VMware, Inc.
ANOMALY DETECTION ON GROUPS OF FLOWS

Last updated:

Abstract:

Some embodiments provide a novel method for analyzing the incoming flow data to detect anomalous behavior. The analysis, in some embodiments, is performed after a deduplication/aggregation operation. In some embodiments, the analysis identifies flows for further investigation by an administrator. The analysis, in some embodiments is also performed based on other received data sets (e.g., context data and configuration data), stored flow data, or both.

Status:
Application
Type:

Utility

Filling date:

23 Jul 2019

Issue date:

28 Jan 2021