| CPC H04L 63/1425 (2013.01) | 20 Claims |

|
1. A method, comprising:
determining, by at least one processor of an anomaly detection system, a maximum similarity value as a maximum of a plurality of similarity values between a flow vector and a plurality of flow clusters associated with a network device;
comparing, by the at least one processor of the anomaly detection system, the maximum similarity value to a threshold, wherein the threshold is based on a minimum confidence threshold; and
in response to the maximum similarity value being less than the threshold:
detecting an anomaly in the network device;
generating an alert message based on the detected anomaly; and
generating a new flow cluster based on the flow vector, wherein the new flow cluster is stored in a memory for a subsequent anomaly detection.
|