Invention Grant
- Patent Title: Cluster-based outlier scoring of network traffic
-
Application No.: US17566825Application Date: 2021-12-31
-
Publication No.: US11979421B2Publication Date: 2024-05-07
- Inventor: Yair Allouche , Aviad Cohen , Ravid Sagy , Ofer Haim Biller , Eitan Daniel Farchi
- Applicant: International Business Machines Corporation
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agent Kristofer Haggerty
- Main IPC: H04L9/40
- IPC: H04L9/40 ; G06F9/48

Abstract:
In some examples, a system for decorating network traffic flows with outlier scores includes a processor and a memory device to store traffic flows received from a network. The processor is configured to receive a set of traffic flows from the memory device and generate a tree model to split the traffic flows into clusters of traffic flows. Each cluster corresponds with a leaf of the tree model. The processor is further configured to generate machine learning models for each of the clusters of traffic flows separately. For a new traffic flow, the processor is configured to identify a specific one of the machine learning models that corresponds with the new traffic flow, compute an outlier score for the new traffic flow using the identified specific one of the machine learning models, and decorate the new traffic flow with the outlier score.
Public/Granted literature
- US20230216870A1 Cluster-Based Outlier Scoring of Network Traffic Public/Granted day:2023-07-06
Information query