Comparing metrics from different data flows to detect flaws in network data collection for anomaly detection

US10742672B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10742672-B2
Application numberUS-201715477910-A
CountryUS
Kind codeB2
Filing dateApr 3, 2017
Priority dateApr 3, 2017
Publication dateAug 11, 2020
Grant dateAug 11, 2020

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

In an embodiment, a computer-implemented method compares metrics from different data flows to detect flaws in collection of data describing operation of a network. The method uses a first network data collection technique to collect a first metric describing a characteristic of a network interface. Using a second network data collection technique different from the first network data collection technique, a second metric describing the characteristic of the network interface is collected. The first metric is compared with the second metric to determine whether the first and second metrics are incongruous. When the first and second metrics are determined to be incongruous, a flaw is detected to exist in the first or second network data collection techniques.

First claim

Opening claim text (preview).

What is claimed is: 1. A computer-implemented method for comparing different metrics from different data flows to detect a network operational fault in a network, comprising: collecting a first metric from a first data flow, wherein the first metric describes a first network characteristic of a first network interface, and wherein the first metric is collected using a first network data collection technique that collects Netflow information; collecting a second metric from a second data flow, wherein the second metric describes a second network characteristic of a second network interface, and wherein the second metric is collected using a second network data collection technique different from the first network data collection technique and includes a Simple Network Management Protocol command; comparing the collected first metric to the collected second metric; in response to the comparing, determining the first metric and the second metric are incongruous metrics indicating the first network interface associated with the first metric is different from the second network interface associated with the second metric; determining that a network operational fault exists in the network due to the determining that the first and second metrics being incongruous metrics; and in response to determining that the network operational fault exists in the network, providing the first metric to an anomaly detection system to use to determine whether the network is being attacked. 2. The method of claim 1 , wherein the first network interface is a port on an edge network element and the first network characteristic of the first network interface is utilization of a circuit connected to the port during a period of time. 3. The method of claim 2 , wherein the collecting using the first network data collection technique includes collecting a first plurality of first metrics, each first metric of the first plurality of first metrics describing the utilization of the circuit at a different time period, wherein the collecting using the second network data collection technique includes collecting a second plurality of second metrics, each second metric of the second plurality of second metrics describing the utilization of the circuit at a respective different time periods, wherein the comparing of the first metric with the second metric includes comparing the first plurality of first metrics and second plurality of second metrics at the respective different time periods. 4. The method of claim 3 , wherein the comparing of the first metric with the second metric includes: determining a correlation coefficient between the first plurality of first metrics and the second plurality of second metrics; determining whether the correlation coefficient is within a predetermined range; and determining that the first plurality of first metrics and second plurality of second metrics are incongruous metrics based at least in part on whether the correlation coefficient is determined not to be within the predetermined range. 5. The method of claim 3 , wherein the first network data collection technique is a technique that samples data quantities from packets on the circuit during the period of time. 6. The method of claim 3 , wherein the comparing of the first metric with the second metric includes: determining a plurality of ratios between each of the first metric of the first plurality of first metrics and the second metric of the second plurality of second metrics for respective time periods; aggregating the plurality of ratios determined for a plurality of time periods to generate an aggregated ratio; determining whether the aggregated ratio determined is within a predetermined range; and determining that the first plurality of first metrics and second plurality of second metrics are incongruous metrics based at least in part on whether the aggregated ratio is determined not to be within the predetermined range. 7. The method of claim 6 , wherein the comparing of the first metric with the second metric includes: determining a variance of the aggregated ratio determined, wherein determining that the first plurality of first metrics and second plurality of second metrics are incongruous metrics based at least in part on the determined variance. 8. The method of claim 1 , wherein the providing occurs when the first metric is determined to be congruous with the second metric. 9. The method of claim 1 , wherein the determining the first metric and the second metric are incongruous metrics comprises performing a comparison technique between the first metric and the second metric, wherein the comparison technique comprises a scaling distribution evaluation between the first metric and the second metric. 10. A non-transitory program storage device storing a program of instruction that when executed by a computer to perform operations for comparing different metrics from different data flows to detect a network operational fault in a network, the operations comprising: collecting a first metric from a first data flow, wherein the first metric describes a first network characteristic of a first network interface, and wherein the first metric is collected using a first network data collection technique that collects Netflow information; collecting a second metric from a second data flow, wherein the second metric describes a second network characteristic of a second network interface, and wherein the second metric is collected using a second network data collection technique different from the first network data collection technique and includes a Simple Network Management Protocol command; comparing the collected first metric to the collected second metric; in response to the comparing, determining the first metric and second metric are incongruous metrics indicating the first network interface associated with the first metric is different from the second network interface associated with second metric; determining that a network operational fault exists in the network due to the determining that the first and second metrics being incongruous metrics; and in response to determining that the network operational fault exists in the network, providing the first metric to an anomaly detection system to use to determine whether the network is being attacked. 11. The program storage device of claim 10 , wherein the first network interface is a port on an edge network element and the first network characteristic of the first network interface is utilization of a circuit connected to the port during a period of time. 12. The program storage device of claim 11 , wherein the collecting using the first network data collection technique includes collecting a first plurality of first metrics, each first metric of the first plurality of first metrics describing the utilization of the circuit at a different time period, wherein the collecting using the second network data collection technique includes collection a second plurality of second metrics, each second metric of the second plurality of second metrics describing the utilization of the circuit at a respective different time periods, wherein the comparing of the first metric with the second metric includes comparing the first plurality of first metrics and second plurality of second metrics at the respective different time periods. 13. The program storage device of claim 12 , wherein the comparing of the first metric with the second metric includes: determining a correlation coefficient between the first plurality of first metrics and the second plurality of second metrics; determining whether the correlation coefficient is with

Assignees

Inventors

Classifications

  • Capturing of monitoring data · CPC title

  • by checking functioning · CPC title

  • Processing captured monitoring data, e.g. for logfile generation · CPC title

  • Denial of Service · CPC title

  • Standardised network management protocols, e.g. simple network management protocol [SNMP] · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10742672B2 cover?
In an embodiment, a computer-implemented method compares metrics from different data flows to detect flaws in collection of data describing operation of a network. The method uses a first network data collection technique to collect a first metric describing a characteristic of a network interface. Using a second network data collection technique different from the first network data collection…
Who is the assignee on this patent?
Level 3 Communications Llc, Level 3 Communication Llc
What technology area does this patent fall under?
Primary CPC classification H04L63/1425. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Aug 11 2020 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 5 related publications on this page (citations in our corpus or others sharing the same primary CPC).