×

Systems, methods, and media for detecting network anomalies using a trained probabilistic model

  • US 8,844,033 B2
  • Filed: 05/27/2009
  • Issued: 09/23/2014
  • Est. Priority Date: 05/27/2008
  • Status: Active Grant
First Claim
Patent Images

1. A method for detecting network anomalies, the method comprising:

  • receiving a training dataset of communication protocol messages having argument strings;

    determining a content and a structure associated with each of the argument strings;

    receiving a mixture size that specifies a number of Markov chains to use in a probabilistic model;

    training the probabilistic model using the determined content and structure of each of the argument strings and using a mixture of Markov chains specified by the received mixture size;

    receiving a communication protocol message having an argument string that is transmitted from a first processor to a second processor across a computer network;

    applying the probabilistic model to the received communication protocol message to determine whether the communication protocol message is anomalous; and

    performing a predetermined action in response to determining that the communication protocol message is anomalous.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×