06484203 is referenced by 278 patents.

A computer-automated method of hierarchical event monitoring and analysis within an enterprise network including deploying network monitors in the enterprise network, detecting, by the network monitors, suspicious network activity based on analysis of network traffic data selected from the following categories: {network packet data transfer commands, network packet data transfer errors, network packet data volume, network connection requests, network connection denials, error codes included in a network packet}, generating, by the monitors, reports of the suspicious activity, and automatically receiving and integrating the reports of suspicious activity, by one or more hierarchical monitors.

Title
Hierarchical event monitoring and analysis
Application Number
9/658137
Publication Number
6484203 (B1)
Application Date
September 8, 2000
Publication Date
November 19, 2002
Inventor
Alfonso Valdes
San Carlos
CA, US
Phillip Andrew Porras
Mountain View
CA, US
Agent
Fish & Richardson P C
US
Assignee
SRI International
CA, US
IPC
G06F 11/30
View Original Source