Method of detecting anomalies in a communication system using numerical packet features
    3.
    发明授权
    Method of detecting anomalies in a communication system using numerical packet features 有权
    使用数字分组特征检测通信系统异常的方法

    公开(公告)号:US08503302B2

    公开(公告)日:2013-08-06

    申请号:US12811204

    申请日:2007-12-31

    IPC分类号: H04L29/00

    摘要: A method of detecting anomalies in a communication system, includes: providing a first packet flow portion and a second packet flow portion; extracting samples of a numerical feature associated with a traffic status of the first and second packet flow portions; computing from said extracted samples a first statistical dispersion quantity and a second statistical dispersion quantity of the numerical feature associated with the first and second packet flow portions, respectively; computing from the dispersion quantities a variation quantity representing a dispersion change from the first packet flow portion to the second packet flow portion; comparing the variation quantity with a comparison value; and detecting an anomaly in the system in response to said comparison.

    摘要翻译: 一种检测通信系统异常的方法,包括:提供第一分组流部分和第二分组流部分; 提取与所述第一和第二分组流部分的业务状态相关联的数字特征的样本; 从所述提取的样本中分别计算与第一和第二分组流部分相关联的数字特征的第一统计色散量和第二统计色散量; 从色散量计算表示从第一分组流部分到第二分组流部分的色散变化的变化量; 将变化量与比较值进行比较; 以及响应于所述比较来检测系统中的异常。

    METHOD OF DETECTING ANOMALIES IN A COMMUNICATION SYSTEM USING NUMERICAL PACKET FEATURES
    7.
    发明申请
    METHOD OF DETECTING ANOMALIES IN A COMMUNICATION SYSTEM USING NUMERICAL PACKET FEATURES 有权
    使用数字分组特征检测通信系统中异常的方法

    公开(公告)号:US20100284283A1

    公开(公告)日:2010-11-11

    申请号:US12811204

    申请日:2007-12-31

    IPC分类号: H04L12/26 H04L12/56

    摘要: A method of detecting anomalies in a communication system, includes: providing a first packet flow portion and a second packet flow portion; extracting samples of a numerical feature associated with a traffic status of the first and second packet flow portions; computing from said extracted samples a first statistical dispersion quantity and a second statistical dispersion quantity of the numerical feature associated with the first and second packet flow portions, respectively; computing from the dispersion quantities a variation quantity representing a dispersion change from the first packet flow portion to the second packet flow portion; comparing the variation quantity with a comparison value; and detecting an anomaly in the system in response to said comparison.

    摘要翻译: 一种检测通信系统异常的方法,包括:提供第一分组流部分和第二分组流部分; 提取与所述第一和第二分组流部分的业务状态相关联的数字特征的样本; 从所述提取的样本中分别计算与第一和第二分组流部分相关联的数字特征的第一统计色散量和第二统计色散量; 从色散量计算表示从第一分组流部分到第二分组流部分的色散变化的变化量; 将变化量与比较值进行比较; 以及响应于所述比较来检测系统中的异常。