Packet capture for anomalous traffic flows
Abstract:
In one embodiment, a first device in a network identifies an anomalous traffic flow in the network. The first device reports the anomalous traffic flow to a supervisory device in the network. The first device determines a quarantine policy for the anomalous traffic flow. The first device determines an action policy for the anomalous traffic flow. The first device applies the quarantine and action policies to one or more packets of the anomalous traffic flow.
Public/Granted literature
Information query
Patent Agency Ranking
0/0