The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Jun. 05, 2018

Filed:

Oct. 02, 2014
Applicant:

Webroot Inc., Broomfield, CO (US);

Inventors:

Hossein Eslambolchi, Rancho Santa Fe, CA (US);

Louie Gasparini, San Mateo, CA (US);

Chandra Madhekar, Del Mar, CA (US);

William Wright, Los Gatos, CA (US);

Assignee:

Webroot Inc., Broomfield, CO (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
H04L 29/06 (2006.01); G06F 21/55 (2013.01);
U.S. Cl.
CPC ...
H04L 63/1425 (2013.01); G06F 21/552 (2013.01); G06F 21/554 (2013.01); H04L 63/1408 (2013.01); H04L 63/1416 (2013.01); H04L 63/1433 (2013.01); H04L 69/22 (2013.01);
Abstract

A system for identifying a network intrusion includes four modules. The first module monitors network transmissions and creates a model of regular network activity. The second module receives the model of regular network activity and sets a threshold for irregular usage based on the model. The third module receives the threshold, compares a value of a candidate inter-nodal transmission of the network to the threshold, and identifies a potential intrusion when the value exceeds the threshold. The fourth module analyzes a transmission behavior of one or more nodes of the candidate inter-nodal transmission and identifies the network intrusion.


Find Patent Forward Citations

Loading…