发明授权
- 专利标题: Aggregator for connection based anomaly detection
- 专利标题(中): 用于基于连接的异常检测的聚合器
-
申请号: US10701356申请日: 2003-11-03
-
公开(公告)号: US08479057B2公开(公告)日: 2013-07-02
- 发明人: Massimiliano Antonio Poletto , Andrew Ratin , Andrew Gorelik
- 申请人: Massimiliano Antonio Poletto , Andrew Ratin , Andrew Gorelik
- 申请人地址: US CA San Francisco
- 专利权人: Riverbed Technology, Inc.
- 当前专利权人: Riverbed Technology, Inc.
- 当前专利权人地址: US CA San Francisco
- 代理机构: Park, Vaughan, Fleming & Dowler, LLP
- 主分类号: G06F11/00
- IPC分类号: G06F11/00
摘要:
A system for detecting network intrusions and other conditions in a network is described. The system includes a plurality of collector devices that are disposed to collect data and statistical information on packets that are sent between nodes on a network. An aggregator device is disposed to receive data and statistical information from the plurality of collector devices. The aggregator device produces a connection table that maps each node on the network to a record that stores information about traffic to or from the node. The aggregator runs processes that determine network events from aggregating of anomalies into network events.
公开/授权文献
- US20040221190A1 Aggregator for connection based anomaly detection 公开/授权日:2004-11-04
信息查询