×

Network surveillance using long-term and short-term statistical profiles to determine suspicious network activity

DC
  • US 7,594,260 B2
  • Filed: 05/05/2003
  • Issued: 09/22/2009
  • Est. Priority Date: 11/09/1998
  • Status: Expired due to Fees
First Claim
Patent Images

1. A method of network surveillance, comprising:

  • monitoring an event stream derived from network packets;

    building a long-term statistical profile and multiple short-term statistical profiles from at least one measure of said event stream;

    comparing one of the multiple short-term statistical profiles with the long-term statistical profile; and

    determining whether the difference between the one of the multiple short-term statistical profiles and the long-term statistical profile indicates suspicious network activity.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×