The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Jun. 13, 2017

Filed:

Dec. 15, 2015
Applicant:

At&t Intellectual Property I, L.p., Atlanta, GA (US);

Inventors:

Nicholas Duffield, Summit, NJ (US);

Patrick Haffner, Atlantic Highland, NJ (US);

Balachander Krishnamurthy, New York, NY (US);

Haakon Andreas Ringberg, Ossining, NY (US);

Assignee:
Attorney:
Primary Examiner:
Int. Cl.
CPC ...
G06F 15/16 (2006.01); H04L 29/06 (2006.01); H04L 12/26 (2006.01); G06F 21/55 (2013.01); H04L 12/703 (2013.01); H04L 12/721 (2013.01); H04L 12/801 (2013.01); H04L 12/851 (2013.01); G06N 5/02 (2006.01); H04L 12/24 (2006.01);
U.S. Cl.
CPC ...
H04L 63/20 (2013.01); G06F 21/552 (2013.01); G06N 5/025 (2013.01); H04L 12/2613 (2013.01); H04L 41/16 (2013.01); H04L 43/026 (2013.01); H04L 45/28 (2013.01); H04L 45/38 (2013.01); H04L 47/10 (2013.01); H04L 47/24 (2013.01); H04L 63/1416 (2013.01); H04L 63/1425 (2013.01); H04L 12/242 (2013.01); H04L 12/2615 (2013.01); H04L 43/16 (2013.01); H04L 63/14 (2013.01); H04L 63/30 (2013.01);
Abstract

A system to detect anomalies in internet protocol (IP) flows uses a set of machine-learning (ML) rules that can be applied in real time at the IP flow level. A communication network has a large number of routers equipped with flow monitoring capability. A flow collector collects flow data from the routers throughout the communication network and provides them to a flow classifier. At the same time, a limited number of locations in the network monitor data packets and generate alerts based on packet data properties. The packet alerts and the flow data are provided to a machine learning system that detects correlations between the packet-based alerts and the flow data to thereby generate a series of flow-level alerts. These rules are provided to the flow time classifier. Over time, the new packet alerts and flow data are used to provide updated rules generated by the machine learning system.


Find Patent Forward Citations

Loading…