SYSTEM AND METHOD FOR AUTOMATED NETWORK MONITORING AND DETECTION OF NETWORK ANOMALIES
First Claim
1. A system for unsupervised detection of system anomalies in a network, comprising:
- one or more network elements;
a flow collector configured to collect instances of network data from the one or more network elements;
a historical dataset database configured to store the instances of network data;
a historical dataset pattern extractor configured to analyze the instances of network data and produce a historical behavioral pattern for each of the instances of network data; and
a flow stream processor configured to analyze instances of network data in real time, produce a current behavioral pattern for each of the instances of network data, compare the current behavioral pattern to a corresponding historical behavioral pattern, and detect an anomaly based on the comparison between the current behavioral pattern and the corresponding historical behavioral pattern.
1 Assignment
0 Petitions
Accused Products
Abstract
A system and method for unsupervised detection of system anomalies in a network, including one or more network elements, a flow collector configured to collect instances of network data from the one or more network elements, a historical dataset database configured to store the instances of network data, a historical dataset pattern extractor configured to analyze the instances of network data and produce a historical behavioral pattern for each of the instances of network data, and a flow stream processor configured to analyze instances of network data in real time, produce a current behavioral pattern for each of the instances of network data, compare the current behavioral pattern to a corresponding historical behavioral pattern, and detect an anomaly based on the comparison between the current behavioral pattern and the corresponding historical behavioral pattern.
51 Citations
20 Claims
-
1. A system for unsupervised detection of system anomalies in a network, comprising:
-
one or more network elements; a flow collector configured to collect instances of network data from the one or more network elements; a historical dataset database configured to store the instances of network data; a historical dataset pattern extractor configured to analyze the instances of network data and produce a historical behavioral pattern for each of the instances of network data; and a flow stream processor configured to analyze instances of network data in real time, produce a current behavioral pattern for each of the instances of network data, compare the current behavioral pattern to a corresponding historical behavioral pattern, and detect an anomaly based on the comparison between the current behavioral pattern and the corresponding historical behavioral pattern. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10)
-
-
11. A method for unsupervised detection of system anomalies in a network, comprising:
-
collecting instances of network data from one or more network elements in the network in a flow collector; storing the instances of network data in a historical dataset database; analyzing the instances of network data and producing a historical behavioral pattern for each of the instances of network data by a historical dataset pattern extractor; analyzing the instances of network data in real time and producing a current behavioral pattern for each of the instances of the network data by a flow stream processor; comparing the current behavioral pattern to a corresponding historical behavioral pattern; and detecting an anomaly based on the comparison between the current behavioral pattern and the corresponding historical behavioral pattern. - View Dependent Claims (12, 13, 14, 15, 16, 17, 18, 19, 20)
-
Specification