- 专利标题: Network alert pattern mining
-
申请号: US14172110申请日: 2014-02-04
-
公开(公告)号: US09794113B2公开(公告)日: 2017-10-17
- 发明人: Rajeev Ranjan , Manoj Kumar Kushwaha
- 申请人: Cisco Technology, Inc.
- 申请人地址: US CA San Jose
- 专利权人: Cisco Technology, Inc.
- 当前专利权人: Cisco Technology, Inc.
- 当前专利权人地址: US CA San Jose
- 代理机构: Parker Ibrahim & Berg LLC
- 代理商 James M. Behmke; Stephen D. LeBarron
- 主分类号: G06F15/173
- IPC分类号: G06F15/173 ; H04L12/24
摘要:
In one embodiment, a device receives a plurality of network alerts over a time frame. A sliding transaction window is used across the time frame to associate each network alert occurring within the transaction window with one or more transactions. A pruning test is applied to subsets of the plurality of network alerts, with the network alerts in a given subset being associated with the same transaction. The pruning test is based in part on the number of co-occurrences of network alerts in a given subset for different transaction windows. The subsets of network alerts are assigned to network alert clusters based on the applied pruning test. The network alerts are then joined within a network alert cluster to identify the largest grouping of network alerts that pass the pruning test. A notification that the identified grouping of network alerts is associated with the same transaction is also provided.
公开/授权文献
- US20150222477A1 NETWORK ALERT PATTERN MINING 公开/授权日:2015-08-06
信息查询