Event detection/anomaly correlation heuristics
Abstract
A system for detecting network intrusions and other conditions in a network is described. The system includes a plurality of collector devices that are disposed to collect data and statistical information on packets that are sent between nodes on a network. An aggregator device is disposed to receive data and statistical information from the plurality of collector devices. The aggregator device produces a connection table that maps each node on the network to a record that stores information about traffic to or from the node. The aggregator runs processes that determine network events from aggregating of anomalies into network events.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method for detecting conditions in a network, comprising:
finding anomalies, which are low-level differences in network operation relative to some comparison period; and collecting anomalies into operationally relevant events.
2 . The method of claim 1 further comprising:
sending event reports to an operator.
3 . The method of claim 1 wherein collecting anomalies into events comprises:
traversing a connection table to identify and correlate anomalies by determining connection patterns that correlate with a particular event class.
4 . The method of claim 1 further comprising determining event severity.
5 . The method of claim 4 wherein the event severity is characterized by at least one of the type, number, and severity of anomalies that led to the identification of the event.
6 . The method of claim 1 wherein collecting anomalies, comprises:
tracking a moving average that allows collecting anomalies to adapt to slowly changing network conditions.
7 . The method of claim 1 wherein collecting anomalies into events comprises
tracking a variance of a parameter to allow collecting to account for burstiness in network traffic.
8 . A computer readable medium tangible storing a computer program product for detecting intrusions in a network, comprises instructions for causing a processor to:
find anomalies, which are low-level differences in network operation relative to some comparison period; and collect anomalies into operationally relevant events.
9 . The product of claim 8 further comprising instructions to:
send event reports to an operator.
10 . The product of claim 8 wherein collecting anomalies into events comprises instructions to:
traverse a connection table to identify and correlate anomalies by determining connection patterns that correlate with a particular event class.
11 . The product of claim 8 further comprising instructions to:
determine event severity.
12 . The product of claim 11 wherein event severity is characterized by at least one of the type, number, and severity of anomalies that led to the identification of the event.
13 . The product of claim 8 wherein instructions to collect anomalies, further comprises instructions to:
track a moving average that allows collecting anomalies to adapt to slowly changing network conditions.
14 . The product of claim 8 wherein instructions to collect anomalies into events comprises instructions to:
track a variance of a parameter to account for burstiness in network traffic.
15 . A device for detecting conditions in a network, comprising:
circuitry to find anomalies, which are low-level differences in network operation relative to some comparison period; and circuitry to collect anomalies into operationally relevant events.
16 . The device of claim 15 further comprising:
circuitry to send event reports to an operator.
17 . The device of claim 15 wherein circuitry to collect anomalies into events comprises:
circuitry to traverse a connection table to identify and correlate anomalies by determining connection patterns that correlate with a particular event class.
18 . The device of claim 15 further comprising circuitry to determine event severity.
19 . The device of claim 18 wherein the circuitry characterizes the event severity by at least one of type, number, and severity of anomalies that led to the identification of the event.
20 . The device of claim 15 wherein circuitry to collect anomalies, comprises:
circuitry to track a moving average that allows collecting anomalies to adapt to slowly changing network conditions.Join the waitlist — get patent alerts
Track US2013167232A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.