IP Library Granted Patent US 10,284,571
Granted Patent B2
US 10,284,571 · App. 10/880,332 · Granted May 7, 2019

Rule based alerting in anomaly detection

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,284,571
App. No.
10/880,332
Granted
May 7, 2019
Kind
B2
Abstract

A graphical user interface for constructing rules to run on an intrusion detection system is described. The user interface includes a field that specifies a first set of nodes on a network by Host-Group, a field that specifies a second set of nodes on a network by Host-Group and a field which determines whether to interpret the first and second host-group fields as Client, server, source, destination or any of these.

Claims (51)

1. A method for detecting an intrusion event in a network, the method comprising:

receiving a threshold value for a monitored network parameter, wherein the threshold value is received from a user via a user interface (UI) associated with a computer, and wherein the threshold value corresponds to an alert severity level;

receiving a threshold type for the monitored network parameter, wherein the threshold type is received from the user via the UI, and wherein the threshold type specifies either a lower limit or an upper limit for the threshold value;

receiving a time duration for the monitored network parameter, wherein the time duration is received from the user via the UI;

constructing, by the computer, a rule for detecting a network intrusion event based on the threshold value, the threshold type, and the time duration;

compiling the constructed rule for execution; and

executing the constructed rule, wherein said executing the constructed rule comprises:

generating an alert when the monitored network parameter remains above the threshold value during the entire time duration when the threshold type is an upper limit;

generating the alert when the monitored network parameter remains below the threshold value during the entire time duration when the threshold type is a lower limit; and

wherein a severity level of the alert is set to the alert severity level corresponding to the threshold value.

2. The method of claim 1 , further comprising:

receiving information about a first set of nodes and a second set of nodes in the network; and

determining whether the second set of nodes are clients, servers, source nodes, or destination nodes based on the received information about the first set of nodes.

3. The method of claim 1 , further comprising receiving information on whether the rule applies to a host or to an aggregate of an entire node set's traffic.

4. The method of claim 1 , further comprising receiving information specifying a start time and a stop time for application of the rule.

5. The method of claim 1 , further comprising:

receiving information specifying services for which the rule is applicable, wherein a respective service is specified by at least a port and a protocol.

6. A non-transitory computer-readable storage medium storing instructions which when executed by a computer cause the computer to perform a method for detecting an intrusion event in a network, the method comprising:

receiving a threshold value for a monitored network parameter, wherein the threshold value is received from a user via a user interface (UI) associated with the computer, and wherein the threshold value corresponds to an alert severity level;

receiving a threshold type for the monitored network parameter, wherein the threshold type is received from the user via the UI, and wherein the threshold type specifies either a lower limit or an upper limit for the threshold value;

receiving a time duration for the monitored network parameter, wherein the time duration is received from the user via the UI;

constructing a rule for detecting a network intrusion event based on the threshold value, the threshold type, and the time duration;

compiling the constructed rule for execution; and

subsequently executing the constructed rule, wherein said executing the constructed rule comprises:

generating an alert when the monitored network parameter remains above the threshold value during the entire time duration when the threshold type is an upper limit;

generating the alert when the monitored network parameter remains below the threshold value during the entire time duration when the threshold type is a lower limit; and

wherein a severity level of the alert is set to the alert severity level corresponding to the threshold value.

7. The non-transitory computer-readable storage medium of claim 6 , wherein the method further comprises:

receiving information about a first set of nodes and a second set of nodes in the network; and

determining whether the second set of nodes are clients, servers, source nodes, or destination nodes based on the received information about the first set of nodes.

8. The non-transitory computer-readable storage medium of claim 6 , wherein the method further comprises receiving information on whether the rule applies to a host or to an aggregate of an entire node set's traffic.

9. The non-transitory computer-readable storage medium of claim 6 , wherein the method further comprises receiving information specifying a start time and a stop time for application of the rule.

10. The non-transitory computer-readable storage medium of claim 6 , wherein the method further comprises receiving information specifying services for which the rule is applicable, wherein a respective service is specified by at least a port and a protocol.

11. A system for detecting an intrusion event in a network comprising:

a processor; and

a non-transitory storage medium storing instructions which, when executed by the processor, cause the system to perform a method comprising:

receiving a threshold value for a monitored network parameter, wherein the threshold value is received from a user via a user interface (UI) associated with the system, and wherein the threshold value corresponds to an alert severity level;

receiving a threshold type for the monitored network parameter, wherein the threshold type is received from the user via the UI, and wherein the threshold type specifies either a lower limit or an upper limit for the threshold value;

receiving a time duration for the monitored network parameter, wherein the time duration is received from the user via the UI;

constructing a rule for detecting a network intrusion event based on the threshold value, the threshold type, and the time duration;

compiling the constructed rule for execution; and

executing the constructed rule, wherein said executing the constructed rule comprises:

generating an alert when the monitored network parameter remains above the threshold value during the entire time duration when the threshold type is an upper limit;

generating the alert when the monitored network parameter remains below the threshold value during the entire time duration when the threshold type is a lower limit; and

wherein a severity level of the alert is set to the alert severity level corresponding to the threshold value.

12. The system of claim 11 , wherein the non-transitory storage medium further comprises instructions that, when executed by the processor, cause the system to:

receive information about a first set of nodes and a second set of nodes in the network; and

determine whether the second set of nodes are clients, servers, source nodes, or destination nodes based on the received information about the first set of nodes.

13. The system of claim 11 , wherein non-transitory storage medium further comprises instructions that, when executed by the processor, cause the system to receive information specifying whether the constructed rule applies to a host or to an aggregate of an entire node set's traffic.

14. The system of claim 11 , wherein the non-transitory storage medium further comprises instructions that, when executed by the processor, cause the system to receive information specifying a start time and a stop time for application of the constructed rule.

15. The system of claim 11 , wherein the non-transitory storage medium further comprises instructions that, when executed by the processor, cause the system to receive information specifying services for which the rule is applicable, wherein a respective service is specified by at least a port and a protocol.

Assignments (18)
RELEASE OF SECURITY INTEREST Recorded Aug 11, 2023
From: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC; RIVERBED HOLDINGS, INC.
Reel/Frame 064673/0739 →
CHANGE OF NAME Recorded Feb 18, 2022
From: RIVERBED TECHNOLOGY, INC.
To: RIVERBED TECHNOLOGY LLC
Reel/Frame 059232/0551 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS U.S. COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0169 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0046 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0108 →
SECURITY INTEREST Recorded Dec 10, 2021
From: RIVERBED TECHNOLOGY LLC (FORMERLY RIVERBED TECHNOLOGY, INC.); ATERNITY LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS U.S. COLLATERAL AGENT
Reel/Frame 058486/0216 →
PATENT SECURITY AGREEMENT Recorded Oct 27, 2021
From: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 057943/0386 →
PATENT SECURITY AGREEMENT SUPPLEMENT - FIRST LIEN Recorded Oct 14, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 057810/0502 →
PATENT SECURITY AGREEMENT SUPPLEMENT - SECOND LIEN Recorded Oct 14, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 057810/0559 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORED AT REEL 056397, FRAME 0750 Recorded Oct 13, 2021
From: MACQUARIE CAPITAL FUNDING LLC
To: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 057983/0356 →
SECURITY INTEREST Recorded May 26, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: MACQUARIE CAPITAL FUNDING LLC
Reel/Frame 056397/0750 →
PATENT SECURITY AGREEMENT Recorded Mar 5, 2021
From: RIVERBED TECHNOLOGY, INC.
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 055514/0249 →
CORRECTIVE ASSIGNMENT TO CORRECT THE CONVEYING PARTY NAME PREVIOUSLY RECORDED ON REEL 035521 FRAME 0069. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST IN PATENTS. Recorded Jun 2, 2015
From: JPMORGAN CHASE BANK, N.A.
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 035807/0680 →
SECURITY INTEREST Recorded May 1, 2015
From: RIVERBED TECHNOLOGY, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 035561/0363 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Apr 28, 2015
From: BARCLAYS BANK PLC
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 035521/0069 →
RELEASE OF SECURITY INTEREST Recorded Mar 30, 2015
From: MORGAN STANLEY & CO. LLC
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 035285/0311 →
PATENT SECURITY AGREEMENT Recorded Dec 27, 2013
From: RIVERBED TECHNOLOGY, INC.
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 032421/0162 →
SECURITY AGREEMENT Recorded Dec 20, 2012
From: RIVERBED TECHNOLOGY, INC.; OPNET TECHNOLOGIES, INC.
To: MORGAN STANLEY & CO. LLC
Reel/Frame 029646/0060 →