Connection table for intrusion detection
First Claim
Patent Images
1. A computer system for tracking network behavior, comprising:
- a processor;
a memory that stores;
a connection table that maps each host of a network to a record that stores traffic information from the host to other hosts or from the other hosts to the host in the network for a specified time interval, anda profile table that stores historical traffic information as exponentially weighted moving average values; and
a merging mechanism configured to merge the record associated with each host for the specified time interval from the connection table into the historical traffic information in the profile table.
21 Assignments
0 Petitions
Accused Products
Abstract
A system for detecting network intrusions and other conditions in a network is described. The system includes a plurality of collector devices that are disposed to collect data and statistical information on packets that are sent between nodes on a network. An aggregator device is disposed to receive data and statistical information from the plurality of collector devices. The aggregator device produces a connection table that maps each node on the network to a record that stores information about traffic to or from the node. The aggregator runs processes that determine network events from aggregating of anomalies into network events.
-
Citations
30 Claims
-
1. A computer system for tracking network behavior, comprising:
-
a processor; a memory that stores; a connection table that maps each host of a network to a record that stores traffic information from the host to other hosts or from the other hosts to the host in the network for a specified time interval, and a profile table that stores historical traffic information as exponentially weighted moving average values; and a merging mechanism configured to merge the record associated with each host for the specified time interval from the connection table into the historical traffic information in the profile table. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17)
-
-
18. A computer system for tracking network behavior, the computer system comprising:
-
a processor; a memory that stores; a connection table that maps each host of a network to a record that stores traffic information from the host to other hosts or from the other hosts to the host in the network for a specified time interval, wherein the connection table is indexed according to one or more of source address, destination address and a specified time interval, and wherein the connection table includes records fields for storing statistical information for traffic between the hosts; and a profile table that stores historical traffic information as exponentially weighted moving average values; and a merging mechanism configured to merge the record associated with each host for the specified time interval from the connection table into the historical traffic information in the profile table. - View Dependent Claims (19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30)
-
Specification