Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

369 results about "NetFlow" patented technology

NetFlow is a feature that was introduced on Cisco routers around 1996 that provides the ability to collect IP network traffic as it enters or exits an interface. By analyzing the data provided by NetFlow, a network administrator can determine things such as the source and destination of traffic, class of service, and the causes of congestion. A typical flow monitoring setup (using NetFlow) consists of three main components...

Dynamic access blocking method based on zero trust

The invention relates to the technical field of network security, in particular to a dynamic access blocking method based on zero trust. Comprising the following steps: step 1, collecting whole network flow data in real time in a bypass monitoring mode through a flow mirroring function of a network switch, performing deep packet inspection analysis on the collected original flow data, and extracting network flow characteristic parameters; 2, maintaining a dynamic identity information base; 3, performing real-time behavior analysis on each network session; 4, according to the risk assessment result and the real-time security context, generating a dynamic access control strategy based on a minimum permission principle; 5, implementing access control at the network execution point; and 6, continuously monitoring the network flow and the strategy execution effect, collecting feedback data, optimizing the risk assessment model and the strategy generation algorithm based on the feedback data, and forming closed-loop control. By dynamically updating the identity and asset information, the system can identify new assets or changes in real time, so that the adaptability and response capability of a network environment are improved.
Owner:SHANDONG NETWORK SECURITY TECHNOLOGY CO LTD

Network intrusion detection method and system based on edge attention learning

The invention discloses a network intrusion detection method and system based on edge attention learning, and a storage medium, and the method comprises the steps: converting an original network flow into a network flow diagram, and constructing a training diagram and a test diagram under the condition that a coarse-grained label and a fine-grained label are reserved; edge embedding representation is obtained through edge feature reservation, adaptive weight distribution and multi-layer feature extraction of the training graph and the test graph; based on the edge embedding representation, performing coarse-grained detection to identify a basic attack category, and performing fine-grained classification by using multi-scale feature fusion related to global graph attributes; and adversarial training: through initializing adversarial disturbance and optimizing disturbance based on loss function gradient iteration, superposing final disturbance into the training graph, and based on loss function back propagation updating, obtaining a trained network intrusion detection model. The method provided by the invention can effectively capture the depth characteristics of the key attack and maintain the stable detection performance in the confrontation environment.
Owner:HARBIN INSTITUTE OF TECHNOLOGY (SHENZHEN) (INSTITUTE OF SCIENCE AND TECHNOLOGY INNOVATION HARBIN INSTITUTE OF TECHNOLOGY SHENZHEN)

Network pipeline abstraction layer (NAPL) emulation

Technologies for creating an optimized and accelerated network pipeline using an emulated network pipeline abstraction layer (NPAL) of an emulated data processing unit (DPU), including an emulated processing device and an emulated acceleration hardware engine, are described. The emulated NPAL supports multiple network protocols and network functions in an emulated network pipeline. The emulated network pipeline includes a set of tables and logic organized in a specific order to be accelerated by the emulated acceleration hardware engine. The emulated acceleration hardware engine can process network traffic data using the emulated network pipeline.
Owner:MELLANOX TECHNOLOGIES LTD(IL)

Hardware-accelerated policy-based routing (PBR) over service function chaining (SFC)

Technologies for creating an optimized and accelerated network pipeline using a network pipeline abstraction layer (NPAL) for policy-based routing (PBR) over Service Function Chaining (SFC) are described. A DPU includes acceleration hardware engine to provide a single accelerated data plane. A processing device can generate a first virtual bridge and a second virtual bridge, the first virtual bridge to be controlled by a first network service hosted on the DPU and having a set of one or more network rules, and the second virtual bridge having a policy-based routing policy (PBR policy). The processing device can add the virtual port between the first virtual bridge and the second virtual bridge. The acceleration hardware engine, in the single accelerated data plane, can route network traffic data using the PBR policy and process the network traffic data using the set of one or more network rules.
Owner:MELLANOX TECHNOLOGIES LTD(IL)

Methods, systems, and computer readable media for filtering inter-public land mobile network (PLMN) messages at security edge protection proxy (SEPP) to implement roaming agreements

A method for screening inter-PLMN messages at a SEPP to implement roaming agreements includes storing an originating and target network mapping database containing records including mappings between originating network identifiers and target network identifiers. The method further includes receiving, at the SEPP, an inter-PLMN SBI request message originating from an NF in a network served by the SEPP. The method further includes determining originating and target network identifiers from the message, locating a matching record in the database, and determining, from the record, whether the message should be allowed to flow from the originating network to the target network. The method further includes forwarding the message to the target network or preventing the forwarding of the message to the target network based on results of the determining.
Owner:ORACLE INT CORP

Dependent task unloading method based on reliability perception of topology reconstruction in industrial internet edge computing

The invention provides a reliability-aware dependent task unloading method based on topology reconstruction in industrial internet edge computing, which comprises the following steps of: constructing a system model covering an edge cloud network platform, an industrial cloud platform and internet of things equipment, and establishing a transmission delay model and a reliability model; constructing a task unloading mathematical model with the maximum reliability level; the method comprises the following steps: modeling a micro-service dependency relationship into a weighted directed acyclic graph based on a network flow theory, and carrying out topology reconstruction on micro-services applied to the Internet of Things through a Ford-Fulkerson approximation algorithm to obtain a micro-service grouping structure formed by minimum cut division; the micro-service grouping structure serves as priori knowledge to be input into the deep Q network, the deep Q network is used for solving a task unloading mathematical model, a task unloading strategy is dynamically adjusted, resource allocation is optimized, and an optimal calculation unloading scheme in the industrial internet edge calculation environment is obtained. The micro-service deployment is optimized, the communication overhead is reduced, and the system reliability and the resource utilization rate are improved through real-time network state dynamic decision making.
Owner:HUBEI UNIV OF ARTS & SCI

Network pipeline abstraction layer (NPAL) optimized pipeline for network acceleration

Technologies for creating an optimized and accelerated network pipeline using a network pipeline abstraction layer (NPAL) are described. A DPU includes DPU hardware and memory that stores DPU software with the NPAL that supports multiple network protocols and network functions in a network pipeline. The network pipeline includes a set of tables and logic organized in a specific order to be accelerated by an acceleration hardware engine of the DPU. The acceleration hardware engine processes network traffic data using the network pipeline.
Owner:MELLANOX TECHNOLOGIES LTD(IL)

Active source dynamic monitoring and tracking method and system for DDoS attack defense

The invention discloses an active source dynamic monitoring and tracking method and system for DDoS attack defense, and the method comprises the steps: collecting Netflow data transmitted by a router in real time; cleaning, normalization processing and feature extraction are carried out on the acquired Netflow traffic data; carrying out statistics on the extracted features, and constructing a traffic baseline; monitoring a reputation value corresponding to each source IP, and constructing an active attack source library for quickly identifying active attack sources; analyzing and detecting the activeness of each monitored source IP based on a sliding time window and a traffic baseline, and further verifying the detected active attack source in combination with the trained LSTM model; performing hop-by-hop tracing, TTL analysis, multi-path probability tracking and probe packet verification on the identified active attack source to realize accurate tracing of the active attack source; and dynamically updating the traffic baseline and the active attack source library according to the traceability result. According to the method and the system, an active attack source is identified through multi-level feature analysis and a cooperative tracking mechanism.
Owner:CHINA UNITECHS

Network flow association method and system based on tetrad metric learning

The invention discloses a network flow association method and system based on tetrad metric learning, and the method comprises the following steps: constructing a tetrad data set containing an adversarial disturbance sample through extracting the packet interval and packet size characteristics of network flow; a double-branch feature embedded network is combined with a channel attention and space attention module, so that the dynamic sensing ability of key features is enhanced; introducing a tetrad loss function to optimize a feature embedding space, and compulsorily confronting a rejection relationship between a disturbance sample and a negative sample; based on a dynamic mixed quantile method, a correlation threshold is adaptively selected, and the robustness is improved in combination with a multi-window voting mechanism. According to the method, the association discrimination of the network flow is realized by adopting a tetrad metric learning method, the anti-disturbance capability and the calculation efficiency are remarkably improved, the distribution characteristics of the original flow are not changed, and the method is suitable for a large-scale real-time anonymous network flow association scene.
Owner:SOUTH CHINA UNIV OF TECH

Network pipeline abstraction layer (NAPL) fast link recovery

Technologies for creating an optimized and accelerated network pipeline using a virtual switch and a network pipeline abstraction layer (NPAL) for fast link recovery are described. The virtual switch can monitor a link availability of each of a plurality of links to a destination, the plurality of links being specified in an initial group of identifiers. The virtual switch can detect a link failure of a first link of the plurality of links. The NPAL can remove a first link identifier, associated with the first link, from the initial group of link identifiers to obtain a modified group of link identifiers. The NPAL can cause a routing table in the NPAL to be updated to remove the first link identifier. The acceleration hardware engine can process network traffic data using the network pipeline and distribute the network traffic data to only the remaining links of the plurality of links.
Owner:MELLANOX TECHNOLOGIES LTD(IL)

Network pipeline abstraction layer (NAPL) split interfaces

Technologies for creating an optimized and accelerated network pipeline using a network pipeline abstraction layer (NPAL) for split interfaces are described. A DPU includes a physical port configured to couple to a breakout cable that physically couples to a set of a plurality of devices, DPU hardware, and a memory operatively coupled to the DPU hardware. The NPAL supports a plurality of logical split ports, each logical split port corresponding to one of the plurality of devices, wherein the network pipeline comprises a set of tables and logic organized in a specific order to be accelerated by the acceleration hardware engine. The acceleration hardware engine is to process the network traffic data using the network pipeline.
Owner:MELLANOX TECHNOLOGIES LTD(IL)

Optical cable performance intelligent prediction method and system for data center

The invention provides an intelligent optical cable performance prediction method and system for a data center, and relates to the technical field of data center performance analys.The intelligent optical cable performance prediction method comprises the steps that firstly, an optical cable microstructure disturbance quantization model is constructed, and an optical cable is divided into a plurality of virtual quantization units in the longitudinal direction; each unit packages a real-time stress-strain state parameter and a response sensitivity coefficient of the basic structure unit, inputting a Brillouin scattering spectrum frequency shift data flow collected in real time into the model for disturbance source analysis, generating a physical excitation decomposition sequence, driving a virtual quantization unit to perform state evolution iterative operation according to the physical excitation decomposition sequence, and obtaining a Brillouin scattering spectrum frequency shift data flow model; a stress-strain state evolution track set is obtained, a time-space correlation network of optical cable link disturbance propagation is constructed according to the stress-strain state evolution track set, network flow characteristic analysis is conducted on the time-space correlation network, an early warning node set is extracted, the future evolution trend of the early warning node set is calculated, and serialized optical cable performance abnormity early warning information is generated. The optical cable performance abnormity can be predicted in advance, and stable operation of the data center optical cable is guaranteed.
Owner:SICHUAN JIAWANG OPTICAL COMM CO LTD

Low-delay SDN (Software Defined Network) flow table updating method

The invention provides a low-delay SDN (Software Defined Network) flow table updating method, and belongs to the technical field of network communication. The method comprises the following steps: firstly, proposing a shortest mobile rule chain for updating a single forwarding rule; and then, aiming at a plurality of concurrency rules which simultaneously reach the switch, designing a dynamic mode to update the concurrency rules, and heuristically updating the plurality of rules in a TCAM limited area, so that the flow table updating efficiency is improved. The method and the device are used for reducing updating delay caused by the rule dependency relationship.
Owner:THE QUARTERMASTER RES INST OF THE GENERAL LOGISTICS DEPT OF THE CPLA

Power grid material vehicle path planning method

The invention discloses a power grid material vehicle path planning method, and provides a space-time hierarchical modeling and cloud edge collaborative optimization architecture aiming at the problems of dynamic embargo, channel capacity fluctuation, multi-resource conflict, response lag and the like faced by power grid material dispatching in the prior art. By constructing a space-time coupled channel capacity-path planning hierarchical model, multi-commodity network flow pre-calculation and real-time vehicle path dynamic decoupling are carried out, and material distribution is optimized in combination with a space-time double-coding genetic algorithm; a multi-agent deep game decision-making mechanism is designed, channel priorities of different types of materials are dynamically balanced through reinforcement learning, and distributed conflict resolution is achieved; a block chain-based cross-domain scheduling instruction synchronization system is developed, low-delay path re-planning is realized by adopting a differential updating mechanism, and second-level updating of a scheduling scheme under an emergent road condition is supported; the on-chain evidence storage technology is introduced to guarantee instruction integrity and operation tracing, and the scheduling deadlock risk is reduced in combination with a key channel competition early warning model.
Owner:NAN FANG DIAN WANG GONG YING LIAN (YUN NAN) YOU XIAN GONG SI

Method and device for detecting and identifying cryptographic algorithms in a communication network

The invention relates to a method for detecting a particular cryptographic algorithm used in a computer system, comprising steps of capturing data packets exchanged with a target machine in order to obtain initial measurements of time and data volume, calculating response delays by measuring the time elapsed between sending and receiving the captured data packets, determining a first time signature indicative of a cryptographic algorithm used to generate the captured packets on the basis of the calculated response delays and the exchanged data volumes, determining a level of correspondence between the first time signature determined and at least one second time signature determined beforehand for a particular cryptographic algorithm, and transmitting an alert comprising at least one identifier of a source apparatus and / or of a destination apparatus of the network flow when the level of correspondence is greater than a threshold.
Owner:ORANGE SA

Method and device for detecting unknown malicious traffic

The invention provides an unknown malicious traffic detection method and device. The method comprises the following steps: converting a network stream to be detected into a grey-scale map; an encoder in the trained generative model is utilized to extract encoding features of the grey-scale map, the minimum distance between the encoding features and Gaussian prototypes corresponding to all known traffic categories is calculated, if the minimum distance is smaller than a preset threshold value, the network flow to be detected is considered to belong to the traffic category corresponding to the minimum distance, and otherwise, the network flow to be detected is considered to be an unknown traffic category; wherein the training process of the generative model comprises the following steps of: constructing a traffic data set marked with category labels; converting each network flow sample in the flow data set into a grey-scale map, sequentially inputting all the grey-scale maps into a conditional variation auto-encoder, calculating ELBO loss according to a generation limit, calculating identification loss according to an identification limit, and calculating total loss to update network parameters; after training is completed, the conditional variation auto-encoder is a generative model, and Gaussian prototypes corresponding to all known traffic categories are obtained.
Owner:Chinese People's Liberation Army Cyberspace Force Information Engineering University

Scenario planning solutions

A system and method are disclosed for performing rough cut capacity planning. The method includes receiving supply chain transaction data as transaction tables, generating a base plan and generating updated transaction tables, denormalizing the base plan and the updated transaction tables, generating supply chain network flow paths and supply chain network data, solving a rough cut capacity planning problem based at least in part on the supply chain network flow paths, the supply chain network data and simulation data, repeating at least the generating and solving until business goals of the rough cut capacity planning meet a threshold, and updating the simulation data based on an upsert process. The method further includes relaxing supply chain network constraints, inverting the supply chain network, and traversing a perturbation in the supply chain network constraints as demands in a reverse direction towards customer nodes.
Owner:BLUE YONDER GROUP INC

Network data threat detection model training method, threat detection method and device

The invention provides a network data threat detection model training method, a threat detection method and a threat detection device. The method comprises the following steps: intercepting network flow front-end data in a preset byte range from each sample flow, and performing word segmentation to obtain words; the word one-hot vector is used as a byte node, and the TF-IDF sequence of each word in the stream is used as a network stream node. Setting a first type of edge weight as a TF-IDF value to realize byte-stream association; and extracting semantic embedding of all byte nodes by using a pre-trained bidirectional LSTM (Long Short Term Memory), establishing a second class of edges for byte pairs of which the cosine similarity is higher than a threshold value, and calculating the weights of the byte pairs by using global co-occurrence statistics to form a semantic association graph without topology. And constructing an initial model containing double layers of GCN and Softmax, taking graph data with threat type labels as a training set, and updating parameters by minimizing cross entropy loss to obtain a network threat data detection model. According to the method, the generalization ability can be improved, and when the graph data topology is incomplete, the graph structure capable of representing the behavior association relationship is effectively constructed to improve the network data threat detection ability.
Owner:BEIJING UNIV OF POSTS & TELECOMM +1

Domain name analysis method, device, system and equipment

The invention relates to a domain name analysis method, device, system and equipment. The method is applied to a first-level cluster, and comprises the following steps: obtaining network flow message data corresponding to a network flow; forwarding the network flow message data to a secondary cluster according to a message forwarding strategy; wherein the network flow message data is used for indicating the secondary cluster to perform domain name resolution processing on the network flow message data to obtain domain name information. According to the invention, the domain name extraction efficiency can be effectively improved.
Owner:CHINA TELECOM CLOUD TECH CO LTD

Multi-task-oriented edge computing resource allocation method and device, equipment and medium

The invention discloses a multi-task-oriented edge computing resource allocation method and device, equipment and a medium. The method comprises the following steps: acquiring a user terminal set, an MEC server set, a to-be-computed task group of each terminal and a sub-channel set of each server; constructing a network flow graph which takes each sub-channel as a first type of nodes, takes each user terminal as a second type of nodes, and takes a connecting line between the first type of nodes and the second type of nodes as an edge; constructing a cost calculation formula corresponding to the edge in the network flow graph; dynamically searching a task execution strategy with the minimum total cost by adopting a shortest path fast algorithm based on the network flow graph; according to the technical scheme provided by the embodiment of the invention, through joint optimization calculation unloading and resource allocation, the throughput is remarkably improved on the premise of ensuring the task time delay demand; a dynamic cost adjusting mechanism can adapt to network environment changes in real time, and efficient utilization of resources is achieved.
Owner:AGRICULTURAL BANK OF CHINA

Route anomaly detection method and device of autonomous system and electronic equipment

The invention relates to the technical field of network security, in particular to a routing anomaly detection method and device of an autonomous system and electronic equipment. Determining a traffic behavior data set of each AS node based on the routing data and the Netflow traffic statistical data of each AS node in a preset time window; constructing a spatial-temporal feature sequence based on the registration data and the traffic behavior data set of each AS node in a preset time window; performing spatial enhancement processing on the spatial-temporal feature sequence by using a structured correlation model to generate a spatially optimized spatial-temporal feature sequence, the structured correlation model being generated according to the topological relationship among the AS nodes; performing time feature extraction on the spatially optimized spatial-temporal feature sequence to obtain a spatial-temporal feature abstract matrix of each AS node in a preset time window; and performing anomaly judgment on the spatial-temporal feature abstract matrix to obtain a detection result of each AS node route. The accuracy of AS routing anomaly identification is enhanced, and the false alarm rate is effectively reduced.
Owner:CHINA TELECOM NETWORK SECURITY TECH CO LTD

Flow classification method and system based on SmartNIC

The invention discloses a flow classification method based on SmartNIC, and the method comprises the steps: monitoring the network flow in real time, and obtaining a to-be-processed data package in the network flow; determining a hash value of a network flow corresponding to the to-be-processed data packet, determining a hash bucket where the to-be-processed data packet is located according to the hash value, and tracking the state of the network flow according to the hash bucket; accumulating the number of the data packets to be processed to a first preset number; performing standardization processing on the target number of to-be-processed data packets to obtain a target number of target data packets; and performing traffic classification on the target number of target data packets. After the Hash value and the Hash bucket are obtained, the state of the network flow can be effectively tracked, the calculation pressure of a CPU and a GPU of a server is reduced, the system delay, the throughput and the energy consumption are reduced, and the real-time performance and the stability of a flow classification system are ensured. In addition, the invention also provides a flow classification system based on the SmartNIC.
Owner:NORTHEASTERN UNIV CHINA

Abnormal node monitoring method and device, equipment and storage medium

The invention provides an abnormal node monitoring method, apparatus and device, and a storage medium. The method comprises the steps of collecting six-tuple network flow data; calculating a data entropy change rate of the six-tuple network flow data, wherein the data entropy change rate divides the six-tuple network flow data into a plurality of segmented network flow data; constructing a source node network according to the segmented network flow data, and performing feature extraction on the source node network to obtain a three-dimensional network feature vector; according to the three-dimensional network feature vector, constructing an Isolation Forest isolation tree, and after training, obtaining a node anomaly score; and performing incremental updating on the node exception score, and determining an exceptional node from the source node network according to the updated node exception score and a preset dynamic exception threshold.
Owner:SHENZHEN DINSTAR TECH

Lossless-ethernet flow control method and apparatus

PCT designated stage expiredWO2025118933A1Biological modelsTransmissionHigh bandwidthAlgorithm
Provided in the present invention are a lossless-Ethernet flow control method and apparatus. A designed lossless-Ethernet flow control algorithm based on deep learning is combined with the idea of reinforcement learning and a convolutional neural network model, which can provide a dynamic threshold adjustment mechanism for complex and changeable network environments, so that the cache space between an ECN threshold and a PFC threshold can accommodate traffic transmitted during the period from ECN congestion marking to a speed reduction at a source end, the triggering of network PFC is avoided as much as possible, and the performance of PFC and ECN in RDMA is maximized, thereby realizing anti-packet-loss, high bandwidth utilization, and low-delay transmission of lossless Ethernet in the complex and changeable network environments.
Owner:CHENGDU AIRCRAFT DESIGN INST OF AVIATION IND CORP OF CHINA

Methods to manage QOS and qoe in 6g

The present disclosure is directed to implementations of systems and methods for quality-of-experience (QoE)-aware quality-of-service (QoS) management for network flows. In some implementations, a wireless transmit receive unit (WTRU) may transmit to a network a registration request comprising quality-of-experience (QoE) assistance information. The WTRU may receive, from the network, a registration acceptance response indicating a QoE-Aware Quality-of-Service Function (QQF) of the network is configured to provide flow control or QoS management for an application of the WTRU based on the QoE assistance information. The WTRU may execute the application and monitor a QoE score during execution of the application. Responsive to a change in the QoE score, the WTRU may transmit to the QQF one or more network or application performance measurements.
Owner:INTERDIGITAL PATENT HOLDINGS INC

Edge calculation collaborative reasoning method for adaptive model segmentation, medium and equipment

The invention discloses an edge calculation collaborative reasoning method for adaptive model segmentation, a medium and equipment. The method comprises the following steps: pre-training a DNN model by adopting a data set in a model application field; quantizing the DNN model by adopting a post-training quantization method; analyzing layering calculation time delay and data output quantity based on layering characteristics of the DNN model, and constructing a directed acyclic graph of the model; generating a feasible segmentation strategy set by adopting a network flow graph mode in a graph theory; and solving an optimal segmentation strategy under the dynamic network quality by adopting a deep Q network. According to the method, the storage pressure of the terminal equipment is relieved by adopting a model compression method, the action space of the DQN is solved by combining the DAG of the DNN and utilizing a graph theory method, the problem that the action space is too large due to too many feasible segmentation strategies is solved, and then the time for solving the optimal segmentation strategy is shortened, and the reasoning efficiency is improved.
Owner:HEFEI UNIV OF TECH

Communication data analysis system and method for network security

The invention discloses a communication data analysis system and method for network security, and relates to the technical field of computer internet. Time sequence features, protocol semantic features and interactive topology features of communication session historical data are extracted based on network flow data; the method comprises the following steps of: acquiring a time sequence feature, a protocol semantic feature and an interactive topology feature, fusing the time sequence feature, the protocol semantic feature and the interactive topology feature into a unified high-dimensional feature vector, acquiring a communication behavior record and a communication behavior dynamic feature vector of network equipment in a communication network, calculating a digital feature of a coupling relationship evaluation value, and when a certain communication session occurs, judging whether the communication session occurs or not. The method comprises the following steps of: calculating real-time coupling relationship evaluation values among network equipment, quantifying the difference degree of the real-time coupling relationship evaluation values through digital characteristics, accumulating the coupling relationship evaluation values in the process of performing a certain communication session, calculating the total anomaly degree of the communication session, and calculating the abnormal degree of the communication session. The method aims at solving the problems that advanced persistent threats are difficult to effectively recognize, feature expression is insufficient and the perceptual ability is weak in the prior art.
Owner:YANCHENG HUAFEI DATA TECHNOLOGY CO LTD

Techniques for processing network flows

Improved network traffic flow processing techniques are described. In a network device providing multiple processing planes, each processing plane comprising multiple processing units, techniques are described that take advantage of flow affinity / locality principles such that the same processing component of a processing plane, which previously performed processing for a network flow, is used for performing subsequent processing for the same network flow. This enables faster processing of network traffic flows by the network device. In certain implementations, the techniques described herein can be implemented in a network virtualization device (NVD) that is configured to perform network virtualization functions.
Owner:ORACLE INT CORP