×

Vector-based anomaly detection

  • US 8,683,591 B2
  • Filed: 02/09/2011
  • Issued: 03/25/2014
  • Est. Priority Date: 11/18/2010
  • Status: Active Grant
First Claim
Patent Images

1. A method of detecting anomalous behavior of a network fabric, the method comprising:

  • characterizing a nominal behavior of a fabric as a baseline vector of behavior metrics having nominal values, the fabric comprising networked nodes, wherein the baseline vector comprises at least two correlated behavior metrics;

    establishing anomaly detection criteria as a function of a variation from the baseline vector, the detection criteria defining a fabric anomalous behavior;

    disaggregating the anomaly detection criteria into a plurality of anomaly criterion;

    disseminating the plurality of anomaly criterion among nodes of the fabric;

    calculating, by the receiving nodes, anomaly criterion statuses at each receiving node as a function the node'"'"'s anomaly criterion and a measured vector of behavior metrics;

    aggregating anomaly criterion statuses from at least some of the receiving nodes;

    detecting satisfaction of the anomaly detection criteria as a function of the anomaly criterion statuses indicating occurrence of the fabric anomalous behavior relative to the nominal behavior; and

    notifying a manager of the fabric anomalous behavior.

View all claims
  • 3 Assignments
Timeline View
Assignment View
    ×
    ×