US2013167232A1PendingUtilityA1

Event detection/anomaly correlation heuristics

Assignee: RIVERBED TECHNOLOGY INCPriority: Nov 4, 2002Filed: Feb 20, 2013Published: Jun 27, 2013
Est. expiryNov 4, 2022(expired)· nominal 20-yr term from priority
H04L 63/1458H04L 63/145H04L 63/1425H04L 63/00
50
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A system for detecting network intrusions and other conditions in a network is described. The system includes a plurality of collector devices that are disposed to collect data and statistical information on packets that are sent between nodes on a network. An aggregator device is disposed to receive data and statistical information from the plurality of collector devices. The aggregator device produces a connection table that maps each node on the network to a record that stores information about traffic to or from the node. The aggregator runs processes that determine network events from aggregating of anomalies into network events.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method for detecting conditions in a network, comprising:
 finding anomalies, which are low-level differences in network operation relative to some comparison period; and   collecting anomalies into operationally relevant events.   
     
     
         2 . The method of  claim 1  further comprising:
 sending event reports to an operator. 
 
     
     
         3 . The method of  claim 1  wherein collecting anomalies into events comprises:
 traversing a connection table to identify and correlate anomalies by determining connection patterns that correlate with a particular event class. 
 
     
     
         4 . The method of  claim 1  further comprising determining event severity. 
     
     
         5 . The method of  claim 4  wherein the event severity is characterized by at least one of the type, number, and severity of anomalies that led to the identification of the event. 
     
     
         6 . The method of  claim 1  wherein collecting anomalies, comprises:
 tracking a moving average that allows collecting anomalies to adapt to slowly changing network conditions. 
 
     
     
         7 . The method of  claim 1  wherein collecting anomalies into events comprises
 tracking a variance of a parameter to allow collecting to account for burstiness in network traffic. 
 
     
     
         8 . A computer readable medium tangible storing a computer program product for detecting intrusions in a network, comprises instructions for causing a processor to:
 find anomalies, which are low-level differences in network operation relative to some comparison period; and   collect anomalies into operationally relevant events.   
     
     
         9 . The product of  claim 8  further comprising instructions to:
 send event reports to an operator. 
 
     
     
         10 . The product of  claim 8  wherein collecting anomalies into events comprises instructions to:
 traverse a connection table to identify and correlate anomalies by determining connection patterns that correlate with a particular event class. 
 
     
     
         11 . The product of  claim 8  further comprising instructions to:
 determine event severity. 
 
     
     
         12 . The product of  claim 11  wherein event severity is characterized by at least one of the type, number, and severity of anomalies that led to the identification of the event. 
     
     
         13 . The product of  claim 8  wherein instructions to collect anomalies, further comprises instructions to:
 track a moving average that allows collecting anomalies to adapt to slowly changing network conditions. 
 
     
     
         14 . The product of  claim 8  wherein instructions to collect anomalies into events comprises instructions to:
 track a variance of a parameter to account for burstiness in network traffic. 
 
     
     
         15 . A device for detecting conditions in a network, comprising:
 circuitry to find anomalies, which are low-level differences in network operation relative to some comparison period; and   circuitry to collect anomalies into operationally relevant events.   
     
     
         16 . The device of  claim 15  further comprising:
 circuitry to send event reports to an operator. 
 
     
     
         17 . The device of  claim 15  wherein circuitry to collect anomalies into events comprises:
 circuitry to traverse a connection table to identify and correlate anomalies by determining connection patterns that correlate with a particular event class. 
 
     
     
         18 . The device of  claim 15  further comprising circuitry to determine event severity. 
     
     
         19 . The device of  claim 18  wherein the circuitry characterizes the event severity by at least one of type, number, and severity of anomalies that led to the identification of the event. 
     
     
         20 . The device of  claim 15  wherein circuitry to collect anomalies, comprises:
 circuitry to track a moving average that allows collecting anomalies to adapt to slowly changing network conditions.

Join the waitlist — get patent alerts

Track US2013167232A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.