IP Library Granted Patent US 7,738,373
Granted Patent B2
US 7,738,373 · App. 11/083,399 · Granted Jun 15, 2010

Method and apparatus for rapid location of anomalies in IP traffic logs

Assignee: AT&T Intellectual Property II, L.P.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,738,373
App. No.
11/083,399
Granted
Jun 15, 2010
Kind
B2
Abstract

An efficient method and apparatus for rapidly detecting anomalies from massive data streams is disclosed. In one embodiment, the method enables near real time detection of anomaly behavior in networks. The invention rapidly identifies the addresses that require further analysis and reduces the cost of monitoring, the cost of managing the security of the network as well as reduces the time needed to initiate mitigation steps.

Claims (18)

1. A method for identifying an anomaly, comprising:

receiving at least one unit of data, where said at least one unit of data is associated with an event;

monitoring at least one object associated with said event;

ranking said at least one object with a ranking on a rank list;

identifying, via a processor, an anomaly in accordance with a movement of said at least one object within said rank list, wherein said movement comprises at least one of: a rate of entry of said at least one object to said rank list, a rate of exit of said at least one object from said rank list, or a rate of movement of said at least one object between rankings of said rank list; and

comparing said ranking of said at least one object to data collected for siblings or cousins.

2. A computer-readable medium having stored thereon a plurality of instructions, the plurality of instructions including instructions which, when executed by a processor, cause the processor to perform steps of a method for identifying an anomaly, comprising:

receiving at least one unit of data, where said at least one unit of data is associated with an event;

monitoring at least one object associated with said event;

ranking said at least one object with a ranking on a rank list;

identifying an anomaly in accordance with a movement of said at least one object within said rank list, wherein said movement comprises at least one of: a rate of entry of said at least one object to said rank list, a rate of exit of said at least one object from said rank list, or a rate of movement of said at least one object between rankings of said rank list; and

comparing said ranking of said at least one object to data collected for siblings or cousins.

3. An apparatus for identifying an anomaly, comprising:

means for receiving at least one unit of data, where said at least one unit of data is associated with an event;

means for monitoring at least one object associated with said event;

means for ranking said at least one object with a ranking on a rank list;

means for identifying an anomaly in accordance with a movement of said at least one object within said rank list, wherein said movement comprises at least one of: a rate of entry of said at least one object to said rank list, a rate of exit of said at least one object from said rank list, or a rate of movement of said at least one object between rankings of said rank list; and

means for comparing said ranking of said at least one object to data collected for siblings or cousins.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 2, 2005
From: LERNER, MICHAH
To: AT&T CORP.
Reel/Frame 016186/0983 →
Continuity (2)
Provisional Application 6055421300 · Mar 18, 2004
Related Publication 20050207413A1 · Sep 22, 2005