Patent · US Active

Method, apparatus, and system for identifying abnormal IP data stream

US9923794B2 · kind B2 · utility

0Cited by
2References
29Claims
0Family size

Assignee

Inventors

Key dates

Filing dateJul 14, 2015
Grant dateMar 20, 2018
Priority date
Expiry dateJan 31, 2036

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L63/1441
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

A method, an apparatus, and a system for identifying an abnormal IP data stream, which are used to improve identification accuracy. The method provided by the embodiments of the present invention includes: receiving Y elements sent by a data collection node; mapping the Y elements to N buckets; acquiring a bucket in the N buckets as a target bucket; acquiring r upper traffic limits of a first object in r buckets within the current time interval, the first object is any object mapped to the target bucket; and identifying, according to a preset abnormal object type and the r upper traffic limits within the current time interval, whether the first object is an abnormal object, where the preset abnormal object type is a heavy hitter or a heavy changer.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.