Invention Application
US20160352765A1 FINGERPRINT MERGING AND RISK LEVEL EVALUATION FOR NETWORK ANOMALY DETECTION
审中-公开
网络异常检测的指纹合并和风险等级评估
- Patent Title: FINGERPRINT MERGING AND RISK LEVEL EVALUATION FOR NETWORK ANOMALY DETECTION
- Patent Title (中): 网络异常检测的指纹合并和风险等级评估
-
Application No.: US15072526Application Date: 2016-03-17
-
Publication No.: US20160352765A1Publication Date: 2016-12-01
- Inventor: Grégory Mermoud , Jean-Philippe Vasseur , Yannick Weibel
- Applicant: Cisco Technology, Inc.
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
In one embodiment, a device in a network receives fingerprints of two or more network anomalies detected in the network by different anomaly detectors. Each fingerprint comprises a hash of tags that describe a detected anomaly. The device associates the fingerprints with network records captured within a timeframe in which the two or more network anomalies were detected. The device compares the fingerprints associated with the network records to determine that the two or more detected anomalies are part of a singular anomaly event. The device generates a notification regarding the singular anomaly event, wherein the notification includes those of the fingerprints that are associated with the singular anomaly event.
Public/Granted literature
- US10320825B2 Fingerprint merging and risk level evaluation for network anomaly detection Public/Granted day:2019-06-11
Information query