Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

195 results about "Enterprise networking" patented technology

Method to detect and prevent business email compromise (BEC) attacks associated with new employees

Techniques for an email-security detection system to analyze incoming emails for Business Email Comprise (BEC) attacks of targeted new email users in an enterprise based on peer models of email recipients in an enterprise and the conversation history of recipients. A method is disclosed that includes analyzing an incoming email and identifying one or more recipients of the incoming email in an enterprise network; analyzing contextual information in the incoming email for the email intent, and associating the email with a target recipient; applying a relational model associated with peers of the target recipient for detecting whether the incoming email is a business email compromise (BEC) attack directed to the target recipient; applying a relationship model of other recipients of the incoming email for detecting whether the BEC attack is associated with the target recipient; and determining, whether the incoming email is a BEC attack.
Owner:CISCO TECHNOLOGY INC

System and method for enterprise-wide data utilization tracking and risk reporting

A system and method for comprehensive data utilization and tracking comprising an ontological engine which in some embodiments is configured to create and curate various industry-specific ontologies which can be used to provide deeper context to an enterprise's network traffic and data transmission. The system and method further comprise a tagging and tracking engine configured to inspect network packets, apply a first tag associated with an authentication object, apply a second tag associated with an identified ontology, and track the tagged packets as they traverse the enterprise network, generating data utilization tracking information as the packets move through the network. A scoring engine may leverage the data utilization tracking information in combination with user entity and behavior data to compute a risk score associated with data utilization on the enterprise network.
Owner:QOMPLX INC

Enterprise network threat detection

In a threat management platform, a number of endpoints log events in an event data recorder. A local agent filters this data and feeds a filtered data stream to a central threat management facility. The central threat management facility can locally or globally tune filtering by local agents based on the current data stream, and can query local event data recorders for additional information where necessary or helpful in threat detection or forensic analysis. The central threat management facility also stores and deploys a number of security tools such as a web-based user interface supported by machine learning models to identify potential threats requiring human intervention and other models to provide human-readable context for evaluating potential threats.
Owner:SOPHOS LTD

Next gen zero trust network access (ZTNA) and virtual private network (VPN) including cloud secure access service edge (SASE)

Techniques for leveraging the MASQUE protocol to provide remote clients with full application access to private enterprise resources are described herein. One or more network nodes may be configured to execute a MASQUE proxy service to provide a remote client device with full access to an enterprise / private application resource executing on an application node and hosted in an enterprise / application network, behind the MASQUE proxy service. In some examples, the MASQUE proxy service may execute on a single proxy node hosted at an edge of a cloud network or at an edge of an enterprise network. Additionally, or alternatively, a first instance of the MASQUE proxy service may execute on a first proxy node hosted at an edge of a cloud network (e.g., an ingress proxy node) and a second instance of the MASQUE proxy service may execute on a second proxy node hosted at an edge of the enterprise network.
Owner:CISCO TECHNOLOGY INC

Training trusted users of an enterprise network for phishing attacks on a per-user basis

A user behavior training model is generated, using machine learning, from tracking a plurality of trusted users for interactions with respect to a plurality of monitored phishing e-mails. When a unique phishing attack is detected from an incoming email, a new campaign is initiated. A unique phishing attack email that is modified by the user behavior model is generated for each user. In particular, a first test phishing e-mail for a first user is modified based on interactions tracked for the first user and a second test phishing e-mail for a second user is modified based on interactions tracked for the second user. Based on responses to the plurality of test phishing emails, a plurality of custom training videos is generated. A first training video is modified based on a response from the first user and a second training video is modified based on a response from the second user.
Owner:FORTINET INC

Incremental enrichment of threat data

A threat management facility receives data from a variety of sources such as compute instances within an enterprise network, cloud service providers supporting the enterprise network, and third-party data providers such as geolocation services. In order to facilitate prompt notification of potential risks, the threat management facility may incrementally update data for use in threat assessments as the data becomes available from these different sources, and create suitable alerts or notifications whenever the currently accumulated data provides an indication of threat meeting a predetermined threshold.
Owner:SOPHOS LTD

Platform for managing threat data

A platform for managing threat data integrates threat data from a variety of sources including internal threat data from instrumented compute instances associated with an enterprise network and threat data from one or more independent, external resources. Threat assessments are incrementally revised as this threat data is asynchronously received from various sources, and a threat intervention container is automatically created and presented to an investigator when a composite threat score for one or more of the compute instances meets a predetermined threshold.
Owner:SOPHOS LTD

Threat-informed adversary attack simulation

PendingUS20250310351A1Securing communicationData packAdversary
A dynamic adversary profile is generated for a simulated attack on components of the enterprise network by selecting a profile of at least one specific threat group. The simulated attack is based on historical attack data, threat intelligence feeds, and real-time monitoring of adversary profiles. One or more relevant adversary group profiles is selected. An attack pattern (e.g., an APT attack pattern) is simulated on the components by injecting data packets based on the specific threat group without malicious components of the specific threat group to test security defenses of the components. Logs are collected from the simulated attack pattern. Based on results of the simulated attack pattern, defenses to the simulated attack on components are measured. Optionally, a security action concerning at least one of the components to better protect against an actual attack.
Owner:FORTINET INC

Analytical attack graph abstraction for resource-efficiencies

Implementations include methods, systems, computer-readable storage medium for mitigating cyber security risk of an enterprise network. A method includes: receiving an initial analytic attack graph (AAG) that is representative of paths within the enterprise network with respect to at least one target asset, the initial AAG comprising nodes and edges between the nodes; identifying, from the nodes of the initial AAG, a plurality of node groups, each node group including two or more nodes having at least one common attribute; generating an abstract AAG from the initial AAG, the abstract AAG including at least one abstract node, wherein each node group of the initial AAG is represented by a respective abstract node of the abstract AAG; determining a set of remedial actions at least partially based on the abstract AAG; and executing remedial actions in the set of remedial actions to reduce a cyber security risk to the enterprise network.
Owner:ACCENTURE GLOBAL SOLUTIONS LTD

Applying security policies based on endpoint and user attributes

An example network access control system includes a memory storing one or more security policies for an enterprise network; and one or more processors coupled to the memory and configured to: receive a request to connect to the enterprise network from a client device of a user, in response to the receipt of the request, determine one or more user attributes associated with the user and one or more endpoint attributes of the client device, identify a security policy of the one or more security policies based on the one or more user attributes and the one or more endpoint attributes, and configure an access control module of a network device of the enterprise network in accordance with the security policy.
Owner:JUNIPER NETWORKS INC

AI Agent-assisted enterprise data analysis method and system

The invention discloses an AI Agent-assisted enterprise data analysis method and system, and relates to the technical field of data analysis, and the method comprises the steps: connecting an enterprise network switch, deploying an RS-485 management network, and deploying at least two AI Agent computing nodes at the edge side of the enterprise network switch; carrying out storage redundancy analysis to obtain a redundancy label matrix; establishing a distribution relationship; issuing a redundancy processing task according to the distribution relationship, and performing data processing to obtain a plurality of return data sets; and performing overlay storage on a metadatabase of the enterprise storage management center according to the plurality of return data sets. The technical problems that in the prior art, storage redundancy of an enterprise meta-database is difficult to recognize accurately, storage optimization after data processing is insufficient, and consequently enterprise data storage efficiency is low are solved, efficient redundancy processing and optimized storage of the meta-database of the enterprise storage management center are achieved, and the enterprise data storage efficiency is improved. And the technical effect of enterprise data storage efficiency is improved.
Owner:NANJING ICRODE INFORMATION TECHNOLOGY CO LTD

Providing dynamic user-behavior-aware policies in software defined wide area networks

This disclosure describes techniques and mechanisms for enabling and enforcing user behavior aware policies within an enterprise network. The techniques include receiving flow data and learning network traffic patterns and user behavior patterns of user(s) of the network. The techniques map user(s) to behavior group(s) based on forecast(s) and historical data of network conditions and / or user behavior patterns. The techniques monitor the flow data and dynamically re-map user(s) to new behavior group(s) based on real-time user behavior and / or real-time network conditions. Mapping(s) and / or updated mapping(s) and user behavior aware policies may be sent to edge device(s) for enforcement. The edge device(s) may dynamically prioritize a link, de-prioritize a link, block traffic, drop traffic etc. for user(s). The techniques may extend application aware and user aware routing policies to account for dynamic user behavior and network conditions, provide improved application experience and network utilization.
Owner:CISCO TECHNOLOGY INC

Automated cybersecurity vulnerability prioritization

Implementations include a computer-implemented method comprising: obtaining data representing observed conditions in an enterprise network, each observed condition being associated with at least one cybersecurity issue, a cybersecurity issue comprising one of (i) a vulnerability comprising an instance of a vulnerable condition or (ii) a weakness that is likely to cause a vulnerability to occur; using a plurality of exploitation prediction models to determine probabilities of exploitation of the cybersecurity issues associated with the observed conditions in the enterprise network, wherein the plurality of exploitation prediction models are trained using a knowledge mesh generated using data from cybersecurity repositories; assigning a priority ranking to each of the observed conditions in the enterprise network based on the respective probabilities of exploitation for the cybersecurity issues associated with the observed conditions; and performing one or more actions to mitigate the observed conditions in the enterprise network based on the priority rankings.
Owner:ACCENTURE GLOBAL SOLUTIONS LTD

Tracking, evaluating, and improving responses to malicious threats in a network security system

Disclosed are systems and methods for identifying threat events in an enterprise network and managing detection rules and responses to the events. A threat intelligence computer system can receive information about a detected threat event including a phase of attack and a detected domain of the threat event, apply at least one tag to the detected event that associates the event with at least one of the rules triggered in response to detecting the event, evaluate the tagged rules against the information, flag the event as having an improvement opportunity, determine whether the rule tagged to the event is a candidate for improvement, generate, based on the determination, instructions for improving the rule, generate a prioritization scheme indicating an order to address the instructions to improve the rule amongst instructions to improve various threat detection rules, and generate and return output indicating the prioritization scheme for presentation at user devices.
Owner:TARGET BRANDS INC

Enterprise risk data determination method and device, storage medium and electronic device

The invention discloses an enterprise risk data determination method and device, a storage medium and an electronic device, and the method comprises the steps: constructing an enterprise relation graph corresponding to an enterprise set according to the risk of each enterprise in the to-be-predicted enterprise set and the incidence relation between the enterprises, each enterprise serves as a node in the enterprise relation graph, and the nodes of the enterprises with the incidence relation are mutually connected; nodes with self risks larger than a first threshold value in the enterprise relation graph serve as risk nodes; respectively spreading the risk signal of the risk node to all non-risk nodes which are connected with the risk node and meet the spreading condition; and determining and updating the risk data of the non-risk node according to the risk data of the non-risk node and received risk signals transmitted by all risk nodes connected with the non-risk node. Accurate prediction of enterprise risks is realized by simulating diffusion of risk signals in an enterprise network.
Owner:CHINA CONSTRUCTION BANK +1

Centralized management cloud connecting multiple enterprise networks

This disclosure provides systems, methods and apparatus, including computer programs encoded on computer storage media, for centralized management cloud connecting multiple enterprise networks. A network agent may be deployed within a private cellular network and act as an interface between the node(s) of the private cellular network and a cloud network controller. The network agent may obtain a local-based request to initiate a cloud-based procedure associated with network parameter(s), the network parameter(s) being associated with cloud network credential(s) that correspond to the private cellular network. The network agent may output a cloud-based request to the cloud network controller to initiate the cloud-based procedure. The cloud-based request may indicate at least a portion of the network parameter(s) and omit at least a portion of local credential(s) of the private cellular network. The cloud-based request may hide the cloud network credentials of the private cellular network from the cloud network controller.
Owner:QUALCOMM INC

Enterprise-level intelligent point inspection identification and analysis system based on graph neural network

The invention discloses an enterprise-level intelligent point inspection identification and analysis system based on a graph neural network, and the system comprises a point inspection standard management module which is used for building a point inspection standard library and a unified coding system, and generating a point inspection route; the inspection task generation and execution module is used for generating a periodic point inspection task set; the data uploading and analyzing module is used for uploading the inspection data to a server through an enterprise network to form a trend sequence; the graph structure construction module is used for constructing an inspection network graph and forming an inspection feature set; the graph neural network analysis module is used for calculating an equipment health score and an abnormal confidence coefficient by improving a MixHop model; the abnormity identification and work order management module is used for triggering early warning notification and assessment index updating according to a preset rule; and the data synchronization and report generation module is used for generating a statistical report and an audit log, so that standardized, networked and intelligent management of enterprise-level polling is realized.
Owner:AVIC HIGH-TECH (BEIJING) TECHNOLOGY CO LTD

Enterprise information security defense strategy generation method based on adaptive rule engine

The invention discloses an enterprise information security defense strategy generation method based on an adaptive rule engine, and relates to the technical field of network and information security, and the method comprises the steps: carrying out the multi-dimensional feature vectorization processing of real-time security event data, and generating a threat feature vector set; based on the threat feature vector set, constructing a dynamic threat model, calculating a risk assessment score of each threat feature vector, and performing clustering analysis on the threat feature vectors to generate a threat scene classification result and a threat level identifier; inputting the threat scene classification result into an adaptive rule engine to generate an initial defense rule set, and correcting the rule priority of the initial defense rule set in real time through a rule weight dynamic adjustment mechanism to form an adaptive defense rule set; and generating a hierarchical enterprise information security defense strategy according to the self-adaptive defense rule set, and sending the hierarchical enterprise information security defense strategy to an enterprise network. According to the method, the dynamic adaptation capability of defense rules and the hierarchical accuracy of strategy deployment are ensured.
Owner:NANJING CHAOS INTERNET OF THINGS TECH CO LTD

Load balancing secure network traffic

Techniques for load balancing secure network traffic are disclosed. A system, process, and / or computer program product for load balancing secure network traffic includes monitoring network traffic for one branch of a plurality of branches for an enterprise network, and splitting the network traffic of the one branch into a plurality of network segments based on a determination that the network traffic exceeds traffic capacity of at least one security processing node (SPN) of a plurality of SPNs using a network load balancer (NLB) in communication with a plurality of Network Processing Nodes (NPNs), the plurality of monitored branches being distributed to the plurality of SPNs via a plurality of tunnels.
Owner:PALO ALTO NETWORKS INC

Security integration for cloud services

A threat management facility for an enterprise network integrates native threat management capabilities with threat data from a cloud service provider used by the enterprise. By properly authenticating to the cloud service and mapping data feeds from the cloud service to a native threat management environment, the threat management facility can extend threat detection and management capabilities beyond endpoint-centric techniques.
Owner:SOPHOS LTD

Managed detection and response system and method based on endpoints

A managed detection and response system includes an enterprise network including a plurality of endpoints in which an endpoint agent is installed or not installed to detect and block malware through a machine learning algorithm and a plurality of network security solutions for applying a predetermined security policy to the plurality of endpoints, a threat analysis server configured to generate an IOC by analyzing the detected and blocked malware in any one of the plurality of endpoints and establish the security policy according to the generated IOC to be linked with a corresponding network security solution of the plurality of network security solutions, and a cloud server that connects the enterprise network and the threat analysis server.
Owner:PAGO NETWORKS INC

Dynamic network access control system under zero-trust architecture

The invention discloses a dynamic network access control system under a zero-trust architecture, which relates to the technical field of network security, and comprises a multi-dimensional trust evaluation module, a self-adaptive micro-segmentation engine, a strategy decision execution module and a risk perception feedback module, the multi-dimensional trust evaluation module calculates a comprehensive trust score based on five-dimensional features of identity, equipment, network, application and data; the self-adaptive micro-segmentation engine dynamically generates network micro-segments based on a graph diffusion algorithm; the strategy decision execution module adopts deep reinforcement learning to generate an access decision; the risk perception feedback module identifies abnormity based on the LSTM network and adjusts trust parameters through closed-loop feedback, the four modules are deeply coupled and cooperated, refined dynamic access control is realized, the occurrence rate of security events is reduced by more than 85%, and an innovative solution is provided for enterprise network security.
Owner:INFORMATION CENT OF YELLOW RIVER WATER RESOURCES COMMISSION

Inline detect and block relayed DNS tunneling traffic

The present application discloses a method, system, and computer system for detecting DNS tunneling traffic. The method includes (i) obtaining non-DNS network traffic across an enterprise network, (ii) obtaining a hostname comprised in the non-DNS network traffic, (iii) querying a security service for a Domain Name System (DNS) tunneling attack verdict based at least in part on the hostname, (iv) determining whether the non-DNS network traffic is malicious traffic based at least in part on the DNS tunneling attack verdict, and (v) handling the non-DNS network traffic based at least in part on a determination of whether the non-DNS network traffic is malicious traffic based at least in part on the DNS tunneling attack verdict.
Owner:PALO ALTO NETWORKS INC

Systems and methods for artificial intelligence-based security policy development

A method includes receiving, from an enterprise network, data associated with one or more industrial automation systems operated by an enterprise, wherein the data includes design artifacts of the one or more industrial automation systems, run time data collected from the one or more industrial automation systems, or both, inputting the data to a machine learning-based security policy development engine to generate a set of recommended security policies for the enterprise based on the data, receiving the set of recommended security policies for the one or more industrial automation systems output by the security policy development engine, wherein the set of recommended security policies define access, use, or both, of the one or more industrial automation systems operated by the enterprise; and transmitting the set of recommended security policies to the enterprise.
Owner:ROCKWELL AUTOMATION TECH INC

Load balancing secure network traffic

Techniques for load balancing secure network traffic are disclosed. A system, process, and / or computer program product for load balancing secure network traffic includes monitoring network traffic for one branch of a plurality of branches for an enterprise network, and splitting the network traffic of the one branch into a plurality of network segments based on a determination that the network traffic exceeds traffic capacity of at least one security processing node (SPN) of a plurality of SPNs using a network load balancer (NLB) in communication with a plurality of Network Processing Nodes (NPNs), the plurality of monitored branches being distributed to the plurality of SPNs via a plurality of tunnels.
Owner:PALO ALTO NETWORKS INC

Vulnerability scoring based on organization-specific metrics

In one example, a non-transitory computer-readable storage medium stores executable program instructions that detect, at a remote device node, vulnerability data associated with an exploitable vulnerability of a target enterprise network; retrieve, by a first local device node, the vulnerability data, which may include a CVSS score, determine, by a second local device node, a vulnerability score VT by determining a first subscore VT1, where the first subscore VT1 is based on a Maximized Confidentiality Impact (MCI) metric that is a modified privacy metric to capture the privacy impact of the exploitable vulnerability, where the first subscore VT1 is also based on a Maximized Highest Impact (MHI) metric to capture reputation damage based on an outsized single impact attribute, and on a Modified Confidentiality (MC) metric, Modified Integrity (MI) metric and Modified Availability (MA) as provided by CVSS; and remediate the exploitable vulnerability based on the vulnerability score VT.
Owner:JPMORGAN CHASE BANK NA

Accelerated detection of spear phishing during email malware detection on enterprise networks

PendingUS20260006073A1Securing communicationSpear phishingAttack
Emails suspected to include a spear phishing attack are identified from the stream of incoming emails using a Related Anomaly Score (RAS). The RAS is calculated by identifying feature vectors from the stream of incoming emails associated with a sender of the email and a link of the email. The suspicious spear phishing emails are mapped by feature vectors and prioritizing according to map position. For reliability, in one case, relative distances are calculated between suspicious emails, and if a relative distance between the specific email and prioritized suspicious emails exceeds a predetermined distance threshold, take a security action based on spear phishing rules on the filtered highest suspicious emails, and if the relative distance does not exceed the predetermined distance threshold, take a second security action including forwarding the specific email for standard phishing analysis.
Owner:FORTINET INC

Method for detecting authenticity of network public opinion of platform enterprise based on time sequence knowledge graph

The application discloses a platform enterprise network public opinion authenticity detection method based on a time sequence knowledge graph. The platform enterprise network public opinion authenticity detection method comprises the following steps: splitting a platform enterprise time sequence knowledge graph into multiple static knowledge graphs connected in series in a time dimension; performing vectorization processing on the multiple static knowledge graphs; obtaining a to-be-detected public opinion text, and constructing a to-be-detected time sequence knowledge graph; splitting the to-be-detected time sequence knowledge graph into at least one to-be-detected static knowledge graph connected in series in the time dimension; performing vectorization processing on the at least one to-be-detected static knowledge graph, and constructing a to-be-detected public opinion time sequence knowledge graph vector; obtaining a subgraph similar in semantics to the to-be-detected public opinion time sequence knowledge graph vector from the platform enterprise time sequence knowledge graph vector, and determining the authenticity of the to-be-detected public opinion text according to the similarity degree of the subgraph and the to-be-detected public opinion time sequence knowledge graph vector. The application improves the accuracy of the determination and effectively reduces the calculation cost.
Owner:CHINA ACADEMY OF ELECTRONICS AND INFORMATION TECHNOLOGY OF CHINA ELECTRONICS TECHNOLOGY GROUP CORPORATION

Dynamic generation of a capacity-based provisioning for enterprise architectures

This disclosure relates to systems and methods for generating enterprise architectures for enterprise networks. As an example, one method may include: receiving historical information from multiple enterprise networks, the historical information including information about the enterprise architecture of each enterprise network; analyzing the historical information from the multiple enterprise networks to generate a network health score for each enterprise network; training a machine learning model using multiple machine learning algorithms based on the historical information and the network health scores of each enterprise network; and using the machine learning model to generate an enterprise architecture for a first enterprise network, which is either a new enterprise network or an existing enterprise network among the multiple enterprise networks.
Owner:EXTREME NETWORKS INC