The Boeing Company
SYSTEMS AND METHODS FOR REAL-TIME NETWORK TRAFFIC ANALYSIS

Last updated:

Abstract:

A system for detecting malicious traffic flows in a network is provided. The system includes a processor. Based on packet information received for a plurality of data packets transmitted over the network the processor is programmed to calculate inter-arrival times and packet durations for the plurality of data packets. The processor is also programmed to filter the packet information to remove noise. The processor is further programmed to generate at least one histogram based on the packet information, the inter-arrival times, and the packet durations. In addition, the processor is programmed to generate a power spectral density estimate based on the packet information, the inter-arrival times, and the packet durations. Moreover, the processor is programmed to analyze the at least one histogram and the power spectral density estimate to detect one or more unexpected data flows. Furthermore, the processor is programmed to report the one or more unexpected data flows.

Status:
Application
Type:

Utility

Filling date:

24 Nov 2021

Issue date:

23 Jun 2022