Invention Grant
- Patent Title: Sanity check of potential learned anomalies
-
Application No.: US15184252Application Date: 2016-06-16
-
Publication No.: US10218727B2Publication Date: 2019-02-26
- Inventor: Andrea Di Pietro , Jean-Philippe Vasseur
- Applicant: Cisco Technology, Inc.
- Applicant Address: US CA San Jose
- Assignee: Cisco Technology, Inc.
- Current Assignee: Cisco Technology, Inc.
- Current Assignee Address: US CA San Jose
- Agency: Parker Ibrahim & Berg LLP
- Agent James M. Behmke; Stephen D. LeBarron
- Main IPC: G06F21/00
- IPC: G06F21/00 ; H04L29/06 ; H04L29/12

Abstract:
In one embodiment, a device in a network receives, from a supervisory device, trace information for one or more traffic flows associated with a particular anomaly. The device remaps network addresses in the trace information to addresses of one or more nodes in the network based on roles of the one or more nodes. The device mixes, using the remapped network addresses, the trace information with traffic information regarding one or more observed traffic flows in the network, to form a set of mixed traffic information. The device analyzes the mixed traffic information using an anomaly detection model. The device provides an indication of a result of the analysis of the mixed traffic information to the supervisory device.
Public/Granted literature
- US20170279832A1 SANITY CHECK OF POTENTIAL LEARNED ANOMALIES Public/Granted day:2017-09-28
Information query