Patent · US Active

Network anomaly detection

US9503467B2 · kind B2 · utility

30Cited by
10References
21Claims
0Family size

Assignee

Inventors

Key dates

Filing dateMay 22, 2014
Grant dateNov 22, 2016
Priority date
Expiry dateMay 22, 2034

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L63/1466
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

Methods, systems, and apparatus, including computer programs encoded on computer storage media, for determining network related anomaly scores. One of the methods includes generating a network map including at least a plurality of network nodes and a plurality of edges that indicate communications paths between the plurality of network nodes, obtaining first data indicating network activity over the edges and between the plurality of network nodes for a first time period, generating a model of expected network activity over the edges and between the plurality of network nodes for a future time period using the network map and the first data, obtaining second data indicating network activity over the edges and between the plurality of network nodes for a second time period, and determining an anomaly score using a comparison between the second data and the model of expected network activity.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.