×

Anomaly detection systems for a computer network

  • US 7,808,916 B1
  • Filed: 12/28/2005
  • Issued: 10/05/2010
  • Est. Priority Date: 12/28/2005
  • Status: Expired due to Fees
First Claim
Patent Images

1. A network server, comprising:

  • a processor;

    memory storing executable instructions that, when executed by the processor, perform a method for detecting anomalous traffic in a data stream, said method comprising steps of;

    a) generating a baseline value corresponding to non-anomalous data in the data stream;

    b) generating a first test value based on current data of the data stream;

    c) adjusting the baseline value based on the first test value; and

    d) triggering an anomaly alarm when the first test value varies from the baseline by at least a predetermined value,wherein step a) comprises steps of;

    i) initializing parameters using the formulas;


    μ

    1=X1
    S1=S2= . . . =SN=1
    Var1=MinSD2 where N represents a number of intervals per cycle, MinSD>

    0, and X represents a data point, andii) generating the baseline by evaluating the formulas;

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×