Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

112 results about "Deep packet inspection" patented technology

Deep packet inspection (DPI) is a type of data processing that inspects in detail the data being sent over a computer network, and usually takes action by blocking, re-routing, or logging it accordingly. Deep packet inspection is often used to ensure that data is in the correct format, to check for malicious code, eavesdropping and internet censorship among other purposes. There are multiple headers for IP packets; network equipment only needs to use the first of these (the IP header) for normal operation, but use of the second header (such as TCP or UDP) is normally considered to be shallow packet inspection (usually called stateful packet inspection) despite this definition.

Dynamic access blocking method based on zero trust

The invention relates to the technical field of network security, in particular to a dynamic access blocking method based on zero trust. Comprising the following steps: step 1, collecting whole network flow data in real time in a bypass monitoring mode through a flow mirroring function of a network switch, performing deep packet inspection analysis on the collected original flow data, and extracting network flow characteristic parameters; 2, maintaining a dynamic identity information base; 3, performing real-time behavior analysis on each network session; 4, according to the risk assessment result and the real-time security context, generating a dynamic access control strategy based on a minimum permission principle; 5, implementing access control at the network execution point; and 6, continuously monitoring the network flow and the strategy execution effect, collecting feedback data, optimizing the risk assessment model and the strategy generation algorithm based on the feedback data, and forming closed-loop control. By dynamically updating the identity and asset information, the system can identify new assets or changes in real time, so that the adaptability and response capability of a network environment are improved.
Owner:SHANDONG NETWORK SECURITY TECHNOLOGY CO LTD

Policy-based transparent packet inspection for last mile zero-trust workload protection

Disclosed are systems, apparatuses, methods, and computer-readable media for policy-based transparent packet inspection for last mile zero-trust workload protection. The method comprises receiving a packet on a network interface of a provisioned resource in a data center or a user device within a network; determining, by a first intercepting agent provisioned within the network interface, whether to inspect the packet based on rules received from a control plane of the network, wherein the network interface comprises a smart network interface card (SmartNIC) or a data processing unit (DPU) and is configured with the first intercepting agent based on the control plane; selectively invoking a deep packet inspection of the packet based on inspection of the packet by the first intercepting agent using the rules from the control plane; and blocking the packet at the network interface based on the deep packet inspection identifying malicious content within the packet.
Owner:CISCO TECHNOLOGY INC

AI-powered cybersecurity system for regulatory compliance in energy distribution

A system for AI-supported cybersecurity and regulatory compliance in energy distribution networks, consisting of: a hardware-embedded data acquisition module configured to intercept, capture, and time-stamp operational data streams and to control data traffic from SCADA (Supervisory Control and Data Acquisition) systems, AMI (Advanced Metering Infrastructure) systems, and energy management systems (EMS) via multiple communication protocols without operational latency; an FPGA-based deep packet inspection unit coupled with the data acquisition module, wherein the FPGA firmware is configured to perform line rate filtering, protocol decomposition and metadata extraction of the acquired data and forwards preprocessed packet data to an AI processing unit; an AI processing unit consisting of a multi-core central processing unit (CPU), a dedicated AI accelerator selected from a graphics processing unit (GPU) or a tensor processing unit (TPU), and a volatile memory buffer; a response orchestration module that is communicatively coupled with network management devices and operations controllers, wherein the response orchestration module is configured to perform automated security and compliance remediation measures, including network isolation of compromised segments, enforcement of protocol encryption, and privilege revocation; and an immutable audit logging subsystem configured to record all detected events, compliance assessments, and corrective actions in a blockchain-based distributed ledger, with each log entry cryptographically anchored with a secure hash value and digitally signed with keys stored in a secure hardware enclave.
Owner:ALIF MUHAMMAD +11

Dynamic resource optimal configuration method for electric power communication network

The invention discloses a dynamic resource optimal configuration method for an electric power communication network, and belongs to the technical field of electric power system communication. The problems of low communication resource utilization rate and poor real-time response in the existing electric power communication are solved, the communication resources of physical network equipment are acquired through a network management system, and network operation state data and traffic flow characteristics are acquired in real time by utilizing a network probe or NETCONF / YANG; the method comprises the following steps: identifying service flows flowing into a communication network by adopting a deep packet inspection technology, classifying the service flows according to security partitions of power services, and mapping different types of service flows to different service levels; a quantitative QoS demand template is established for each type of services; and on the basis of the network operation state data, the service flow characteristics and the QoS demand template, constructing a multi-objective optimization model which takes guarantee of the service quality of key services as a highest priority objective, and solving by adopting an optimization algorithm to obtain an optimal resource allocation strategy. The method is suitable for optimal configuration of dynamic resources of the power communication network.
Owner:国网黑龙江省电力有限公司信息通信公司

Data leakage real-time blocking system based on deep packet inspection

The invention discloses a data leakage real-time blocking system based on deep packet inspection, and relates to the technical field of data security. The system comprises a data integrity parameter quantization module, a data acquisition-transmission integrity optimization module, a collaborative effectiveness parameter quantization module and an interception-blocking collaborative effectiveness optimization module. According to the method, an integrity quantization result is obtained by obtaining data integrity parameter quantization in a front-end data acquisition and transmission link, whether data acquisition-transmission integrity optimization is carried out or not is judged, if yes, an interception and blocking collaborative link is executed after the data acquisition-transmission integrity optimization, and the data acquisition-transmission integrity optimization is completed. Otherwise, directly executing an interception and blocking collaboration link, quantifying according to the obtained collaboration effectiveness parameter to obtain an effectiveness quantification result, and judging whether to carry out interception-blocking collaboration effectiveness optimization or not, thereby improving the real-time blocking effectiveness of data leakage. The problem of low effectiveness of real-time blocking of data leakage caused by the lack of a full-link coordination mechanism exists in the prior art.
Owner:BEIJING ZHI YOU WANG AN TECH CO LTD +1

Fraud-related application detection method and device based on flow behavior analysis, medium and program product

The invention provides a fraud-related application detection method and device based on flow behavior analysis, a medium and a program product, and the method comprises the steps: carrying out the deep packet detection analysis of the current network downloading flow, comparing an application sample obtained through analysis with a preset white list and a black list, and screening out a missed to-be-detected sample; running a to-be-tested sample in a sandbox environment, collecting an interface image, extracting text features, and inputting a fraud-related classification model to judge whether the application program is a fraud-related application program or not; the method comprises the following steps: performing deep packet detection analysis on current network use traffic, extracting multi-dimensional behavior characteristics such as a terminal identifier, an application use frequency and an active time period, performing coding and scaling processing to form a fraud-related feature vector, and inputting a random forest detection model to judge whether a terminal has a fraud-related application use behavior or not. According to the method, through complementary fusion of content feature and behavior feature detection links, full-process identification of fraud-related applications in downloading and using stages is realized, and the coverage rate, the accuracy rate and the real-time performance of fraud-related detection are improved.
Owner:SINO TELECOM TECHNOLOGY CO INC

Center position determination method and device and electronic equipment

The invention discloses a central position determination method and apparatus, and an electronic device. The method comprises the following steps: on the basis of deep packet inspection signaling data of an operator, determining feature data of a service cell, the deep packet inspection signaling data at least comprising a user identifier, a service cell identifier and service occurrence time, and the feature data at least comprising stay durations of different users in different service cells; based on the feature data, performing clustering processing on the service cells to obtain a plurality of first clustering results; performing clustering processing on the physical position of the service cell in each first clustering result to obtain a plurality of second clustering results; and determining the central point of the second clustering result according to the mean value of the second clustering result, and determining the position information of the central point. The technical problem that high-precision and low-cost data support cannot be provided for public services due to the fact that the center position of the area cannot be efficiently and accurately determined in the related technology is solved.
Owner:CHINA TELECOM CORP LTD

Traffic data recommendation method based on Internet

The invention discloses a traffic data recommendation method based on the Internet, and particularly relates to the technical field of computer network communication, which comprises the following steps: S1, through a DPI (Deep Packet Inspection) module and a NetFlow analysis module which are arranged in parallel, acquiring a transmission layer network quality index and an application layer service type label in real time, s2, a dynamic mapping matrix of service SLA requirements and network state indexes is constructed, the service SLA requirements at least comprise a time delay sensitive type, a throughput sensitive type and a fault-tolerant sensitive type, and the network state indexes at least comprise round-trip delay, packet loss probability and link throughput, and S3, according to a flow burst coefficient calculated in real time, the service SLA requirements and the network state indexes are subjected to dynamic mapping according to the flow burst coefficient calculated in real time. And S4, generating a three-dimensional recommendation tuple comprising a target edge node ID, a recommendation transmission protocol and QoS parameter configuration, and outputting the three-dimensional recommendation tuple to a routing control plane. According to the invention, multi-dimensional data acquisition can be realized, and the traffic scheduling accuracy, the network adaptability and the resource utilization efficiency are improved.
Owner:HAINAN YUANFA INTERACTIVE TECHNOLOGY CO LTD

Industrial Internet of Things data transmission method

The invention discloses an industrial Internet of Things data transmission method, and relates to the technical field of industrial Internet of Things. The system comprises a protocol adaptation analysis module, a data standardization processing module, a heterogeneous data fusion module and a deterministic transmission management module. The plug-in protocol analysis engine comprises a protocol feature fingerprint database and a plug-in engine maintenance unit, and breaks through the traditional curing mode of one protocol and one program: on one hand, the protocol feature fingerprint database can collect bottom features of more than 30 industrial protocols, and rapid matching is realized through a structured index table; and on the other hand, when the protocol is newly added or updated, only a new plug-in needs to be developed and put into a specified directory, the plug-in manager loads in real time without restarting an engine, the tedious operation of rewriting a program in a traditional scheme is reduced, meanwhile, the deep packet detection unit ensures the protocol analysis accuracy, and the protocol processing reliability is further improved through an abnormal alarm mechanism.
Owner:JIANGSU YANCHENG YIHUANG TECHNOLOGY CO LTD

Lightweight encryption method and system for industrial real-time data stream

The invention relates to the technical field of industrial internet security communication, and discloses a lightweight encryption method and system for an industrial real-time data stream, and the method comprises the following steps: intercepting an original data packet, and carrying out the deep packet detection to extract a network layer quintuple and application layer metadata; matching an optimal strategy in a strategy rule set according to the feature vector and generating a scheduling instruction; in response to the instruction, calling a corresponding pre-compilation password operation pipeline to carry out differential encryption processing on the load; and constructing a fixed-length security policy head containing the algorithm template identifier, and packaging and sending the fixed-length security policy head. According to the invention, task fragmentation is carried out by using a consistent Hash technology so as to ensure processing order-preserving. By adopting a lightweight message structure without handshake negotiation and a multi-level strategy scheduling mechanism, content-based fine-grained security protection is realized, and the communication requirements of low delay and high certainty are met while the security of industrial control data is ensured.
Owner:MAINTENANCE & TEST CENTRE CSG EHV POWER TRANSMISSION CO

Data leakage real-time blocking method fusing micro-isolation strategy and context awareness

The invention relates to the technical field of network security, and discloses a data leakage real-time blocking method fusing a micro-isolation strategy and context awareness. According to the method, a micro-isolation strategy engine based on a data sensitivity level is constructed, a logic security domain is defined, and an independent access control rule is configured; collecting a network data flow in real time, identifying sensitive data by using a deep packet detection technology, and extracting context information; dynamically analyzing and generating risk metadata, calculating a real-time risk index, and establishing a behavior baseline model to detect behavior deviation; in combination with behavior deviation, a risk index and a data operation type, an access control rule is adaptively decided and dynamically updated, a high-risk or unauthorized data transmission session is blocked in real time, and the data leakage protection capability is improved.
Owner:JIANGSU MR ZHI INFORMATION TECH CO LTD

Malicious message quarantine systems for enhanced security via deep packet inspection

Systems and methods receive, by an internet provider, a network traffic analysis subscription request to screen incoming network traffic using a DPI protocol, the network traffic including data messages from external parties to a plurality of recipient devices, the DPI protocol being configured to detect malicious code by examining contents of data packets as well as a packet header of the data packets and predict that a source of the data packets is likely a fraudulent source, the network traffic analysis subscription request identifying a plurality of subscribed devices. Incoming network traffic directed to the subscribed devices is monitored using the DPI protocol at a network gateway. Based on the monitoring, it is determined that a message that includes data packet(s) is coming from a source predicted to be fraudulent and a screening action is performed to quarantine the message.
Owner:TRUIST BANK

Network interface card testing method and device

The invention discloses a network interface card testing method and device, and relates to the technical field of computer network testing, and the method comprises the steps: dynamically generating mixed traffic simulating a real network environment through an intelligent traffic generation engine; performing all-directional performance measurement from a physical layer to an application layer by utilizing a full-stack performance analysis framework, and dynamically generating and optimizing a test case; constructing a virtualized test environment, and inputting the test case into the virtualized test environment for parallel testing; and automatically generating a test report containing the problem diagnosis suggestions, thereby solving the technical problems of low test efficiency and automation degree of a network card test technology, large limitation of a test scene, difficulty in effectively analyzing data packet content, serious waste of hardware resources and difficulty in fully performing compatibility verification in related technologies. The technical effect of comprehensively testing the performance, the stability, the reliability and the like of the network card through the intelligent flow generation and deep packet inspection technology is achieved.
Owner:INSPUR SUZHOU INTELLIGENT TECH CO LTD

Abnormal traffic identification method, system and device based on deep packet inspection, and medium

The invention discloses an abnormal traffic identification method, system and device based on deep packet inspection, and a medium. The method comprises the following steps: collecting original traffic data in a network through a mirror image port or a probe, obtaining original message data, cleaning and labeling the original message data, and generating a structured data set; performing depth feature extraction on the structured data set to generate a feature vector; training a classification model by using the feature vectors, generating a detection model, analyzing the new flow data through the detection model, and outputting an abnormal probability and grading early warning; positioning an abnormal type according to the abnormal probability and graded early warning, generating a structured report, and linking the safety equipment to execute a blocking operation; and performing incremental training according to the detected feedback data, and updating the detection model. The invention provides an abnormal traffic identification method based on deep packet inspection according to the characteristics of diversified protocol levels and strong concealment and evolution of abnormal behaviors in network traffic.
Owner:YUNNAN POWER GRID CO LTD

Application assurance system having a method of offloading service from an edge device to the cloud

A cloud-based application assurance service system and method using Deep Packet Inspection (DPI) enables Network Elements (NE) to access the cloud-based application assurance service to search a rules / signature database, without impacting latency on network-firewall decisions. Additionally, the application assurance service system distributes the associated mapping of the NE cache's latest contents to neighboring NEs, where a given user might next access the network. The system can recognize applications associated with network traffic and apply firewall rules. Further, the system tracks applications and uses this data to update NE caches periodically, such that NE caches are more likely to store the relevant application signatures in advance. Moreover, a historical user usage matrix is generated to track application use per user, which is used to detect a highly probable user path and transfer mapping to an associated NE.
Owner:HEWLETT PACKARD ENTERPRISE DEV LP

Systems and methods for hierarchical deep packet inspection for scalable network monitoring and cyber security functions

A system and method for hierarchical network monitoring functions are disclosed. An order of execution for layer functions of a network architecture is determined. The layer functions may be distributed across multiple layers. The layers may include a sensor layer, a federated application layer, and a data lake layer. A machine learning model may be executed at a first layer. The first layer may be the sensor layer.
Owner:NETSCOUT SYSTEMS INC

A method and apparatus for route state awareness through distributed network probe collaborative monitoring

ActiveCN120567748BTransmissionNetwork awarenessAdaptive routing
This invention provides a route status awareness method and apparatus for distributed network probe collaborative monitoring, relating to the field of communication network monitoring technology. It includes: deploying a distributed probe device at key nodes, integrating an active detection module, a passive traffic monitoring module, a data fusion analysis unit, and a detection control module; the active detection module supports periodic and targeted detection, dynamically adjusting detection priority and path; the passive monitoring module uses deep packet inspection and machine learning models to achieve fault location and anomaly tracing; the data fusion analysis unit constructs a dynamic route status graph using a spatiotemporal correlation algorithm to characterize link health and abnormal situations; and the detection control module dynamically switches detection modes based on network load, resource consumption, and historical indicators to balance detection accuracy and overhead. This invention improves network awareness accuracy and reduces resource consumption through active-passive collaborative detection and intelligent decision-making mechanisms, supporting efficient autonomous operation and maintenance of 5G / 6G networks.
Owner:BEIJING UNIV OF POSTS & TELECOMM

An information interaction method based on DPI deep packet analysis

The present application relates to the technical field of deep packet inspection, and in particular to a kind of information interaction method based on DPI deep packet analysis.The present application comprises data stream classification, and determines the analysis mode according to the classification result.The present application automatically monitors the network traffic of power system in real time, determines different analysis modes according to the classification result of data stream, analyzes the abnormal state of the second type of data stream, extracts the telemetry signal, identifies the characteristics of the telemetry signal, analyzes whether there are abnormal characteristics, if no abnormality is identified, analyzes the actual parameters of the power supply module to verify the characteristic identification result of the telemetry signal, determines whether to intercept the second type of data stream, effectively prevents potential security risks, improves the monitoring and analysis efficiency of data stream in power network, ensures the security and reliability of network traffic, discovers and responds to potential abnormalities or attacks in a timely manner, and enhances the network security protection capability of power system.
Owner:STATE GRID ZHEJIANG ELECTRIC POWER CO LTD NINGBO POWER SUPPLY CO

Tag-based selective packet duplication

Disclosed is technology for selectively determining whether to duplicate a packet based on factors beyond just the application it is associated with. For example, some methods determine a criticality of the packet by reading a tag stored in a header of the packet. The tag can represent a group to which the user is associated with, e.g., the financial department, and assign a criticality score based on that group and in some cases other factors. The criticality score can be measured against a threshold to determine whether duplication should occur in the next hop. The method therefore selectively determines whether to duplicate a packet, thereby avoiding costly overduplication, while also placing this tag in a header of the packet, which can be read easily and without deep packet inspection.
Owner:CISCO TECHNOLOGY INC

A data processing method, device, apparatus, and storage medium

ActiveCN116866066BData packOriginal data
The application discloses a data processing method and device, equipment and storage medium, relates to the technical field of deep packet inspection and data analysis, and comprises the following steps: defining a streaming label rule and a streaming index calculation rule based on an initialized anti-fraud identification model; filtering original data collected by using a deep packet inspection technology, and performing standardization processing on the filtered data; performing real-time index calculation on the standardized data according to the streaming index calculation rule; forwarding the standardized data to a risk calculation and analysis node, so that the risk calculation and analysis node performs real-time risk calculation by using index results corresponding to the standardized data to obtain risk information corresponding to user behaviors existing gambling and fraud risks, and outputs the risk information. The technical scheme of the application realizes second-level early warning of the user behaviors existing gambling and fraud risks, and improves the timeliness and accuracy of gambling and fraud data processing.
Owner:CHINA MOBILE(ZHEJIANG) RESEARCH & INNOVATION INSTITUTE

A power grid dispatching data dynamic perception and protection method based on a commercial secret algorithm

PendingCN122437681AData packData stream
The present application relates to the field of power grid dispatching data security, and more particularly to a power grid dispatching data dynamic perception and protection method based on a commercial secret algorithm. The method captures power grid dispatching network data streams in real time, obtains original service data containing dispatching instructions, measurement data and state information through protocol analysis and deep packet detection; then uses a dynamic data perception engine to identify sensitive data units, and dynamically generates data sensitivity labels according to the business type and the power grid operation state; dynamically matches commercial cryptographic algorithms from the commercial secret algorithm library according to the labels and distributes temporary session keys to generate an encryption strategy; encrypts the sensitive units, adds a security mark containing an algorithm identifier and a key index to the data packet header to form a protected data stream; sends the protected data stream to the target end, updates the session key state and uploads the execution log to the audit center. The present application realizes dynamic, accurate identification and differentiated encryption protection of power grid dispatching sensitive data.
Owner:HAINAN POWER GRID CO LTD

Data caching method and device and storage medium

The invention relates to the technical field of communication, and discloses a data caching method and device and a storage medium, the method comprises the following steps: copying a network flow which flows through a first electronic device and comprises a resource request and return data in real time, the resource request being a request sent by a user to an internet source station through a second electronic device via the first electronic device, the resource request is used for accessing a resource object of the Internet source station, and the return data is data of the resource object returned by the Internet source station to the second electronic equipment through the first electronic equipment based on the resource request; performing deep packet inspection (DPI) analysis on the network traffic to determine features of the network traffic; setting labels for the resource objects according to the features; determining a resource popularity value of the resource object according to the label and the weight corresponding to the label; determining a cache value score of the resource object according to the resource popularity value; and if the cache value score is greater than the current threshold, caching the resource object to a storage device. The utilization rate of the data cached by the storage device is improved.
Owner:BEIJING QIANHAI YANXIANG ELECTRONIC TECHNOLOGY CO LTD

Including packet processing data for deep packet inspection classification rules in a combined lookup table used for packet classification at a network device

Systems and methods for determining whether to perform deep packet inspection (DPI) on packets received at a network device based on shallow packet inspection data are disclosed. Embodiments may include DPI classification data in a combined lookup table that is utilized for shallow packet data based packet classification at a network device. Using the results of lookups in such a combined look table based on received packets, determinations can be made whether to perform DPI on such received packets, and those packets forwarded accordingly.
Owner:ARISTA NETWORKS INC

Modbus hold register process parameter dynamic extraction method and device based on deep packet inspection (DPI)

The invention discloses a modbus hold register process parameter dynamic extraction method and device based on deep packet inspection (DPI), and relates to the technical field of industrial automation communication, and the modbus hold register process parameter dynamic extraction device comprises a flow capture module, a message preprocessing module, a DPI deep analysis module, a parameter mapping and conversion module, an abnormity monitoring module, a data output module and a power supply module. The flow capturing module captures Modbus flow, the message preprocessing module achieves frame segmentation and CRC verification through an FPGA, the DPI deep analysis module filters key function codes and extracts original data, the parameter mapping and conversion module automatically converts the key function codes into actual parameters according to pre-configuration, the abnormity monitoring module achieves threshold and behavior warning, and the data output module supports multi-interface transmission. The device supports passive monitoring and active subscription modes, realizes non-intrusive, low-load and high-precision process parameter extraction, solves the problems that traditional acquisition depends on interfaces, polling is low in efficiency and conversion is easy to make mistakes, and is suitable for industrial automatic production scenes.
Owner:BEIJING CATHAY INTERNET INFORMATION TECH CO LTD

Data packet hierarchical detection method, system and electronic device

The application discloses a data packet hierarchical detection method, a system and an electronic device, wherein the hierarchical detection method is used when a data packet sent by a terminal or a data packet sent to the terminal is acquired; the current data packet detection level of the terminal is determined; when it is determined that the current data packet detection level of the terminal is a shallow layer detection, shallow layer detection is performed on the data packet; when it is determined that the current data packet detection level of the terminal is a middle layer detection, middle layer detection is performed on the data packet; and when it is determined that the current data packet detection level of the terminal is a deep layer detection, deep layer detection is performed on the data packet. The method can realize data packet detection with different depths according to the data packet detection levels corresponding to the terminals, effectively avoids the problems of high consumption and large delay caused by uniformly using deep packet detection, and is beneficial to improving network throughput, reducing operation and maintenance cost and reducing security policy configuration work.
Owner:SUZHOU MAXNET NETWORK SECURITY TECH CO LTD

Network security area boundary threat mimicry protection method and system

PendingCN121864349Atime-varyingBe differentiatedSecuring communicationNode clusteringPathPing
The invention provides a network security area boundary threat mimicry protection method and system, and relates to the technical field of network security, and the method comprises the steps: extracting a flow quintuple and load features through a deep packet inspection engine; inputting the quantity feature vector set into a graph neural network behavior pattern mining model, decoding to obtain an attacker target asset priority sequence and a potential attack path graph, and generating a dynamic service camouflage fingerprint matrix and a response bait sequence through parameter set mapping; configuration of a migration condition register is completed, and a programmable mimicry service node cluster is constructed; presetting a malicious request induction template in the response bait sequence, performing selective response delay and content tampering operation on an attacker request, and aggregating to generate an attacker tactical technology process feature chain; and driving the genetic algorithm population library to carry out iterative crossover variation to generate a new generation of protection strategy chromosomes. The attack residence time is obviously prolonged, the decoy success rate is improved, and the protection strategy can be automatically evolved according to the attack mode.
Owner:GUIZHOU POWER GRID CO LTD

Inference-based selective flow inspection

Techniques for augmenting deep packet inspection capabilities of a network security device provisioned in a networked computing environment with inference-based flow selection to focus processing resources on network traffic that is likely to be malicious. The network device(s) may receive decryption policies comprising one or more decrypt and / or do not decrypt rules for applying the decryption policy to the network traffic. The network device may receive network traffic associated with a given connection flow through the network between a client device and a workload application, and the network device may determine whether to decrypt or refrain from decrypting the network traffic associated with the network flow based on a risk score that is generated by the network device using connection fingerprints associated with the client device and the workload application, respectively, based on behavioral characteristics of the client device and the workload, respectively.
Owner:CISCO TECHNOLOGY INC

Systems and methods for wireless network management

Disclosed are computerized systems and methods for a decision intelligence (DI)-based framework that automatically and / or dynamically provides mechanisms for managing, optimizing and configuring a WiFi network at a location. The framework provides network management utilizing edge processing capabilities to bridge local WiFi and cloud systems. The framework implements comprehensive device typing through multi-layered analysis combining passive monitoring, deep packet inspection and hybrid deterministic-probabilistic classification methods. State synchronization between local and cloud networks can be achieved through hierarchical data modeling and differential synchronization algorithms. The framework can implement advanced features that include automated channel optimization, QoS management, and security monitoring. The framework incorporates self-healing capabilities using reinforcement learning techniques and maintains operational efficiency through intelligent resource management and workload distribution. The framework can operate autonomously while requiring minimal cloud connectivity, featuring extensible architecture through a plugin system that enables adaptation to evolving network requirements while maintaining stable operation of existing capabilities.
Owner:PLUME DESIGN INC

Full-domain traffic collection and auditing system and method based on deep packet inspection

The invention relates to the technical field of network communication, and discloses a global traffic collection and auditing system and method based on deep packet inspection, and the system comprises a traffic collection module, a deep packet inspection module, a traffic storage module, an auditing analysis module, a visual display module, a strategy management module, and a log recording module. The traffic acquisition module comprises a high-performance acquisition engine, and the traffic acquisition module, a deep packet detection module, a traffic storage module, an audit analysis module, a visual display module, a strategy management module and a log recording module are integrated, so that real-time acquisition, deep analysis and audit of global network traffic can be realized; the traffic monitoring and auditing method meets the traffic monitoring requirements in a large-scale network environment, has the advantages of high concurrent processing capability, deep traffic analysis, flexible auditing rules, efficient data storage and retrieval and visual display, and is suitable for traffic monitoring and auditing application in various network environments.
Owner:BENXI IRON & STEEL (GROUP) INFORMATION AUTOMATION CO LTD