IP Library › Granted Patent US 10,542,024
Granted Patent B2
US 10,542,024 · App. 15/838,301 · Granted Jan 21, 2020

Method and system for confident anomaly detection in computer network traffic

Inventors: Igor Balabine (Menlo Park, CA); Alexander Velednitsky (Menlo Park, CA)
Assignee: NETFLOW LOGIC CORPORATION
H04L63/1425G06F21/554H04L43/04H04L63/0227H04L63/1416H04L63/1458
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,542,024
App. No.
15/838,301
Filed
Dec 11, 2017
Granted
Jan 21, 2020
Kind
B2
Art Unit
2437
USPC
726/22
Abstract

The present invention relates to systems and methods for detecting anomalies in computer network traffic with fewer false positives and without the need for time-consuming and unreliable historical baselines. Upon detection, traffic anomalies can be processed to determine valuable network insights, including health of interfaces, devices and network services, as well as to provide timely alerts in the event of attack.

Claims (35)

1. A method for detecting and classifying network traffic anomalies, comprising:

receiving a packet of information related to network traffic;

passing said packet to a plurality of network traffic analyzers, each network traffic analyzer capable of applying a corresponding one of a plurality of analytical algorithms to information contained in the packet;

receiving results of analysis performed by the plurality of analyzers, each result corresponding to an event type;

evaluating results of analysis performed by the plurality of analyzers as a collection by applying an exponentially decayed weight to each of the results, dependent upon event type, and calculating a cumulative confidence metric as a sum of the weights;

determining if the result of evaluation signifies a network traffic anomaly by comparing the cumulative confidence metric to a threshold; and

emitting an alert if the result of evaluation signifies a network traffic anomaly.

2. A method as set forth in claim 1 , further comprising the step of performing trend analysis upon the results of said evaluating step to reduce false positives.

3. A method for detecting and classifying network traffic anomalies, comprising:

configuring a data observation interval (dt);

setting a traffic observation interval (T) as T=2n*dt, where n is a positive whole number;

receiving a stream of packets of information related to network traffic over the traffic observation interval as a series of observations, wherein each observation in the series of observations is the data observation interval length;

passing at least a portion of said stream of information packets to a network traffic analyzer;

applying a wavelet series algorithm to a characteristic of the observations to perform a change detection, wherein at least one change points are detected;

determining if said applying step indicates the existence of a network traffic anomaly by calculating a trend for the characteristic after the change point, and determining the anomaly exists when the trend is increasing; and

emitting an alert if a network traffic anomaly is detected;

wherein said applying and said determining step are practiced prior to any step of permanently storing said portion of said stream of information packets.

4. A method for assessing the condition of an interface of a network device, comprising:

receiving a stream of packets of information related to network traffic passing through said network device interface;

passing at least a portion of said stream of information packets to a network traffic analyzer;

applying at least one analytical algorithm to said portion of said stream of information packets, wherein the at least one analytical algorithm includes a change detection function to detect a change point, and analyzing a characteristic after the change point as

a metric for assessing an operational condition of said network device interface;

applying an exponentially decayed weight to the metric and calculating a cumulative confidence metric as a sum of the metric weight along with weights of other metrics;

emitting an alert if said cumulative confidence metric indicates an abnormal operational condition of said network device interface;

wherein said applying and said metric computation are practiced prior to any step of permanently storing said portion of said stream of information packets.

5. A method as set forth in claim 4 , further comprising the step of performing trend analysis upon the results of said metric computation to predict a risk of failure of said network device interface.

6. A method as set forth in claim 4 , further comprising the step of assessing the operational condition of the said network device as a function of assessed operational condition of the interface of said network device;

wherein said assessing step is practiced prior to any step of permanently storing said portion of said stream of information packets.

7. A method as set forth in claim 6 , further comprising the step of assessing the operational condition of a second network service, comprising:

receiving a second stream of packets of information related to network traffic passing through more than one network devices that forward said network traffic to and from said second network service;

passing at least a portion of said second stream of information packets to a second network traffic analyzer;

applying said method to information packets pertaining to at least a portion of said network devices that forward said network traffic to and from said second network service;

determining if said applying step indicates an abnormal operational condition of at least one of said network devices;

emitting a second alert pertaining to the second network service if said applying step indicates an abnormal operational condition of at least one said network device that forwards said second network traffic to and from said second network service;

wherein said determining and said emitting steps are practiced prior to any step of permanently storing said portion of said second stream of information packets.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 14, 2018
From: BALABINE, IGOR; VELEDNITSKY, ALEXANDER
To: NETFLOW LOGIC CORPORATION
Reel/Frame 046798/0126 →
Continuity (8)
Continuation 14627963 · Feb 20, 2015
Continuation In Part 13669235 · Nov 5, 2012
Continuation In Part 13830924 · Mar 14, 2013
Provisional Application 61987440 · May 1, 2014
Provisional Application 61556817 · Nov 7, 2011
Provisional Application 61699823 · Sep 11, 2012
Provisional Application 61751243 · Jan 10, 2013
Related Publication 20180337836A1 · Nov 22, 2018
Cited By (4)
US 12,356,198 US 12,363,147 US 12,580,865 US 12,671,701