The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Aug. 20, 2019

Filed:

Jul. 15, 2016
Applicant:

Cisco Technology, Inc., San Jose, CA (US);

Inventors:

Laurent Sartran, Palaiseau, FR;

Grégory Mermoud, Veyras, CH;

Assignee:

Cisco Technology, Inc., San Jose, CA (US);

Attorneys:
Primary Examiner:
Int. Cl.
CPC ...
H04L 12/26 (2006.01); H04L 12/723 (2013.01); H04L 29/06 (2006.01); H04L 29/12 (2006.01); H04L 12/24 (2006.01);
U.S. Cl.
CPC ...
H04L 43/08 (2013.01); H04L 41/14 (2013.01); H04L 43/045 (2013.01); H04L 43/062 (2013.01); H04L 45/50 (2013.01); H04L 61/6022 (2013.01); H04L 67/42 (2013.01);
Abstract

In one embodiment, a device in a network identifies a plurality of traffic records as anomalous. The device matches each of the plurality of traffic records to one or more anomalies using one or more anomaly graphs. A particular anomaly graph represents hosts in the network as vertices in the graph and communications between hosts as edges in the graph. The device applies one or more ordering rules to the traffic records, to uniquely associate each traffic record to an anomaly in the one or more anomalies. The device sends an anomaly notification for a particular anomaly that is based on the traffic records associated with the particular anomaly.


Find Patent Forward Citations

Loading…