Detection of anomalies in a network

    公开(公告)号:US11349732B1

    公开(公告)日:2022-05-31

    申请号:US17237606

    申请日:2021-04-22

    Abstract: Examples relate to detection of anomalies in a network. Some examples determine a dictionary including a set of keys for a set of packet length values for a selected sequence of packets associated with a traffic flow over a network, each key represents a combination of two or more successive packet length values from the set of packet length values. An aggregated set of statistical features is determined based in part on the set of statistical features using a machine learning algorithm. Upon determining another set of packet length values for another selected sequence of packets, another set of statistical features for the other set of packet length values is determined. The other set of statistical features is compared with the aggregated set of statistical features. Based on the comparison, an indication that an anomaly has occurred in the traffic flow is transmitted to an administrator.

    Real-time network application visibility classifier of encrypted traffic based on feature engineering

    公开(公告)号:US11233744B2

    公开(公告)日:2022-01-25

    申请号:US17085528

    申请日:2020-10-30

    Abstract: Systems and methods are provided for a light-weight model for traffic classification within a network fabric. A classification model is deployed onto an edge switch within a network fabric, the model enabling traffic classification using a set of statistical features derived from packet length information extracted from the IP header for a plurality of data packets within a received traffic flow. The statistical features comprise a number of unique packet lengths, a minimum packet length, a maximum packet length, a mean packet length, a standard deviation of the packet length, a maximum run length, a minimum run length, a mean run length, and a standard deviation of run length. Based on the calculated values for the statistical features, the edge switch determines a traffic class for the received traffic flow and tags the traffic flow with an indication of the determined traffic class.

Patent Agency Ranking