The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Mar. 10, 2020

Filed:

Jul. 31, 2018
Applicant:

Splunk Inc., San Francisco, CA (US);

Inventors:

Sudhakar Muddu, Cupertino, CA (US);

Christos Tryfonas, Foster City, CA (US);

Marios Iliofotou, Santa Clara, CA (US);

Assignee:

SPLUNK INC., San Francisco, CA (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
H04L 9/00 (2006.01); H04L 29/06 (2006.01); G06N 20/00 (2019.01); G06F 16/25 (2019.01); G06F 16/28 (2019.01); G06F 16/44 (2019.01); G06F 16/901 (2019.01); G06F 16/2457 (2019.01); H04L 12/26 (2006.01); G06N 7/00 (2006.01); G06F 3/0482 (2013.01); G06K 9/20 (2006.01); G06F 3/0484 (2013.01); H04L 12/24 (2006.01); G06N 5/04 (2006.01); G06N 5/02 (2006.01);
U.S. Cl.
CPC ...
H04L 63/1416 (2013.01); G06F 3/0482 (2013.01); G06F 3/0484 (2013.01); G06F 3/04842 (2013.01); G06F 3/04847 (2013.01); G06F 16/24578 (2019.01); G06F 16/254 (2019.01); G06F 16/285 (2019.01); G06F 16/444 (2019.01); G06F 16/9024 (2019.01); G06K 9/2063 (2013.01); G06N 5/022 (2013.01); G06N 5/04 (2013.01); G06N 7/005 (2013.01); G06N 20/00 (2019.01); H04L 41/0893 (2013.01); H04L 41/145 (2013.01); H04L 41/22 (2013.01); H04L 43/00 (2013.01); H04L 43/045 (2013.01); H04L 43/062 (2013.01); H04L 43/08 (2013.01); H04L 63/06 (2013.01); H04L 63/1408 (2013.01); H04L 63/1425 (2013.01); H04L 63/1433 (2013.01); H04L 63/1441 (2013.01); H04L 63/20 (2013.01); H05K 999/99 (2013.01); H04L 2463/121 (2013.01);
Abstract

The disclosed embodiments include a method performed by a computer system. The method includes forming groups of traffic, where each group includes a subset of detected connection requests. The method further includes determining a periodicity of connection requests for each group, identifying a particular group based on whether the periodicity of connection requests of the particular group satisfies a periodicity criterion, determining a frequency of the particular group in the traffic, and identifying the particular group as an anomaly based on whether the frequency of the particular group satisfies a frequency criterion.


Find Patent Forward Citations

Loading…