IP Library Granted Patent US 8,458,795
Granted Patent B2
US 8,458,795 · App. 12/106,272 · Granted Jun 4, 2013

Event detection/anomaly correlation heuristics

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,458,795
App. No.
12/106,272
Granted
Jun 4, 2013
Kind
B2
Abstract

A system for detecting network intrusions and other conditions in a network is described. The system includes a plurality of collector devices that are disposed to collect data and statistical information on packets that are sent between nodes on a network. An aggregator device is disposed to receive data and statistical information from the plurality of collector devices. The aggregator device produces a connection table that maps each node on the network to a record that stores information about traffic to or from the node. The aggregator runs processes that determine network events from aggregating of anomalies into network events.

Claims (36)

1. A method for detecting conditions in a network, comprising:

finding, by computer, anomalies by analyzing connection patterns, wherein anomalies are differences in connection patterns between hosts relative to some comparison period; and

collecting anomalies into operationally relevant events, wherein an operationally relevant event is a collection of anomalies related to a singular cause, wherein collecting anomalies into events comprises traversing a connection table to identify and correlate anomalies by determining connection patterns that correlate with a particular event class.

2. The method of claim 1 further comprising:

sending event reports to an operator.

3. The method of claim 1 further comprising determining event severity.

4. The method of claim 3 wherein the event severity is characterized by at least one of a type, number, and severity of anomalies that led to an identification of the event.

5. The method of claim 1 wherein collecting anomalies, comprises:

tracking a moving average that allows collecting anomalies to adapt to slowly changing network conditions.

6. The method of claim 1 wherein collecting anomalies into events comprises

tracking a variance of a parameter to allow collecting to account for burstiness in network traffic.

7. The method of claim 1 , wherein the connection table includes a first map which maps a first host identifier to a host object, wherein the host object includes a second map which maps a second host identifier to a host-pair record, and wherein the host-pair record includes information about traffic between hosts corresponding to the first and second host identifiers.

8. The method of claim 1 , wherein the connection table includes a first map and a second map, wherein the first map maps a host identifier to a host object, wherein the host object includes information about traffic to or from a host corresponding to the host identifier, wherein the second map maps a pair of host identifiers to a host-pair record, and wherein the host-pair record includes information about traffic between hosts corresponding to the pair of host identifiers.

9. A computer program product tangibly stored in a non-transitory computer readable medium for detecting intrusions in a network, comprising instructions for causing a processor to:

find anomalies by analyzing connection patterns, wherein anomalies are differences in connection patterns between hosts relative to some comparison period; and

collect anomalies into operationally relevant events, wherein an operationally relevant event is a collection of anomalies related to a singular cause, wherein collecting anomalies into events comprises traversing a connection table to identify and correlate anomalies by determining connection patterns that correlate with a particular event class.

10. The computer program product of claim 9 further comprising instructions to:

send event reports to an operator.

11. The computer program product of claim 9 further comprising instructions to:

determine event severity.

12. The computer program product of claim 11 wherein event severity is characterized by at least one of a type, number, and severity of anomalies that led to an identification of the event.

13. The computer program product of claim 9 wherein instructions to collect anomalies, further comprises instructions to:

track a moving average that allows collecting anomalies to adapt to slowly changing network conditions.

14. The computer program product of claim 9 wherein instructions to collect anomalies into events comprises instructions to:

track a variance of a parameter to account for burstiness in network traffic.

15. A device for detecting conditions in a network, comprising:

circuitry to find anomalies by analyzing connection patterns, wherein anomalies are differences in connection patterns between hosts relative to some comparison period; and

circuitry to collect anomalies into operationally relevant events, wherein an operationally relevant event is a collection of anomalies related to a singular cause, wherein collecting anomalies into events comprises traversing a connection table to identify and correlate anomalies by determining connection patterns that correlate with a particular event class.

16. The device of claim 15 further comprising:

circuitry to send event reports to an operator.

17. The device of claim 15 further comprising circuitry to determine event severity.

18. The device of claim 17 wherein the circuitry characterizes the event severity by at least one of a type, number, and severity of anomalies that led to an identification of the event.

19. The device of claim 15 wherein circuitry to collect anomalies, comprises:

circuitry to track a moving average that allows collecting anomalies to adapt to slowly changing network conditions.

20. The device of claim 15 wherein circuitry to collect anomalies into events comprises:

circuitry to track a variance of a parameter to account for burstiness in network traffic.

Assignments (24)
RELEASE OF SECURITY INTEREST Recorded Aug 11, 2023
From: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC; RIVERBED HOLDINGS, INC.
Reel/Frame 064673/0739 →
CHANGE OF NAME Recorded Feb 18, 2022
From: RIVERBED TECHNOLOGY, INC.
To: RIVERBED TECHNOLOGY LLC
Reel/Frame 059232/0551 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS U.S. COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0169 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0108 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0046 →
SECURITY INTEREST Recorded Dec 10, 2021
From: RIVERBED TECHNOLOGY LLC (FORMERLY RIVERBED TECHNOLOGY, INC.); ATERNITY LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS U.S. COLLATERAL AGENT
Reel/Frame 058486/0216 →
PATENT SECURITY AGREEMENT Recorded Oct 27, 2021
From: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 057943/0386 →
PATENT SECURITY AGREEMENT SUPPLEMENT - FIRST LIEN Recorded Oct 14, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 057810/0502 →
PATENT SECURITY AGREEMENT SUPPLEMENT - SECOND LIEN Recorded Oct 14, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 057810/0559 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORED AT REEL 056397, FRAME 0750 Recorded Oct 13, 2021
From: MACQUARIE CAPITAL FUNDING LLC
To: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 057983/0356 →
SECURITY INTEREST Recorded May 26, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: MACQUARIE CAPITAL FUNDING LLC
Reel/Frame 056397/0750 →
PATENT SECURITY AGREEMENT Recorded Mar 5, 2021
From: RIVERBED TECHNOLOGY, INC.
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 055514/0249 →
CORRECTIVE ASSIGNMENT TO CORRECT THE CONVEYING PARTY NAME PREVIOUSLY RECORDED ON REEL 035521 FRAME 0069. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST IN PATENTS. Recorded Jun 2, 2015
From: JPMORGAN CHASE BANK, N.A.
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 035807/0680 →
SECURITY INTEREST Recorded May 1, 2015
From: RIVERBED TECHNOLOGY, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 035561/0363 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Apr 28, 2015
From: BARCLAYS BANK PLC
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 035521/0069 →
PATENT SECURITY AGREEMENT Recorded Dec 27, 2013
From: RIVERBED TECHNOLOGY, INC.
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 032421/0162 →
RELEASE OF PATENT SECURITY INTEREST Recorded Dec 26, 2013
From: MORGAN STANLEY & CO. LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 032113/0425 →
PATENT SECURITY AGREEMENT Recorded Sep 13, 2013
From: RIVERBED TECHNOLOGY, INC.
To: MORGAN STANLEY & CO. LLC
Reel/Frame 031216/0968 →
SECURITY AGREEMENT Recorded Dec 20, 2012
From: RIVERBED TECHNOLOGY, INC.; OPNET TECHNOLOGIES, INC.
To: MORGAN STANLEY & CO. LLC
Reel/Frame 029646/0060 →
CORRECTIVE ASSIGNMENT TO CORRECT THE DOC DATES PREVIOUSLY RECORDED ON REEL 022847 FRAME 0771. ASSIGNOR(S) HEREBY CONFIRMS THE DOC DATES OF 05/20/2009 SHOULD BE 05/20/2004 FOR ALL 3 INVENTORS. Recorded Feb 2, 2010
From: WEBER, DANIEL; GOPALAN, PREM; POLETTO, MASSIMILIANO ANTONIO
To: MAZU NETWORKS, INC.
Reel/Frame 023887/0945 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 26, 2009
From: WEBER, DANIEL; GOPALAN, PREM; POLETTO, MASSIMILIANO ANTONIO
To: MAZU NETWORKS, INC.
Reel/Frame 022884/0125 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 18, 2009
From: WEBER, DANIEL; GOPALAN, PREM; POLETTO, MASSIMILIANO ANTONIO
To: MAZU NETWORKS, INC.
Reel/Frame 022847/0771 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 15, 2009
From: MAZU NETWORKS, LLC
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 022542/0800 →
CHANGE OF NAME Recorded Mar 30, 2009
From: MAZU NETWORKS, INC.
To: MAZU NETWORKS, LLC
Reel/Frame 022460/0886 →