发明名称 |
FLOW SAMPLE |
摘要 |
A network anomaly may be detected by comparing the network behavior of a packet to an expected network behavior. The network behavior may be determined using a packet sample of a packet matching a flow rule that includes a sampling rule. |
申请公布号 |
US2017054609(A1) |
申请公布日期 |
2017.02.23 |
申请号 |
US201515306719 |
申请日期 |
2015.04.24 |
申请人 |
HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP |
发明人 |
CHETAN AMBI;RAMAPRASAD ALLU;DEVARAJAN VENKATAVARADHAN |
分类号 |
H04L12/26;H04L29/06;H04L12/24 |
主分类号 |
H04L12/26 |
代理机构 |
|
代理人 |
|
主权项 |
1. A method, comprising:
transmitting a flow rule to a network device, the flow rule including a sampling rule; obtaining a packet sample of a packet matching the flow rule, the packet sample complying with the sampling rule; using the packet sample to identify the packet; identifying a network behavior for the packet; and comparing the network behavior to an expected network behavior to detect a network anomaly. |
地址 |
Houston TX US |