×

System and method for detection of aberrant network behavior by clients of a network access gateway

  • US 8,019,866 B2
  • Filed: 08/06/2009
  • Issued: 09/13/2011
  • Est. Priority Date: 03/10/2004
  • Status: Active Grant
First Claim
Patent Images

1. A system for detecting aberrant network, comprising:

  • a processor;

    a first network interface coupled to the processor, wherein the first network interface is coupled to one or more clients;

    a memory accessible by the processor;

    wherein the system is configured to;

    receive network communications at the first network interface, wherein each of the network communications is associated with a first client;

    determine if aberrant network behavior is occurring with respect to the first client wherein determining if the network behavior is aberrant comprises;

    analyzing the received network communications based upon one or more rules to determine if the network communication matches any of the one or more rules, wherein the one or more rules are configured to identify particular network communications,if a network communication associated with the first client matches a first rule;

    updating a first list of statistical information associated with the first client and the first rule wherein the statistical information is accumulated over a time period, the first list is one of a first set of lists corresponding to the first client and each list comprises statistical information associated with at least one of the one or more rules; and

    testing the statistical information in each list of the first set of lists using a set of conditions corresponding to aberrant network behavior, wherein each of the set of conditions is associated with at least one list of the first set of lists.

View all claims
  • 7 Assignments
Timeline View
Assignment View
    ×
    ×