Splunk Inc.
Anomaly detection based on connection requests in network traffic

Last updated:

Abstract:

The disclosed embodiments include a method performed by a computer system. The method includes forming groups of traffic, where each group includes a subset of detected connection requests. The method further includes determining a periodicity of connection requests for each group, identifying a particular group based on whether the periodicity of connection requests of the particular group satisfies a periodicity criterion, determining a frequency of the particular group in the traffic, and identifying the particular group as an anomaly based on whether the frequency of the particular group satisfies a frequency criterion.

Status:
Grant
Type:

Utility

Filling date:

31 Jul 2018

Issue date:

10 Mar 2020