Network surveillance

  • US 6,711,615 B2
  • Filed: 09/25/2002
  • Issued: 03/23/2004
  • Est. Priority Date: 11/09/1998
  • Status: Expired due to Term
First Claim
Patent Images

1. A computer-automated method of hierarchical event monitoring and analysis within an enterprise network comprising:

  • deploying a plurality of network monitors in the enterprise network;

    detecting, by the network monitors, suspicious network activity based on analysis of network traffic data selected from one or more of the following categories;

    {network packet data transfer commands, network packet data transfer errors, network packet data volume, network connection requests, network connection denials, error codes included in a network packet, network connection acknowledgements, and network packets indicative of well-known network-service protocols};

    generating, by the monitors, reports of said suspicious activity; and

    automatically receiving and integrating the reports of suspicious activity, by one or more hierarchical monitors.

View all claims

    Thank you for your feedback