Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

471 results about "Internet traffic" patented technology

Internet traffic is the flow of data within the entire Internet, or in certain network links of its constituent networks. Common measurements of traffic are total volume, in units of multiples of the byte, or as transmission rates in bytes per certain time units.

Agentless Workload Vulnerability Scanning

PendingUS20260149730A1Securing communicationRisk exposureOperational system
Systems and methods provide agentless security assessment for workloads and cloud posture control across multi-cloud environments. Discovery modules are configured with collection intervals to ingest posture control data including assets, identities, configurations, activities, network flows, and build-time artifacts. A multi-cloud configuration inventory maintains current and historical states and produces misconfiguration and identity-activity findings. For workload vulnerability evaluation, an external snapshot manager obtains point-in-time root-disk state without installing an in-workload agent. A file system data processor derives operating system and package metadata, and a detector matches the metadata against a vulnerability feed refreshed on a recurring basis to identify vulnerabilities. Identified vulnerabilities are correlated with misconfiguration and activity findings to generate prioritized risk exposures. Results are stored per workload and presented through graphical user interfaces that display risk levels, timelines, alerts, and guided remediation, enabling continuous, low-overhead security coverage for cloud workloads and configurations.
Owner:ZSCALER INC

Distributed denial of service (DDOS) based accelerated solution

Apparatuses, systems, and techniques for detecting distributed denial of service (DDoS) attacks are described. A system includes a plurality of switches in a monitored data center, each switch comprising network monitoring logic to sample network packets and generate flow records representing behavior of network traffic. A dataflow collector receives the flow records from the plurality of switches. A streaming pipeline coupled to the dataflow collector processes the flow records. A data store stores the flow records processed by the streaming pipeline. A trainer accesses the flow records in the data store and trains one or more machine learning (ML) models to detect DDoS attacks based on the flow records. At least one of the one or more ML models is deployable to at least one switch of the plurality of switches to determine whether a host device coupled to the at least one switch is subject to a DDoS attack.
Owner:MELLANOX TECHNOLOGIES LTD(IL)

Auditing access control lists of a network infrastructure

Systems and methods for auditing access control lists (ACLs) of a network infrastructure are provided. A plurality of network interfaces associated with a specified entity is identified. A plurality of access control lists (ACLs) is received. Each ACL of the plurality of ACL includes a plurality of rules associated with a respective network interface of the plurality of network interfaces. Network traffic metadata associated with the plurality of network interfaces is received. A corresponding set of rule utilization parameters is identified for each rule of the plurality of rules by matching the network traffic metadata to the plurality of rules.
Owner:GOOGLE LLC

A Lightweight Vehicle Network Intrusion Detection System and Method Based on Parallel CNN-Mamba Fusion Network

This invention discloses a lightweight vehicle network intrusion detection system and method based on a parallel CNN-Mamba fusion network. The system includes a data receiving module, a data preprocessing module, a pseudo-color image construction module for mapping network traffic data into a three-channel pseudo-color image and scaling it, and a parallel dual-branch network composed of a CNN spatial branch and a Mamba sequence branch for averaging and fusing the outputs of the parallel dual-branch network to output the final detection category. The CNN spatial branch is used to extract local texture patterns and cross-feature coupling relationships, and the Mamba sequence branch is used to extract long-distance dependent features. When facing the CICIDS2018 11-class fine-grained multi-class classification task, the system can still stably distinguish between normal traffic and various attack types under the conditions of extremely imbalanced classes and scarce minority class samples, and has good engineering application value.
Owner:CHANGCHUN UNIV

A method for security threat perception and detection of global network devices

ActiveCN121841825BInternet trafficAttack
This invention discloses a security threat perception and detection method for global network devices. It simultaneously collects three types of data: network traffic, behavior logs, and attack characteristics, forming multi-dimensional factual evidence. The method utilizes a firework algorithm to optimize the deployment of logical monitoring points (feature nodes) in the virtual network and calculates the dynamic intensity of threat propagation at each point, thereby constructing a node-level threat field that quantifies the spatial distribution of threats. Subsequently, peak, mean, and dispersion indicators are extracted, and behavioral load, threat polarization, and cumulative threat indicators are calculated from the raw data, forming a six-dimensional vector. This vector is input into a pre-trained global threat level classification model, outputting a discrete threat level. Finally, based on this level, firewall rules, intrusion detection feature libraries, and other protection strategies are dynamically adjusted to achieve automatic matching of security configuration and threat posture.
Owner:BEIJING SHANGZHANG INFORMATION TECHNOLOGY CO LTD

Network traffic detection method, device, storage medium and program product

Embodiments of the present application provide a network traffic detection method, device, storage medium and program product, the method comprising: performing semantic coding processing on network traffic data to obtain a first feature vector, the network traffic data comprising payload data; performing redundant feature screening and feature dimension reduction processing on the first feature vector to obtain a feature subset of the first feature vector; obtaining a local correlation feature matrix and a multi-scale feature matrix of the feature subset, wherein the local correlation feature matrix is used to represent the correlation between local features of the feature subset, and the multi-scale feature matrix is used to represent the correlation between local features of the feature subset at different scales; performing fusion processing on the local correlation feature matrix and the multi-scale feature matrix to obtain a fused feature matrix, and determining the category of the network traffic data according to the fused feature matrix.
Owner:CHINA MOBILE ZIJIN INNOVATION INST CO LTD +3

Network traffic map data processing method and system for digital services

The embodiment of the application provides a network traffic map data processing method and system applied to digital services, determines a target network traffic map sequence and a network behavior mining node sequence corresponding to each target network traffic map in the target network traffic map sequence, obtains an initial node change instruction corresponding to the target network traffic map sequence, determines a changed network traffic map sequence corresponding to the target network traffic map sequence according to the initial node change instruction, obtains a first model scheduling distinguishing parameter corresponding to the changed network traffic map sequence, obtains a second model scheduling distinguishing parameter corresponding to the changed network traffic map sequence, determines a target change instruction according to the first model scheduling distinguishing parameter and the second model scheduling distinguishing parameter corresponding to each initial node change instruction, and changes the network behavior mining node in the target network traffic map sequence according to the target change instruction, thereby improving the feature mining reliability of the network traffic map.
Owner:HANGYIN CONSUMER FINANCE CO LTD

An intelligent detection method for network abnormal behavior

This invention proposes an intelligent method for detecting abnormal network behavior, including acquiring target network traffic data, constructing a multi-dimensional feature fusion model based on an attention mechanism, and building an abnormal behavior classification model based on deep learning. By automatically allocating attention to different network traffic features through the attention mechanism, it solves the problems of unreasonable feature weight allocation and insufficient feature fusion in traditional methods, significantly improving the detection capability for low-frequency and covert abnormal behaviors and effectively reducing false positive and false negative rates. The classification model employs a hybrid CNN and LSTM structure, taking into account both the local spatial and temporal features of network traffic, and can accurately identify various types of abnormal network behaviors such as DDoS attacks, port scanning, SQL injection, and malicious code propagation, adapting to diverse attack scenarios with high classification accuracy.
Owner:SHIJIAZHUANG ANJIE FUTURE TECHNOLOGY CO LTD

A network attack defense method, device, intrusion detection equipment, and storage medium.

This application provides a network attack defense method, apparatus, intrusion detection device, and storage medium. Applied to an intrusion detection device, the device maintains multiple attack rules, each labeled with an attack chain tag. The attack chain tag indicates the attack chain to which the attack rule belongs. The method includes: performing intrusion detection on network traffic to determine a first attack rule that the network traffic has hit; the first attack rule is labeled with a target attack chain tag; querying at least one second attack rule labeled with the target attack chain tag from the multiple attack rules; sending the first and second attack rules belonging to the same attack chain to a firewall, so that the firewall performs attack defense according to a protection policy; the protection policy is generated based on the first and second attack rules. The firewall can also perform pre-defense against subsequent attack behaviors based on the attack rules associated with the attack chain, thereby improving the firewall's defense effectiveness.
Owner:BEIJING TOPSEC NETWORK SECURITY TECH +2

BGP anomalous route identification method and apparatus, device and medium

PCT designated stageWO2026103459A1TransmissionPathPingInternet traffic
Disclosed in the present application are a BGP anomalous route identification method and apparatus, a device and a medium. The method comprises: acquiring from a border router of each AS a plurality of pieces of network traffic data and a plurality of route update messages whose AS paths have a target AS as the origin AS within a current time period; on the basis of route announcement data or route withdrawal data of each route update message, determining an anomalous IP prefix and a normal IP prefix of the target AS; on the basis of a destination IP address of each piece of network traffic data, the anomalous IP prefix and the normal IP prefix, determining indicator data of the anomalous IP prefix and indicator data of the normal IP prefix within the current time period; on the basis of the indicator data of the anomalous IP prefix and the indicator data of the normal IP prefix within the current time period, determining a degree of anomaly impact; and, on the basis of the degree of anomaly impact and a set threshold, determining whether an anomalous route is present in the target AS within the current time period. The method can improve the accuracy of identifying BGP anomalous routes.
Owner:CHINA TELECOM NETWORK SECURITY TECH CO LTD

Method and system for automating management of network traffic at network functions

The present disclosure relates to a method [400] and system [300] for automating management of network traffic at one or more network functions in a network. The method [400] comprises identifying, by a processing unit at a node, the one or more network functions from a plurality of network functions. Further, the method [400] comprises establishing, by a transceiver unit at the node, a network connection between the node and the identified one or more network functions. The method [400] further comprises selecting, by the processing unit at the node, an interface based on the established network connection. Also, the method [400] comprises triggering, by the processing unit at the node, via the selected interface, at the one or more network functions, an automation task remotely. Furthermore, the method [400] comprises performing, by the processing unit at the node, a sanity check associated with the automation task, on the one or more network functions.
Owner:JIO PLATFORMS LTD

An APT traffic detection method based on a knowledge graph

ActiveCN115694933BData streamInternet traffic
The application discloses an APT flow detection method based on a knowledge graph, which comprises the following steps: analyzing network data flow characteristics in network flow, establishing a knowledge graph of network data flow, and classifying the established network flow knowledge graph by using a graph neural network algorithm to detect APT attack flow in the network, so that the attack behavior of an APT organization can be detected from the network level. The application can detect unknown APT attack network data flow, and is helpful for flexibly and accurately detecting APT flow.
Owner:ZHEJIANG UNIV

Terminal-side load balancing system, method and apparatus based on energy storage device

This invention provides a terminal-side load balancing system, method, and apparatus based on energy storage devices. The system includes: a signal conversion module for converting digital traffic signals representing network traffic received from a base station by a communication module into analog traffic signals; a memristor detection circuit connected between the signal conversion module and ground for detecting current changes corresponding to the analog traffic signals to generate feedback signals reflecting network traffic volume; and a main control chip for calculating real-time network bandwidth based on the feedback signals and comparing the real-time network bandwidth with a preset threshold. When the main control chip detects that the real-time network bandwidth is lower than the preset threshold, it generates a load balancing feedback command and reports it to the operator's network side via the communication module to trigger network-side load balancing operations. This achieves high-precision network traffic detection at the terminal side and can proactively trigger network-side load balancing based on the detection results.
Owner:SHENZHEN NANHE MOBILE COMM TECH CO LTD

Systems and methods for filtering traffic

Systems and methods for network communication degradation are disclosed. The system includes one or more processors configured to monitor network traffic associated with one or more devices to identify communication patterns. Upon detecting a predefined communication pattern in the monitored network traffic, the system generates a blocking event configured to degrade the network traffic associated with a specific application or service. The system implements the blocking event by instructing one or more network components to degrade the network traffic related to the specific application or service. This degradation reduces communication quality over a predefined temporal period.
Owner:INFOBIP LTD

A flow-aware intelligent network interface card optimization system and method

The application discloses a kind of based on flow perception intelligent network interface card optimization system and method, it belongs to computer network technical field.The optimization system of the application includes flow perception module, flow prediction module, resource scheduling module, priority queue module and load balancing module.The application introduces resource monitoring, flow perception, resource prediction and dynamic scheduling module, real-time monitoring network flow and predicting its change trend, according to flow mode dynamically adjusts resource allocation.The application effectively solves the problem of resource contention, through priority ordering and load balancing, ensure the stable operation of high priority task, improve the throughput and stability of system, reduce resource waste.The application is suitable for resource management of intelligent network interface card in data center and cloud computing environment, improves network processing efficiency and resource utilization, guarantees service quality, reduces resource waste, and enhances the adaptive capacity of system to dynamic load and complex flow mode.
Owner:HARBIN INST OF TECH AT WEIHAI

A Multi-Dimensional Fusion Network Protocol Identification Method Based on Traffic Features

PendingCN122316782AInternet trafficEngineering
This invention discloses a multi-dimensional fusion network protocol identification method based on traffic features, belonging to the field of network security technology. It comprises four steps: probe-based traffic acquisition and session reassembly, multi-level fusion feature extraction and standardization, protocol classification and reasoning based on XGBoost ensemble learning, and multi-session aggregation recommendation output based on IP:PORT granularity. Addressing the application layer protocol identification problem, in a real-world network environment, a custom probe tool is deployed to acquire network packets. Multi-dimensional statistical feature extraction technology and ensemble learning algorithms are used to construct highly separable feature vectors based on the statistical characteristics of network traffic. Through a multi-session aggregation voting mechanism, the identification and classification of mainstream application layer protocols are achieved. This invention does not rely on port numbers or payload decryption and can effectively identify application layer protocols in non-standard ports and encrypted scenarios, achieving an accuracy of 99.56% and an average recall rate of 99.26%.
Owner:FIBERHOME TELECOMMUNICATION TECHNOLOGIES CO LTD

Network traffic handling for user equipment cooperation

Various aspects of the present disclosure generally relate to wireless communication. In some aspects, a user equipment (UE) may communicate network traffic splitting information associated with the UE and a companion UE, the network traffic splitting information indicating splitting information of network traffic associated with a first modality corresponding to a multi-modal service identifier and a second modality corresponding to the multi-modal service identifier. The UE may communicate, based at least in part on the network traffic splitting information, one or more network packets of the network traffic. Numerous other aspects are described.
Owner:QUALCOMM INC +5

Network traffic load balancing method and apparatus for data center

PendingUS20260205415A1Data packNetwork link
Disclosed are a network traffic load balancing method and apparatus for a data center, which are applied to the data center including a switch, a host, and a server. The method includes the following steps: collecting connection information between the switch, the host, and the server, and constructing a network topology structure of the data center according to the connection information; monitoring working information about each network link under the network topology structure, and correspondingly determining a congestion condition of each network link according to the working information about each network link; and allocating pre-transmitted data traffic packets to each network link according to the congestion condition to balance data traffic on each network link.
Owner:INSPUR SUZHOU INTELLIGENT TECH CO LTD

Device for autonomous detection of cyber threats

A device for the autonomous detection of cyber threats, consisting of: a housing that encloses a multitude of interconnected hardware components; a network interface unit configured to receive and send data packets from one or more communication networks; a data acquisition unit that is operationally connected to the network interface unit and configured to capture packet-level data, metadata, and system event logs; a preprocessing processor configured to analyze captured data, decodecode protocols, reconstruct communication flows, and generate structured data representations; a feature extraction processor that is operationally coupled with the preprocessing processor and is configured to calculate statistical, temporal and entropy-based features from the structured data representations; a storage unit consisting of volatile memory for real-time processing and non-volatile memory for storing historical data and learned patterns; an inference processor that is operationally coupled with the feature extraction processor and the storage unit, wherein the inference processor is configured to execute a variety of trained models to identify anomalous behavior based on deviations from stored patterns; a classification unit that is operationally coupled with the inference processor and configured to assign detected anomalies to one or more threat categories based on calculated confidence values; a response control unit configured to generate and transmit remedial actions, including blocking network traffic, isolating network segments, and terminating suspicious processes; and a control processor configured to coordinate the data flow between the network interface unit, the data acquisition unit, the preprocessing processor, the feature extraction processor, the inference processor, the classification unit, the response control unit, and the storage unit, with the device operating autonomously to detect and respond to cyber threats in real time.
Owner:ALMOMANI DUAA SHAWKAT +1

Deep learning-based network intrusion detection method and system

This application provides a network intrusion detection method and system based on deep learning. The method includes: capturing raw network traffic data in real time using traffic collectors deployed on network nodes; performing data cleaning, feature standardization, and feature filtering on the raw traffic data to obtain optimized feature vectors; constructing an ensemble model containing base classifiers and meta classifiers, and training the ensemble model using the optimized feature vectors, wherein training the ensemble model includes stacking the prediction results of the base classifiers to form new feature vectors to train the meta classifiers; collecting network traffic features in real time and preprocessing the network traffic features; inputting the preprocessed network traffic feature vectors into the trained ensemble model, and determining the risk of intrusion behavior based on the output probability of the ensemble model, as well as performing risk classification and alarms.
Owner:HUANENG POWER INT INC +1

System for adaptive management of downstream technology elements

A system is provided for detecting and remediating computing system breaches using computing network traffic monitoring. In particular, the system may identify one or more technology elements within a network as well as relationships between computing systems associated with said elements to determine a network topology. Based on the network topology, the system may use historical network traffic data associated with the technology elements in the network to generate predicted entry points and lateral pathways of a security breach that may take place within particular computing systems. Then, based on the technology elements affected as well as entry points and path traversals of the breach, the system may generate and / or implement one or more remediation steps to address existing and / or future breaches. In this way, the system may provide an intelligent method of augmenting the security of a computing network.
Owner:BANK OF AMERICA CORP

A method and system for assessing data security protection capabilities in the industrial internet

PendingCN122093138ARealize high-precision detectionReduce false alarm rateSecuring communicationTopology mappingPathPing
This invention relates to the field of industrial internet security technology, and discloses a method and system for evaluating industrial internet data security protection capabilities. The method includes acquiring network traffic logs and system response records; performing time-series correlation analysis and sequence causal relationship completion based on the logs and records to obtain a dynamic evolution sequence of attack behavior; constructing an attack path graph model and parsing the correlation structure based on the sequence to obtain an attack path correlation structure; identifying high-latency paths and calculating response time differences to obtain a set of high-latency paths; extracting time feature vectors and quantifying the similarity of protection effectiveness from this set to obtain a quantitative score for path protection effectiveness; combining the score and difference index to perform a comprehensive risk assessment of physical topology mapping and node cascade failure analysis to obtain the system's comprehensive protection weaknesses; and performing adaptive scenario reconstruction closed-loop verification based on the weaknesses. This method can achieve accurate evaluation and dynamic verification of system protection weaknesses in complex adversarial scenarios.
Owner:北京优信新星科技有限公司

Network traffic anomaly detection method, apparatus, device, medium, and program product

Embodiments of the present application disclose a network traffic anomaly detection method, device, equipment, medium and program product. The network traffic anomaly detection method comprises: performing feature preprocessing on network traffic data to obtain to-be-detected traffic features; determining a normal traffic confidence of the network traffic data according to the to-be-detected traffic features by using a discriminator in a generative adversarial network, wherein the generative adversarial network is trained based on normal traffic features; determining whether the network traffic is abnormal traffic based on the normal traffic confidence; and in a case where the normal traffic confidence is in a doubtful interval, obtaining simulated normal traffic features generated by a generator in the generative adversarial network, and determining whether the network traffic is abnormal traffic according to a difference between the to-be-detected traffic features and the simulated normal traffic features. The technical solution of the embodiments of the present application can reduce the false positive rate and improve the accuracy of network traffic anomaly detection.
Owner:CHINA MOBILE GRP FUJIAN CO LTD +1

Transparent, On-Demand Route Determination and Delegated Authorization in a Large-Scale, Decentralized Service Mesh

A system can intercept, by a kernel-space application of a node of nodes, a call from a microservice that is directed to a remote endpoint that is external to a decentralized service mesh architecture, wherein the kernel-space application operates in a kernel space of the node, and wherein the microservice executes in a user space of the node. The system can perform, by the kernel-space application, an authorization check on the call based on the microservice and a virtual address of the remote endpoint identified in the call, to produce an authorization result determine, by the kernel-space application, connectivity information of the remote endpoint based on the virtual address of the remote endpoint identified in the call. The system can relay, by the kernel-space application, network traffic between the microservice and the remote endpoint, based on the authorization result indicating that the call is authorized and using the connectivity information.
Owner:DELL PROD LP

A system and method for enterprise strategy planning lifecycle closed-loop management

This invention discloses a closed-loop management and method for the entire lifecycle of enterprise strategic planning, relating to the fields of enterprise information management and network security technology. It involves acquiring the enterprise strategic plan and creating a separate version after each change; encrypting the version and obtaining a hash fingerprint; storing the hash fingerprint and unique version number in a decentralized manner; storing the encrypted version and key on a cloud server; when a user accesses the platform, network traffic characteristics are collected and input into a network security analysis model trained by a spatially limited multi-stage exploration algorithm to determine the security monitoring results; if secure, the target version data is scheduled and its integrity is verified using the decentralized hash fingerprint; after successful verification, the data and the key encrypted with the user's public key are securely transmitted to the user. This achieves absolute tamper-proof and closed-loop traceability of the strategic planning version, and improves the accuracy of network environment perception through a multi-stage exploration algorithm, constructing a highly secure data access and transmission defense line.

Method, device and medium for protecting full-link of API level data flow

The application relates to the technical field of data processing, and provides an API-level data flow transfer full-link protection method and device, equipment and a medium, which can collect application layer business log data and kernel state network flow data as to-be-processed data in real time by adopting a non-buried point mechanism, realizes non-intrusive full-amount data collection, identifies to-be-protected data by adopting a non-feature data supplement identification mechanism, improves the accuracy and generalization ability of data identification, solves the problem that non-feature data cannot be controlled, constructs an API-level full-link data flow transfer map according to the to-be-protected data and the to-be-processed data, provides a complete topology basis for subsequent risk detection and tracing, performs risk detection according to the API-level full-link data flow transfer map, improves the effectiveness of risk detection, performs bidirectional tracing according to the detection result and the API-level full-link data flow transfer map, obtains a tracing report, can quickly locate a data anomaly source and an influence range, and provides a complete evidence chain.
Owner:PACIFIC BUSINESS SOLUTIONS (CHINA) CO LTD

An AI-based real-time detection method and system for abnormal network traffic

This invention relates to the field of network traffic technology, and more particularly to an AI-based real-time abnormal network traffic detection method and system. The system includes: a data processing module that collects network traffic data in real time and sequentially cleans, de-identifies, structures, and extracts features from the data; a traffic detection module that trains an initial model, analyzes the network traffic data, and issues an early warning when anomalies are detected in the analysis results; an executability judgment module that determines whether the executability of the analysis results does not meet requirements based on the quality characterization value of the analysis results; a depth adjustment module that determines the elastic resolution coefficient of the network traffic data parsing depth based on the packet loss rate of the network traffic data; and a granularity adjustment module that determines the triggering dynamic response granularity of the traffic features based on the generation delay of the early warning information. This invention improves the stability of real-time detection.
Owner:BEIJING SKYWALKER TECH CO LTD

Multicast network traffic scheduling method and system, electronic device and readable medium

PendingCN122293575AInternet trafficMulticast network
This disclosure provides a multicast network traffic scheduling method, system, electronic device, and readable medium, belonging to the field of communications. The method includes: dividing the uplink of an access node into multiple link groups, each link group containing multiple uplinks corresponding to the same relay node; and dividing multiple downlink multicast sources from the access node into multiple source groups; constructing a weight matrix, where rows correspond to source groups and columns correspond to relay nodes; and determining unicast routes for each source group based on the weight matrix, so that each source group selects the node with the highest weight among multiple relay nodes as the traffic-carrying node, thereby distributing traffic from different source groups to different relay nodes. The multicast network traffic scheduling method, system, electronic device, and readable medium provided in this disclosure can achieve load balancing and reduce congestion risk; simultaneously, it can be implemented using conventional routing strategies without changing the terminal and multicast protocol, resulting in low modification costs and strong scalability.
Owner:SUZHOU CENTEC COMM CO LTD

Intelligent bandwidth reservation for satellite beam cells in a non-terrestrial network

PCT designated stageWO2026148304A1Interference (communication)Internet traffic
Spectrum allocation in non-terrestrial wireless networks is efficiently and intelligently managed by predicting traffic loads for beam cells using historical network traffic data and a trained model. Beam cells with higher predicted traffic loads are assigned larger spectrum bandwidths, while other beam cells are assigned smaller, non-overlapping bandwidths that dynamically change frequencies according to a predefined hopping sequence. Example solutions disclosed herein optimize bandwidth utilization and minimize interference, enhancing service quality and coverage in satellite communication systems.
Owner:T MOBILE US INC