发明名称 Network anomaly detection
摘要 <p>A method and apparatus for anomaly detection in a network management system is described. The method may comprise: collecting metric data from a plurality of managed network devices; determining metric types for the collected metric data using metric type reference data; determining and applying properties from the metric type reference data to collected metrics of the determined metric types; and monitoring subsequent collected metric data for anomalies that do not conform to the applied properties. The method is particularly aimed at avoiding manually configuring multiple threshold definitions for large, complex networks wherein the system is self-learning of the expected characteristics (e.g. reference levels/baseline) of the multiple types of metrics that are collected for the network. The multiple types of metrics may include percentage 402 type values, availability 404 type values, response time-type values 406, counter-type values 408 and other/general types 410. Various metrics may be monitored as the system described is data agnostic. Monitored metrics could include, for example, CPU/processor/memory usage, availability, response times etc.</p>
申请公布号 GB2518151(A) 申请公布日期 2015.03.18
申请号 GB20130016143 申请日期 2013.09.11
申请人 INTERNATIONAL BUSINESS MACHINES CORPORATION 发明人 ERIC THIEBAUT-GEORGE;IAN MANNING
分类号 H04L12/26;G06F11/30;H04L12/24 主分类号 H04L12/26
代理机构 代理人
主权项
地址