×

Aggregator for connection based anomaly detection

  • US 8,479,057 B2
  • Filed: 11/03/2003
  • Issued: 07/02/2013
  • Est. Priority Date: 11/04/2002
  • Status: Active Grant
First Claim
Patent Images

1. A device, comprising:

  • a processor;

    a memory storing;

    a connection table that maps each node of a network to a host object that stores information about traffic to the node and from the node, wherein the connection table includes a plurality of sub-tables to track data at different time-scales, and the connection sub-tables include a time-slice connection table that operates on a small unit of time and at least one other sub-table that operates on a larger unit of time than the time slice sub-table with each sub-table holding the sum of records received from all collectors during respective units of time; and

    a computer readable medium storing a computer program product comprising instructions for causing the device to;

    detect anomalies in network traffic based on information in the connection table and to aggregate the anomalies into network events according to connection patterns.

View all claims
  • 23 Assignments
Timeline View
Assignment View
    ×
    ×