发明名称 System for analysing network traffic and a method thereof
摘要 A method of analyzing network traffic comprising the steps of providing reference network traffic information associated with a remote access server and obtaining current network traffic information associated with the remote access server. Current network traffic information is analyzed using statistical analysis to determine whether values of the current network traffic information are within or outside a statistical range associated with the reference network traffic information. If a value of the current network traffic information is outside the statistical range, the value of the current network traffic information is an outlier which is included in an outlier information table, and an alert is generated. If a value of the current network traffic information is within the statistical range, a similarity value between the value of the current traffic information and outliers is determined. An action is then performed.
申请公布号 US9369364(B2) 申请公布日期 2016.06.14
申请号 US201414209134 申请日期 2014.03.13
申请人 TELEKOM MALAYSIA BERHAD 发明人 Jaafar Mohd. Daud;Nor Hamzah Azmirul Hamzah;Sidik Mohamad Suwandi;AB. Raub Rosmawati;Jusof Faeizah;Harun Ab. Aziz
分类号 H04L12/26;H04L12/24 主分类号 H04L12/26
代理机构 Jacobson Holman, PLLC. 代理人 Jacobson Holman, PLLC.
主权项 1. A method of analyzing network traffic, the method comprising the steps of: providing reference network traffic information associated with a remote access server; obtaining current network traffic information associated with the remote access server; analyzing the current network traffic information using statistical analysis to determine whether values of the current network traffic information are within or outside a statistical range associated with the reference network traffic information; performing an action based on the statistical analysis, wherein: when a value of the current network traffic information is outside the statistical range, the value of the current network traffic information is determined to be an outlier, the outlier is included in an outlier information table, and an alert is generated, and when a value of the current network traffic information is within the statistical range, a similarity value between the value of the current traffic information and outliers contained in the outlier information table is determined; and performing an action based on the similarity value between the value of the current traffic information and the outliers, wherein: when the similarity value is greater than or equal to a predetermined value, the corresponding outlier is removed from the outlier information table and the value of the current traffic information is included in the reference traffic information, and when the similarity value is less than the predetermined value, the value of the current traffic information is included in the reference traffic information; wherein the predetermined threshold of at least one similarity value is 95%; wherein the remote access server is a broadband remote access server (B-RAS); and wherein the current and reference network traffic information is based on the following network parameters associated with the remote access server: network traffic usage ‘in’ per port, network traffic usage ‘out’ per port, point to point protocol (PPP) sessions per port, utilization ratio of total traffic ‘in’ per slot group, utilization ratio of total traffic ‘out’ per slot group, and utilization ratio of total traffic PPP sessions per slot.
地址 Kuala Lumpur MY