Invention Application
- Patent Title: SECURITY THREAT DETECTION BASED ON NETWORK FLOW ANALYSIS
-
Application No.: US17220550Application Date: 2021-04-01
-
Publication No.: US20220239683A1Publication Date: 2022-07-28
- Inventor: Santhanakrishnan Kaliya Perumal , Tejas Sanjeev Panse , Aditi Vutukuri , Rajiv Mordani , Margaret Petrus
- Applicant: VMware, Inc.
- Applicant Address: US CA Palo Alto
- Assignee: VMware, Inc.
- Current Assignee: VMware, Inc.
- Current Assignee Address: US CA Palo Alto
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
Some embodiments provide a method for identifying security threats to a datacenter. From multiple host computers in the datacenter, the method receives data indicating port usage for a particular time period for each of multiple destination data compute nodes (DCNs) executing on the host computers. For each DCN of a set of the destination DCNs, identifies whether the port usage for the particular time period deviates from a historical baseline port usage for the DCN. When the port usage for a particular DCN deviates from the historical baseline for the particular DCN, the method identifies the particular DCN as a target of a security threat.
Public/Granted literature
- US11785032B2 Security threat detection based on network flow analysis Public/Granted day:2023-10-10
Information query