Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

284 results about "Enterprise networking" patented technology

Enabling cellular based zero trust network access

PendingUS20250203367A1Security arrangementGeneric Bootstrapping ArchitectureInternet privacy
A method performed by a user equipment to establish a secured connection with an application entity in an enterprise network. The method comprises sending an establishment request to a secure access secure edge (SASE) entity: receiving an establishment response from the application entity if the SASE entity determines to allow the establishment request and authorizes Generic Bootstrapping Architecture / Authenticated Key Management for Application (GBA / AKMA) platform to share a session key with the application entity; and establishing a connection with the application entity based on the session key.
Owner:TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)

Automated prioritization of cyber risk mitigation by simulating exploits

Implementations include receiving graph data representative of a process-aware analytical attack graph (AAG) representing paths within an enterprise network with respect to observed facts of the enterprise network, the process-aware AAG at least partially defining a digital twin of the enterprise network, receiving data indicating at least one non-observed fact of the enterprise network, generating, from the graph data and the received data, an augmented process-aware AAG representing paths within the enterprise network with respect to the observed facts and the at least one non-observed fact, determining, by a process-aware risk assessment module, a risk assessment based on the augmented process-aware AAG, and providing, by a mitigation simulator module, a mitigation list based on the process-aware AAG and the risk assessment, the mitigation list comprising a prioritized list of observed facts of the process-aware AAG.
Owner:ACCENTURE GLOBAL SOLUTIONS LTD

Security Escrow System

Various aspects of the disclosure relate to enforcing dynamically updated network security policies in real-time (or upon an identified update) from multiple organizations and anonymously analyze computing system configuration information uploaded from third-party computing systems. An analysis engine monitors compliance information and compare the compliance information against the security rules and / or requirements for one or more enterprise networks. A visualization providing a network map with a visual representation of each product system service system may include communication links between internal applications and / or computing systems and drill-down capability to identify issues as they are occurring or are predicted to occur. The security escrow system may include a mechanism to automatically enable / disable access between third party networks and one or more enterprise computing systems in real-time based on identified compliance information.
Owner:BANK OF AMERICA CORP

Intelligent Attack Vector Analysis and Mitigation System

An intelligent attack vector analysis and mitigation system incorporates an intelligent process to analyze potential attack vectors from a suspicious attacker. The intelligent attack vector analysis and mitigation system leverages a generative artificial intelligence (AI)-enabled simulation environment to isolate and / or simulate attackers using federated identity and a hypermedia application programming interface (API). The system analyzes actual and / or potential attack vectors by leveraging the generative AI simulation and provides behavioral analysis with a specific focus on federated identity and / or hypermedia API components. As such, the system provides insights into novel attack vectors, vulnerabilities, and effective mitigation strategies that may then be automatically incorporated and / or implemented on the enterprise network by the intelligent attack vector analysis and mitigation system. The process utilizes continuous improvement, adaptation to evolving threats, and a holistic understanding of the system's security posture to improve and enable the enterprise organization's network security system.
Owner:BANK OF AMERICA CORP

Network information security dynamic early warning method and system based on knowledge graph

The invention discloses a network information security dynamic early warning method and system based on a knowledge graph, and relates to the technical field of network information security. According to the method, network equipment logs, threat intelligence texts and flow metadata are acquired in real time through a multi-source heterogeneous data acquisition module, and a dynamic knowledge graph is constructed by adopting a streaming knowledge extraction technology. And predicting a threat propagation path by using a graph attention network and gating loop unit hybrid model, and generating a hierarchical defense strategy in combination with a three-dimensional risk assessment value. The system comprises a multi-modal data acquisition module, a dynamic knowledge graph construction module, a threat propagation dynamics modeling module, a self-adaptive strategy generation module, a digital twinborn verification module and the like, and the effectiveness of a defense strategy is verified by simulating an attack path. According to the method, dynamic early warning and automatic response of network security are realized, the network protection capability is effectively improved, and the method is suitable for scenes such as enterprise network security protection and cloud service provider security protection.
Owner:SANYA UNIVERSITY

Artificial intelligence assistant for network services and management

An artificial intelligence assistant analyzes network observations to generate regular expressions using an artificial intelligence model for network automation management pipelines that identify and resolve network issues. A method includes obtaining at least one instruction and information about a plurality of enterprise network assets and configuration of an enterprise network that includes the plurality of enterprise network assets and generating at least one regular expression using an artificial intelligence model based on context description of the at least one instruction and the information about the plurality of enterprise network assets and the configuration of the enterprise network. The method further includes generating at least one solution for configuring at least one network asset of the plurality of enterprise network assets based on the at least one regular expression and providing the at least one solution to cause a configuration change in the at least one network asset.
Owner:CISCO TECHNOLOGY INC

System and method for midserver facilitation of mass scanning network traffic detection and analysis

A system and method that uses midservers located between an enterprise network and an external network to provide mass scanning network traffic detection and analysis capabilities for the enterprise network. The midserver may be loaded with configurations that allow it to operate as a mass scan event detector capable of detecting network sniffers, botnets, and malicious peer-to-peer connections which can lead to security vulnerabilities. In such configurations, midserver may receive and analyze network traffic to determine if the network traffic is suspicious based on heuristic and signature-based techniques, and then generate an appropriate response action which can be implemented to mitigate the risk.
Owner:QOMPLX INC

System and method of anomaly detection with configuration-related activity profiles

An anomaly detection system uses configuration-related activity profiles, generated in course of threat samples analysis in a secure testing environment, consisting of features of system events and system configurations of endpoints and shared network assets. Backup archives and activity monitors are used to collect system events and system configurations from corporate networks to analyze them with threat pattern databases including configuration-related activity profiles.
Owner:ACRONIS INT

Method to detect and prevent business email compromise (BEC) attacks associated with new employees

Techniques for an email-security detection system to analyze incoming emails for Business Email Comprise (BEC) attacks of targeted new email users in an enterprise based on peer models of email recipients in an enterprise and the conversation history of recipients. A method is disclosed that includes analyzing an incoming email and identifying one or more recipients of the incoming email in an enterprise network; analyzing contextual information in the incoming email for the email intent, and associating the email with a target recipient; applying a relational model associated with peers of the target recipient for detecting whether the incoming email is a business email compromise (BEC) attack directed to the target recipient; applying a relationship model of other recipients of the incoming email for detecting whether the BEC attack is associated with the target recipient; and determining, whether the incoming email is a BEC attack.
Owner:CISCO TECHNOLOGY INC

System and method for enterprise-wide data utilization tracking and risk reporting

A system and method for comprehensive data utilization and tracking comprising an ontological engine which in some embodiments is configured to create and curate various industry-specific ontologies which can be used to provide deeper context to an enterprise's network traffic and data transmission. The system and method further comprise a tagging and tracking engine configured to inspect network packets, apply a first tag associated with an authentication object, apply a second tag associated with an identified ontology, and track the tagged packets as they traverse the enterprise network, generating data utilization tracking information as the packets move through the network. A scoring engine may leverage the data utilization tracking information in combination with user entity and behavior data to compute a risk score associated with data utilization on the enterprise network.
Owner:QOMPLX INC

Enterprise network threat detection

In a threat management platform, a number of endpoints log events in an event data recorder. A local agent filters this data and feeds a filtered data stream to a central threat management facility. The central threat management facility can locally or globally tune filtering by local agents based on the current data stream, and can query local event data recorders for additional information where necessary or helpful in threat detection or forensic analysis. The central threat management facility also stores and deploys a number of security tools such as a web-based user interface supported by machine learning models to identify potential threats requiring human intervention and other models to provide human-readable context for evaluating potential threats.
Owner:SOPHOS LTD

Next gen zero trust network access (ZTNA) and virtual private network (VPN) including cloud secure access service edge (SASE)

Techniques for leveraging the MASQUE protocol to provide remote clients with full application access to private enterprise resources are described herein. One or more network nodes may be configured to execute a MASQUE proxy service to provide a remote client device with full access to an enterprise / private application resource executing on an application node and hosted in an enterprise / application network, behind the MASQUE proxy service. In some examples, the MASQUE proxy service may execute on a single proxy node hosted at an edge of a cloud network or at an edge of an enterprise network. Additionally, or alternatively, a first instance of the MASQUE proxy service may execute on a first proxy node hosted at an edge of a cloud network (e.g., an ingress proxy node) and a second instance of the MASQUE proxy service may execute on a second proxy node hosted at an edge of the enterprise network.
Owner:CISCO TECHNOLOGY INC

Training trusted users of an enterprise network for phishing attacks on a per-user basis

A user behavior training model is generated, using machine learning, from tracking a plurality of trusted users for interactions with respect to a plurality of monitored phishing e-mails. When a unique phishing attack is detected from an incoming email, a new campaign is initiated. A unique phishing attack email that is modified by the user behavior model is generated for each user. In particular, a first test phishing e-mail for a first user is modified based on interactions tracked for the first user and a second test phishing e-mail for a second user is modified based on interactions tracked for the second user. Based on responses to the plurality of test phishing emails, a plurality of custom training videos is generated. A first training video is modified based on a response from the first user and a second training video is modified based on a response from the second user.
Owner:FORTINET INC

Enterprise application management and migration on a web proxy

A computer-implemented method for management of an application on an enterprise network which accesses external networks via a web proxy. The method comprises obtaining enriched metadata concerning an application executed on the enterprise network, the enriched metadata including at least source code information and ownership information, identifying application traffic on the enterprise network based on proxy log data, source IP and destination URL, generating an access control list (ACL) based on the enriched metadata and identified application traffic, the ACL including a source address of the application and a list of allowed destination addresses, converting the ACL into a proxy policy that can be processed by a web proxy to permit access by the application to the destination addresses in the ACL, and establishing data communication between the application and an external network based on the proxy policy.
Owner:MORGAN STANLEY SERVICES GROUP INC

Artificial Intelligence Based Real-Time Security Escrow System

Various aspects of the disclosure relate to enforcing dynamically updated network security policies in real-time (or upon an identified update) from multiple organizations and anonymously analyze computing system configuration information uploaded from third-party computing systems. An analysis engine monitors compliance information and compare the compliance information against the security rules and / or requirements for one or more enterprise networks. A visualization providing a network map with a visual representation of each product system service system may include communication links between internal applications and / or computing systems and drill-down capability to identify issues as they are occurring or are predicted to occur. The security escrow system may include a mechanism to automatically enable / disable access between third party networks and one or more enterprise computing systems in real-time based on identified compliance information.
Owner:BANK OF AMERICA CORP

Incremental enrichment of threat data

A threat management facility receives data from a variety of sources such as compute instances within an enterprise network, cloud service providers supporting the enterprise network, and third-party data providers such as geolocation services. In order to facilitate prompt notification of potential risks, the threat management facility may incrementally update data for use in threat assessments as the data becomes available from these different sources, and create suitable alerts or notifications whenever the currently accumulated data provides an indication of threat meeting a predetermined threshold.
Owner:SOPHOS LTD

Multi Modal Application Segmentation Data Capture

Systems and methods include obtaining application data for a plurality of applications of an enterprise, wherein the application data relates to applications present in an enterprises network; obtaining log data for a plurality of users of an enterprise where the user data relates to usage of the plurality of applications by the plurality of users; determining i) app-segments that are groupings of application of the plurality of applications and ii) user-groups that are groupings of users of the plurality of users; and providing access policy of the plurality of applications based on the user-groups and the app-segments.
Owner:ZSCALER INC

Platform for managing threat data

A platform for managing threat data integrates threat data from a variety of sources including internal threat data from instrumented compute instances associated with an enterprise network and threat data from one or more independent, external resources. Threat assessments are incrementally revised as this threat data is asynchronously received from various sources, and a threat intervention container is automatically created and presented to an investigator when a composite threat score for one or more of the compute instances meets a predetermined threshold.
Owner:SOPHOS LTD

Network anomaly detection with graph attention network

A multi-instance learning and weakly supervised BGP anomaly detection framework is provided, that detects and analyzes significant statistical correlations across multiple data sources such as model driven telemetry (MDT), network messages, event data logs, and / or device configuration data for network topology. Specifically, methods are provided that involve obtaining, from a plurality of data sources, data related to operation or configuration of Border Gateway Protocol (BGP) in an enterprise network and extracting one or more BGP features based on at least one correlation among the data from the plurality of data sources. The methods further involve detecting one or more network anomalies by performing a weakly supervised machine learning of the one or more BGP features and providing information about the one or more network anomalies for performing one or more actions associated with the enterprise network.
Owner:CISCO TECHNOLOGY INC

Threat-informed adversary attack simulation

A dynamic adversary profile is generated for a simulated attack on components of the enterprise network by selecting a profile of at least one specific threat group. The simulated attack is based on historical attack data, threat intelligence feeds, and real-time monitoring of adversary profiles. One or more relevant adversary group profiles is selected. An attack pattern (e.g., an APT attack pattern) is simulated on the components by injecting data packets based on the specific threat group without malicious components of the specific threat group to test security defenses of the components. Logs are collected from the simulated attack pattern. Based on results of the simulated attack pattern, defenses to the simulated attack on components are measured. Optionally, a security action concerning at least one of the components to better protect against an actual attack.
Owner:FORTINET INC

Analytical attack graph abstraction for resource-efficiencies

Implementations include methods, systems, computer-readable storage medium for mitigating cyber security risk of an enterprise network. A method includes: receiving an initial analytic attack graph (AAG) that is representative of paths within the enterprise network with respect to at least one target asset, the initial AAG comprising nodes and edges between the nodes; identifying, from the nodes of the initial AAG, a plurality of node groups, each node group including two or more nodes having at least one common attribute; generating an abstract AAG from the initial AAG, the abstract AAG including at least one abstract node, wherein each node group of the initial AAG is represented by a respective abstract node of the abstract AAG; determining a set of remedial actions at least partially based on the abstract AAG; and executing remedial actions in the set of remedial actions to reduce a cyber security risk to the enterprise network.
Owner:ACCENTURE GLOBAL SOLUTIONS LTD

Multi-technology fusion network security health assessment method and system

The invention discloses a multi-technology fusion network security health assessment method and system, and the method comprises the steps: generating an activity index of an IP address; performing port detection on the IP address of which the activeness index is greater than a first threshold value through a configurable port scanning mode to obtain open port information; sending a service detection data packet to the open port; extracting a service type and a version number according to response information of the service detection data packet to obtain a service change frequency; calculating an asset dynamic score based on the activity index of the IP address and the service change frequency; dividing the IP addresses into stable assets and temporary assets according to the asset dynamic scores; a low-frequency depth detection mode is adopted for the stable assets, a high-frequency rapid detection mode is adopted for the temporary assets, and a detection result is obtained; inputting the detection result and the asset dynamic score into a risk assessment function for calculation to obtain a risk security value of each IP address; and generating an assessment report according to the security risk value. The method and the device are used for improving the accuracy of enterprise network security assessment.
Owner:BEIJING FULE TECH CO LTD

Applying security policies based on endpoint and user attributes

An example network access control system includes a memory storing one or more security policies for an enterprise network; and one or more processors coupled to the memory and configured to: receive a request to connect to the enterprise network from a client device of a user, in response to the receipt of the request, determine one or more user attributes associated with the user and one or more endpoint attributes of the client device, identify a security policy of the one or more security policies based on the one or more user attributes and the one or more endpoint attributes, and configure an access control module of a network device of the enterprise network in accordance with the security policy.
Owner:JUNIPER NETWORKS INC

AI Agent-assisted enterprise data analysis method and system

The invention discloses an AI Agent-assisted enterprise data analysis method and system, and relates to the technical field of data analysis, and the method comprises the steps: connecting an enterprise network switch, deploying an RS-485 management network, and deploying at least two AI Agent computing nodes at the edge side of the enterprise network switch; carrying out storage redundancy analysis to obtain a redundancy label matrix; establishing a distribution relationship; issuing a redundancy processing task according to the distribution relationship, and performing data processing to obtain a plurality of return data sets; and performing overlay storage on a metadatabase of the enterprise storage management center according to the plurality of return data sets. The technical problems that in the prior art, storage redundancy of an enterprise meta-database is difficult to recognize accurately, storage optimization after data processing is insufficient, and consequently enterprise data storage efficiency is low are solved, efficient redundancy processing and optimized storage of the meta-database of the enterprise storage management center are achieved, and the enterprise data storage efficiency is improved. And the technical effect of enterprise data storage efficiency is improved.
Owner:NANJING ICRODE INFORMATION TECHNOLOGY CO LTD

PON-based FTTR enterprise networking method and system

The invention belongs to the technical field of FTTR enterprise networking, and particularly relates to a PON-based FTTR enterprise networking method and system, a dynamic networking decision model is constructed, an optical line terminal OLT obtains networking demand information, generates networking configuration information and issues the networking configuration information to an optical network unit ONU through the PON, the terminal configuration information is subjected to multi-protocol fusion processing coding, and the terminal configuration information is subjected to multi-protocol fusion processing coding. The method comprises the following steps: establishing trusted communication connection based on a block chain to communicate with an optical network unit ONU, and monitoring data of a region in real time; and uploading the collected monitoring data to an optical line terminal OLT, constructing an enterprise network virtual model by the optical line terminal OLT by using a digital twinning technology, performing network optimization simulation in the virtual model according to the monitoring data to obtain an optimal optimization strategy, and issuing the optimal optimization strategy to an optical network unit ONU for execution. Through intelligent dynamic networking, the flexibility and adaptability of the system are improved, the deployment efficiency is improved based on SDN configuration management, and the network security is enhanced through multi-protocol fusion and intelligent issuing, resource utilization optimization and block chain-based trusted communication.
Owner:SICHUAN TIANYI COMHEART TELECOM

Providing dynamic user-behavior-aware policies in software defined wide area networks

This disclosure describes techniques and mechanisms for enabling and enforcing user behavior aware policies within an enterprise network. The techniques include receiving flow data and learning network traffic patterns and user behavior patterns of user(s) of the network. The techniques map user(s) to behavior group(s) based on forecast(s) and historical data of network conditions and / or user behavior patterns. The techniques monitor the flow data and dynamically re-map user(s) to new behavior group(s) based on real-time user behavior and / or real-time network conditions. Mapping(s) and / or updated mapping(s) and user behavior aware policies may be sent to edge device(s) for enforcement. The edge device(s) may dynamically prioritize a link, de-prioritize a link, block traffic, drop traffic etc. for user(s). The techniques may extend application aware and user aware routing policies to account for dynamic user behavior and network conditions, provide improved application experience and network utilization.
Owner:CISCO TECHNOLOGY INC

Automated cybersecurity vulnerability prioritization

Implementations include a computer-implemented method comprising: obtaining data representing observed conditions in an enterprise network, each observed condition being associated with at least one cybersecurity issue, a cybersecurity issue comprising one of (i) a vulnerability comprising an instance of a vulnerable condition or (ii) a weakness that is likely to cause a vulnerability to occur; using a plurality of exploitation prediction models to determine probabilities of exploitation of the cybersecurity issues associated with the observed conditions in the enterprise network, wherein the plurality of exploitation prediction models are trained using a knowledge mesh generated using data from cybersecurity repositories; assigning a priority ranking to each of the observed conditions in the enterprise network based on the respective probabilities of exploitation for the cybersecurity issues associated with the observed conditions; and performing one or more actions to mitigate the observed conditions in the enterprise network based on the priority rankings.
Owner:ACCENTURE GLOBAL SOLUTIONS LTD

Tracking, evaluating, and improving responses to malicious threats in a network security system

Disclosed are systems and methods for identifying threat events in an enterprise network and managing detection rules and responses to the events. A threat intelligence computer system can receive information about a detected threat event including a phase of attack and a detected domain of the threat event, apply at least one tag to the detected event that associates the event with at least one of the rules triggered in response to detecting the event, evaluate the tagged rules against the information, flag the event as having an improvement opportunity, determine whether the rule tagged to the event is a candidate for improvement, generate, based on the determination, instructions for improving the rule, generate a prioritization scheme indicating an order to address the instructions to improve the rule amongst instructions to improve various threat detection rules, and generate and return output indicating the prioritization scheme for presentation at user devices.
Owner:TARGET BRANDS INC

Enterprise risk data determination method and device, storage medium and electronic device

The invention discloses an enterprise risk data determination method and device, a storage medium and an electronic device, and the method comprises the steps: constructing an enterprise relation graph corresponding to an enterprise set according to the risk of each enterprise in the to-be-predicted enterprise set and the incidence relation between the enterprises, each enterprise serves as a node in the enterprise relation graph, and the nodes of the enterprises with the incidence relation are mutually connected; nodes with self risks larger than a first threshold value in the enterprise relation graph serve as risk nodes; respectively spreading the risk signal of the risk node to all non-risk nodes which are connected with the risk node and meet the spreading condition; and determining and updating the risk data of the non-risk node according to the risk data of the non-risk node and received risk signals transmitted by all risk nodes connected with the non-risk node. Accurate prediction of enterprise risks is realized by simulating diffusion of risk signals in an enterprise network.
Owner:CHINA CONSTRUCTION BANK +1