发明申请
US20090245109A1 METHODS, SYSTEMS AND COMPUTER PROGRAM PRODUCTS FOR DETECTING FLOW-LEVEL NETWORK TRAFFIC ANOMALIES VIA ABSTRACTION LEVELS
失效
用于检测流量网络交通异常的方法,系统和计算机程序产品通过抽取级别
- 专利标题: METHODS, SYSTEMS AND COMPUTER PROGRAM PRODUCTS FOR DETECTING FLOW-LEVEL NETWORK TRAFFIC ANOMALIES VIA ABSTRACTION LEVELS
- 专利标题(中): 用于检测流量网络交通异常的方法,系统和计算机程序产品通过抽取级别
-
申请号: US12056583申请日: 2008-03-27
-
公开(公告)号: US20090245109A1公开(公告)日: 2009-10-01
- 发明人: Paul T. Hurley , Andreas Kind , Marc Ph. Stoecklin
- 申请人: Paul T. Hurley , Andreas Kind , Marc Ph. Stoecklin
- 申请人地址: US NY Armonk
- 专利权人: INTERNATIONAL BUSINESS MACHINES CORPORATION
- 当前专利权人: INTERNATIONAL BUSINESS MACHINES CORPORATION
- 当前专利权人地址: US NY Armonk
- 主分类号: H04L12/26
- IPC分类号: H04L12/26
摘要:
Methods, systems and computer program products for detecting flow-level network traffic anomalies via abstraction levels. An exemplary embodiment includes a method for detecting flow-level network traffic anomalies in a computer network, the method including obtaining current distributions of flow level traffic features within the computer network, computing distances of the current distributions' components from a distributions model, comparing the distances of the current distributions to distance baselines from the distributions model, determining if the distances are above a pre-determined thresholds and in response to one or more of the distances being above the pre-determined thresholds in one or more distributions, identifying the current condition to be abnormal and providing indications to its nature.
公开/授权文献
信息查询