×

Detecting network anomalies by probabilistic modeling of argument strings with markov chains

  • US 9,253,201 B2
  • Filed: 09/03/2014
  • Issued: 02/02/2016
  • Est. Priority Date: 05/27/2008
  • Status: Active Grant
First Claim
Patent Images

1. A method for detecting network anomalies, the method comprising:

  • receiving, by a hardware processor, a communication protocol message having an argument string that is transmitted from a first processor to a second processor across a computer network;

    applying a probabilistic model to the received communication protocol message to determine whether the communication protocol message is anomalous based on determining that at least one n-gram in the communication protocol message is anomalous,wherein the probabilistic model uses at least one Markov chain specified by one or more parameters to determine a probability that the argument string is anomalous based on n-grams in the argument string, andwherein the probabilistic model was trained based on content and structure of an argument string included in each of a plurality of communication protocol messages included in a training dataset; and

    performing a predetermined action in response to determining that the communication protocol message is anomalous.

View all claims
  • 0 Assignments
Timeline View
Assignment View
    ×
    ×