×

Vector-based anomaly detection

  • US 9,716,723 B2
  • Filed: 10/20/2015
  • Issued: 07/25/2017
  • Est. Priority Date: 11/18/2010
  • Status: Active Grant
First Claim
Patent Images

1. A method of detecting anomalous behavior of a network fabric, comprising:

  • determining a baseline vector corresponding to nominal behavior of a fabric, the baseline vector comprising at least two different behavior metrics that are correlated with each other;

    disaggregating anomaly detection criteria into a plurality of anomaly criterion to be distributed among nodes of the fabric, the anomaly detection criteria characterizing a variation from the baseline vector, and each of the plurality of anomaly criterion comprising a function of a measured vector of behavior metrics, the variation calculated based on a variation function applied to a vector of measured behavior metrics having elements corresponding to member elements of the baseline vector;

    aggregating anomaly criterion statuses calculated by at least some of the nodes to detect anomalous behavior, each anomaly criterion status being calculated by a network node as a function of the node'"'"'s anomaly criterion and a measured vector of the at least two different behavior metrics; and

    notifying a manager of the fabric anomalous behavior.

View all claims
  • 3 Assignments
Timeline View
Assignment View
    ×
    ×