×

Device and method for detection of anomalous behavior in a computer network

  • US 9,401,932 B2
  • Filed: 01/03/2014
  • Issued: 07/26/2016
  • Est. Priority Date: 12/04/2012
  • Status: Active Grant
First Claim
Patent Images

1. A method for identifying an anomalous behavior in a network of host computing elements comprising the steps of:

  • providing 1-n network sensors in a computer network and in data communication therewith, wherein each network sensor is configured to sense or identify a characteristic of a network data packet, a network flow, or both being communicated across the computer network,outputting, by at least one of the network sensors, a sensor notification upon the satisfaction of a predetermined set of network data conditions,outputting the 1-n sensor notifications to a 1-n Rete net-based rule engine configured to execute a one or more Rete algorithms configured for the deterministic detection of an anomalous behavior in the network based on the notifications,executing the one or more Rete algorithms, andoutputting an alarm signal upon the detection of the anomalous behavior.

View all claims
  • 7 Assignments
Timeline View
Assignment View
    ×
    ×