Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

155 results about "Deep packet inspection" patented technology

Deep packet inspection (DPI) is a type of data processing that inspects in detail the data being sent over a computer network, and usually takes action by blocking, re-routing, or logging it accordingly. Deep packet inspection is often used to ensure that data is in the correct format, to check for malicious code, eavesdropping and internet censorship among other purposes. There are multiple headers for IP packets; network equipment only needs to use the first of these (the IP header) for normal operation, but use of the second header (such as TCP or UDP) is normally considered to be shallow packet inspection (usually called stateful packet inspection) despite this definition.

Dynamic access blocking method based on zero trust

The invention relates to the technical field of network security, in particular to a dynamic access blocking method based on zero trust. Comprising the following steps: step 1, collecting whole network flow data in real time in a bypass monitoring mode through a flow mirroring function of a network switch, performing deep packet inspection analysis on the collected original flow data, and extracting network flow characteristic parameters; 2, maintaining a dynamic identity information base; 3, performing real-time behavior analysis on each network session; 4, according to the risk assessment result and the real-time security context, generating a dynamic access control strategy based on a minimum permission principle; 5, implementing access control at the network execution point; and 6, continuously monitoring the network flow and the strategy execution effect, collecting feedback data, optimizing the risk assessment model and the strategy generation algorithm based on the feedback data, and forming closed-loop control. By dynamically updating the identity and asset information, the system can identify new assets or changes in real time, so that the adaptability and response capability of a network environment are improved.
Owner:SHANDONG NETWORK SECURITY TECHNOLOGY CO LTD

Network traffic anomaly detection method and system based on knowledge graph

The invention relates to the technical field of network security, and discloses a network traffic anomaly detection method and system based on a knowledge graph, and the network traffic anomaly detection method comprises the following steps: protocol perception metadata feature extraction: extracting metadata features which do not involve content privacy from encrypted network traffic through a deep packet inspection technology, comprising flow statistical characteristics, time sequence characteristics and connection relation characteristics; multi-level knowledge graph construction: based on the extracted metadata features, according to a network architecture, respectively constructing corresponding knowledge graphs on a device layer, a gateway layer and a cloud layer, and respectively representing device behaviors, network activities and global security information; the method does not depend on flow decryption operation, effective recognition of abnormal behaviors in the encrypted flow is achieved only by analyzing the metadata features of the network flow, and therefore the detection accuracy is improved.
Owner:TIANJIN UNIV

Automatic sensing model method and system for illegal access in network security isolation area

The invention provides an automatic perception model method and system for illegal access in a network security isolation area, and belongs to the technical field of computer systems based on specific calculation models.The method comprises the steps that firstly, a network topological graph matrix of the security isolation area is constructed, an equipment asset list is established, and then distributed flow collection nodes are deployed to obtain real-time network data; a deep packet detection technology is used for extracting features to establish an equipment behavior baseline library, a multi-target risk assessment function is used for carrying out risk grade division on equipment, a multi-layer perceptron and a time sequence anomaly detection algorithm are used for identifying abnormal communication, and an equipment fingerprint identification mechanism based on physical layer characteristics is established to verify the legality of the identity of the equipment. A security isolation intelligent sensing network model is utilized to analyze network behaviors, a multi-dimensional abnormal scoring system is constructed to calculate risk scores, a response mechanism based on a rule engine is realized, a federal learning technology can be selectively adopted to optimize the model, and an all-dimensional and multi-level illegal access automatic sensing protection system is formed.
Owner:BEIHAI FORECASTING CENT OF STATE OCEANIC ADMINISTRATION ((QINGDAO MARINE FORECASTING STATION OF STATE OCEANIC ADMINISTRATION) (QINGDAO MARINE ENVIRONMENT MONITORING CENT OF STATE OCEANIC ADMINISTRATION))

Traffic processing system, traffic processing method and traffic processing cluster

The invention provides a flow processing system, a processing method and a flow processing cluster, and the system comprises a converging and shunting module which is used for receiving mirror image flow from a communication link, and carrying out the rule matching, data copying and label marking processing of the mirror image flow, so as to generate a first data flow carrying flow feature information; the integrated exchange processing module is used for receiving the first data stream and forwarding the first data stream to the corresponding deep packet detection module based on the flow characteristic information of the first data stream; the deep packet detection module is used for receiving the second data stream forwarded by the integrated exchange processing module and executing protocol analysis, content identification and behavior log generation processing on the second data stream; and the backboard connection module is used for providing power connection and data communication interconnection among the functional modules. And the converging and shunting module, the integrated exchange processing module and the deep packet detection module are integrated on the same system platform, so that the data circulation efficiency and the resource cooperation capability in the system are improved.
Owner:SINO TELECOM TECHNOLOGY CO INC

Multi-modal adaptive routing device network optimization method based on artificial intelligence

The invention belongs to the technical field of wireless communication networks, and discloses a multi-modal adaptive routing equipment network optimization method based on artificial intelligence, which comprises the following steps of: extracting network flow metadata in a data link layer by adopting deep packet inspection, and analyzing and predicting bandwidth requirements in n periods of time in the future based on a time sequence; planning channel resources by adopting a Nash equilibrium algorithm according to the bandwidth requirement, and generating a channel allocation instruction; synchronously acquiring multi-band channel state data, and constructing a three-dimensional radio frequency environment signal spectrum; analyzing the three-dimensional radio frequency environment signal spectrum, searching a frequency band combination with the minimum interference, and generating a frequency band switching instruction; integrating the channel allocation instruction and the frequency band switching instruction, generating a network QoS optimization strategy, and issuing the network QoS optimization strategy to the routing equipment for execution; and the network transmission efficiency, the security and the adaptive capacity of the routing equipment are improved.
Owner:HUNAN CHIWEI INTELLIGENT TECH CO LTD

Method and system for deep packet inspection in software defined networks

A method for deep packet inspection (DPI) in a software defined network (SDN). The method includes configuring a plurality of network nodes operable in the SDN with at least one probe instruction; receiving from a network node a first packet of a flow, the first packet matches the at least one probe instruction and includes a first sequence number; receiving from a network node a second packet of the flow, the second packet matches the at least one probe instruction and includes a second sequence number, the second packet is a response of the first packet; computing a mask value respective of at least the first and second sequence numbers indicating which bytes to be mirrored from subsequent packets belonging to the same flow; generating at least one mirror instruction based on at least the mask value; and configuring the plurality of network nodes with at least one mirror instruction.
Owner:ORCKIT CORP

Policy-based transparent packet inspection for last mile zero-trust workload protection

Disclosed are systems, apparatuses, methods, and computer-readable media for policy-based transparent packet inspection for last mile zero-trust workload protection. The method comprises receiving a packet on a network interface of a provisioned resource in a data center or a user device within a network; determining, by a first intercepting agent provisioned within the network interface, whether to inspect the packet based on rules received from a control plane of the network, wherein the network interface comprises a smart network interface card (SmartNIC) or a data processing unit (DPU) and is configured with the first intercepting agent based on the control plane; selectively invoking a deep packet inspection of the packet based on inspection of the packet by the first intercepting agent using the rules from the control plane; and blocking the packet at the network interface based on the deep packet inspection identifying malicious content within the packet.
Owner:CISCO TECHNOLOGY INC

AI-powered cybersecurity system for regulatory compliance in energy distribution

A system for AI-supported cybersecurity and regulatory compliance in energy distribution networks, consisting of: a hardware-embedded data acquisition module configured to intercept, capture, and time-stamp operational data streams and to control data traffic from SCADA (Supervisory Control and Data Acquisition) systems, AMI (Advanced Metering Infrastructure) systems, and energy management systems (EMS) via multiple communication protocols without operational latency; an FPGA-based deep packet inspection unit coupled with the data acquisition module, wherein the FPGA firmware is configured to perform line rate filtering, protocol decomposition and metadata extraction of the acquired data and forwards preprocessed packet data to an AI processing unit; an AI processing unit consisting of a multi-core central processing unit (CPU), a dedicated AI accelerator selected from a graphics processing unit (GPU) or a tensor processing unit (TPU), and a volatile memory buffer; a response orchestration module that is communicatively coupled with network management devices and operations controllers, wherein the response orchestration module is configured to perform automated security and compliance remediation measures, including network isolation of compromised segments, enforcement of protocol encryption, and privilege revocation; and an immutable audit logging subsystem configured to record all detected events, compliance assessments, and corrective actions in a blockchain-based distributed ledger, with each log entry cryptographically anchored with a secure hash value and digitally signed with keys stored in a secure hardware enclave.
Owner:ALIF MUHAMMAD +11

Dynamic resource optimal configuration method for electric power communication network

The invention discloses a dynamic resource optimal configuration method for an electric power communication network, and belongs to the technical field of electric power system communication. The problems of low communication resource utilization rate and poor real-time response in the existing electric power communication are solved, the communication resources of physical network equipment are acquired through a network management system, and network operation state data and traffic flow characteristics are acquired in real time by utilizing a network probe or NETCONF / YANG; the method comprises the following steps: identifying service flows flowing into a communication network by adopting a deep packet inspection technology, classifying the service flows according to security partitions of power services, and mapping different types of service flows to different service levels; a quantitative QoS demand template is established for each type of services; and on the basis of the network operation state data, the service flow characteristics and the QoS demand template, constructing a multi-objective optimization model which takes guarantee of the service quality of key services as a highest priority objective, and solving by adopting an optimization algorithm to obtain an optimal resource allocation strategy. The method is suitable for optimal configuration of dynamic resources of the power communication network.
Owner:国网黑龙江省电力有限公司信息通信公司

Encrypted traffic analysis method based on interaction spatio-temporal characteristics

The invention provides an encrypted traffic analysis method based on interaction spatio-temporal characteristics, relates to the field of network security, and aims at an original encrypted stream to construct a FITDect model consisting of an input layer, a GNN layer, an MLP layer and an output layer, and dynamically characterizes the traffic interaction diagram by mining the spatio-temporal interaction relationship of data packets in the original encrypted stream, constructing a dynamic traffic interaction diagram, and finally, analyzing the encrypted traffic. And analyzing a space-time coupling relationship through a GNN layer of the FITDect model by utilizing layered feature extraction, performing classification decision by utilizing an MLP layer of the FITDect model, sending a classification result to an output layer, and finally outputting an analysis result. According to the method, the problems that an existing deep flow detection technology depends on shallow statistical characteristics and a traditional deep packet detection technology fails are solved, fusion analysis of encrypted flow spatio-temporal characteristics is realized, the characterization capability of a model on encrypted flow hidden behaviors is remarkably enhanced, and a hidden behavior mode of the encrypted flow can be effectively captured.
Owner:INFORMATION & COMMNUNICATION BRANCH STATE GRID JIANGXI ELECTRIC POWER CO

Data leakage real-time blocking system based on deep packet inspection

The invention discloses a data leakage real-time blocking system based on deep packet inspection, and relates to the technical field of data security. The system comprises a data integrity parameter quantization module, a data acquisition-transmission integrity optimization module, a collaborative effectiveness parameter quantization module and an interception-blocking collaborative effectiveness optimization module. According to the method, an integrity quantization result is obtained by obtaining data integrity parameter quantization in a front-end data acquisition and transmission link, whether data acquisition-transmission integrity optimization is carried out or not is judged, if yes, an interception and blocking collaborative link is executed after the data acquisition-transmission integrity optimization, and the data acquisition-transmission integrity optimization is completed. Otherwise, directly executing an interception and blocking collaboration link, quantifying according to the obtained collaboration effectiveness parameter to obtain an effectiveness quantification result, and judging whether to carry out interception-blocking collaboration effectiveness optimization or not, thereby improving the real-time blocking effectiveness of data leakage. The problem of low effectiveness of real-time blocking of data leakage caused by the lack of a full-link coordination mechanism exists in the prior art.
Owner:BEIJING ZHI YOU WANG AN TECH CO LTD +1

Wireless Mesh adaptive channel selection method and system

The invention provides a wireless Mesh self-adaptive channel selection method and system, and relates to the technical field of channel selection and optimizing.The wireless Mesh self-adaptive channel selection method comprises the steps that firstly, according to a Mesh network topological structure, a data transmission path and a corresponding channel are marked, and performance parameters such as delay packet loss rate, transmission rate bandwidth signal intensity and noise intensity are collected at fixed time intervals; the method comprises the following steps: calculating a delay packet loss rate transmission rate by detecting a data packet, obtaining bandwidth signal intensity and noise intensity by means of a tool, then extracting the delay packet loss rate transmission rate and bandwidth data, constructing a channel quality model, identifying a service type by using a deep packet inspection engine nDPI, and dynamically adjusting a weight according to a bandwidth proportion. Meanwhile, a channel signal interference quantization model is constructed according to the signal intensity and the noise intensity, finally, a signal interference quantization threshold value is set, the channel meeting the condition is screened out, the channel with the maximum channel quality result is selected as the optimal channel and switched, and the reasonability and communication performance of wireless Mesh network channel selection are effectively improved.
Owner:CHONGQING LANGYIDI IND CO LTD

Gateway service integrated management method and system based on FTTR demand

The invention relates to the technical field of data processing, and discloses a gateway service integrated management method and system based on an FTTR demand. The method comprises the following steps: carrying out topology scanning on a test signal of an optical time domain reflectometer to obtain a room-level FTTR topology mapping table, carrying out feature extraction on service traffic of each room according to deep packet inspection to obtain a room function identification tag library, and carrying out attenuation compensation on a corresponding room optical port by an optical power meter to obtain an FTTR link quality evaluation matrix, and bandwidth allocation is carried out through a reinforcement learning algorithm to obtain a room-level QoS strategy configuration set, and building data interaction is carried out based on an MQTT protocol to obtain an FTTR gateway service integrated management scheme. According to the invention, the intelligent level of FTTR network room-level management and the resource allocation efficiency are improved. According to the invention, the real-time performance of optical fiber link quality monitoring and the collaboration of building network management are improved.
Owner:JIAXING HUASHU TV COMM CO LTD

Fraud-related application detection method and device based on flow behavior analysis, medium and program product

The invention provides a fraud-related application detection method and device based on flow behavior analysis, a medium and a program product, and the method comprises the steps: carrying out the deep packet detection analysis of the current network downloading flow, comparing an application sample obtained through analysis with a preset white list and a black list, and screening out a missed to-be-detected sample; running a to-be-tested sample in a sandbox environment, collecting an interface image, extracting text features, and inputting a fraud-related classification model to judge whether the application program is a fraud-related application program or not; the method comprises the following steps: performing deep packet detection analysis on current network use traffic, extracting multi-dimensional behavior characteristics such as a terminal identifier, an application use frequency and an active time period, performing coding and scaling processing to form a fraud-related feature vector, and inputting a random forest detection model to judge whether a terminal has a fraud-related application use behavior or not. According to the method, through complementary fusion of content feature and behavior feature detection links, full-process identification of fraud-related applications in downloading and using stages is realized, and the coverage rate, the accuracy rate and the real-time performance of fraud-related detection are improved.
Owner:SINO TELECOM TECHNOLOGY CO INC

Offloading packet inspection tasks to a network interface card

The techniques disclosed herein enable systems to offload deep packet inspection tasks to a network interface card. This is accomplished by configuring the network interface card with a configuration file. The configuration file identifies target protocols, target fields, a number of packets to analyze for each target protocol, as well as identification tables that enable the network interface card to identify packet attributes. Once configured, the network interface card can receive and analyze incoming network packets. Accordingly, the network interface card extracts and parses values represented by the network packet in accordance with the parameters of the configuration file. The extracted values are compared against the entries of the identification table to derive an attribute identifier which can be returned to a network protocol stack. Moreover, the configuration file can also provide support for standard and non-standard network protocols.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Center position determination method and device and electronic equipment

The invention discloses a central position determination method and apparatus, and an electronic device. The method comprises the following steps: on the basis of deep packet inspection signaling data of an operator, determining feature data of a service cell, the deep packet inspection signaling data at least comprising a user identifier, a service cell identifier and service occurrence time, and the feature data at least comprising stay durations of different users in different service cells; based on the feature data, performing clustering processing on the service cells to obtain a plurality of first clustering results; performing clustering processing on the physical position of the service cell in each first clustering result to obtain a plurality of second clustering results; and determining the central point of the second clustering result according to the mean value of the second clustering result, and determining the position information of the central point. The technical problem that high-precision and low-cost data support cannot be provided for public services due to the fact that the center position of the area cannot be efficiently and accurately determined in the related technology is solved.
Owner:CHINA TELECOM CORP LTD

Network security-oriented abnormal traffic identification processing method

The invention discloses a network security-oriented abnormal traffic identification processing method. The method comprises the following steps of: constructing a traffic baseline model of target network link access equipment in different scenes and time windows based on historical traffic data; collecting flow characteristic data and bandwidth characteristic data of the equipment in real time, comparing the data with the flow baseline model, and identifying abnormal equipment through the baseline deviation degree; the content type is identified by using URL classification and deep packet inspection technologies, and the destination and the anomaly degree of the abnormal traffic are determined in combination with the attribute and traffic consumption of the known type of content and the traffic consumption and bandwidth occupation duration of the unknown type of content; and generating a detection report and pushing the detection report to an administrator terminal. Through scene-divided and multi-dimensional dynamic baseline modeling and flow feature and bandwidth feature fusion collaborative analysis, abnormal equipment and flow are accurately identified, the misjudgment rate is reduced, the network security operation and maintenance efficiency is improved, and the method is suitable for abnormal flow monitoring of various network environments.
Owner:LIUZHOU CITY VOCATIONAL COLLEGE

Traffic data recommendation method based on Internet

The invention discloses a traffic data recommendation method based on the Internet, and particularly relates to the technical field of computer network communication, which comprises the following steps: S1, through a DPI (Deep Packet Inspection) module and a NetFlow analysis module which are arranged in parallel, acquiring a transmission layer network quality index and an application layer service type label in real time, s2, a dynamic mapping matrix of service SLA requirements and network state indexes is constructed, the service SLA requirements at least comprise a time delay sensitive type, a throughput sensitive type and a fault-tolerant sensitive type, and the network state indexes at least comprise round-trip delay, packet loss probability and link throughput, and S3, according to a flow burst coefficient calculated in real time, the service SLA requirements and the network state indexes are subjected to dynamic mapping according to the flow burst coefficient calculated in real time. And S4, generating a three-dimensional recommendation tuple comprising a target edge node ID, a recommendation transmission protocol and QoS parameter configuration, and outputting the three-dimensional recommendation tuple to a routing control plane. According to the invention, multi-dimensional data acquisition can be realized, and the traffic scheduling accuracy, the network adaptability and the resource utilization efficiency are improved.
Owner:HAINAN YUANFA INTERACTIVE TECHNOLOGY CO LTD

Industrial Internet of Things data transmission method

The invention discloses an industrial Internet of Things data transmission method, and relates to the technical field of industrial Internet of Things. The system comprises a protocol adaptation analysis module, a data standardization processing module, a heterogeneous data fusion module and a deterministic transmission management module. The plug-in protocol analysis engine comprises a protocol feature fingerprint database and a plug-in engine maintenance unit, and breaks through the traditional curing mode of one protocol and one program: on one hand, the protocol feature fingerprint database can collect bottom features of more than 30 industrial protocols, and rapid matching is realized through a structured index table; and on the other hand, when the protocol is newly added or updated, only a new plug-in needs to be developed and put into a specified directory, the plug-in manager loads in real time without restarting an engine, the tedious operation of rewriting a program in a traditional scheme is reduced, meanwhile, the deep packet detection unit ensures the protocol analysis accuracy, and the protocol processing reliability is further improved through an abnormal alarm mechanism.
Owner:JIANGSU YANCHENG YIHUANG TECHNOLOGY CO LTD

Network high-speed traffic acquisition method, system and device based on clouded environment

The invention discloses a network high-speed traffic acquisition method, system and device based on a clouded environment, and relates to the technical field of network communication. According to the invention, a clouded environment is created; a two-stage clouded environment capacity expansion and contraction strategy is constructed by using an optimized FCN network high-speed flow prediction model and a real-time load index, and pre-allocation and accurate adjustment of resources are realized; the optimal solution of the model learning rate is dynamically searched by introducing an optimization algorithm, the session continuity is guaranteed by adopting a consistent Hash algorithm, and the load balance degree and the processing throughput are improved in combination with a three-level dynamic filtering rule and a lightweight DPI (Deep Packet Inspection) technology; due to an annular buffer management strategy and a Kafka message queue synchronization mechanism, the key data loss rate and the data synchronization delay are reduced, and the requirements of real-time analysis and long-term storage in a high-speed network scene are met; according to the method, the problem of insufficient resource elasticity of a clouded environment is effectively solved, the resource supply response speed is improved, and the cost and the prediction error rate are reduced.
Owner:LIZHUANG INFORMATION TECH (SUZHOU) CO LTD

Advanced network threat intelligent detection and defense system

The invention discloses an advanced network threat intelligent detection and defense system and method in the technical field of network defense. The system comprises a data acquisition module which analyzes encrypted traffic through a deep packet inspection technology and marks space-time metadata; the feature extraction module is used for constructing a node behavior association graph by adopting a multi-scale sliding window and a graph neural network; the detection engine module integrates multi-model parallel analysis of LSTM, random forest and the like, and dynamically fuses detection results through an entropy weight method; and the defense execution module is used for realizing flow cleaning and virtual trapping node deployment based on an SDN (Software Defined Network) technology. The method comprises the steps of protocol extension field reverse analysis, covert channel time sequence correlation analysis and dynamic network topology adjustment. According to the method, the encryption APT attack detection accuracy reaches 98.7%, the false alarm rate is reduced to 0.15%, the defense strategy effective time is shorter than 1 second, and the method is suitable for complex network environments such as cloud computing and industrial Internet of Things.
Owner:GUOANYUN (XIAN) TECH GRP CO LTD

Lightweight encryption method and system for industrial real-time data stream

The invention relates to the technical field of industrial internet security communication, and discloses a lightweight encryption method and system for an industrial real-time data stream, and the method comprises the following steps: intercepting an original data packet, and carrying out the deep packet detection to extract a network layer quintuple and application layer metadata; matching an optimal strategy in a strategy rule set according to the feature vector and generating a scheduling instruction; in response to the instruction, calling a corresponding pre-compilation password operation pipeline to carry out differential encryption processing on the load; and constructing a fixed-length security policy head containing the algorithm template identifier, and packaging and sending the fixed-length security policy head. According to the invention, task fragmentation is carried out by using a consistent Hash technology so as to ensure processing order-preserving. By adopting a lightweight message structure without handshake negotiation and a multi-level strategy scheduling mechanism, content-based fine-grained security protection is realized, and the communication requirements of low delay and high certainty are met while the security of industrial control data is ensured.
Owner:MAINTENANCE & TEST CENTRE CSG EHV POWER TRANSMISSION CO

Routing state sensing method and device cooperatively monitored by distributed network probes

The invention provides a routing state sensing method and device for distributed network probe cooperative monitoring, and relates to the technical field of communication network monitoring, and the method comprises the steps: deploying a distributed probe device at a key node, and integrating an active detection module, a passive flow monitoring module, a data fusion analysis unit and a detection control module; the active detection module supports periodic detection and specified detection, and dynamically adjusts the detection priority and path; the passive monitoring module realizes fault positioning and anomaly tracing based on deep packet detection and a machine learning model; the data fusion analysis unit constructs a dynamic routing state map through a space-time association algorithm, and depicts the link health degree and the abnormal situation; the detection control module dynamically switches detection modes according to network load, resource consumption and historical indexes, and balances detection precision and overhead. According to the invention, through active and passive cooperative detection and an intelligent decision-making mechanism, the network sensing precision is improved, the resource consumption is reduced, and efficient autonomous operation and maintenance of a 5G / 6G network are supported.
Owner:BEIJING UNIV OF POSTS & TELECOMM

Data leakage real-time blocking method fusing micro-isolation strategy and context awareness

The invention relates to the technical field of network security, and discloses a data leakage real-time blocking method fusing a micro-isolation strategy and context awareness. According to the method, a micro-isolation strategy engine based on a data sensitivity level is constructed, a logic security domain is defined, and an independent access control rule is configured; collecting a network data flow in real time, identifying sensitive data by using a deep packet detection technology, and extracting context information; dynamically analyzing and generating risk metadata, calculating a real-time risk index, and establishing a behavior baseline model to detect behavior deviation; in combination with behavior deviation, a risk index and a data operation type, an access control rule is adaptively decided and dynamically updated, a high-risk or unauthorized data transmission session is blocked in real time, and the data leakage protection capability is improved.
Owner:JIANGSU MR ZHI INFORMATION TECH CO LTD

Malicious message quarantine systems for enhanced security via deep packet inspection

Systems and methods receive, by an internet provider, a network traffic analysis subscription request to screen incoming network traffic using a DPI protocol, the network traffic including data messages from external parties to a plurality of recipient devices, the DPI protocol being configured to detect malicious code by examining contents of data packets as well as a packet header of the data packets and predict that a source of the data packets is likely a fraudulent source, the network traffic analysis subscription request identifying a plurality of subscribed devices. Incoming network traffic directed to the subscribed devices is monitored using the DPI protocol at a network gateway. Based on the monitoring, it is determined that a message that includes data packet(s) is coming from a source predicted to be fraudulent and a screening action is performed to quarantine the message.
Owner:TRUIST BANK

Network interface card testing method and device

The invention discloses a network interface card testing method and device, and relates to the technical field of computer network testing, and the method comprises the steps: dynamically generating mixed traffic simulating a real network environment through an intelligent traffic generation engine; performing all-directional performance measurement from a physical layer to an application layer by utilizing a full-stack performance analysis framework, and dynamically generating and optimizing a test case; constructing a virtualized test environment, and inputting the test case into the virtualized test environment for parallel testing; and automatically generating a test report containing the problem diagnosis suggestions, thereby solving the technical problems of low test efficiency and automation degree of a network card test technology, large limitation of a test scene, difficulty in effectively analyzing data packet content, serious waste of hardware resources and difficulty in fully performing compatibility verification in related technologies. The technical effect of comprehensively testing the performance, the stability, the reliability and the like of the network card through the intelligent flow generation and deep packet inspection technology is achieved.
Owner:INSPUR SUZHOU INTELLIGENT TECH CO LTD

Machine learning analyzing non-standard configurations for cyber security purposes

The DPD manager adaptively parses IT network traffic with a DPD ML engine based upon determining a port configuration setting in a network server in an IT network and a protocol utilized by IT network traffic. The DPD manager can detect a non-standard configuration set up for IT network traffic to be processed by a port on the network server, a non-standard protocol utilized by the IT network traffic, and any combination of both, and then completes a deep packet inspection upon the IT network traffic that has the non-standard configuration set up and / or the non-standard protocol utilized by the IT network traffic.
Owner:DARKTRACE HLDG LTD

Abnormal traffic identification method, system and device based on deep packet inspection, and medium

The invention discloses an abnormal traffic identification method, system and device based on deep packet inspection, and a medium. The method comprises the following steps: collecting original traffic data in a network through a mirror image port or a probe, obtaining original message data, cleaning and labeling the original message data, and generating a structured data set; performing depth feature extraction on the structured data set to generate a feature vector; training a classification model by using the feature vectors, generating a detection model, analyzing the new flow data through the detection model, and outputting an abnormal probability and grading early warning; positioning an abnormal type according to the abnormal probability and graded early warning, generating a structured report, and linking the safety equipment to execute a blocking operation; and performing incremental training according to the detected feedback data, and updating the detection model. The invention provides an abnormal traffic identification method based on deep packet inspection according to the characteristics of diversified protocol levels and strong concealment and evolution of abnormal behaviors in network traffic.
Owner:YUNNAN POWER GRID CO LTD

Application assurance system having a method of offloading service from an edge device to the cloud

A cloud-based application assurance service system and method using Deep Packet Inspection (DPI) enables Network Elements (NE) to access the cloud-based application assurance service to search a rules / signature database, without impacting latency on network-firewall decisions. Additionally, the application assurance service system distributes the associated mapping of the NE cache's latest contents to neighboring NEs, where a given user might next access the network. The system can recognize applications associated with network traffic and apply firewall rules. Further, the system tracks applications and uses this data to update NE caches periodically, such that NE caches are more likely to store the relevant application signatures in advance. Moreover, a historical user usage matrix is generated to track application use per user, which is used to detect a highly probable user path and transfer mapping to an associated NE.
Owner:HEWLETT PACKARD ENTERPRISE DEV LP

Systems and methods for hierarchical deep packet inspection for scalable network monitoring and cyber security functions

A system and method for hierarchical network monitoring functions are disclosed. An order of execution for layer functions of a network architecture is determined. The layer functions may be distributed across multiple layers. The layers may include a sensor layer, a federated application layer, and a data lake layer. A machine learning model may be executed at a first layer. The first layer may be the sensor layer.
Owner:NETSCOUT SYSTEMS INC