Cisco Systems, Inc.
Learning internal ranges from network traffic data to augment anomaly detection systems

Last updated:

Abstract:

In one embodiment, a device in a network receives traffic records indicative of network traffic between different sets of host address pairs. The device identifies one or more address grouping constraints for the sets of host address pairs. The device determines address groups for the host addresses in the sets of host address pairs based on the one or more address grouping constraints. The device provides an indication of the address groups to an anomaly detector.

Status:
Grant
Type:

Utility

Filling date:

22 Jul 2019

Issue date:

5 Oct 2021