Systems and methods for causation analysis of network traffic anomalies and security threats
US11777966B2 · kind B2 · utility
Assignee
Inventors
Key dates
| Filing date | Nov 25, 2019 |
| Grant date | Oct 3, 2023 |
| Priority date | — |
| Expiry date | Dec 22, 2040 |
Classification
- Technology area (CPC H)Electricity
- CPC primaryH04L43/0835
- WIPO fieldDigital communication
- WIPO sectorElectrical engineering
Abstract
Systems and methods for causation analysis of network anomalies in a network include detecting an alarm condition at a network device, the alarm condition pertaining to an anomaly or increase in a traffic condition such as packet loss. A dominant key is identified in each of one or more key types which contributed to the alarm condition, the key types including dimensions of traffic flow. Two or more dominant keys of two or more key types are aggregated and clustered to determine a combination of dominant keys which contributed to the alarm condition. A dominant traffic flow comprising the combination of dominant keys which contributed to the alarm condition is identified based on the aggregation and clustering. Malware or security threats can be identified from detecting a dominant source IP address or host which contributed to a predominant number of packet drops or retransmissions at ports of the network.
Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.