Stackable aggregation for connection based anomaly detection
First Claim
Patent Images
1. A system, comprising:
- a plurality of collector devices that are disposed to collect statistical information on packets sent between nodes on a network;
a stackable aggregator that receives network data from the plurality of collector devices, the aggregator producing a connection table that maps each node on the network to a record that stores information about traffic to or from the node, the stackable aggregator comprising;
a manager blade,a database blade, andtwo or more analyzer blades.
21 Assignments
0 Petitions
Accused Products
Abstract
A system includes a plurality of collector devices that are disposed to collect statistical information on packets that are sent between nodes on a network. The system also includes a stackable aggregator that receives network data from the plurality of collector devices, and which produces a connection table that maps each node on the network to a record that stores information about traffic to or from the node. The stackable aggregator includes a manager blade, a database blade, and two or more, analyzer blades.
-
Citations
20 Claims
-
1. A system, comprising:
-
a plurality of collector devices that are disposed to collect statistical information on packets sent between nodes on a network; a stackable aggregator that receives network data from the plurality of collector devices, the aggregator producing a connection table that maps each node on the network to a record that stores information about traffic to or from the node, the stackable aggregator comprising; a manager blade, a database blade, and two or more analyzer blades. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13)
-
-
14. A method, comprises:
-
collecting statistical information on packets that are sent between nodes on a network; dispatching statistical information via a reliable protocol to one of two or more analyzer blades in an aggregator to produce a connection table that maps each node on the network to a record that stores information about traffic to or from the node wherein the aggregator comprises a manager blade, a database blade, and the two or more analyzer blades. - View Dependent Claims (15, 16)
-
-
17. A non-transitory computer-readable storage device storing instructions that when executed by a computer cause the computer to:
-
receive network data from a plurality of collector devices that collect statistical information on packets that are sent between nodes on a network; and dispatch received network data from a plurality of collector devices via a reliable protocol to a specific one of the two or more analyzer blades, in an aggregator to produce multiple connection tables each table storing a portion of the collect statistical information on packets sent on the network to a record wherein the aggregator comprises a manager blade, a database blade, and the two or more analyzer blades. - View Dependent Claims (18, 19, 20)
-
Specification