System and method for detection of aberrant network behavior by clients of a network access gateway
First Claim
1. A system for determining if aberrant network behavior is occurring with respect to a first client, comprising:
- a first network interface coupled to one or more clients, wherein the first network interface includes a processor and at least one memory, the at least one memory including instructions to configure the processor to;
analyze received network communications to determine if a first rule of any of one or more rules corresponds to the received network communications associated with the first client;
updating a first set of statistical information associated with the first client responsive to a determination that the first rule corresponds to the network communications, wherein the first set of statistical information is accumulated over a time period; and
analyzing the first set of statistical information to determine if aberrant network behavior is occurring with respect to the first client by applying a set of conditions to the first set of statistical information, each of the set of conditions corresponding to aberrant network behavior and comprising a threshold to be applied to at least a portion of the statistical information.
7 Assignments
0 Petitions
Accused Products
Abstract
A first network interface coupled to one or more clients. The first network interface analyzes received network communications to determine if a first rule of any of one or more rules corresponds to the received network communications associated with a first client. The network interface updates a first set of statistical information accumulated over a time period associated with the first client responsive to a determination that the first rule corresponds to the network communications. The network interface analyzes the first set of statistical information to determine if aberrant network behavior is occurring with respect to the first client by applying a set of conditions to the first set of statistical information. Each of the set of conditions corresponds to aberrant network behavior and comprises a threshold to be applied to at least a portion of the statistical information.
-
Citations
20 Claims
-
1. A system for determining if aberrant network behavior is occurring with respect to a first client, comprising:
a first network interface coupled to one or more clients, wherein the first network interface includes a processor and at least one memory, the at least one memory including instructions to configure the processor to; analyze received network communications to determine if a first rule of any of one or more rules corresponds to the received network communications associated with the first client; updating a first set of statistical information associated with the first client responsive to a determination that the first rule corresponds to the network communications, wherein the first set of statistical information is accumulated over a time period; and analyzing the first set of statistical information to determine if aberrant network behavior is occurring with respect to the first client by applying a set of conditions to the first set of statistical information, each of the set of conditions corresponding to aberrant network behavior and comprising a threshold to be applied to at least a portion of the statistical information. - View Dependent Claims (2, 3, 4, 5, 6, 7)
-
8. A method determining if aberrant network behavior is occurring with respect to a first client, comprising:
-
analyzing received network communications associated with the first client to determine if a first rule of any of one or more rules corresponds to the received network communications associated with the first client; updating a first set of statistical information associated with the first client responsive to a determination that the first rule corresponds to the received network communications, wherein the first set of statistical information is accumulated over a time period; and analyzing the first set of statistical information to determine if aberrant network behavior is occurring with respect to the first client by applying a set of conditions to the first set of statistical information, each of the set of conditions corresponding to aberrant network behavior and comprising a threshold to be applied to at least a portion of the statistical information. - View Dependent Claims (9, 10, 11, 12, 13, 14)
-
-
15. A method for detecting aberrant network behavior in one or more clients coupled to a first network interface, comprising:
-
receiving network communications at a first network interface, wherein each of the received network communications is associated with a first client; analyzing the received network communications to determine if a first rule of any of one or more rules corresponds to the received network communications associated with the first client; updating the first set of statistical information associated with the first client responsive to a determination that the first rule corresponds to the network communications; and analyzing a first set of statistical information accumulated over a period of time associated with the first client to determine if aberrant network behavior is occurring with respect to the first client by applying a set of conditions to the first set of statistical information, each of the set of conditions corresponding to the aberrant network behavior and comprising a threshold to be applied to at least a portion of the statistical information. - View Dependent Claims (16, 17, 18, 19, 20)
-
Specification