| CPC H04L 43/0876 (2013.01) | 24 Claims |

|
1. A method comprising:
for each of a set of one or more device identifiers indicated in network traffic, determining similarity measurements for variables across time intervals of the network traffic, wherein the variables are variables previously identified as correlating to device behavior and device identity;
for each set of similarity measurements determined for each device identifier,
generating a feature vector with the set of similarity measurements;
inputting the feature vector into a local outlier factor with novelty detection model that was trained based on network traffic constrained to devices with stable behavior; and
indicating detection of an anomaly if the local outlier factor with novelty detection indicates an outlier.
|