×

Systems and methods for anomaly detection in patterns of monitored communications

  • US 7,124,438 B2
  • Filed: 03/08/2002
  • Issued: 10/17/2006
  • Est. Priority Date: 03/08/2002
  • Status: Active Grant
First Claim
Patent Images

1. A system for detecting an anomalous communication transmitted over a communications network, the system comprising:

  • a) an interface coupling the system with the communications network;

    b) a system data store capable of storing data associated with communications transmitted over the communications network and information associated with one or more responses to be initiated if an anomaly is detected;

    c) a system processor in communication with the interface and the data store, wherein the system processor comprises one or more processing elements and wherein the system processor executes;

    i) a collection engine that;

    1) receives a communication via the interface; and

    2) generates data associated with the received communication by applying one or more tests to the received communication;

    ii) an analysis engine that detects whether an anomaly exists with respect to the received communication based upon the data generated by the collection engine and data associated with previously received communications from the system data store; and

    iii) an action engine that initiates a predetermined response from the system data store if an anomaly was detected by the analysis engine;

    wherein the analysis engine detects whether an anomaly exists by;

    1) determining a set of anomaly types of interest;

    2) for each of the anomaly types of interest in the determined set,(a) acquiring one or more anomaly thresholds associated with the respective anomaly type based at least in part upon accumulated data associated with received communications from the system data store;

    (b) comparing information in the stored risk profile against at least one of the acquired one or more anomaly thresholds; and

    (c) determining whether an anomaly of the respective anomaly type exists with respect to the received communication based upon the comparison.

View all claims
  • 14 Assignments
Timeline View
Assignment View
    ×
    ×