Please download the dossier by clicking on the dossier button x
×

Network intrusion detection visualization

  • US 8,245,301 B2
  • Filed: 09/15/2009
  • Issued: 08/14/2012
  • Est. Priority Date: 09/15/2009
  • Status: Expired due to Fees
First Claim
Patent Images

1. A network monitoring and visualization system comprising:

  • a computer coupled to a network and adapted to receive data from the network, the computer including a computer readable medium having stored thereon software instructions for programming the computer to monitor the network and to provide a graphical visualization of monitored network activity, the software instructions, when executed by the computer, cause the computer to perform operations including;

    retrieving a plurality of minimum description length (MDL) models, each MDL model representing a different network activity behavior and each MDL model including a grammar having a plurality of motifs;

    receiving a network activity data sample corresponding to network activity;

    applying the grammar of each MDL model to the data sample to determine a measure of similarity between the data sample and the MDL model corresponding to the grammar being applied;

    characterizing the data sample based on the measure of similarity, including mapping a normalized difference value for each motif of a grammar to a generate a plurality of statistical features;

    generating a plurality of intelligent icons, each corresponding to one of the MDL models and each including a plurality of graphical representations corresponding to one of the statistical features representing the normalized difference value of a respective one of the motifs for that MDL model;

    simultaneously displaying the intelligent icons on a display device coupled to the computer;

    determining a relative importance of a corresponding motif within the MDL model associated with that motif;

    arranging the graphical representations based on the relative importance of the corresponding motif within the MDL model associated with that motif; and

    dynamically updating the intelligent icons in response to changes in data associated with each respective intelligent icon, such that the intelligent icons displayed on the display device represent only the most recent data values of the corresponding MDL model.

View all claims
  • 3 Assignments
Timeline View
Assignment View
    ×
    ×