MACHINE LEARNING BASED NETWORK ANOMALY DETECTION SYSTEM

    公开(公告)号:US20240244070A1

    公开(公告)日:2024-07-18

    申请号:US18130966

    申请日:2023-04-05

    Applicant: VMWARE, INC.

    CPC classification number: H04L63/1425 H04L41/16

    Abstract: The disclosure provides an approach for detecting anomalous behavior of network traffic within a network environment. Embodiments include receiving, by a risk analyzer operating on a server, network traffic flow records for one or more traffic flows in a network environment. Embodiments also include serializing flow entries within the network traffic flow records into a plurality of temporal buckets. Embodiments includes analyzing the network traffic flow records by a machine learning model configured to detect anomalous behavior based on (i) spatial patterns between at least a first set of features of flow entries and (ii) temporal patterns between the flow entries. Further embodiments include initiating a network action in response to detecting anomalous behavior in at least one of the network traffic flow records.

    Generating network flow profiles for computing entities

    公开(公告)号:US11165676B1

    公开(公告)日:2021-11-02

    申请号:US17172101

    申请日:2021-02-10

    Applicant: VMWARE, INC.

    Abstract: A method for creating a flow profile is provided. The method identifies a first plurality of flow measurements, each of which corresponding to one of a plurality of flows exchanged between a computing entity and a service during a first time period. The method, for each of a first plurality of buckets each of which has a pair of lower and upper bounds, increments a counter of the corresponding bucket for each of the plurality of flow measurements that falls within the pair of bounds of that bucket. The method generates a second plurality of buckets by merging and splitting at least some of the first plurality of buckets, identifies a second plurality of flow measurements for the computing entity during a second time period, and distributes these measurements into the second plurality of buckets. The method generate the flow profile by aggregating the first and second pluralities of buckets.

Patent Agency Ranking