ANOMALY DETECTION BASED ON INFORMATION TECHNOLOGY ENVIRONMENT TOPOLOGY

    公开(公告)号:US20190158524A1

    公开(公告)日:2019-05-23

    申请号:US16250989

    申请日:2019-01-17

    申请人: SPLUNK INC.

    IPC分类号: H04L29/06 H04L12/26

    摘要: Techniques are described for analyzing data regarding activity in an IT environment to determine information regarding the entities associated with the activity and using the information to detect anomalous activity that may be indicative of malicious activity. In an embodiment, a plurality of events reflecting activity by a plurality of entities in an IT environment are processed to resolve the identities of the entities, discover how the entities fit within a topology of the IT environment, and determine what the entities are. This information is then used to generate an entity relationship graph that includes nodes representing the entities in the IT environment and edges connecting the nodes representing interaction relationships between the entities. In some embodiments, baselines are established by monitoring the activity between entities. This baseline information can be represented in the entity relationship graph in the form of directionality applied to the edges. The entity relationship graph can then be monitored to detect anomalous activity.

    PACKET THROUGHPUT AND LOSS RATIO MEASUREMENTS OF A SERVICE FUNCTION CHAIN

    公开(公告)号:US20180331931A1

    公开(公告)日:2018-11-15

    申请号:US15593882

    申请日:2017-05-12

    申请人: Ciena Corporation

    发明人: Marc Holness

    IPC分类号: H04L12/26 H04L29/08 H04L29/06

    摘要: A method for monitoring a network includes generating a first receiving sequence number representing a first location within a first ordered sequence of a number of data packets as received by a receiving device, and extracting a first transmission sequence number representing a second location within a second ordered sequence of the number of data packets as transmitted by a transmitting device. The method further includes generating a second receiving sequence number representing a third location within the first ordered sequence of the number of data packets, extracting a second transmission sequence number representing a fourth location within the second ordered sequence of the number of data packets. The method further includes generating a measurement of network transmission based at least on the first receiving sequence number, the first transmission sequence number, the second receiving sequence number, and the second transmission sequence number.

    SCHEDULED NETWORK SETUP TEST METHOD AND SYSTEM

    公开(公告)号:US20180316592A1

    公开(公告)日:2018-11-01

    申请号:US15949096

    申请日:2018-04-10

    发明人: Lars ELLEGAARD

    IPC分类号: H04L12/26

    摘要: A setup test method for scheduled networks, the method constituted of: transmitting a frame to at least one network switch; responsive to the transmitted frame arriving at a first time gate of the at least one network switch, timestamping the transmitted frame with a first time stamp; responsive to the transmitted frame traversing a second time gate of the at least one network switch, additionally timestamping the transmitted frame with a second time stamp; reading the first time stamp; responsive to the read first time stamp, determining the time of arrival of the transmitted frame at the first time gate; reading the second time stamp; and responsive to the read first time stamp, determining the time of traversal of the transmitted frame through the second time gate.