ASSIGNMENT OF OUTLIERS-BASED CLASSIFICATIONS TO TRAFFIC FLOWS ACROSS MULTIPLE TIME WINDOWS
The multi-sub-time window sampling architecture with network device-level outlier detection improves real-time traffic flow analysis by reducing average convergence and aggregating classifications to quickly identify and address malicious traffic flows.
Patent Information
- Application Number
- DE102022109007
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2021-10-29
- Filing Date
- 2022-04-13
- Publication Date
- 2026-02-05
- Estimated Expiration
- 2042-04-13
AI Technical Summary
Existing traffic flow analysis methods lack real-time refinement and accuracy in detecting outliers, leading to delayed preventive actions due to remote analysis and high false positive rates.
Implementing a multi-sub-time window sampling architecture with outlier detection at the network device level, analyzing traffic flows in short sub-time slots (e.g., 10 minutes, 1 minute, 30 seconds) to reduce average value convergence and aggregate outlier-related classifications across multiple sub-time slots.
Enhances real-time outlier detection by reducing false positives and enabling quicker identification of malicious or problematic traffic flows, allowing for immediate preventive measures.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
BackgroundData may be transmitted from one computer network to another computer network in the form of data packets (in some cases, this transmission may be over the Internet). Similarly, a computer network may exchange data packets with the Internet.A "traffic flow" may refer to a sequence of one or more data packets sent from a particular source to a particular destination. A traffic flow may be, for example, a sequence of messages sent from a source computer to a destination computer during a chat session. Similarly, a traffic flow may be associated with a web browser session between the Internet and a destination computer.Network devices (e.g., switches, routers, firewalls, or other hardware or software-implemented systems capable of controlling traffic flows, etc.) may transmit traffic flows between computer networks (they may also transmit traffic flows between components / devices within a computer network). For example, a network device may transmit traffic flows between the Internet and the various client devices of an office network. Similarly, a network device may transmit a traffic flow from a computer in one network (e.g., a Kancele computer network) to a computer in another network (e.g., a bank computer network). With the complex computer networks of today, millions of data streams can be transmitted daily from a single network device.Machine learning may refer to the use of artificial intelligence (e.g., machine learning algorithms) to mimic the manner in which people learn. Machine learning algorithms can build models to make predictions or decisions based on example data, the so-called "training data.".Unsupervised machine learning is an approach to machine learning. In unsupervised machine learning (as opposed to supervised machine learning), no input examples are provided to the machine learning algorithms. Instead, machine learning algorithms must find the structure in their own inputs. US 2020 / 0387797 A1 discloses a method for determining patterns in time series data and for detecting outliers in network data, wherein a sliding time window is applied over a data stream in order to train a machine learning-based algorithm.Brief Description of the DrawingsThe present disclosure will be described in detail by way of one or more different examples with reference to the following figures. The figures are for illustrative purposes only and are merely representative or exemplary examples. FIG. 1 is a diagram illustrating an example scenario in which a network device is transmitting traffic flows between computers / devices in different networks. FIG. 2 is a flow chart illustrating example operations that may be performed to detect outliers in traffic flow behavior across multiple sub-time slots. FIG. 3 shows an example of an iterative process performed by a computer system for detecting outliers in the traffic flow behavior over a plurality of sub-time windows. FIG. 4 shows an example of an iterative process performed by a computer system to detect outliers in the traffic flow behavior over a plurality of sub-time windows. FIG. 5 is an example of a computer system that may be used to implement various features of the examples described in the present disclosure.The figures are not exhaustive and do not limit the present disclosure to the precise form disclosed.Detailed DescriptionAs described above, network devices may transmit traffic flows between computer networks. Network devices may be used, for example, to connect computer networks of various companies (e.g., banks, hospitals, authorities, data centers) to the Internet and / or to one another. In the complex computer networks of today, millions of traffic flows can be transmitted daily by a single network device.Traffic flow analysis (referred to herein as traffic flow analysis) may be used to identify malicious / problematic activities (e.g., hacker attacks, bank fraud, device malfunctions, network configuration failures, and other activities) from this immense amount of traffic flow data. Traditionally, traffic flow analysis has been considered an "export-type" process. In particular, traffic flow data is sampled at the network device level (e.g., by the network device transmitting the sampled traffic flows) and exported to an external analytics service (e.g., a cloud-based analytics service). In this approach, the sampled traffic flow data is typically exported in large amounts (e.g., after one or more hours, after one or more days, etc.) to conserve network resources (e.g., network bandwidth, data storage, etc.). Accordingly, an external analysis service typically examines samples of traffic flow data / behaviors over long time intervals (e.g., one or more hours, one or more days, etc.). However, those skilled in the art do not know that these external analysis services may lack refinement of techniques such as outlier detection in performing traffic flow analyses over long time intervals. In addition, since the sampled traffic flow data is exported to external analytics services in large amounts, the analytic findings may be behind real-time traffic flow behavior at the network device level. In other words, since the traffic flow analysis is remote from the actual data source (e.g., the network device), it may be too late to take preventative / remedial action at the time a malicious / problematic traffic flow is detected.In view of this, examples of the presently disclosed technology provide improved / optimized real-time traffic flow analysis by combining an architecture for scanning multiple sub-time slots with outlier detection implemented at the network device level. As described below, this multi-sub-time window sampling architecture improves / optimizes outlier detection by comparing average value convergence (as used herein, average value convergence may refer to the tendency of average behavioral characteristic values for sampled traffic flows to converge to common / similar values over time), and false positives (as used herein, false positive may refer to a case where a sampled traffic flow is classified as outliers, although the activity to which it is associated is not malicious / problematic).The detection of outliers at the level of the network device eliminates the intermediate step of export which is required in other technologies. Accordingly, traffic flow data may be analyzed in numerous sub-time slots without loading network resources through numerous / frequent data exports. In addition, because the sampled traffic flow data is analyzed in relatively short sub-time slots (e.g., 10 minutes, 1 minute, 30 seconds, 1 second, etc.), the analytic findings may respond more quickly to the real-time behavior of the traffic flow than would be possible with a conventional "export-type" approach. In other words, since the analysis of traffic flow is performed (a) more quickly and (b) closer to the data source, examples of the technology presented herein can identify problematic / harmful traffic flow behavior more quickly than other technologies.Examples of the present technology improve / optimize outlier detection by assigning outlier-related classifications (as used herein, an outlier-related classification may refer to a classification assigned to a sampled traffic flow that either (a) classifies a sampled traffic flow as outliers or not as outliers; or (b) quantitates to what extent a sampled traffic flow is an outlier compared to other sampled traffic flows) to sampled traffic flows over multiple sub-time windows. In various examples, these sub-time slots may be relatively short (e.g., 10 minutes, 1 minute, 30 seconds, 1 second, etc.) By assigning outlier-related classifications in short sub-time slots, examples may reduce average value convergence. By reducing average convergence, the examples may improve outlier detection by identifying / classifying more traffic flows than outliers.As more traffic flows are identified / classified in shorter sub-time slots than outliers, examples may reduce the occurrence of false positive results by aggregating outlier-related classifications across multiple sub-time slots. The basic idea here is that traffic flows associated with malicious / problematic activities (e.g., hacker attacks, defective devices, etc.) are likely to have an outlier-like behavior over a larger number of sub-time slots than traffic flows associated with benign activities (here benign activities refer to activities that are not malicious / problematic).Accordingly, in examples of the presently disclosed technology, a network device may obtain a sample of traffic flow data during a defined time window. The sample of traffic flow data may include information associated with a sample subset of traffic flows transmitted from the network device in the defined time window. Each sampled traffic flow may have certain behavior characteristics (e.g., total number of packets, average packet length, rate of packet transmission, etc.).The network device may subdivide the specified time slot into two or more sub-time slots. As described above, the length of these sub-time slots may be relatively short (e.g., 10 minutes, 5 minutes, 1 minute, 30 seconds, 2 seconds, etc.).In each sub-time window, the network device may assign an outlier-related classification to one or more of the sampled traffic flows using machine learning based on the relative behavioral characteristics of the sampled traffic flows. This may include comparing one or more behavioral characteristics of a traffic flow with corresponding behavioral characteristics of other sampled traffic flows. For example, the network device may determine that a particular traffic flow (i.e., suspect traffic flow") has a much greater average packet length than all other traffic flows (as described below, this may be an indication of anomalous activities in the network). The network device may assign an outlier-related classification to the suspect traffic flow based on this determination. For example, the network device may classify the suspect traffic flow as outliers for this sub-time window using a simple binary classification approach (i.e., outliers or not outliers). In another example, the network device may quantify what extent a traffic flow was an outlier during a sub-time window (e.g., by assigning it an outlier-related classification on a numerical scale using a "sliding scale approach").Either during or after expiration of the defined time window, the network device may summarize the outlier-related classifications for one or more of the sampled traffic flows. For example, using the simple binary classification approach described above, the network device can count the number of times a sampled traffic flow has been classified as outliers. As described further below, the network device may improve outlier detection accuracy by aggregating outlier-related classifications across multiple sub-time slotsBased on the aggregated outlier-related classifications for one or more sampled traffic flows, the network device may define a subset of the sampled traffic flows as "top outliers" for the defined time window (as used herein, the subset of the top outliers may include the subset of the sampled traffic flows that have higher aggregated outlier-related classifications than sampled traffic flows that are not included in the subset of the top outliers). The network device may take into account any number of factors when defining this subset. For example, the network device may consider whether the aggregated outlier-related classification of a sampled traffic flow exceeds a threshold. Accordingly, those sampled traffic flows whose aggregated outlier-related classifications exceed the threshold may be included in the top outlier subset.The network device may then process traffic flows based on the aggregated outlier-related classifications for the one or more sampled traffic flows. For example, the network device may process traffic flows belonging to the top outlier subset with precautions that it does not apply to other traffic flows. These precautions may include one or a combination of (1) redirecting a traffic flow to a firewall; (2) reauthentifying a traffic flow; (3) discarding a traffic flow from a network; and (4) providing information associated with the traffic flow to a user interface (e.g., which may be viewed by a network administrator). As described above, since outlier detection occurs at the network device level in relatively short time slots, examples can take preventive measures to remove malicious / problematic activities faster than other technologies.Sub-time window length: As described above, by dividing a defined time window into relatively short sub-time windows (e.g., 10 minutes, 5 minutes, 1 minute, 30 seconds, 2 seconds, etc.), outlier detection can be optimized / improved by reducing average convergence. As used herein, average value convergence may refer to the tendency of average behavioral characteristic values for different sampled traffic flows to converge to common / similar values over time. As FIG. 1 shows, by reducing the average convergence, outlier detection can be improved.FIG. 1 is a diagram showing an example scenario in which a network device transmits traffic flows between computers / devices in different networks.In FIG. 1, network device 102 connects computers in bank network 100 (e.g., bank computers 110, 112, and 114) to customer devices external to bank network 110 (e.g., customer devices 120, 122, 124, and 126).In the example shown, bank computers may communicate with customer devices via a chat application of the customer service. Each chat is associated with a traffic flow (e.g., traffic flows 130, 132, 134, and 136). In particular, each traffic flow may correspond to a sequence of chat messages sent from a particular bank network computer to a particular customer device (in other examples, the service chat application may be replaced with a financial transaction application, and each financial transaction may correspond to a traffic flow). In this case, each chat message sent from a bank computer to a customer device may correspond to a data packet. These data packet / chat messages may have a typical packet length (e.g., 200-500 bytes).The network device 102 may sample traffic flow data and assign outlier-related classifications to one or more sampled traffic flows in the same / similar manner as described above. In this simplified example, network device 102 has sampled traffic flows 130, 132, 134, and 136 (in various examples, a network device may sample many additional traffic flows).As described above, the network device 102 may assign outlier-related classifications to the sampled traffic flows in a particular time window based on the relative behavioral characteristics of the sampled traffic flows. In this simplified example, the network device 102 takes into account how the sampled traffic flows are compared in terms of a behavior characteristic - the mean packet length.In an example one hour time window, traffic flow 130 (i.e., "suspect traffic flow") may include two very long data packets (e.g., 1000 bytes or more) and numerous very short data packets (e.g., 50 bytes or less). In contrast, traffic flows 132, 134, and 136 may include all data packets of approximately equal length that are shorter than the two long data packets of traffic flow 130, but longer than the numerous very short data packets of traffic flow 130. For example, the data packets for traffic flows 132, 134, and 136 may all be between 200 and 500 bytes long.The two long data packets of traffic flow 130 may indicate that the chat application on bank computer 100 has been used to send two large files. This would be an atypical use for the chat application of the customer service and could indicate suspect activities. Likewise, the numerous very short packets of traffic flow 130 may indicate atypical / suspect usage of the chat application. In contrast, the relatively short / uniform length of the data packets associated with traffic flows 132, 134, and 136 may indicate that the chats associated with these traffic flows correspond to typical / unjustible usage of the chat application.When the network device 102 views the average packet length over the entire one hour window, the average packet length for the traffic flow 130 may not substantially deviate from the average packet lengths for the other sampled traffic flows. This is because the traffic flow 130 has (a) two packets that are much longer than the typical packets of the traffic flows 132, 134, and 136, and (b) numerous packets that are relatively shorter than the typical data packets of the traffic flows 132, 134, and 136. Thus, the average packet length for traffic 130 may be equal / similar to the average packet length for the other sampled traffic flows. Because the network device 102 assigns outlier-related classifications to the sampled traffic flows based on the average packet length, the network device 102 cannot classify the traffic flow 130 as outliers in this one hour time window. In other words, because the average packet length for traffic flow 130 converges to a value that is not an outlier over the one hour time window, network device 102 cannot classify traffic flow 130 as an outlier.Here (as well as in other cases), dividing the one hour time slot into short sub-time slots (e.g., 10 minutes or less) may improve outlier detection by reducing the convergence of the averages. For example, if the one hour time slot were divided into 30 two minute sub-time slots, the traffic flow 130 would likely be classified as outliers in the sub-time slots in which it contains the unusually long data packets. In particular, in these sub-time slots, the average packet length of the traffic flow 130 would be significantly longer than the average packet length of the other traffic flows examined. The traffic flow 130 would probably also be classified as outliers in the sub-time slots in which it contained the unusually short data packets. In particular, the average packet length of the traffic flow 130 could have been less than the average packet length of the other sampled traffic flows in these sub-time slots.Multiple sub-time slots: As the length of a sub-time slot decreases, the convergence of the averages may decrease, and the examples may tend to classify a greater number / fraction of traffic flows within the given sub-time slot as outliers. In some cases, this may result in false positives (e.g., the examples may classify certain traffic flows as outliers for certain time slots, although the underlying activity is not malicious / problematic). Accordingly, certain benign traffic flows (i.e., traffic flows not associated with malicious / problematic activities) may be redirected to a firewall, reauthenticated, or removed from the network, etc. This may negatively impact network communication.Accordingly, in certain applications, it may be advantageous to use multiple sub-time slots to reduce the occurrence of false alarms. The basic idea here is that traffic flows associated with malicious / problematic activities (e.g., hacking, malfunctions of devices, etc.) are likely to exhibit outlier-like behavior over a larger number of sub-time slots than traffic flows associated with benign activities. With respect to the example described in FIG. 1, traffic flows 132, 134, and 136 may be classified as outliers in a few sub-time slots (e.g., 1-5 sub-time slots). However, by aggregating outlier-related classifications over multiple sub-time slots, the network device 102 may identify the traffic flow 130 as true outliers for the entire one-hour time slot because it has been classified more frequently as outliers than the other sampled traffic flows (e.g., 26 times versus 1-5 times). Accordingly, the network device 102 may process the traffic flow 130 using precautions it does not apply to other traffic flows (e.g., redirecting the traffic flow 130 to a firewall; reauthentifying the traffic flow 130; discarding the traffic flow 130 from the bank network 100; or providing information related to the traffic flow 130 to a user interface).In summary, by analyzing sampled traffic flows in short sub-time slots, examples of the presently disclosed technology may reduce average convergence. By reducing the average convergence, the examples can identify a larger number of sampled traffic flows than outliers in a given sub-time window. To reduce the occurrence of false positives (i.e., cases where a sampled traffic flow is classified as outliers, although the underlying activity is not malicious / problematic), the examples aggregate outlier-related classifications over multiple sub-time slots. In other words, examples may reduce the occurrence of false alarms by viewing the "overall image" before deciding to classify a traffic flow as "real" outliers.FIG. 2 is a flow chart illustrating example operations that may be performed to detect outliers in traffic flow behavior across multiple sub-time slots.At operation 200, a sampling module samples traffic flow data transmitted from a network device during a particular time window (e.g., one hour, 30 minutes, etc.). The sampling module may be implemented as part of the network device. For example, the sampling module may be a software application (e.g., the HPE sFlow application) that was installed on the network device.In various examples, the time window may be defined by a network administrator or a machine learning algorithm. As described above, the defined time window may be divided into two or more sub time windows. These sub-time slots may each be a subset of the entire defined time slot. In certain examples, these sub-time slots may be relatively short (e.g., 10 minutes, 5 minutes, 1 minute, 30 seconds, 2 seconds, etc.) to reduce average convergence and improve outlier detection.The traffic flow data may include information associated with all traffic flows transmitted by the network device (e.g., a router, a switch, a gateway, etc.) during the specified time slot. Accordingly, the traffic flow data sample may include information associated with a sampled subset of these traffic flows. In this case, the traffic flows can be sampled as it would require an enormous amount of storage space to analyze each traffic flow transmitted by the network device during the defined time window.As described above, the traffic flow data sample may include information associated with a sampled subset of all traffic flows transmitted by the network device in the defined time window. The information associated with each sensed traffic flow may include one or more identifying features and one or more behavioral features.An identifying feature may be any feature that can be used to identify a traffic flow. An identifying feature may include, for example, one or a combination of the following features: (1) Source Internet Protocol (IP); (2) Destination IP; (3) Source port; (4) Destination port; (5) IP protocol; and (6) other identifying features. In certain examples, a network administrator (or machine learning algorithm) may adapt the identifying characteristics that are recorded / examined to the network managed by it. For example, in a call center, a machine learning algorithm may learn that the identifying features associated with the source of traffic flow are more valuable for outlier detection than the features associated with the destination of the traffic flow (this may be due to inbound traffic flows being randomly directed to the same group of destinations). The machine learning algorithm at the call center may adjust the recorded / checked detection characteristics accordingly.A behavior feature may be any feature that can be used to characterize the behavior of a traffic flow during a particular sub-time window. For example, a behavior characteristic may include any combination of (1) data packet volume (i.e., the total number of bytes exchanged per packet), (2) mean packet length, (3) median packet length, (4) minimum packet length, (5) maximum packet length, (6) total number of packets, and (7) other behavior characteristics. As with the identification of features, a network administrator (or machine learning algorithm) may adjust the behavioral features being recorded / examined to improve / optimize outlier detection for its network (this may be a manual process or an automated process). For example, a machine learning algorithm for a bank may learn that large data packets are often characteristic of hacker attacks. Accordingly, the machine learning algorithm may automatically tune the behavior characteristics being recorded / examined to characteristics tracking the packet length (e.g., maximum packet length, mean packet length, etc.).In certain examples, the sampled traffic flow data may consist of the individual data packets that make up the sampled traffic flows. The scanning module may scan the data packets that make up a scanned traffic flow using a software application such as HPE sFlow. The software application may achieve this by scanning data packets that have the same header information (e.g., "source IP address, destination IP address"). As described further below, a collection module may then assemble these data packets into the "sampled traffic flows" using the same / similar software application. For example, sFlow of HPE (or other similar application) may be used to (1) collect the data packets that make up a collected traffic flow and (2) construct the collected traffic flow from the collected data packets.At operation 202, the sample of traffic flow data is collected by a collection module. Like the sampling module, the sensing module may also be implemented as part of the network device through which the traffic flow data flows. The capture module may be, for example, a software application (e.g., HPE sFlow) that has been installed on the network device.In certain examples, the collection module may store the sampled traffic flow data locally to the Open vSwitch Database (OVSDB) of a network device. The term OVSDB may refer to a network accessible database system. Schemes in the OVSDB may specify tables and column types in a database and include data, uniqueness, and referencing integrity constraints.In some examples, the acquisition module may convert the raw traffic flow data sampled by the sampling module to a dataset that may be analyzed by the analysis module. As described above, in certain examples, this may include constructing traffic flows from sampled data packets using a software application such as HPE's s s.The dataset created by the detection module may describe the one or more identifiers and the one or more behavioral characteristics of the sampled traffic flows in an analyzable format. In certain examples, the collection module may use a software application such as Pandas (or other similar databases / conversion applications) for this conversion. An example of an analyzable dataset that includes various identifying and behavioral characteristics of the detected traffic flows is presented below. Here, each row of the example dataset corresponds to a sample traffic flow and each column corresponds to either an identifying or a behavioral characteristic. This record relates to a single sub-time slot. Accordingly, there may be similar records for each sub-time window.172.31.255.255131.31.25.255117617694.43.781.10922.105.205.141213213140.76.32.12362.35.85.1232786943.141.16.166920.45.3051514514194.153.68.2322.105.89.11136553111.147.53.176237.995.444118318343.153.82.18038.174.5.23311979757.183.188.4552.105.230.8945344114.53.100.2262.35.105.22228782104.3.78.244108.78.108.761103103In operation 204, an analysis module assigns outlier-related classifications to one or more sampled traffic flows. In certain examples, the analysis module may be a machine learning algorithm implemented on the network device. In some examples, this machine learning algorithm may be an unsupervised machine learning algorithm. Here, unsupervised machine learning may be used because it may group data dynamically based on behaviors.An outlier-related classification may refer to a classification that is assigned to a sampled traffic flow and that either (a) classifies a sampled traffic flow as outliers or not as outliers or (b) quantitates to what extent a sampled traffic flow is an outlier compared to other sampled traffic flows. For example, the analysis module may assign outlier-related classifications on a numerical scale (e.g., 0=no outlier; 1= small outlier; 2= medium outlier; 3= larger outlier; etc.).As described above, the defined time window may be divided into two or more sub time windows. Accordingly, the analysis module may assign an outlier-related classification in one or more sub-time slots to a sampled traffic flow. For example, if a defined time window of one hour is divided into 30 two-minute sub-time windows, the analysis module may assign an outlier-related classification to the sampled traffic flow in each of the 30 two-minute sub-time windows.In certain examples, the analysis module may assign an outlier-related classification to a particular sampled traffic flow based on the relative behavioral characteristics of the sampled traffic flows during a sub-time window. This may include comparing one or more behavioral characteristics of the given sampled traffic flow with corresponding behavioral characteristics of the other sampled traffic flows. For example, the analysis module may compare the minimum packet length for a particular traffic flow with the minimum packet length of the other sampled traffic flows.In certain examples, comparing a behavioral characteristic of a given sampled traffic flow with the corresponding behavioral characteristic of the other sampled traffic flows may include comparing the behavioral characteristic of the given sampled traffic flow with an average value (e.g., average, median, or mode) for the behavioral characteristic for the sample. For example, if there are four traffic flows in the sample, the first traffic flow in the sample may have a minimum packet length of 200 bytes, the second traffic flow in the sample may have a minimum packet length of 210 bytes, the third traffic flow in the sample may have a minimum packet length of 220 bytes, and the fourth traffic flow in the sample may have a minimum packet length of 230 bytes. The average value (in this case, the average value) for the minimum packet length for the sample can be calculated as follows: (200+210+220+230) / 4=215 bytes. Accordingly, the minimum packet length for each traffic flow detected in the sample may be compared to the average value for the minimum packet length for the sample. In assigning an outlier-related classification for the first sampled traffic flow, the analysis module may take into account that the minimum packet length for the first sampled traffic flow (i.e., 200 bytes) deviates by 15 bytes from the average value for the sample (i.e., 215 bytes). In contrast, the minimum packet length for the second sampled traffic flow (i.e., 210 bytes) only deviates by 5 bytes from the average value for the sample. Accordingly, the analysis module may rank the first sampled traffic flow as a larger outlier than the second sampled traffic flow.As shown above, the analysis module may assign an outlier-related classification to a given traffic flow based on the amount of deviation from an average characteristic behavior value for the sample. In a simple binary classification example, the analysis module may classify the given traffic flow as (a) outliers if the amount of the deviations exceeds a threshold (this threshold may be determined by the analysis module or a network administrator); or (b) not outliers if the amount of the deviation is less than or equal to the threshold. In a more differentiated example, the analysis module may assign an outlier-related classification for a particular sample traffic flow on a "sliding scale" (i.e., a numerical scale) that quantitates the amount of deviation from an average behavioral characteristic value for the sample. For example, the first traffic flow may be assigned an outlier-related classification of 15 (since it deviates by 15 bytes from the average value for the sample) and the second traffic flow may be assigned an outlier-related classification of 5 (since it deviates by 5 bytes from the average value for the sample).In certain examples, the analysis module may take into account how a sampled traffic flow across multiple behavior characteristics is compared. These comparisons can in turn be used to assign an outlier-related classification to the traffic flow under investigation in a specific sub-time window. In another example, the analysis module may take into account a standard deviation for a particular behavioral characteristic for the sample. In a first sub-time window, the average minimum packet length for a sample may be, for example, 175, with a standard deviation of 50. In this sub-time window, a traffic flow with a minimum packet length of 130 cannot be classified as outlier because it is within a standard deviation of the average for the sample. In contrast, in a second sub-time window, the average minimum packet length for a sample may be 175, with a standard deviation of 5. Here, a traffic flow with a minimum packet length of 130 may be classified as outlier because it is far outside the standard deviation for the sample.At operation 206, an aggregation and ranking module aggregates the outlier-related classifications for one or more sampled traffic flows during the defined time window.As described above, the basic idea behind aggregating outlier-related classifications over multiple sub-time slots is that traffic flows associated with malicious / problematic activities (e.g., hacker attacks, defective devices, etc.) are likely to have an outlier-like behavior over a larger number of sub-time slots than traffic flows associated with benign activities.As shown in FIG. 2, the aggregation and ranking module may aggregate the outlier-related classifications for one or more traffic flows under investigation, either during or after expiration of the defined time window. For example, if the analysis module has assigned outlier-related classifications using a simple binary classification approach (i.e., outliers or not outliers), the aggregation and ranking module may count the number of cases in which each sampled traffic flow was classified as outliers. If the analysis module assigns outlier-related classifications using a sliding scale approach (e.g., in each time window, a sample traffic flow is assigned a numerical value indicating to what extent the traffic flow is an outlier), the aggregation and ranking module may sum the outlier-related classifications for each sample traffic flow.Based on the aggregated outlier-related classifications for the sample traffic flows, the aggregation and ranking module may define a subset of sample traffic flows as "top outliers" for the defined time window. This top outlier subset may include the subset of sample traffic flows that have higher aggregated outlier-related classifications than sample traffic flows that are not included in the top outlier subset. The aggregation and ranking module may take into account any number of factors in defining this subset of top outliers.In some examples, the aggregation and ranking module may consider whether the aggregated outlier classification for a sampled traffic flow exceeds a threshold. For example, in a defined one hour time window with 30 two minute sub-time windows, a first sampled traffic flow may have an aggregated outlier-related classification of 16 (this may mean that the first sampled traffic flow has been classified as outliers in 16 of the 30 sub-time windows). A second sampled traffic flow may have an aggregated outlier-related classification of 2, and a third sampled traffic flow may have an aggregated outlier-related classification of 25. The threshold / separation line for defining the subset of top outliers may be 18 (this threshold / separation line may be predefined or determined by the aggregation and ranking module using machine learning techniques). Accordingly, only the third traffic flow under investigation would be defined as a top outlier because its aggregated outlier-related classification of 25 exceeds the threshold / separation line of 18.In other examples, the aggregation and ranking module may define the top outlier subset based on the number. Thus, the aggregation and ranking module may define the top outlier subset as the 10 traffic flows with the highest aggregated outlier classifications. In another example, the aggregation and ranking module may define the top outlier subset as the 150 sampled traffic flows with the highest aggregated outlier classifications.In operation 208, a processing module processes traffic flows based on the aggregated outlier-related classifications for the traffic flows under investigation. For example, the processing module may process traffic flows belonging to the top outlier subset using precautions it does not apply to other traffic flows. These precautions may include one or a combination of (1) redirecting a traffic flow to a firewall; (2) reauthentifying a traffic flow; (3) discarding a traffic flow from a network; and (4) providing information associated with the traffic flow to a user interface (e.g., which may be displayed by a network administrator).FIG. 3 shows an example of an iterative process performed by a computer system 300 to detect outlier traffic behavior over multiple sub-time slots. Computing system 300 may be comprised of one or more computing components, e.g., computing component 302. Computing component 302 may be, for example, a server computer, a controller, or other similar computing component capable of processing data. In the example implementation of FIG. 3, the computing component 302 includes a hardware processor 304 and a machine readable storage medium 306.The hardware processor 304 may be one or more central processing units (CPUs), semiconductor-based microprocessors, and / or other hardware devices suitable for fetching and executing instructions stored in the machine-readable storage medium 306. The hardware processor 304 may fetch, decode, and execute instructions, such as instructions 308- 316, to control processes or operations to optimize the system during runtime. Alternatively or additionally to fetching and executing instructions, the hardware processor 304 may include one or more electronic circuits including electronic components for executing the functionality of one or more instructions, such as a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), or other electronic circuits.A machine-readable storage medium, such as machine-readable storage medium 306, may be any electronic, magnetic, optical, or other physical storage device that includes or stores executable instructions. The machine readable storage medium 306 may be, for example, random access memory (RAM), non-volatile random access memory (NVRAM), electrically erasable programmable read only memory (EEPROM), storage device, optical disk, or the like. In some examples, the machine readable storage medium 306 may be a non-transitory storage medium, wherein the term "non-transitory" does not include the transitory transmission signals. As described in detail below, machine-readable storage medium 306 may be encoded with executable instructions, e.g., instructions 308- 316.The hardware processor 304 may execute the instruction 308 to obtain a sample of traffic flow data during a defined time window. The sample of traffic flow data may include information associated with a sampled subset of all traffic flows transmitted by a network device in the defined time window. In certain examples, computing system 300 may be implemented on this network device.A sensed traffic flow may have one or more behavior characteristics (as described in connection with FIG. 2 ). These behavior characteristics may include, for example, one or a combination of the following features: (1) data packet volume; (2) average data packet length; (3) median data packet length; (4) minimum data packet length; (5) maximum data packet length; (6) total number of data packets; and (7) other behavior characteristics.In certain examples, a sampled traffic flow may also include one or more identifying features (as described in connection with FIG. 2 ). These identifying features may include, for example, one or a combination of the following features: (1) Source Internet Protocol (IP); (2) Destination IP; (3) Source port; (4) Destination port; (5) IP protocol; and (6) other identifying features.The hardware processor 304 may execute the instruction 310 to subdivide the defined time slot into two or more sub-time slots. The longer defined time window may be divided into shorter sub-time windows to reduce average convergence. By reducing the average convergence, the hardware processor 304 may improve outlier detection by, for example, increasing the number of traffic flows that it classifies as outliers in a particular sub-time window.In certain examples, the hardware processor 304 may use a machine learning algorithm to determine the length / number of sub-time slots that improves outlier detection. In certain examples, the enhancement of outlier detection may correspond to maximizing the number of traffic flows sampled that are classified as outliers. For example, the first half hour machine learning STWD algorithm may subdivide the e half hour window into three ten minute sub-time windows. At the end of the half-hour window, the machine learning STWD algorithm may determine that 25 average sampled traffic flows per sub-time window have been ranked as outliers. In a second half hour, the machine learning STWD algorithm may subdivide the half hour window into 6 five minute sub-time windows. At the end of the second half-hour window, the machine learning STWD algorithm may determine that average 68 sampled traffic flows per sub-time window have been ranked as outliers. In a third half hour, the machine learning STWD algorithm may subdivide the half hour window into 10 three minute sub-time windows. At the end of the third half-hour window, the machine learning STWD algorithm may determine that 75 average sampled traffic flows per sub-time window have been ranked as outliers. The machine learning algorithm STWD may then repeat the test for the three different sub-time slots (i.e., 10, 5, and 3 minutes) and observe how many sampled traffic flows per sub-time slot have been ranked as outliers. Based on these observations, the machine learning STWD algorithm may learn that, for example, most sampled traffic flows per sub-time slot in the three-minute sub-time slots have been ranked as outliers. Accordingly, the machine learning algorithm of STWD may learn that a three minute sub-time window is the sub-time window length that maximizes outlier detection for this application.Once the defined time window has been divided into two or more sub-time windows, the hardware processor 304 may execute, in at least one sub-time window, the instruction 312 to use a machine learning algorithm for outlier classification to assign an outlier-related classification to one or more of the sampled traffic flows based on the relative behavioral characteristics of the sampled traffic flows. This can be done in the same / similar manner as described in connection with Figures 1 and 2. As described above, the hardware processor 304 may compare one or more behavioral characteristics of a traffic flow with corresponding behavioral characteristics of other sampled traffic flows. For example, the hardware processor 304 may compare (1) the minimum packet length for a given traffic flow with the minimum packet length of the other sampled traffic flows; and (2) the total number of packets for the given traffic flow with the total number of packets of the other sampled traffic flows. In certain examples, this may include comparing the minimum packet length and the total number of packets for the given traffic flow with average values (e.g., mean, median, or mode) for the other sampled traffic flows. In these examples, the hardware processor 304 may assign an outlier-related classification to the given traffic flow based on the magnitude of its deviation from one or both of these averages. In a simple binary classification example, the analysis module may classify the given traffic flow as (a) outliers if the magnitude of the deviation exceeds a threshold; or (b) not outliers if the magnitude of the deviation is less than or equal to the threshold. In a more differentiated example, the hardware processor 304 may assign an outlier-related classification to a given traffic flow on a sliding scale that measures the amount of deviation of the given traffic flow from an average value. In certain examples, the hardware processor 304 may also take into account standard deviations for the sample.The hardware processor 304 may execute the instruction 314 to aggregate the outlier-related classifications for one or more sampled traffic flows during the defined time window. By aggregating outlier-related classifications over multiple sub-time slots, the hardware processor 304 may improve the accuracy of outlier detection. The basic idea here is that traffic flows associated with malicious / problematic activities (e.g., hacking, malfunctions of devices, etc.) are likely to have outlier-like behavior over a larger number of sub-time slots than traffic flows associated with benign activities.The hardware processor 304 may summarize outlier-related classifications in any manner. For example, if a simple binary classification approach was used (i.e., outliers or not outliers), the hardware processor 304 may count the number of sub-time slots in which each traffic flow was classified as outliers. If a sliding scale has been used for outlier classification (e.g., each sampled traffic flow is assigned a numerical value in each time window indicating to what extent the traffic flow is an outlier), outlier-related classifications for each sampled traffic flow may be summed.In certain examples, the hardware processor 304 may also define a subset of sampled traffic flows as top outliers for the defined time window based on the aggregated outlier-related classifications for the sampled traffic flows. As described in connection with FIG. 2, the hardware processor 304 may take into account any number of factors in defining this subset. For example, the hardware processor 304 may consider whether the aggregated outlier-related classifications for a particular sampled traffic flow exceed a threshold (this threshold may be preselected by a network administrator or determined by a machine learning algorithm). Accordingly, those traffic flows whose aggregated outlier-related classifications exceed the threshold may be included in the subset "top outliers.".The hardware processor 304 may execute the instruction 316 to process traffic flows based on the aggregated outlier-related classifications for the sampled traffic flows. For example, the hardware processor 304 may process traffic flows with higher aggregated outlier-related classifications using precautions that it does not apply to traffic flows with lower aggregated outlier-related classifications. These precautions may include one or a combination of the following: (1) redirecting a traffic flow to a firewall; (2) reauthentication of a traffic flow; (3) discarding a traffic flow from a network; and (4) providing information related to the traffic flow to a user interface (which may be viewed by, e.g., a network administrator).FIG. 4 shows an example of an iterative process performed by a computer system 400 to detect outlier traffic behavior over multiple sub-time slots.Computing system 400 may be comprised of one or more computing components, e.g., computing component 402. Like computing component 302, computing component 402 may be, for example, a server computer, a controller, or other similar computing component capable of processing data. In the example implementation of FIG. 4, computing component 402 includes a hardware processor 404 and a machine readable storage medium 406. Here, the hardware processor 404 and the machine readable storage medium 406 may be identical / similar to the hardware processor 304 and the machine readable storage medium 306, respectively. Accordingly, hardware processor 404 may fetch, decode, and execute instructions, such as instructions 408- 418.The hardware processor 404 may execute the instruction 408 to obtain a sample of traffic flow data during a defined time window. The sample of traffic flow data may include information associated with a sampled subset of traffic flows transmitted by a network device in the defined time window. In certain examples, computing system 400 may be implemented on this network device. The hardware processor 404 may obtain the sample of traffic flow data in the same / similar manner as described in connection with FIG. 3.The hardware processor 404 may execute the instruction 410 to subdivide the defined time slot into two or more sub-time slots. This can be done in the same / similar manner as described in connection with Fig. 3.Once the defined time window has been divided into two or more sub-time windows, the hardware processor 404 may execute, in at least one sub-time window, the instruction 412 to use a machine-learning outlier-related classification algorithm to assign an outlier-related classification to each sampled traffic flow based on the relative behavioral characteristics of the sampled traffic flows. This may be done in the same / similar manner as described in connection with FIG. 3.The hardware processor 404 may execute the instruction 414 to aggregate the outlier-related classifications for each traffic flow during the defined time window. This can be done in the same / similar manner as described in connection with Fig. 3.The hardware processor 404 may execute the instruction 416 to define a subset of the sampled traffic flows as top outliers for the defined time window based on the aggregations. As described in connection with FIGS. 2 and 3, the hardware processor 404 may take into account any number of factors in defining this subset. For example, the hardware processor 304 may consider whether the aggregated outlier-related classifications for a particular sampled traffic flow exceed a threshold (this threshold may be preselected by a network administrator or determined by a machine learning algorithm). Accordingly, those traffic flows whose aggregated outlier-related classifications exceed the threshold may be included in the subset "top outliers.".The hardware processor 404 may execute the instruction 418 to process traffic flows based on the defined subset of top outlier traffic flows. For example, the processing module may process traffic flows belonging to the subset of the "top outliers" using precautions that it does not apply to other traffic flows. These precautions may include one or a combination of the following: (1) redirecting a traffic flow to a firewall; (2) reauthentication of a traffic flow; (3) discarding a traffic flow from a network; and (4) providing information associated with the traffic flow to a user interface (e.g., which may be viewed by a network manager).FIG. 5 shows a block diagram of an example computer system 500 in which various of the examples described herein may be implemented. Computer system 500 includes a bus 502 or other communication mechanism for communicating information, and one or more hardware processors 504 coupled to bus 502 for processing information. The hardware processor(s) 504 may be, for example, one or more general purpose microprocessors.The computer system 500 also includes a main memory 506, such as random access memory (RAM), a cache, and / or other dynamic storage devices, coupled to the bus 502 for storing information and instructions to be executed by the processor 504. Main memory 506 may also be used to store temporary variables or other intermediate information during execution of instructions to be executed by processor 504. When such instructions are stored in storage media accessible by the processor 504, the computer system 500 becomes a special purpose machine adapted to perform the operations specified in the instructions.Computer system 500 also includes read only memory (ROM) 508 or other static storage device coupled to bus 502 for storing static information and instructions for processor 504. A storage device 510, e.g., a magnetic disk, optical disk, or USB stick (flash drive), etc., is provided and connected to bus 502 to store information and instructions.The computer system 500 may be connected via the bus 502 to a user interface 512, e.g., a liquid crystal display (LCD) (or touch screen) to display information to a computer user. An input device 514, including alphanumeric and other keys, is coupled to bus 502 for communicating information and command selections to processor 504. Another type of user input device is cursor control 516, such as a mouse, trackball, or cursor direction keys for communicating direction information and command selections to processor 504 and for controlling cursor movement on user interface 512. In some examples, the same directional information and command selections as cursor control may be implemented via receiving touches on a touch screen without a cursor.Computer system 500 may include a user interface module for implementing a graphical user interface, which may be stored in a mass storage device as executable software code executed by the computing device(s). This and other modules may include, for example, components such as software components, object oriented software components, class components and task components, processes, functions, attributes, procedures, subroutines, segments of program code, drivers, firmware, microcode, circuitry, data, databases, data structures, tables, arrays, and variables.In general, the term "component", "engine", "system", "database", "data storage", and the like, as used herein, may refer to logic embodied in hardware or firmware, or to a collection of software instructions that may have entry and exit points and are written in a programming language such as Java, C, or C++. A software component may be compiled and linked into an executable program, installed in a dynamic link library, or written in an interpreted programming language such as BASIC, Perl, or Python. It will be appreciated that software components may be callable from other components or may be callable by themselves and / or may be invoked in response to detected events or interrupts. Software components configured for execution on computing devices may be provided on a computer readable medium, such as a compact disc, digital video disc, flash drive, magnetic disk, or other tangible medium, or as a digital download (and may be originally stored in a compressed or installable format that needs to be installed, decompressed, or decrypted prior to execution). Such software code may be partially or completely stored in a memory of the executing computing device for execution by the computing device. Software instructions may be embedded in firmware such as an EPROM. Moreover, the hardware components may consist of connected logic units such as gates and flip-flops and / or programmable units such as programmable gate arrays or processors.The computing system 500 may implement the techniques described herein using custom hard-wired logic, one or more ASICs or FPGAs, firmware, and / or program logic that, in combination with the computing system, causes or programs the computing system 500 to be a special-purpose machine. According to an example, the techniques described herein are performed by computer system 500 in response to processor(s) 504, executing / executing one or more sequences of one or more instructions contained in main memory 506. Such instructions may be read into main memory 506 from another storage medium, such as storage device 510. Execution of the sequences of instructions contained in main memory 506 causes processor(s) 504 to perform the process steps described herein. In alternative examples, hardwired circuitry may be used in place of or in combination with software instructions.The term "non-transitory media" and similar terms as used herein refer to any media that stores data and / or instructions that a machine operates in a particular manner. Such non-volatile media may include non-volatile media and / or volatile media. The non-volatile media includes, for example, optical or magnetic hard disks, such as storage device 510. The volatile media includes dynamic memory, such as main memory 506. Common forms of non-volatile media include, for example, floppy disks, flexible disks, hard disks, solid state drives, magnetic tapes or other magnetic data storage media, CD-ROMs, other optical data storage media, physical media with patterns of holes, RAM, PROM and EPROM, FLASH-EPROM, NVRAM, other memory chips or cartridges, and their networked versions.Non-transitory media are different from transmission media but may be used in conjunction with them. Transmission media participates in the transmission of information between non-transitory media. Transmission media includes, for example, coaxial cables, copper wire, and fiber optic cables, including the wires forming bus 502. Transmission media can also occur in the form of sound or light waves, as are generated during data communication via radio and infrared.Computer system 500 also includes a communication interface 518 connected to bus 502. Network interface 518 establishes a two-way data communication link to one or more network links connected to one or more local area networks. The communication interface 518 may be, for example, an integrated services digital network (ISDN) card, a cable modem, a satellite modem, or a modem to establish a data communication connection to a corresponding type of telephone line. As another example, network interface 518 may be a local area network (LAN) card to establish a data communication link to a compatible LAN (or WAN component for communication with a WAN). Wireless connections may also be implemented. In each of these implementations, the network interface 518 sends and receives electrical, electromagnetic, or optical signals that transmit digital data streams having different types of information.A network connection typically allows data communication over one or more networks to other data devices. For example, a network connection may connect via a local area network to a host computer or to data devices operated by an Internet Service Provider (ISP). The ISP, in turn, provides data communication services over the world wide packet data communication network, commonly referred to today as the "Internet.". Both the local area network and the Internet use electrical, electromagnetic or optical signals that transmit digital data streams. The signals over the various networks and the signals on the network connection and over the communication interface 518 that transmit the digital data to and from the computer system 500 are examples of transmission media.The computer system 500 may send messages and receive data including program code via the network(s), network connection, and communication interface 518. In the Internet example, a server could transmit a requested code for an application program over the Internet, the ISP, the local area network, and the communication interface 518.The received code may be executed by the processor 504 upon receipt thereof and / or stored in the storage device 510 or other non-volatile memory for later execution.Each of the processes, methods, and algorithms described in the preceding paragraphs may be embodied in, and fully or partially automated by, code components executed by one or more computer systems or computer processors having computer hardware. The one or more computer systems or computer processors may also operate to support execution of the respective operations in a cloud computing environment or as a software as a service (SaaS). The processes and algorithms can be partially or fully implemented in application specific circuitry. The various features and methods described above may be used independently or combined in various ways. Various combinations and sub-combinations are intended to fall within the scope of this disclosure, and certain method or process blocks may be omitted in some implementations. The methods and processes described herein are also not limited to a particular sequence, and the blocks or states associated therewith may be performed in other suitable sequences, in parallel, or in other ways. Blocks or states may be added to or removed from the disclosed examples. The execution of certain operations or processes may be distributed among computing systems or computer processors that are not only located on a single machine, but are distributed across a number of machines.As used herein, circuitry may be implemented in any form of hardware, software, or a combination thereof. For example, one or more processors, controllers, ASICs, PLAs, PALs, CPLDs, FPGAs, logic components, software routines, or other mechanisms may be implemented to form a circuit. In implementation, the various circuits described herein may be implemented as discrete circuits, or the described functions and features may be partially or totally shared among one or more circuits. Although various features or functional elements are individually described or claimed as separate circuits, these features and functions may be shared among one or more common circuits, and such description is not intended to imply or imply that separate circuits are required to implement these features or functions. When a circuit is implemented in whole or in part with software, this software may be implemented to operate with a computer or processing system capable of executing the functionality described with respect thereto, e.g., computer system 500.As used herein, the term "or" may be understood in both the inclusive and exclusive sense. Moreover, the description of resources, acts, or structures in the singular is not to be understood as excluding the plural. Conditional terms such as "may", "could", "could" or "permitted" are generally intended to convey that certain examples include certain features, elements and / or steps, while other examples do not include these unless expressly stated otherwise or understood differently in the context of each.The terms and expressions and their modifications used in this document are not to be understood as limiting, but rather as open-ended, unless expressly stated otherwise. Adjectives such as "conventional", "traditional", "normal", "standard", "known", and terms of similar meaning are not to be understood as limiting the described subject matter to a particular time period or to an available subject matter at a particular time, but should be understood as including conventional, traditional, normal, or standard technologies, which may be available or known now or at any time in the future. The presence of extending words and formulations such as "one or more", "at least", "but not limited to", or similar formulations in some instances is not to be understood as the narrower case is intended or required when such extending formulations are not present.As used herein, the terms "optimize", "optimal", and the like may be used to make or achieve performance as effective or perfect as possible. However, as one skilled in the art reading this document will recognize, perfection cannot always be achieved. Accordingly, these terms may also mean to make or achieve performance as good or effective as possible or practicable under the given circumstances, or to make or achieve performance better than that which can be achieved with other settings or parameters.
Claims
A method comprising: obtaining a sample of traffic flow data during a defined time window, wherein: the sample of traffic flow data comprises information associated with a sampled subset of all traffic flows (130, 132, 134, 136) transmitted from a network device (102) in the defined time window, and the sampled traffic flows (130, 132, 134, 136) have one or more behavior characteristics; dividing the set time window into two or more sub-time windows; into at least two sub-time windows, using a machine learning algorithm for outlier classification to assign an outlier-related classification to one or more of the sampled traffic flows (130, 132, 134, 136) based on relative behavior characteristics of the sampled traffic flows (130, 132, 134, 136); Aggregating the outlier-related classifications for one or more sampled traffic flows (130, 132, 134, 136) during the defined time window; defining a subset of the sampled traffic flows (130, 132, 134, 136) as top outliers for the defined time window based on the aggregated outlier-related classifications for one or more sampled traffic flows (130, 132, 134, 136); and processing traffic flows (130, 132, 134, 136) based on the defined subset of the top outliers.The method of claim 1, wherein processing traffic flows (130, 132, 134, 136) based on the aggregated outlier-related classifications for one or more sampled traffic flows (130, 132, 134, 136) comprises providing information associated with the top outliers to a user interface.The method of claim 1, wherein the one or more behavior characteristics comprise at least one of: volume of data packets; mean value of length of data packets; median value of length of data packets; minimum length of data packets; maximum length of data packets; and total number of data packets.The method of claim 1, wherein one or more of the sampled traffic flows (130, 132, 134, 136) also comprise one or more identifiers, the identifiers comprising at least one of: source Internet Protocol (IP); destination IP; source port; destination port; and IP protocol.The method of claim 1, wherein the two or more sub-time slots are of equal length and are each ten minutes or less.The method of claim 1, wherein the length of the two or more sub-time slots is determined using a machine learning determination sub-time slot length algorithm.The method of claim 6, wherein the length of the two or more sub-time slots maximizes the number of traffic flows (130, 132, 134, 136) sampled that are classified as outliers per sub-time slot.The method of claim 6, wherein the machine learning algorithm for outlier classification is an unsupervised machine learning algorithm.A network device (102) having at least one processor; and a memory storing instructions that, when executed by the at least one processor, cause the system to perform a method comprising: obtaining a sample of traffic flow data during a defined time window, wherein: the sample of traffic flow data comprises information associated with a sampled subset of all traffic flows (130, 132, 134, 136) transmitted by the network device in the defined time window, and each detected traffic flow (130, 132, 134, 136) has one or more behavior characteristics; dividing the determined time window into two or more sub-time windows; in at least two sub-time slots, using a machine learning algorithm for outlier classification to assign an outlier-related classification to one or more sampled traffic flows (130, 132, 134, 136) based on relative behavioral characteristics of the sampled traffic flows (130, 132, 134, 136); aggregating the outlier-related classifications for one or more sampled traffic flows (130, 132, 134, 136) during the defined time slot; defining a subset of the sampled traffic flows (130, 132, 134, 136) as top outliers for the defined time slot based on the aggregated outlier-related classifications for one or more sampled traffic flows; and processing the traffic flows (130, 132, 134, 136) based on the defined subset of the top outliers.The network device (102) of claim 9, wherein processing traffic flows (130, 132, 134, 136) based on the defined subset of top outliers comprises at least one of: providing information about the top outliers on a user interface; reauthentication of the top outliers; and redirecting the largest outliers to a firewall.The network device (102) of claim 10, wherein the one or more behavioral characteristics comprise at least one of: volume of data packets; mean of the length of data packets; median of the length of data packets; minimum length of data packets; maximum length of data packets; and total number of data packets.The network device (102) of claim 11, wherein each sampled traffic flow (130, 132, 134, 136) also comprises one or more of the following identifying features: source Internet Protocol (IP); destination IP; source port; destination port; and IP protocol.The network device (102) of claim 9, wherein the two or more sub-time slots are of equal length and are each ten minutes or less.The network device (102) of claim 13, wherein the length of the two or more sub-time slots is determined using a machine learning determination sub-time slot length algorithm.The network device (102) of claim 14, wherein the length of the two or more sub-time slots maximizes the number of traffic flows (130, 132, 134, 136) sampled that are classified as outliers per sub-time slot.The network device (102) of claim 14, wherein the machine learning algorithm for outlier classification is an unsupervised machine learning algorithm.A non-transitory computer readable storage medium (406) containing instructions that, when executed by at least one processor (404) of a computer system (400), cause the computer system (400) to perform a method comprising: obtaining (408) a sample of traffic flow data during a defined time window, wherein: the sample of traffic flow data comprises information associated with a sample subset of all traffic flows (130, 132, 134, 136) transmitted from a network device in the defined time window, and each detected traffic flow (130, 132, 134, 136) has one or more behavior characteristics; dividing (410) the defined time window into two or more sub-time windows; in each sub-time window, using a machine learning algorithm for outlier classification to assign (412) an outlier-related classification to one or more sampled traffic flows (130, 132, 134, 136) based on relative behavioral characteristics of the sampled traffic flows (130, 132, 134, 136); aggregating (414) the outlier-related classifications for each sampled traffic flow (130, 132, 134, 136) during the specified time window; processing traffic flows (130, 132, 134, 136) based on the aggregated outlier-related classifications for one or more sampled traffic flows (130, 132, 134, 136), wherein the lengths of the two or more sub-time windows are determined using a machine learning sub-time window length determination algorithm.
Citation Information
Patent Citations
Unsupervised outlier detection in time-series data
US20200387797A1