IP Library Patent Application 13772011
Patent Application
App. No. 13/772,011

EVENT DETECTION/ANOMALY CORRELATION HEURISTICS

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
13/772,011
Filed
Feb 20, 2013
Art Unit
2431
USPC
726/23
Abstract

A system for detecting network intrusions and other conditions in a network is described. The system includes a plurality of collector devices that are disposed to collect data and statistical information on packets that are sent between nodes on a network. An aggregator device is disposed to receive data and statistical information from the plurality of collector devices. The aggregator device produces a connection table that maps each node on the network to a record that stores information about traffic to or from the node. The aggregator runs processes that determine network events from aggregating of anomalies into network events.

Claims (38)

1 . A method for detecting conditions in a network, comprising:

finding anomalies, which are low-level differences in network operation relative to some comparison period; and

collecting anomalies into operationally relevant events.

2 . The method of claim 1 further comprising:

sending event reports to an operator.

3 . The method of claim 1 wherein collecting anomalies into events comprises:

traversing a connection table to identify and correlate anomalies by determining connection patterns that correlate with a particular event class.

4 . The method of claim 1 further comprising determining event severity.

5 . The method of claim 4 wherein the event severity is characterized by at least one of the type, number, and severity of anomalies that led to the identification of the event.

6 . The method of claim 1 wherein collecting anomalies, comprises:

tracking a moving average that allows collecting anomalies to adapt to slowly changing network conditions.

7 . The method of claim 1 wherein collecting anomalies into events comprises

tracking a variance of a parameter to allow collecting to account for burstiness in network traffic.

8 . A computer readable medium tangible storing a computer program product for detecting intrusions in a network, comprises instructions for causing a processor to:

find anomalies, which are low-level differences in network operation relative to some comparison period; and

collect anomalies into operationally relevant events.

9 . The product of claim 8 further comprising instructions to:

send event reports to an operator.

10 . The product of claim 8 wherein collecting anomalies into events comprises instructions to:

traverse a connection table to identify and correlate anomalies by determining connection patterns that correlate with a particular event class.

11 . The product of claim 8 further comprising instructions to:

determine event severity.

12 . The product of claim 11 wherein event severity is characterized by at least one of the type, number, and severity of anomalies that led to the identification of the event.

13 . The product of claim 8 wherein instructions to collect anomalies, further comprises instructions to:

track a moving average that allows collecting anomalies to adapt to slowly changing network conditions.

14 . The product of claim 8 wherein instructions to collect anomalies into events comprises instructions to:

track a variance of a parameter to account for burstiness in network traffic.

15 . A device for detecting conditions in a network, comprising:

circuitry to find anomalies, which are low-level differences in network operation relative to some comparison period; and

circuitry to collect anomalies into operationally relevant events.

16 . The device of claim 15 further comprising:

circuitry to send event reports to an operator.

17 . The device of claim 15 wherein circuitry to collect anomalies into events comprises:

circuitry to traverse a connection table to identify and correlate anomalies by determining connection patterns that correlate with a particular event class.

18 . The device of claim 15 further comprising circuitry to determine event severity.

19 . The device of claim 18 wherein the circuitry characterizes the event severity by at least one of type, number, and severity of anomalies that led to the identification of the event.

20 . The device of claim 15 wherein circuitry to collect anomalies, comprises:

circuitry to track a moving average that allows collecting anomalies to adapt to slowly changing network conditions.

Assignments (3)
CORRECTIVE ASSIGNMENT TO CORRECT THE CONVEYING PARTY NAME PREVIOUSLY RECORDED ON REEL 035521 FRAME 0069. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST IN PATENTS. Recorded Jun 2, 2015
From: JPMORGAN CHASE BANK, N.A.
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 035807/0680 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Apr 28, 2015
From: BARCLAYS BANK PLC
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 035521/0069 →
PATENT SECURITY AGREEMENT Recorded Dec 27, 2013
From: RIVERBED TECHNOLOGY, INC.
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 032421/0162 →