Network monitoring of behavior probability density
First Claim
1. A method, including steps ofmaintaining, at a network monitoring device, information regarding long-term historical activity of a network;
- maintaining information regarding short-term activity of that network;
receiving information regarding recent activity of that network;
comparing that information regarding recent activity with that information regarding long-term activity, and determining the presence of abnormal activity in response to a result of said steps of comparing recent with long-term activity;
comparing that information regarding recent activity with that information regarding short-term activity, determining the presence of changes in network activity in response to a result of said steps of comparing recent with short-term activity, and updating that short-term activity if and only if that information regarding recent activity is within normal behavior for that network;
comparing that information regarding short-term activity with that information regarding long-term activity, and determining the presence of changes in network activity in response to a result of said steps of comparing short-term with long-term activity, and updating that long-term activity using that recent activity if and only if that information regarding recent activity is within normal behavior for that network.
11 Assignments
0 Petitions
Accused Products
Abstract
A network monitoring system maintains both information regarding historical activity of a network, and information regarding emergent activity of the network. Comparison of historical activity of the network with emergent activity of the network allows the system to determine whether network activity is changing over time. The network monitoring system maintains data structures representing a p.d.f. for observable values of network parameters. Recent activity of the network can be compared with both the p.d.f. for historical activity and for emergent activity to aid in determining whether that recent activity is within the realm of normal, and whether network activity is changing over time. The network monitoring system adjusts that information regarding historical activity of a network in response to emergent activity of that network. The network monitoring device determines information regarding time-dependent activity of that network in response to spectral analysis regarding historical activity of that network.
170 Citations
22 Claims
-
1. A method, including steps of
maintaining, at a network monitoring device, information regarding long-term historical activity of a network; -
maintaining information regarding short-term activity of that network; receiving information regarding recent activity of that network; comparing that information regarding recent activity with that information regarding long-term activity, and determining the presence of abnormal activity in response to a result of said steps of comparing recent with long-term activity; comparing that information regarding recent activity with that information regarding short-term activity, determining the presence of changes in network activity in response to a result of said steps of comparing recent with short-term activity, and updating that short-term activity if and only if that information regarding recent activity is within normal behavior for that network; comparing that information regarding short-term activity with that information regarding long-term activity, and determining the presence of changes in network activity in response to a result of said steps of comparing short-term with long-term activity, and updating that long-term activity using that recent activity if and only if that information regarding recent activity is within normal behavior for that network. - View Dependent Claims (2, 3, 4, 6, 19)
-
-
5. A method, including steps of
maintaining, at a network monitoring device, information regarding historical activity of a network; -
maintaining information regarding emergent activity of that network; comparing recent network activity to a predetermined parameter and the emergent activity, and determining the presence of changes in network activity in response to a result of said steps of comparing; also comparing recent network activity to the historical activity, and also determining the presence of abnormal activity in response to said steps of also comparing; if and only if said steps of also comparing recent network activity to the historical activity indicate lack of abnormal activity, adjusting that information regarding emergent activity of that network in response to the comparing; and if and only if said steps of also comparing recent network activity to the historical activity indicate lack of abnormal activity, adjusting that information regarding historical activity of that network in response to that information regarding emergent activity of that network. - View Dependent Claims (7, 8, 9, 10, 11, 12, 20, 22)
-
-
13. A method, including steps of
maintaining, at a network monitoring device, information regarding relatively long-term historical activity of a network; -
maintaining information regarding short-term activity of said network; receiving a value indicative of recent network activity; comparing said recent network activity to said short-term activity and a predetermined threshold value, determining the presence of changes in network activity in response to said steps of comparing recent activity with short-term activity; comparing said recent network activity to said long-term activity, and determining the presence of abnormal activity in response to said steps of comparing recent activity with long-term activity; maintaining a history of the values in response to the steps of comparing recent activity with long-term activity; if and only if said steps of determining the presence of abnormal activity indicate lack of abnormal activity, adjusting that information regarding the long-term historical activity of a network in response to said short-term activity of that network; and determining information regarding time-dependent activity of that network in response to that information regarding long-term historical activity of that network. - View Dependent Claims (14, 15, 16, 17, 18, 21)
-
Specification