Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

124 results about "NetFlow" patented technology

NetFlow is a feature that was introduced on Cisco routers around 1996 that provides the ability to collect IP network traffic as it enters or exits an interface. By analyzing the data provided by NetFlow, a network administrator can determine things such as the source and destination of traffic, class of service, and the causes of congestion. A typical flow monitoring setup (using NetFlow) consists of three main components...

Optical cable performance intelligent prediction method and system for data center

The invention provides an intelligent optical cable performance prediction method and system for a data center, and relates to the technical field of data center performance analys.The intelligent optical cable performance prediction method comprises the steps that firstly, an optical cable microstructure disturbance quantization model is constructed, and an optical cable is divided into a plurality of virtual quantization units in the longitudinal direction; each unit packages a real-time stress-strain state parameter and a response sensitivity coefficient of the basic structure unit, inputting a Brillouin scattering spectrum frequency shift data flow collected in real time into the model for disturbance source analysis, generating a physical excitation decomposition sequence, driving a virtual quantization unit to perform state evolution iterative operation according to the physical excitation decomposition sequence, and obtaining a Brillouin scattering spectrum frequency shift data flow model; a stress-strain state evolution track set is obtained, a time-space correlation network of optical cable link disturbance propagation is constructed according to the stress-strain state evolution track set, network flow characteristic analysis is conducted on the time-space correlation network, an early warning node set is extracted, the future evolution trend of the early warning node set is calculated, and serialized optical cable performance abnormity early warning information is generated. The optical cable performance abnormity can be predicted in advance, and stable operation of the data center optical cable is guaranteed.
Owner:SICHUAN JIAWANG OPTICAL COMM CO LTD

Domain name analysis method, device, system and equipment

The invention relates to a domain name analysis method, device, system and equipment. The method is applied to a first-level cluster, and comprises the following steps: obtaining network flow message data corresponding to a network flow; forwarding the network flow message data to a secondary cluster according to a message forwarding strategy; wherein the network flow message data is used for indicating the secondary cluster to perform domain name resolution processing on the network flow message data to obtain domain name information. According to the invention, the domain name extraction efficiency can be effectively improved.
Owner:CHINA TELECOM CLOUD TECH CO LTD

Techniques for processing network flows

Improved network traffic flow processing techniques are described. In a network device providing multiple processing planes, each processing plane comprising multiple processing units, techniques are described that take advantage of flow affinity / locality principles such that the same processing component of a processing plane, which previously performed processing for a network flow, is used for performing subsequent processing for the same network flow. This enables faster processing of network traffic flows by the network device. In certain implementations, the techniques described herein can be implemented in a network virtualization device (NVD) that is configured to perform network virtualization functions.
Owner:ORACLE INT CORP

Encrypted traffic classification method and system based on semi-supervised contrast learning, and storage medium

The invention relates to an encrypted traffic classification method and system based on semi-supervised contrast learning, and a storage medium, and the method comprises the steps: 1, carrying out the flow division of an original encrypted traffic, respectively aligning the header and load of a data packet in a network flow, and generating an enhanced header and an enhanced load according to an enhancement strategy; step 2, multi-granularity feature extraction: a double-branch feature extractor is adopted to process an enhanced head and an enhanced load respectively, a cross attention mechanism is utilized to obtain fused flow level representation, and depth features are extracted through Mama; and step 3, semi-supervised contrast learning: the contrast learning loss and the cross entropy loss of the label data and the FixMatch loss of the non-label data are integrated, and an encrypted traffic fine-grained classifier is trained. The method has the beneficial effects that the noise propagation is jointly inhibited by comparing the feature structured constraint of learning and a high-confidence threshold filtering mechanism in FixMatch, the training stability is improved, and the labeling cost is remarkably reduced.
Owner:HARBIN INSTITUTE OF TECHNOLOGY (SHENZHEN) (INSTITUTE OF SCIENCE AND TECHNOLOGY INNOVATION HARBIN INSTITUTE OF TECHNOLOGY SHENZHEN)

A method, device and medium for dividing network flow packets

ActiveCN121940364BData packTerminal equipment
This invention provides a method, device, and medium for segmenting network flow data packets, relating to the field of network flow data packet segmentation technology. The method includes: determining the communication type between terminal devices corresponding to target network flow data; segmenting the target network flow data using a preset fixed duration; obtaining the target task identifier corresponding to the target network flow data; segmenting the target network flow data using the segmentation duration corresponding to the task identifier in the segmentation duration mapping table that is the same as the target task identifier; if the target task identifier does not exist in the preset segmentation duration mapping table, then segmenting the target network flow data using a preset fixed duration to obtain several network flow data packets corresponding to the target network flow data. This invention can significantly improve the processing efficiency and resource utilization of subsequent data packet caching, transmission, disk storage, and analysis stages.
Owner:HANGZHOU GUYI NETWORK TECH CO LTD

An APT traffic detection method based on a knowledge graph

ActiveCN115694933BData streamInternet traffic
The application discloses an APT flow detection method based on a knowledge graph, which comprises the following steps: analyzing network data flow characteristics in network flow, establishing a knowledge graph of network data flow, and classifying the established network flow knowledge graph by using a graph neural network algorithm to detect APT attack flow in the network, so that the attack behavior of an APT organization can be detected from the network level. The application can detect unknown APT attack network data flow, and is helpful for flexibly and accurately detecting APT flow.
Owner:ZHEJIANG UNIV

Charging demand regulation and guidance method and device for autonomous on-demand mobile vehicle fleet

ActiveCN117788081BUnlock your full flexibility potentialMobile vehicleSimulation
The application provides a charging demand regulation and guidance method and device for autonomous on-demand mobile vehicle fleet, and belongs to the field of electric vehicle charging regulation and guidance. The method comprises the following steps: a network flow optimization scheduling model of the autonomous on-demand mobile vehicle fleet and an optimal pricing model of a charging station operator are respectively constructed; based on master-slave game, the optimal pricing model of the charging station operator is taken as an upper model, and the network flow optimization scheduling model of the autonomous on-demand mobile vehicle fleet is taken as a lower model; the lower model is embedded into the upper model as a constraint condition, an updated optimal pricing model of the charging station operator is obtained and solved, so that a pricing scheme for regulating the charging demand of the autonomous on-demand mobile vehicle fleet is obtained. In the decision-making process of charging pricing, the time and space behavior mode and the price response characteristics of the autonomous on-demand mobile vehicle fleet are fully considered, and a targeted price signal is formulated according to the price response characteristics, so that the regulation efficiency of the autonomous on-demand mobile vehicle fleet is improved.
Owner:山西省能源互联网研究院 +1

Network flow table automatic analysis method and system based on OpenFlow technology

The invention provides a network flow table automatic analysis method and system based on an OpenFlow technology, relates to the technical field of operation and maintenance of a cloud computing data center network and a software defined network, and aims to carry out automatic routing inspection and positioning aiming at the problems of missing, repetition and inconsistency of a CVK host flow table at a bottom layer of a cloud platform. The method comprises the following steps: inputting target CVK host access information and carrying out connectivity and authentication verification; traversing virtual machine network information on the CVK host, connecting the Redis to query security group information associated with a virtual network card, and detecting missing of a security group flow table; the offline state of the network-cvk-agent service is checked, whether the network-cvk-agent service is caused by missing of a basic flow table of a network port or not is positioned in the offline mode, and missing information is output; detecting repetition and inconsistency of the basic flow table when the basic flow table is not offline or not missing; and finally, all task results are summarized and output to a console, and repair guidance is provided in a knowledge base link form, so that operation and maintenance personnel are helped to quickly position root causes and recover businesses.
Owner:UNICLOUD TECH CO LTD

SPLIT NPAL (NETWORK PIPELINE ABSTRACTION LAYER) INTERFACES

Technologies for creating an optimized and accelerated network pipeline using a shared interface Network Pipeline Abstraction Layer (NPAL) are described. A Data Processing Unit (DPU) comprises a physical port configured to couple with a breakout cable, which is physically coupled to a set of multiple devices, DPU hardware, and memory operationally coupled to the DPU hardware. The NPAL supports multiple logically split ports, with each logically split port corresponding to one of the multiple devices. The network pipeline comprises a set of tables and logic organized in a specific order to be accelerated by the acceleration hardware engine. The acceleration hardware engine is designed to process network traffic data using the network pipeline.
Owner:MELLANOX TECHNOLOGIES LTD(IL)

Overlaid encoding and transmission at a server

A method for cloud gaming. The method includes generating a video frame while executing a video game at a server. The method includes scanning the video frame into an encoder at the server on a scan line by scan line basis. The method includes encoding one or more encoder slices into one or more encoded slices at the encoder, where each encoded slice is transferred to a buffer at an encoder fill rate. The method includes draining a first encoded slice from the buffer to stream the first encoded slice to a client over a network at a buffer drain rate, where the first encoded slice is streamed over the network before one or more slices of a fully encoded video frame.
Owner:SONY INTERACTIVE ENTERTAINMENT LLC

FAST NPAL (NETWORK PIPELINE ABSTRACTION LAYER) LINK RESTORING

Technologies for creating an optimized and accelerated network pipeline using a virtual switch and a Network Pipeline Abstraction Layer (NPAL) for rapid link recovery are described. The virtual switch can monitor the link availability of each of several links to a destination, where the multiple links are specified in an initial set of identifiers. The virtual switch can detect a link failure of the first of the multiple links. The NPAL can remove the first link identifier associated with the first link from the initial set of link identifiers to obtain a modified set of link identifiers. The NPAL can cause a routing table within the NPAL to be updated to remove the first link identifier.The acceleration hardware engine can process network traffic data using the network pipeline and distribute the network traffic data only to the remaining of the multiple links.
Owner:MELLANOX TECHNOLOGIES LTD(IL)

A method and system for encrypted traffic identification based on spatio-temporal features and semantic alignment

This invention discloses a method and system for identifying encrypted traffic based on spatiotemporal features and semantic alignment. The method first extracts the spatial and temporal feature sequences of the network flow, and uses a byte-pair encoding algorithm to convert the spatial packet length into discrete symbols. Then, the discrete symbols and temporal features are mapped to a high-dimensional space and fused together. A global spatiotemporal feature vector is extracted through a network using a concatenated one-dimensional convolution and multi-head self-attention mechanism. Next, the text semantic bullseye matrix of fine-grained behaviors of various known applications is obtained offline from a large language model. Finally, the similarity between the spatiotemporal features and the text bullseye is calculated, and a multi-instance learning max-pooling mechanism is introduced for dynamic routing. Based on this, a contrastive learning loss function optimization model is constructed or cross-modal inference is performed. This invention completely overcomes the conceptual drift problem caused by changes in encrypted features, achieving extremely high generalization accuracy and feature interpretability across generations.
Owner:WUHAN UNIV

An intelligent project success rate prediction method and device

A project success rate intelligent prediction method and device, comprising: acquiring multi-source data, and constructing a structured knowledge base containing project success cases and their characteristics; applying the merged tree representation technology and the extended transformation to the project data in the structured knowledge base to construct a data structure, realize feature extraction and substructure search; based on the project feature set, multi-dimensional feature analysis is carried out from the time dimension and the space dimension; based on the multi-dimensional feature vector, a project-platform allocation model with group fairness is constructed; for the allocation model, a polynomial time approximation algorithm based on linear programming and network flow is designed to solve the optimal allocation scheme; according to the optimal allocation scheme and the historical project success data, the improved Reed-Solomon code technology is used for feature coding to construct a project success rate prediction model; based on the prediction model, the success rate of the project to be evaluated is evaluated and the support intensity trend is predicted. The present application improves the accuracy and efficiency of project success rate prediction.
Owner:GUIZHOU UNIVERSITY OF FINANCE AND ECONOMICS +1

Method and system for consumption based on virtual power plant

The application provides a kind of based on virtual power plant's accommodation method and system, by obtaining power grid equipment information, based on power generation equipment information constructs virtual power plant, based on power consumption equipment information estimates power consumption load, based on estimated power consumption load, renewable energy accommodation constraint and energy storage equipment information, mapping relationship is constructed between virtual power plant, power consumption equipment, energy storage equipment, based on the mapping relationship between virtual power plant, power consumption equipment, energy storage equipment, network transmission resource is configured, obtains network configuration information, based on the matching degree between virtual power plant and power consumption equipment, mapping relationship and network configuration information are updated, can make the accommodation process of renewable energy be effectively managed, and can be configured to NFV network equipment and the configuration of network flow table, guarantee the effective transmission of data and monitoring information in virtual power plant.
Owner:STATE GRID JIBEI ENERGY SAVING SERVICE +1

A network traffic concept drift detection method based on count-min sketch data structure

The application relates to a network traffic concept drift detection method based on a Count-Min sketch data structure and belongs to the network traffic analysis field. The application records the multidimensional statistical information of network traffic through a CM sketch data structure, starts from the multidimensional probability distribution of network flow, monitors the multidimensional Hellinger distance change condition every certain period, performs network traffic concept drift detection, and detects the type of network traffic concept drift based on the Euclidean distance. The application records the multidimensional statistical information of network traffic through a CM sketch data structure, saves the storage space, each dimension is relatively independent, can be processed in parallel, and saves the detection time; starts from the multidimensional probability distribution of network flow, monitors the multidimensional Hellinger distance change condition, performs network traffic concept drift detection, reduces the concept drift false detection rate and the missed detection rate, makes the detection result more accurate; can correctly identify the network traffic concept drift type, discovers new applications and distributed drift applications, and has important significance in network intrusion detection and the like.
Owner:BEIJING INST OF COMP TECH & APPL

METHOD FOR ANALYZING THE COMPUTER RISK OF A NETWORK OF INTEREST RELATED TO EXCHANGES WITH AT LEAST ONE THIRD-PARTY NETWORK

The invention relates to a method for analyzing the IT risk of a network of interest (20) directly or indirectly exchanging network flows with at least one third-party network (30, 40, 50), comprising the following steps: - retrieval of network flows captured by at least one firewall (32, 42, 52) belonging to at least one third-party network; - comparison of the destination and origin internet addresses of each retrieved network flow with at least one database of toxic internet addresses (64); each network flow incorporating at least one destination or origin internet address stored in said database of toxic internet addresses corresponding to a toxic flow; and - identification, for each toxic flow, of the nature of the risk in order to determine whether each toxic flow presents a risk to the network of interest or to one of said at least one third-party network. Figure 2.
Owner:SERENICITY

Inference-based selective flow inspection

Techniques for augmenting deep packet inspection capabilities of a network security device provisioned in a networked computing environment with inference-based flow selection to focus processing resources on network traffic that is likely to be malicious. The network device(s) may receive decryption policies comprising one or more decrypt and / or do not decrypt rules for applying the decryption policy to the network traffic. The network device may receive network traffic associated with a given connection flow through the network between a client device and a workload application, and the network device may determine whether to decrypt or refrain from decrypting the network traffic associated with the network flow based on a risk score that is generated by the network device using connection fingerprints associated with the client device and the workload application, respectively, based on behavioral characteristics of the client device and the workload, respectively.
Owner:CISCO TECHNOLOGY INC

SDN traffic classification method based on hybrid model

The invention discloses an SDN (Software Defined Network) traffic classification method based on a hybrid model, which comprises the following steps of: firstly, periodically acquiring flow table statistical information from a switch by an SDN controller, then extracting a key attribute of each network flow of the flow table statistical information in a statistical period, and preprocessing to obtain traffic characteristic data; converting the traffic characteristic data into a time sequence sample through a sliding window method; and obtaining a global correlation feature sequence of the time sequence sample by using an improved Transform, and obtaining a final time sequence feature representation of the global correlation feature sequence by using an enhanced GRU. And a classifier is used to calculate category probability distribution represented by the final time sequence features, and a flow classification result is obtained. According to the method, through an intelligent flow classification method which fuses Transform and GRU models and is combined with software defined network (SDN) architecture characteristics, online classification and strategy linkage of network flow are realized through a processing link of global correlation modeling, time sequence dependence enhancement and online feedback control.
Owner:GUILIN UNIV OF ELECTRONIC TECH

Dynamic flow rate control method and device between heterogeneous network element devices

PendingCN121967334ARealize intelligent dynamic controlimprove performanceTransmissionHigh level techniquesPacket arrivalData pack
The invention discloses a dynamic flow rate control method and device between heterogeneous network element devices, and relates to the technical field of heterogeneous network element device collaboration.The method comprises the steps that a control plane analyzes network flow duration and packet counting features through a flow feature perception model, and a flow state probability model is established to dynamically calculate the processing priority of each flow; in combination with the model and the real-time processing capacity and load of downstream equipment, a data plane dynamically adjusts the flow transmission rate by adopting a probability token bucket mechanism, and global statistical information is used for guiding a local decision; triggering statistical updating by a data packet arrival event, checking whether a preset period is exceeded or not, and synchronously updating traffic characteristics; and after reasoning analysis of the heterogeneous device coprocessing sub-model, a result is fed back to a control plane, token bucket parameters and model weights are dynamically adjusted, and closed-loop feedback of flow distribution is realized. According to the method, the overall throughput performance and the load balancing capacity in a high-speed network environment are remarkably enhanced.
Owner:TSINGHUA UNIVERSITY

Credit and credential data transmission secrecy method based on self-adaptive dynamic authority control

The invention discloses a credential data transmission secrecy method based on self-adaptive dynamic authority control. The method comprises the following steps: S1, constructing a topological structure of a data transmission network, and outputting a preliminary scheme of a dependency relationship and an encryption strategy; s2, generating a dynamically adjusted encryption and authority control strategy combination through a causal inference module; s3, the encryption and authority control strategy combination is input into a perturbation analysis module, small-range strategy perturbation is carried out, and an optimized strategy result is output; s4, inputting an optimized strategy result into a space-time adaptive prediction model based on meta-learning, and obtaining a foresight optimization strategy; s5, inputting the prospective optimization strategy into an adaptive feedback control module, and outputting a dynamic optimization real-time strategy; s6, inputting the dynamic optimization real-time strategy to a network flow state real-time monitoring module, and optimizing an encryption and authority control strategy; and S7, forming closed-loop adaptive regulation and control. According to the method, dynamic encryption and authority control are realized by adopting network topology, causal inference and meta-learning.
Owner:杭州西湖风景名胜区综合事务保障中心

DDoS attack recognition detection method and system based on self-training word segmentation device

PendingCN122053198AImplement adaptive generationAchieve collaborative optimizationSemantic analysisBiological modelsData packAttack
The invention discloses a DDoS attack recognition detection method and system based on a self-training word segmentation device, and the method comprises the steps: obtaining a data packet embedding vector through the mapping of a packet encoder, and forming a network flow packet-level embedding sequence; enabling the network flow packet-level embedding sequence to pass through a flow aggregator to obtain a flow-level embedding vector; calculating a risk score of the network flow level embedded vector through a lightweight discrimination head; inputting the risk score into a trigger, and identifying a high-risk network flow; generating a fusion embedded representation of the high-risk network flow: constructing the flow part into a flow text sequence, encoding through a self-training word segmentation device to obtain an embedded representation, and fusing the embedded representation of the natural language part and the embedded representation of the flow part into a fusion embedded representation; and inputting the fusion embedded representation of the high-risk network flow into an attack identification model to predict whether a DDoS attack exists or not. The invention relates to the field of information security networks, can solve the problems of insufficient flow representation capability, poor adaptation to attack mode change, strong dependence on annotated data and the like in the prior art, and realizes accurate detection of DDoS attacks.
Owner:BEIJING UNIV OF POSTS & TELECOMM

Method and system for constructing power intelligent device network traffic feature information library

The embodiment of the application provides a kind of power intelligent device network flow feature information library construction method and system, belong to electric digital signal processing technical field.The construction method includes: obtaining the network stream information to be processed;According to the network stream information, construct space-time diagram;The similarity of each node in space-time diagram is calculated using dynamic time warping method, to determine the weight of the edge between each two nodes;Space-time dependent feature vector in the space-time diagram is extracted using space-time attention network;The space-time dependent feature vector is trained and learned using federated self-supervised feature learning method, to obtain corresponding robust feature vector;Dynamic feature selector determines feature subset according to the robust feature vector;Based on the feature subset, construct feature information library.The construction method and system can construct power equipment network flow feature information library suitable for diversified network flow.
Owner:国网思极网安科技(北京)有限公司 +1

A method and device for evaluating the capacity of a vertical take-off and landing field for a drone

The application discloses a kind of unmanned plane vertical take-off and landing field capacity evaluation method and device, the method according to unmanned plane vertical take-off and landing field topological structure, abstract unmanned plane operation flow, determine the queuing system in unmanned plane operation flow;According to the operation mode of vertical take-off and landing field, respectively establish the queuing theory model of each queuing system in unmanned plane operation flow;According to the parameter set in the process of unmanned plane vertical take-off and landing and vertical take-off and landing field field operation parameter, determine the average service speed of each queuing system, obtain the relationship curve of the average queuing time under the stable state of each queuing system and the average arrival speed of unmanned plane;According to the maximum unmanned plane queuing time accepted by each queuing system and the relationship curve, determine the operation capacity of each queuing system;According to network flow theory, the node with minimum operation capacity of each queuing system in unmanned plane operation flow is regarded as blocked flow, and the overall operation capacity of vertical take-off and landing field is obtained.The application lays the foundation for unmanned plane flow intelligent regulation and control.
Owner:NANJING UNIV OF AERONAUTICS & ASTRONAUTICS

SDN (Software Defined Network) data center network energy-saving traffic scheduling method, equipment and storage medium

The invention discloses an SDN (Software Defined Network) data center network energy-saving traffic scheduling method, equipment and a storage medium, and belongs to the technical field of computer networks. The method comprises the following steps: determining available paths through differential evolution according to real-time traffic by utilizing the global monitoring capability of SDN on network nodes, taking a result of differential evolution as input of a simulated annealing algorithm, determining a global optimal path from the available paths, selecting a path with the highest bandwidth utilization rate while meeting the current traffic demand, and selecting a path with the highest bandwidth utilization rate. The unused switches are closed or dormant, so that the transmission of the network flow is concentrated on the least links, the number of devices working simultaneously in the network is reduced, and the purpose of reducing the energy consumption of the data center network is achieved. According to the scheduling method, the differential evolution algorithm and the simulated annealing algorithm are fused, global scheduling of the flow is achieved on the premise that the network performance requirement is met, and therefore the purpose of saving energy is achieved.
Owner:INNER MONGOLIA AGRICULTURAL UNIVERSITY

Unique element estimation in hardware

PendingUS20260135806A1TransmissionData packEngineering
A hardware-based framework is provided that enables a network device to accurately estimate the cardinality of (or in other words, the number of unique elements in) a stream of network packets processed by the device, using minimal memory and compute resources. For example, this framework can enable the network device to accurately estimate the number of unique network flows in the packet stream, the number of unique source Internet Protocol (IP) addresses in the packet stream, the number of unique flows for each of a plurality of packet classification characteristics (e.g., ingress ports on which the packets were received, egress ports on which the packets are sent out, etc.), and so on.
Owner:ARISTA NETWORKS INC

Intranet traffic-oriented security detection method, device, equipment and medium

The present disclosure provides an intranet traffic-oriented security detection method, device, equipment and medium, comprising: reassembling interactive traffic packets into complete network session flows; deeply analyzing the network session flows to obtain unstructured data; structuring and converting the unstructured data to obtain structured feature data; extracting network flow features, application layer semantic features and entity behavior sequence features from the structured feature data; performing anomaly detection on the network flow features, application layer semantic features and entity behavior sequence features according to an unsupervised anomaly detection model to obtain an anomaly representation score; if it is determined that the intranet interactive behavior belongs to an abnormal event, performing context enhancement analysis on the intranet interactive behavior according to interactive correlation information to obtain context enhancement analysis data; adjusting the anomaly representation score according to the context enhancement analysis data; and determining an intranet traffic detection result according to the anomaly representation score. Thus, the security detection accuracy of intranet traffic is effectively improved.
Owner:NO 15 INST OF CHINA ELECTRONICS TECH GRP

Traffic light detection method, system and device based on network flow multi-target tracking

The application discloses a signal lamp detection method, system and device based on network flow multi-target tracking, and belongs to the field of image and video processing. First, the detection results of a YOLOv7 target detection neural network are divided into auxiliary signal lamp detection results and direction indicating signal lamp detection results, a minimum cost flow network flow graph is constructed for the auxiliary signal lamp target detection results, a plurality of auxiliary signal lamp trajectories are obtained by solving, then the shape categories of the auxiliary signal lamps in each auxiliary signal lamp trajectory are determined according to the direction indicating signal lamp detection results, and the color categories of the direction indicating signal lamps in the auxiliary signal lamps are detected by using a color detection classification network. Statistics and image color features are used to supplement detection and classification of the direction indicating signal lamps. The application can improve the detection accuracy of signal lamps by using the signal lamp detection results of a video, multi-target tracking and supplementary detection.
Owner:NANKAI UNIV

A bot host detection method, device, equipment and storage medium

This application discloses a method, apparatus, device, and storage medium for detecting botnet hosts. The method includes: acquiring NetFlow data of the network traffic of the host to be detected; extracting features from the NetFlow data to obtain target feature information; and using a KNN algorithm model to detect the target feature information to determine whether the host to be detected is a botnet host. This method improves detection efficiency by extracting target feature information consistent with botnet hosts based on NetFlow data. Furthermore, the use of the KNN algorithm model improves detection accuracy, enabling rapid identification of botnet hosts and timely blocking of malicious requests initiated by them, resulting in good timeliness.
Owner:CHINA MOBILEHANGZHOUINFORMATION TECH CO LTD +1

Model creation and management using a model management service

ActiveUS12694198B2Data packModel management
Model creation and management using a model management service can include obtaining model management data that comprises modeling data that defines a project to model, the project including a network flow, a network system, a device, or a process; detecting, in the model management data, a selection of a template to apply to the project to generate the model; and creating, based on the model management data and the template, the model. The model can include a directory, a data structure, and a diagram that describes the project. The model can be converted into a device-agnostic format version of the model and loaded to a data storage resource as model data that can include the device-agnostic format version of the model.
Owner:AT&T INTELLECTUAL PROPERTY I L P

Efficient DDoS detection and defense method and system suitable for industrial internet of things

The application discloses a DDoS detection and defense method and system suitable for an industrial Internet of Things, comprising the following steps: acquiring network packet data to be detected, extracting statistical features of five-tuple network flow and three-tuple network flow from the network packet data to be detected respectively, so as to obtain a first feature set and a second feature set respectively; performing slice field integrity verification and packet feature information conflict determination on the detection network packet data, so as to obtain a packet feature check feature set; fusing the first feature set, the second feature set and the packet feature check feature set to form a fusion feature set, then performing feature filtering to obtain a target feature set; inputting the target feature set into a random forest classification model to obtain a classification result; and outputting a defense instruction according to the classification result. The method has a detection accuracy, precision, recall rate and F1 value of more than 99% in a high-bandwidth and low-delay environment, and has high robustness and engineering usability.
Owner:ZHEJIANG UNIV +1