MULTI-DIMENSIONAL SYSTEM ANOMALY DETECTION
First Claim
1. A method comprising:
- receiving, at a device in a network, a first plurality of measurements for network metrics captured during a first time period;
determining, by the device, a first set of correlations between the network metrics using the first plurality of measurements captured during the first time period;
receiving, at the device, a second plurality of measurements for the network metrics captured during a second time period;
determining, by the device, a second set of correlations between the network metrics using the second plurality of measurements captured during the second time period; and
identifying, by the device, a difference between the first and second sets of correlations between the network metrics as a network anomaly.
1 Assignment
0 Petitions
Accused Products
Abstract
In one embodiment, a device in a network receives a first plurality of measurements for network metrics captured during a first time period. The device determines a first set of correlations between the network metrics using the first plurality of measurements captured during the first time period. The device receives a second plurality of measurements for the network metrics captured during a second time period. The device determines a second set of correlations between the network metrics using the second plurality of measurements captured during the second time period. The device identifies a difference between the first and second sets of correlations between the network metrics as a network anomaly.
41 Citations
20 Claims
-
1. A method comprising:
-
receiving, at a device in a network, a first plurality of measurements for network metrics captured during a first time period; determining, by the device, a first set of correlations between the network metrics using the first plurality of measurements captured during the first time period; receiving, at the device, a second plurality of measurements for the network metrics captured during a second time period; determining, by the device, a second set of correlations between the network metrics using the second plurality of measurements captured during the second time period; and identifying, by the device, a difference between the first and second sets of correlations between the network metrics as a network anomaly. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8)
-
-
9. An apparatus, comprising:
-
one or more network interfaces to communicate with a network; a processor coupled to the network interfaces and configured to execute one or more processes; and a memory configured to store a process executable by the processor, the process when executed operable to; receive a first plurality of measurements for network metrics captured during a first time period; determine a first set of correlations between the network metrics using the first plurality of measurements captured during the first time period; receive a second plurality of measurements for the network metrics captured during a second time period; determine a second set of correlations between the network metrics using the second plurality of measurements captured during the second time period; and identify a difference between the first and second sets of correlations between the network metrics as a network anomaly. - View Dependent Claims (10, 11, 12, 13, 14, 15, 16)
-
-
17. A tangible, non-transitory, computer-readable medium storing program instructions that cause a device in a network to execute a process comprising:
-
receiving a first plurality of measurements for network metrics captured during a first time period; determining a first set of correlations between the network metrics using the first plurality of measurements captured during the first time period; receiving a second plurality of measurements for the network metrics captured during a second time period; determining a second set of correlations between the network metrics using the second plurality of measurements captured during the second time period; and identifying a difference between the first and second sets of correlations between the network metrics as a network anomaly. - View Dependent Claims (18, 19, 20)
-
Specification