×

Detecting network anomalies by probabilistic modeling of argument strings with markov chains

  • US 10,819,726 B2
  • Filed: 07/26/2018
  • Issued: 10/27/2020
  • Est. Priority Date: 05/27/2008
  • Status: Active Grant
First Claim
Patent Images

1. A method for detecting network anomalies, the method comprising:

  • receiving, using a hardware processor, a communication protocol message having an argument string that is transmitted from a first processor to a second processor across a computer network;

    determining, using the hardware processor, whether the communication protocol message is anomalous based on n-grams in the argument string by applying a probabilistic model that uses at least one Markov chain to generate a score that indicates a deviation of the argument string of the communication protocol message from previously received communication protocol messages and determining whether the score is greater than a threshold value; and

    performing, using the hardware processor, a predetermined action in response to determining that the communication protocol message is anomalous.

View all claims
  • 0 Assignments
Timeline View
Assignment View
    ×
    ×