CPC H04L 41/0654 (2013.01) [H04L 41/069 (2013.01)] | 13 Claims |
1. Method for detecting incidents in a local area network by way of an incident detection device, the incident detection device being connected to the local area network via a wide area network, the local area network comprising a data collection agent collecting data describing the connections between stations and nodes of the local area network and data describing the connections between the nodes, wherein the incident detection device is able to detect various types of anomaly and in that the method comprises the following steps, performed by the incident detection device:
receiving messages from the collection agent, validating and aggregating the data describing the connections between the stations and the nodes and the data describing the connections between the nodes and contained in each received message into groups of data,
calculating, for each group of data, a severity score for each type of anomaly and calculating a total severity score for each group of data on the basis of the severity scores calculated for the group of data,
calculating a total criticality score from all of the total severity scores for the aggregated groups of data during a predetermined duration, the predetermined duration being such that a plurality of groups of data are aggregated during the predetermined duration,
generating recommendation messages or corrective actions at least on the basis of the total criticality score.
|