identifying, by a device in a network, a new interaction between two or more nodes in the network;
forming, by the device, a feature vector using contextual information associated with the new interaction between the two or more nodes;
causing, by the device, generation of an anomaly detection model for new node interactions using the feature vector; and
using, by the device, the anomaly detection model to determine whether a particular node interaction in the network is anomalous.
1 Assignment
0 Petitions
Accused Products
Abstract
In one embodiment, a device in a network identifies a new interaction between two or more nodes in the network. The device forms a feature vector using contextual information associated with the new interaction between the two or more nodes. The device causes generation of an anomaly detection model for new node interactions using the feature vector. The device uses the anomaly detection model to determine whether a particular node interaction in the network is anomalous.
-
Citations
20 Claims
-
1. A method comprising:
-
identifying, by a device in a network, a new interaction between two or more nodes in the network; forming, by the device, a feature vector using contextual information associated with the new interaction between the two or more nodes; causing, by the device, generation of an anomaly detection model for new node interactions using the feature vector; and using, by the device, the anomaly detection model to determine whether a particular node interaction in the network is anomalous. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11)
-
-
12. An apparatus, comprising:
-
one or more network interfaces to communicate with a network; a processor coupled to the one or more network interfaces and configured to execute one or more processes; and a memory configured to store a process executable by the processor, the process when executed operable to; identify a new interaction between two or more nodes in the network; form a feature vector using contextual information associated with the new interaction between the two or more nodes; cause generation of an anomaly detection model for new node interactions using the feature vector; and use the anomaly detection model to determine whether a particular node interaction in the network is anomalous. - View Dependent Claims (13, 14, 15, 16, 17, 18, 19)
-
-
20. A tangible, non-transitory, computer-readable media having software encoded thereon, the software when executed by a device in a network configured to:
-
identify a new interaction between two or more nodes in the network; form a feature vector using contextual information associated with the new interaction between the two or more nodes; cause generation of an anomaly detection model for new node interactions using the feature vector; and use the anomaly detection model to determine whether a particular node interaction in the network is anomalous.
-
Specification