The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Mar. 31, 2026

Filed:

Dec. 16, 2022
Applicant:

Amazon Technologies, Inc., Reno, NV (US);

Inventors:

Catherine Watkins, Minneapolis, MN (US);

Wayne Alan Fullen, Falls Church, VA (US);

Jared Sylvester, Ellicott City, MD (US);

Patrick Collard, Arlington, VA (US);

Evripidis Paraskevas, Washington, DC (US);

Jacob Nguyen, Annandale, VA (US);

John Paul Schweitzer, Seattle, VA (US);

Luke Kenneth Schubert, Virginia Beach, MD (US);

Michael Lowney, Edgewater, VA (US);

Parnavi Tamhankar, Arlington, VA (US);

Stephen Goodman, Owings Mills, MD (US);

William Kupersanin, Pasadena, MD (US);

Ravi Karnam, Novi, MI (US);

Sai Srinivas Vemula, Frederick, MD (US);

Sameer Anil Murudkar, Sammamish, WA (US);

Assignee:

Amazon Technologies, Inc., Reno, NV (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
H04L 9/40 (2022.01);
U.S. Cl.
CPC ...
H04L 63/1425 (2013.01); H04L 63/1416 (2013.01);
Abstract

Approaches presented herein relate to the monitoring of network traffic, and identification of potentially malicious behavior, in a networked resource environment. Values for key features of interest can be extracted from monitored network traffic. This data can be aggregated for one or more data dimensions, such as for a given region, and modeling can be performed to generate distributions for those values in that region. A threshold can be applied to this distribution to identify anomalous activity, where the same threshold can be applied to distributions for different regions and the values that meet or exceed that threshold will differ across regions based at least in part upon different levels of activity or different behavior. Such an approach scales with changes in the amount or type of traffic to be monitored, and can handle very large numbers of resources and volumes of traffic. If potentially malicious behavior is identified, one or more remedial or mitigation actions may be taken.


Find Patent Forward Citations

Loading…