Invention Grant
- Patent Title: Systems and methods for causation analysis of network traffic anomalies and security threats
-
Application No.: US16693884Application Date: 2019-11-25
-
Publication No.: US11777966B2Publication Date: 2023-10-03
- Inventor: Yu Jiang , Saravanan Radhakrishnan , Jeffrey Cai , Yuefeng Jiang
- Applicant: Cisco Technology, Inc.
- Applicant Address: US CA San Jose
- Assignee: Cisco Technology, Inc.
- Current Assignee: Cisco Technology, Inc.
- Current Assignee Address: US CA San Jose
- Agency: Polsinelli
- Main IPC: H04L9/40
- IPC: H04L9/40 ; H04L43/087 ; H04L43/16 ; H04L43/0829

Abstract:
Systems and methods for causation analysis of network anomalies in a network include detecting an alarm condition at a network device, the alarm condition pertaining to an anomaly or increase in a traffic condition such as packet loss. A dominant key is identified in each of one or more key types which contributed to the alarm condition, the key types including dimensions of traffic flow. Two or more dominant keys of two or more key types are aggregated and clustered to determine a combination of dominant keys which contributed to the alarm condition. A dominant traffic flow comprising the combination of dominant keys which contributed to the alarm condition is identified based on the aggregation and clustering. Malware or security threats can be identified from detecting a dominant source IP address or host which contributed to a predominant number of packet drops or retransmissions at ports of the network.
Public/Granted literature
- US20210160263A1 SYSTEMS AND METHODS FOR CAUSATION ANALYSIS OF NETWORK TRAFFIC ANOMALIES AND SECURITY THREATS Public/Granted day:2021-05-27
Information query