The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
May. 03, 2022

Filed:

Mar. 16, 2020
Applicant:

Extrahop Networks, Inc., Seattle, WA (US);

Inventors:

Joel Benjamin Deaguero, Silverdale, WA (US);

Edmund Hope Driggs, Seattle, WA (US);

Xue Jun Wu, Seattle, WA (US);

Nicholas Jordan Braun, Seattle, WA (US);

Michael Kerber Krause Montague, Lake Forest Park, WA (US);

Michael Christopher Kelly, Seattle, WA (US);

Assignee:

ExtraHop Networks, Inc., Seattle, WA (US);

Attorneys:
Primary Examiner:
Int. Cl.
CPC ...
G06F 11/00 (2006.01); H04L 29/06 (2006.01); H04L 43/08 (2022.01); H04L 43/16 (2022.01); H04L 43/062 (2022.01); H04L 41/0631 (2022.01); H04L 67/30 (2022.01); G06N 5/04 (2006.01); H04L 41/14 (2022.01); G06N 20/00 (2019.01); G06F 12/14 (2006.01);
U.S. Cl.
CPC ...
H04L 63/1425 (2013.01); G06N 5/04 (2013.01); G06N 20/00 (2019.01); H04L 41/0645 (2013.01); H04L 41/14 (2013.01); H04L 43/062 (2013.01); H04L 43/08 (2013.01); H04L 43/16 (2013.01); H04L 67/30 (2013.01);
Abstract

Embodiments are directed to monitoring network traffic associated with networks to provide metrics. A monitoring engine may determine an anomaly based on the metrics exceeding threshold values. An inference engine may be instantiated to provide an anomaly profile based on portions of the network traffic that are associated with the anomaly. The inference engine may provide an investigation profile based on the anomaly profile such that the investigation profile includes information associated with investigation activities associated with an investigation of the anomaly. The inference engine may monitor the investigation of the anomaly based on other portions of the network traffic such that the other portions of the network traffic are associated with monitoring an occurrence of the investigation activities. The inference engine may modify a performance score associated with the investigation profile based on the occurrence of the investigation activities and a completion status of the investigation.


Find Patent Forward Citations

Loading…