METHOD AND SYSTEM FOR DETECTING AN ANOMALOUS NETWORKED DEVICE
First Claim
Patent Images
1. A method for detecting one or more anomalous devices, the method comprising:
- for each of a plurality of devices, receiving semi-structured data from the device;
for each pair of devices of the plurality of devices, determining a similarity measurement between semi-structured data from a first device of the pair of devices and semi-structured data from a second device of the pair of devices;
identifying one or more anomalous devices; and
performing one or more remedial actions for the one or more identified anomalous devices.
6 Assignments
0 Petitions
Accused Products
Abstract
Methods and systems for detecting one or more anomalous devices are disclosed. For each of a plurality of devices, semi-structured data may be received from the device. For each pair of devices, of the plurality of devices, a similarity measurement may be determined between semi-structured data from a first device of the pair of devices and semi-structured data from a second device of the pair of devices. One or more anomalous devices may then be identified and one or more remedial actions may be performed for the one or more identified anomalous devices.
77 Citations
24 Claims
-
1. A method for detecting one or more anomalous devices, the method comprising:
-
for each of a plurality of devices, receiving semi-structured data from the device; for each pair of devices of the plurality of devices, determining a similarity measurement between semi-structured data from a first device of the pair of devices and semi-structured data from a second device of the pair of devices; identifying one or more anomalous devices; and performing one or more remedial actions for the one or more identified anomalous devices. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12)
-
-
13. A system for detecting one or more anomalous devices, the system comprising:
-
a processor; a communication port in communication with the processor; and a processor-readable storage medium in communication with the processor, wherein the processor-readable storage medium contains one or more programming instructions for performing a method of detecting one or more anomalous devices, the method comprising; for each of a plurality of devices, receiving semi-structured data from the device, for each pair of devices of the plurality of devices, determining a similarity measurement between semi-structured data from, a first device of the pair of devices and semi-structured data from a second device of the pair of devices, identifying one or more anomalous devices, and performing one or more remedial actions for the one or more identified anomalous devices. - View Dependent Claims (14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24)
-
Specification