×

Verifying network attack detector effectiveness

  • US 9,922,196 B2
  • Filed: 12/21/2016
  • Issued: 03/20/2018
  • Est. Priority Date: 07/23/2014
  • Status: Active Grant
First Claim
Patent Images

1. A method, comprising:

  • identifying, by a coordinator device in a network, a type of network attack;

    determining, by the coordinator device, a verification schedule during which an attack classifier executed by a device in the network is to be tested;

    coordinating, by the coordinator device, a validation test for the attack classifier for execution during the verification schedule and for the identified type of network attack, wherein the validation test includes instructing the device in the network to;

    classify a set of network traffic that includes traffic observed by the device and attack traffic specified by the coordinator device;

    generate classification results based on the classified set of network traffic; and

    provide the classification results to the coordinator device,wherein the attack traffic and the observed traffic are received from one or more other devices in the network, and wherein the coordinator device instructs the one or more other devices to send the attack traffic at a low priority;

    receiving, at the coordinator device, results of the validation test from the device; and

    evaluating, by the coordinator device, a performance of the attack classifier based on the results of the validation test, wherein evaluating includes determining when the performance of the attack classifier is above a specified performance threshold to determine whether the attack classifier is still adequately able to detect an attack.

View all claims
  • 0 Assignments
Timeline View
Assignment View
    ×
    ×