Creating aggregate network flow time series in network anomaly detection systems
In an embodiment, a computer implemented method receives flow data for one or more flows that correspond to a device-circuit pair. The method calculates a time difference for each flow that corresponds to a device-circuit pair. Based on the calculated time differences and the received flow data, the...
Saved in:
Main Author | |
---|---|
Format | Patent |
Language | English |
Published |
14.03.2023
|
Subjects | |
Online Access | Get full text |
Cover
Loading…
Summary: | In an embodiment, a computer implemented method receives flow data for one or more flows that correspond to a device-circuit pair. The method calculates a time difference for each flow that corresponds to a device-circuit pair. Based on the calculated time differences and the received flow data, the method updates a probability distribution model associated with the device-circuit pair. Then, the method determines whether a time bucket is complete or open based on the updated probability distribution model. |
---|---|
Bibliography: | Application Number: US202217684488 |