The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Oct. 21, 2025

Filed:

Apr. 06, 2021
Applicant:

Mcafee, Llc, San Jose, CA (US);

Inventors:

Sherin M. Mathews, Santa Clara, CA (US);

Vaisakh Shaj, Kollam, IN;

Sriranga Seetharamaiah, Bangalore, IN;

Carl D. Woodward, Santa Clara, CA (US);

Kantheti V V S M B Kumar, Bangalore, IN;

Assignee:

McAfee, LLC, San Jose, CA (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
H04L 9/40 (2022.01); G06N 3/02 (2006.01); G06N 20/00 (2019.01); H04L 41/14 (2022.01); H04L 41/142 (2022.01); H04L 43/045 (2022.01); G06F 16/901 (2019.01); H04L 101/668 (2022.01);
U.S. Cl.
CPC ...
H04L 63/1425 (2013.01); G06N 3/02 (2013.01); G06N 20/00 (2019.01); H04L 41/142 (2013.01); H04L 41/145 (2013.01); H04L 43/045 (2013.01); H04L 63/1441 (2013.01); G06F 16/9024 (2019.01); H04L 2101/668 (2022.05);
Abstract

Methods, systems, and media for detecting anomalous network activity are provided. In some embodiments, a method for detecting anomalous network activity is provided, the method comprising: receiving information indicating network activity, wherein the information includes IP addresses corresponding to devices participating in the network activity; generating a graph representing the network activity, wherein each node of the graph indicates an IP address of a device; generating a representation of the graph, wherein the representation of the graph reduces a dimensionality of information indicated in the graph; identifying a plurality of clusters of network activity based on the representation of the graph; determining that at least one cluster corresponds to anomalous network activity; and in response to determining that the at least one cluster corresponds to anomalous network activity, causing a network connection of at least one device included in the at least one cluster to be blocked.


Find Patent Forward Citations

Loading…