×

Anomaly detection through header field entropy

  • US 10,623,283 B2
  • Filed: 06/03/2016
  • Issued: 04/14/2020
  • Est. Priority Date: 06/05/2015
  • Status: Active Grant
First Claim
Patent Images

1. A computer-implemented method comprising:

  • detecting, using a sensor installed on an endpoint, a first plurality of flows associated with the endpoint;

    determining a first entropy associated with at least one of a plurality of header fields for the first plurality of flows, the plurality of header fields having various entropy values and determined to indicate malicious flows;

    determining whether the first entropy is greater than a predetermined amount, the predetermined amount being a cutoff level indicative of a malicious flow and based on a second entropy associated with a second plurality of flows;

    determining the first plurality of flows is anomalous when the first entropy is determined to be greater than the predetermined amount; and

    cutting off the first plurality of flows when the first plurality of flows is determined to be anomalous,wherein,the at least one of the plurality of header fields includes multiple ones of the plurality of header fields, andthe first entropy is determined based on a combined entropy of the multiple ones of the plurality of header fields.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×