Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

189 results about "Network activity" patented technology

Systems and methods for system collusion detection

Systems and methods of generating fraud detection models and controlling network permissions of one or more systems within a network environment are disclosed. A network activity dataset comprising data representative of network activity within a network environment is received and at least one co-controlled system in the network activity dataset is identified by implementing a trained fraud detection model configured to receive the network activity dataset and output a fraud determination for each system having at least a first role in the network activity data. The fraud determination represents a likelihood of a system having the first role engaging in a co-controlled network activity. In response to identifying the at least one co-controlled system, one or more permissions of the at least one co-controlled system for operating within the network environment are modified.
Owner:WALMART APOLLO LLC

Network traffic anomaly detection method and system based on knowledge graph

The invention relates to the technical field of network security, and discloses a network traffic anomaly detection method and system based on a knowledge graph, and the network traffic anomaly detection method comprises the following steps: protocol perception metadata feature extraction: extracting metadata features which do not involve content privacy from encrypted network traffic through a deep packet inspection technology, comprising flow statistical characteristics, time sequence characteristics and connection relation characteristics; multi-level knowledge graph construction: based on the extracted metadata features, according to a network architecture, respectively constructing corresponding knowledge graphs on a device layer, a gateway layer and a cloud layer, and respectively representing device behaviors, network activities and global security information; the method does not depend on flow decryption operation, effective recognition of abnormal behaviors in the encrypted flow is achieved only by analyzing the metadata features of the network flow, and therefore the detection accuracy is improved.
Owner:TIANJIN UNIV

Risk engine that utilizes key performance indicators

Risk engine using key performance indicators, including: monitoring network activity associated with a customer to identify one or more infrastructure risks; calculating, based on the identified one or more infrastructure risks, a key performance indicator (KPI); and presenting, via a user interface, a comparison of a risk metric associated with the customer to one or more other risk metrics corresponding to one or more cohorts of the customer selected based on a variable input to a user interface element of the user interface.
Owner:FORTINET INC

Adaptive anomaly context description

Techniques are disclosed for providing a context-aware description of anomalous behavior in a computer network. According to one embodiment of the present disclosure, a description of an anomaly detected in computer network activity is received. The description includes one or more features of the computer network associated with the anomaly. Contextual information relating to at least one of the features is generated based on a logical network topology. The logical network topology specifies a plurality of network traffic attributes of the computer network. An alert that includes a second description of the anomaly and the contextual information is generated.
Owner:INTELLECTIVE AI INC

Cloud resource risk scenario assessment and remediation

An illustrative method for performing a risk scenario assessment and remediation may include identifying, based on posture data associated with a compute environment, one or more compute resources deployed in the compute environment that are configured to be connected to a network, accessing runtime workload data associated with the one or more compute resources representative of network activity for the one or more compute resources, and performing, based on the posture data and the runtime workload data, a remediation operation associated with the one or more compute resources.
Owner:FORTINET INC

Real-time neural network architecture adaptation through supervised neurogensis during inference operations

A system and method for adaptive neural network architecture with real-time neurogenesis capabilities during inference operations. The system processes data through a core neural network with integrated supervisory and neurogenesis control systems. A hierarchical supervisory network, comprising low-level, mid-level, and high-level nodes, monitors network activity patterns and information flow. The neurogenesis control system maintains continuous activity maps, detects processing bottlenecks, and determines optimal placement of new neurons using geometric optimization. A modification subsystem implements controlled neurogenesis operations while maintaining network stability. The system handles data through adaptive codeword allocation and fusion of dissimilar data types. This sophisticated approach enables neural networks to dynamically expand their processing capacity during operation, responding to detected bottlenecks while maintaining operational stability through carefully managed integration of new neurons.
Owner:ATOMBEAM TECH INC

Anomaly detection in network traffic data

This disclosure relates to systems, methods, and devices for identifying anomalous network activity. In some embodiments, a baseline model is used for identifying anomalous network activity. In some embodiments, anomalous network activity is detected based on a z-score, modified z-score, or both being above respective thresholds when compared to the baseline. In some embodiments, multiple baseline models are used, and anomalous network activity is detected when multiple baseline models identify a network activity session as anomalous. In some embodiments, two baseline models are used.
Owner:ARMIS SECURITY LTD

Intelligent liquid cooling of electronic devices by actively controlled manifolds

A system configured for cooling electronic devices comprises a pair of opposing, active manifolds that control a flow of cooling liquid through pipes or through an immersion tank past the electronic devices. A controller detects and / or predicts localized hotspots and adjusts flow control devices associated with inlets and outlets of the manifolds to direct proportionately more cooling liquid to the hotspots. The flow control devices can be any combination of variable speed pumps and / or adjustable valves, vents, and / or baffles. Manifolds can be placed on two opposing sides of the devices, on four opposing sides, and / or above and / or below the devices. Temperatures proximate the devices can be measured by separate sensors and / or sensors integral to components of the electronic devices. Hotspots can be predicted by monitoring current flows, power flows, and / or voltages of the electronic devices, and / or inferred from network activity and / or from a workload queue.
Owner:FLOWSERVE PTE LTD

Network attack tracing method, device, equipment and medium

The invention discloses a network attack tracing method, device and equipment and a medium, and the method comprises the steps: obtaining a plurality of network flow data packets, a plurality of pieces of weblog data and a plurality of equipment state parameters of a plurality of monitoring nodes in a target network domain; determining an abnormal node with a network attack behavior in the plurality of monitoring nodes based on the plurality of network flow data packets, the plurality of pieces of network log data and the plurality of equipment state parameters; and tracing the network attack behavior based on the abnormal data packet of the abnormal node, the abnormal weblog data and the abnormal equipment state parameter to obtain an attack type, an initial attack node and an attack path of the network attack behavior. The collaborative analysis value of data packet deep features and multi-source equipment information is fully utilized, real threats and normal network activities are accurately distinguished, and the traceability accuracy and reliability are remarkably improved. Meanwhile, through correlation analysis of multi-dimensional data, an attack source positioning range can be converged step by step, and an attack path can be completely reconstructed.
Owner:CHINA DATANG CORPORATION SCIENCE AND TECHNOLOGY GENERAL RESEARCH INSTITUTE

System and method for outage prediction

An exemplary method, for preventing an outage in a network, includes collecting network metrics and producing statistical features of the network during a predetermined time window based on statistical analysis of the collected metrics. The method further includes selecting, from the produced statistical features, a first data set of relevant statistical features. Further, the method includes collecting information about a past event, extracting event data from the past event, and vectorizing the extracted event data to form a second data set. The method further includes concatenating the first data set and the second data set to form a third data set and classifying the third data set relative to a model of historical network performance to determine a probability of the outage. Further, the method includes modifying, in response to the probability being above a threshold, the network / activity within the network to avoid onset of the outage.
Owner:COMPUTER SCIENCES CORP

Signature quality evaluation

Systems and methods for scanning network activity. The methods include receiving at an interface connection data regarding a plurality of network connections, wherein the connection data includes a signature used to classify each of the plurality of network connections; determining, using one or more processors executing instructions stored on memory to provide a signature analysis engine configured to analyze the connection data, the signature is prohibitively prone to misclassifying network activity as malicious, wherein the determination is based on the analysis of the connection data; and implementing a signature policy to prevent the signature from misclassifying network activity as malicious.
Owner:SOPHOS LTD

System and method of identifying malicious activity in a network

Disclosed herein are methods and systems for identifying malicious network activity. In an embodiment, a method comprises monitoring, by a computer, network activity of a user having a baseline network activity; executing, by the computer, a machine learning model to determine a network activity score indicating a likelihood of the network activity being malicious activity for the baseline network activity, the machine learning model having been previously trained based on malicious activity and corresponding baseline network activity; and displaying, by the computer, the network activity score.
Owner:MASSACHUSETTS MUTUAL LIFE INSURANCE CO

Network attack path deduction method and device based on large language model, equipment and medium

The invention discloses a network attack path deduction method and device based on a large language model, equipment and a medium, and relates to the technical field of network security, and the method comprises the steps: generating each initial deduction result corresponding to a current abnormal network activity through employing a target large language model and a beam search algorithm; verifying each initial network attack deduction path by using a target knowledge graph to obtain a target confidence degree corresponding to each initial network attack deduction path; and determining a target network attack path with the highest target confidence from the initial network attack deduction paths, and determining an initial deduction result corresponding to the target network attack path as a target deduction result so as to display the target deduction result by using a time sequence animation. The initial network attack deduction path is generated by using the large language model, and the target network attack deduction path is determined based on the knowledge graph, so that the problem that complex and changeable attack techniques cannot be adapted due to rule engine stiffness is solved.
Owner:SHANDONG LANGCHAO YUNTOU INFORMATION TECH CO LTD

Network attack and defense simulation engine system based on discrete event driving

The invention belongs to the technical field of network attack and defense simulation, and discloses a network attack and defense simulation engine system based on discrete event driving, which comprises an event scheduling module, a simulation network construction module, an attack and defense simulation module, a simulation kernel module and a panoramic situation awareness module, the event scheduling module is in the form of MITRE ATTamp; the CK is constructed as a theoretical base and is used for converting all network activities into a dispatchable discrete event sequence; the network activities comprise data packet sending, protocol timeout and attack triggering; and the simulation network construction module can construct a simulation network containing complete service logic. According to the application, the MITRE ATTamp is scheduled by the event scheduling module; the CK tactical intention is converted into an ordered event stream, a hierarchical task network planner in the attack and defense simulation module dynamically decomposes and re-plans a high-level target, and ATTamp can be utilized; and the CK technology ID reconstructs an attack chain in real time.
Owner:BEIJING ZHANGBA NETWORK SECURITY TECH CO LTD

Alarm causal association attack investigation method fusing honey point intelligence

The invention discloses an alarm causal association attack investigation method fusing honey point intelligence, which comprises three steps of benign database construction, abnormal score calculation and alarm point association. The method comprises the following steps: firstly, collecting an original audit log, normalizing the original audit log into a triple format, constructing a traceability graph, and constructing a benign database; then obtaining an audit log to be detected, normalizing the audit log to be detected into a triple format to construct a traceability graph to be detected, and comparing the traceability graph to be detected with the benign database to calculate an event occurrence frequency of a system event to be detected; calculating a weight score for each to-be-detected system event in combination with honey point information; and finally, reading an alarm point from the to-be-detected audit log, constructing a weighted traceability graph to perform backtracking causal analysis, and finding an attack entry point by using a depth-first search algorithm. And forward analysis is carried out to restore a complete attack scene graph. According to the method, the key attack path can be positioned more quickly, the whole network activity does not need to be comprehensively analyzed, and computing resources and analysis time are saved.
Owner:GUANGZHOU UNIVERSITY

Closed-loop feedback target extraction method based on frontal top electroencephalogram network activity reference model

The invention discloses a closed-loop feedback target extraction method based on a frontal top electroencephalogram network activity reference model, and relates to the fields of neural information decoding, neuroscience application and brain-computer interfaces. According to the method, the problem of insufficient target selection and feedback regulation and control precision in traditional electroencephalogram closed-loop feedback is solved, and a new electroencephalogram network target extraction mode which is good in ecological property and high in robustness is provided. The method mainly comprises the steps that firstly, a brain network path closely related to memory cognitive function abnormity of mild cognitive impairment (MCI) is extracted in a natural film watching state, network characteristics are refined in combination with metabolic map information, a new brain network target fed back by a real-time electroencephalogram closed loop is formed, and the ecological property of the target and the pertinence of feedback are remarkably improved. Besides, based on a large amount of normal elderly group electroencephalogram data, a frontal top electroencephalogram network activity reference model of the normal elderly group in a movie recalling state is constructed, key feedback indexes are extracted by using a machine learning algorithm, real-time evaluation of the relative performance level of MCI individuals is realized, and the accuracy of evaluation is improved. And a technical support is provided for improving the cognitive function of the MCI patient.
Owner:UNIV OF ELECTRONICS SCI & TECH OF CHINA

Network anomaly detection

A method of identifying anomalous network activity. The method includes identifying, based on network data representative of network activity within a network, at least one instance of a sequence of events that occurred within the network. A probability of the sequence of events occurring during non-anomalous network activity is obtained based on transition probabilities between events in the sequence of events. A frequency characteristic dependent on a frequency at which the sequence of events occurred within the network is determined. A likelihood of the sequence of events occurring within the network at the frequency is determined based on a combination of the probability and the frequency characteristic. It is identified, based on the likelihood, that at least a portion of the network data is anomalous.
Owner:BRITISH TELECOM PLC

An IoT-based backup and recovery system

An IoT-based backup and recovery system that features: a system initialization to load policies and set baselines; a microcontroller connected to several modules, including: a multi-layered module that captures kernel events, network activity, user behavior, memory analysis, and container inspection; a module for time-bound differential micro-snapshots for signal processing to obtain spectral values; an AI-driven threat classification module for precise attack identification; an event tree-based forensic tagging module for creating maps of causal relationships between system events for a complete attack path; Policy-oriented recovery rules with context-aware policies that adapt depending on the type of attack and business impact; and a surgical rollback engine for component-specific recovery without service interruption.
Owner:DESWAL SATVIR SINGH +6

Method and system for sensor alarm reporting and UE-to-UE communication in radio access networks

The present disclosure provides a method (100) and a system (200) for reporting a sensor alarm and facilitating UE-to-UE communication in a radio access network (RAN). The method (100) includes the radio access network receiving (102) within a predefined margin, an early notification of the sensor alarm from a first user equipment (UE), terminating (104) one or more scheduled or ongoing network activities impacting call performance of a UE upon receipt of the early notification of the sensor alarm and initiating (106) tracking of reachability of the first UE by the RAN. Further, the method (100) includes continuing (108) tracking of reachability of the first UE by the RAN, where if the first UE remains reachable no further action is taken by the RAN, and if the first UE becomes unreachable send a command from the RAN to one or more surrounding UEs instructing them to activate UE-to-UE wireless communication.
Owner:YAMINE BADAWI

Detecting security threats from logon data

This disclosure describes techniques for analyzing network traffic to generate an actionable insight pertaining to a security threat to a network. In one example, this disclosure describes a method that includes obtaining, by a computing system, historical network activity data that includes information about authentication traffic within a network; determining, by the computing system and based on the historical network activity, a baseline of network activity; collecting, by the computing system, a set of network activity data; applying, by the computing system, an unsupervised algorithm to identify the set of network activity data as anomalous relative to the baseline of network activity; classifying, by the computing system, the network activity data into an identified threat category from among a plurality of threat categories; and taking action, by the computing system and based on the identified threat category, to mitigate a security threat posed by the network activity data.
Owner:WELLS FARGO BANK NA

System and method for mitigating cyber security threats by devices using risk factors

A system and method for mitigating cyber security threats by devices using risk factors. The method includes determining a plurality of risk factors for a device based on a plurality of risk behaviors indicated by network activity and information of the device, wherein the plurality of risk behaviors includes observed risk behaviors and assumed risk behaviors, wherein the observed risk behaviors are indicated by data related to network activity by the device, wherein the assumed risk behaviors are extrapolated based on known contextual information related to the device; determining a risk score for the device based on the plurality of risk factors and a plurality of weights, wherein each of the plurality of weights is applied to one of the plurality of risk factors; and performing at least one mitigation action based on the risk score.
Owner:ARMIS SECURITY LTD

Systems and methods for web spike attribution

Systems and methods are disclosed that measure web activity bursts after ad broadcasts that may be sent to multiple persons. One system uses a cookie-less / cookie-optional, anonymous / personal-identification-not-required, method for web-based conversion tracking that will work on broadcast media systems such as television, and could also be applied to measuring spikes from email, radio, and other forms of advertising where an episodic ad event is broadcast to multiple parties, and where responses occur in a batch after the broadcast.
Owner:YAHOO IP HOLDINGS LLC +1

System and method for real-time detection of code integrity violations

A system and method are provided for real-time detection of code integrity violations by combining behavioral stylometry, biometric fingerprinting, and environmental threat analysis. Baseline data of a user's coding style such as indentation, variable naming, and keystroke patterns are stored and compared to live input to calculate deviation scores. Typing behaviors like dwell time, rhythm, and simulated pressure form a biometric fingerprint, while environmental scans detect suspicious network activity, browser extensions, or virtual machine use. A combined risk score is generated, and automated interventions are triggered when it exceeds a threshold, enabling early detection of unauthorized access, AI-generated code, or compromised environments for secure software development.
Owner:BOYLE DANIEL

Unified device identity through correlation of multi-interface network activity

Methods and systems for accurately identifying and tracking electronic devices communicating across heterogeneous networks, even when those devices utilize multiple in-device network interfaces and change identifiers. The system receives network activity indications from various devices, each indication associated with a specific network interface and identifier. A correlation process, potentially employing a machine learning model, analyzes these indications to identify a sub-set originating from a single physical electronic device, spanning at least two different in-device network interfaces (e.g., cellular and Wi-Fi). A unified device identity, a persistent digital representation (or “digital twin”) of the device, is generated based on this correlated sub-set. This unified identity remains associated with the physical device regardless of interface changes, enabling consistent application of security policies, improved network visibility, accurate device tracking, and efficient resource allocation. The system handles both mandatory identifiers, which are associated with specific in-device network interfaces, as well as weak transitory identifiers.
Owner:ONE LAYER LTD

Systems and methods for managing network devices using augmented reality

Systems and methods are described herein for controlling network devices in an augmented reality environment. A user may point a second network device at a first network device to determine a network activity the first network device. The second network device may display a user control interface to enable the user to control the network activity of the first network device (e.g., a pinch gesture control). In response to receiving the user input, the second network device causes the modification of the network activity based on the user input.
Owner:ADEIA GUIDES INC

Network security monitoring method

The invention discloses a network security monitoring method, which comprises the following steps of: acquiring full-life-cycle data and attributes of network processes in real time, constructing a process chain table and an associated network, and sorting a relationship between the processes; secondly, matching a network event with a process timeline, dynamically dividing a time window according to a process life cycle, calculating a process time characteristic and a network activity characteristic, comparing a historical normal mode, quantifying a difference by utilizing an algorithm, and identifying an abnormal process; then, inputting the comparison process into a support vector machine to establish a prediction model, and predicting an abnormal process in real time; and finally, abnormal process information is fed back to the security equipment, and abnormal files are positioned and isolation / deletion operation is executed in combination with network behavior data association analysis. According to the method, the abnormal process can be accurately identified, misjudgment is reduced, the sensitivity requirements of different service scenes are met, the abnormal file is positioned by means of network behaviors, and the accuracy and timeliness of network security protection are effectively improved.
Owner:GUIZHOU BLUESKY INNOVATIVE SCI & TECH CO LTD

Systems and methods for managing network devices using augmented reality

Systems and methods are described herein for controlling network devices in an augmented reality environment. A user may point a second network device at a first network device to determine a network activity the first network device. The second network device may display a user control interface to enable the user to control the network activity of the first network device (e.g., a pinch gesture control). In response to receiving the user input, the second network device causes the modification of the network activity based on the user input.
Owner:ADEIA GUIDES INC

Methods and apparatus of identification of streaming activity and source for cached media on streaming devices

Methods, apparatus, systems and articles of manufacture are disclosed for identification of streaming activity and source for cached media on streaming devices. An example system stores, in a content identification information library, first content identification information of a first media presentation, wherein the first media presentation is a streamed media presentation; inspects a network connection of a media streaming device for network activity associated with a second media presentation; determine, in response to an absence of the network activity, the second media presentation is a cached media presentation; infers a streaming source of the second media presentation by matching second content identification information of the second media presentation with the first content identification information of the first media presentation; and generates a second media credit for the second media presentation that includes an inferred streaming source identifier.
Owner:THE NIELSEN CO (US) LLC

Method for outputting brain region reality through neural feedback training

The invention relates to a method for outputting brain region reality through neural feedback training. The method comprises the following steps: transmitting a physical and psychological parameter related to a testee in the form of a neurophysiological signal; performing signal processing, feature acquisition and mode judgment on the neurophysiological signal; providing a neurophysiological feedback parameter and performing a brain area network activity; and converting into a brain region reality through a brain-computer interface so as to present an interaction scene and an interaction element for the testee to perform brain / brain region training. Therefore, the brain region training state of the testee can be obtained in real time, and the testee can know the brain region state of the testee through a visual means, so that communication between the testee (or family members or related persons) and professionals (such as doctors) is facilitated.
Owner:SUZHOU GOOD MATCH HEALTH MANAGEMENT CO LTD +1

system

We provide the system. [Solution] Data collection methods for monitoring online activity, AI processing means for analyzing the aforementioned data and detecting anomalies, A notification means for sending an alert to a guardian based on the aforementioned abnormality, A system that includes this.
Owner:SOFTBANK GROUP CORP