×

Vector-based anomaly detection

  • US 9,197,658 B2
  • Filed: 02/14/2014
  • Issued: 11/24/2015
  • Est. Priority Date: 11/18/2010
  • Status: Active Grant
First Claim
Patent Images

1. A hybrid-fabric apparatus for detecting anomalous behavior of a network fabric comprising a plurality of network nodes, the hybrid-fabric apparatus comprising:

  • a black box memory configured to store a plurality of behavior metrics; and

    an anomaly agent coupled with the black box and configured to;

    characterize a nominal behavior of a fabric as a baseline vector comprising at least two correlated behavior metrics selected from the plurality of behavior metrics, the at least two correlated behavior metrics having nominal values,establish anomaly detection criteria as a function of a variation from the baseline vector, the detection criteria defining a fabric anomalous behavior,disaggregate the anomaly detection criteria into a plurality of anomaly criterion,aggregate anomaly criterion statuses from at least some of the plurality of network nodes, each anomaly criterion status being calculated by a network node as a function of the node'"'"'s anomaly criterion and a measured vector of behavior metrics;

    detect satisfaction of the anomaly detection criteria as a function of the anomaly criterion statuses indicating occurrence of the fabric anomalous behavior relative to the nominal behavior, andpresent to a user the fabric anomalous behavior.

View all claims
  • 3 Assignments
Timeline View
Assignment View
    ×
    ×