CPC H04L 63/1458 (2013.01) [H04L 63/1425 (2013.01); H04W 4/14 (2013.01); G06N 20/00 (2019.01)] | 20 Claims |
1. A method, comprising:
monitoring, by network equipment comprising a processor, an external data source, wherein the external data source is external to a cellular network comprising the network equipment;
monitoring, by the network equipment, a traffic condition of the cellular network, wherein:
the traffic condition varies within a variable traffic condition range, and
variation of the variable traffic condition range is correlated with variation of the external data source;
based on the traffic condition, the external data source, and the variable traffic condition range, identifying, by the network equipment, an anomalous traffic condition, wherein the anomalous traffic condition is outside of the variable traffic condition range; and
initiating, by the network equipment, an attack mitigation procedure in response to identifying the anomalous traffic condition.
|