- 专利标题: Anomaly detection in computer networks
-
申请号: US16619767申请日: 2018-06-08
-
公开(公告)号: US11509671B2公开(公告)日: 2022-11-22
- 发明人: Maximilien Servajean , Yipeng Cheng
- 申请人: British Telecommunications Public Limited Company
- 申请人地址: GB London
- 专利权人: British Telecommunications Public Limited Company
- 当前专利权人: British Telecommunications Public Limited Company
- 当前专利权人地址: GB London
- 代理机构: Patterson Thuente IP
- 优先权: EP17175329 20170609
- 国际申请: PCT/EP2018/065211 WO 20180608
- 国际公布: WO2018/224669 WO 20181213
- 主分类号: H04L9/40
- IPC分类号: H04L9/40 ; G06N20/00 ; G06N3/04 ; G06N20/10
摘要:
A method of anomaly detection for network traffic communicated by devices via a computer network, the method including receiving a set of training time series each including a plurality of time windows of data corresponding to network communication characteristics for a first device; training an autoencoder for a first cluster based on a time series in the first cluster, wherein a state of the autoencoder is periodically recorded after a predetermined fixed number of training examples to define a set of trained autoencoders for the first cluster; receiving a new time series including a plurality of time windows of data corresponding to network communication characteristics for the first device; for each time window of the new time series, generating a vector of reconstruction errors for the first device for each autoencoder based on testing the autoencoder with data from the time window; and evaluating a derivative of each vector; training a machine learning model based on the derivatives so as to define a filter for identifying subsequent time series for a second device being absent anomalous communication.
信息查询