Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

67 results about "Network activity" patented technology

Cloud resource risk scenario assessment and remediation

An illustrative method for performing a risk scenario assessment and remediation may include identifying, based on posture data associated with a compute environment, one or more compute resources deployed in the compute environment that are configured to be connected to a network, accessing runtime workload data associated with the one or more compute resources representative of network activity for the one or more compute resources, and performing, based on the posture data and the runtime workload data, a remediation operation associated with the one or more compute resources.
Owner:FORTINET INC

Network security monitoring method

The invention discloses a network security monitoring method, which comprises the following steps of: acquiring full-life-cycle data and attributes of network processes in real time, constructing a process chain table and an associated network, and sorting a relationship between the processes; secondly, matching a network event with a process timeline, dynamically dividing a time window according to a process life cycle, calculating a process time characteristic and a network activity characteristic, comparing a historical normal mode, quantifying a difference by utilizing an algorithm, and identifying an abnormal process; then, inputting the comparison process into a support vector machine to establish a prediction model, and predicting an abnormal process in real time; and finally, abnormal process information is fed back to the security equipment, and abnormal files are positioned and isolation / deletion operation is executed in combination with network behavior data association analysis. According to the method, the abnormal process can be accurately identified, misjudgment is reduced, the sensitivity requirements of different service scenes are met, the abnormal file is positioned by means of network behaviors, and the accuracy and timeliness of network security protection are effectively improved.
Owner:GUIZHOU BLUESKY INNOVATIVE SCI & TECH CO LTD

system

We provide the system. [Solution] Data collection methods for monitoring online activity, AI processing means for analyzing the aforementioned data and detecting anomalies, A notification means for sending an alert to a guardian based on the aforementioned abnormality, A system that includes this.
Owner:SOFTBANK GROUP CORP

Systems, methods, and computer programs (dynamic resource compliance determination for containerized systems)

For crypto assets mounted to pods as files or environment variables, security and compliance can be complex and therefore may be inadequately managed. [Solution] The system may include memory and a processor that communicates with the memory. The processor may be configured to perform operations. The operations may include steps to monitor network actions between resources in a network and steps to extract encrypted data from the network actions. The operations may include steps to detect connection security data from the encrypted data and steps to obtain resource health reports for the resources in the network. The operations may include steps to merge the connection security data with the resource health reports and steps to generate security compliance reports.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Multi-model detection of malicious URL using its network

A URL is input into a virtual browser of a crawler which requests that URL and all of its resource URLs in order to form a network graph. Network features are extracted. An identity stage uses an identity model based upon lexical and host features to determine if the input URL and resource URLs are malicious or benign. A similarity stage uses a similarity model and similarity functions to produce a similarity score between each pair of the input URL and a resource URL. An activity stage uses an activity model to determine if the input URL's network is malicious or benign based upon the network graph and extracted network activity features. Edges of the graph are weights, similarity scores, attributes or network features. A finality stage concludes malicious if the identity stage concluded that the URL was malicious or the activity stage concluded that the URL's network was malicious.
Owner:TREND MICRO INC

Microservice architecture-oriented network security detection method and device

The embodiment of the invention provides a micro-service architecture-oriented network security detection method and device. The method comprises the following steps of: respectively acquiring communication flow between virtual machines and a network activity track of a container through a virtual switch port mirror image and a log interface of a container platform; constructing a dynamic baseline model containing a legal communication matrix, a protocol white list and a traffic threshold; comparing the acquired data with the dynamic baseline model by adopting a real-time stream processing technology, and detecting an abnormal behavior of the container or the virtual machine; and executing response measures of different levels according to the seriousness of the abnormal behavior threat. According to the scheme, internal attack behaviors such as container escape and transverse penetration can be effectively identified and coped with.
Owner:NO 15 INST OF CHINA ELECTRONICS TECH GRP

Zero-knowledge secure and private monitoring channel

Systems and methods for securely and privately monitoring risky web activities in an enterprise computing system. A service is provided that communicates with a first client- application deployed on a user device and a second client-application deployed on an administrator device. A secure enclave is deployed by the service that ensures zero-knowledge to store sensitive user data (e.g., activity logs of risky web activity logged by the first client- application). Team-Service Logged-Out keys and Team-Enclave Logged-Out keys are deployed to the user device. When an end user associated with the user device is not logged into the service, the Team-Service Logged-Out keys and Team-Enclave Logged-Out keys are used to authenticate the logged-out end user so that an activity log can be sent to the secure enclave and stored. The activity log can be accessed by the second client-application upon authentication of the administrator using a Device-Enclave key pair associated with the administrator.
Owner:DASHLANE

Full-flow threat sensing and tracing system oriented to cloud native environment

The invention belongs to the technical field of cloud native environments, and particularly relates to a cloud native environment-oriented full-flow threat sensing and tracing system, which comprises a data acquisition layer deployed on each computing node of a cloud native cluster and used for acquiring east-west network flow and north-south network flow; the data preprocessing and storage layer is connected with the data acquisition layer, and is used for performing analysis, specification and standardization processing on the acquired original traffic and storing the processed original traffic as a structured traffic log; the dynamic strategy engine is connected with the data preprocessing and storage layer and is used for generating and adjusting a security strategy based on a real-time flow analysis result; and carrying out visualization and traceability analysis. According to the invention, through multi-level data acquisition and fusion, all-around deep monitoring of network activities in a cloud native environment is realized, and specifically, an eBPF probe is deployed on a kernel layer of an operating system in a data acquisition layer, so that basic network connections and data packets of all Pods can be captured without invasion.
Owner:SHAOYANG JINXIN TECHNOLOGY CO LTD

Device anomaly detection based on DNS queries

PCT designated stageWO2026049806A1TransmissionDomain nameNetwork activity
Techniques for providing device anomaly detection based on DNS queries are disclosed. In some embodiments, a system, a process, and / or a computer program product for device anomaly detection based on DNS queries includes receiving Domain Name System (DNS) network activity, wherein the DNS network activity includes a plurality of DNS queries; processing the DNS network activity to generate a plurality of metrics; and automatically detecting anomalies associated with one or more devices for a monitored network.
Owner:INFOBLOX INC

Method and system for monitoring and addressing anomalies detected during a field operation

A method for monitoring and autonomously addressing anomalies related to a site. The method includes receiving data from a plurality of sources or equipment disposed within a wellsite. An anomaly may be identified within the received data by analyzing performance metrics to determine a high latency and load related to the equipment within the wellsite, analyzing firewall logs and IDS alerts to confirm if there has been suspicious network activity related to the wellsite, identifying repeated connection errors and latency spikes from the network connectivity data or identifying a rapid increase in data volume within the database data related to the wellsite equipment. An insight may then be generated based on the identified anomaly and then a command based on the generated insight is transmitted to the wellsite equipment. A wellsite action based on the transmitted command can then be performed to resolve the anomaly.
Owner:SCHLUMBERGER TECH CORP +3

A network attack and defense simulation engine system based on discrete event driving

The application belongs to the technical field of network attack and defense simulation, and discloses a network attack and defense simulation engine system based on discrete event driving, which comprises an event scheduling module, a simulation network construction module, an attack and defense simulation module, a simulation kernel module and a panoramic situation awareness module; the event scheduling module is constructed based on MITRE ATT&CK as a theoretical base and is used for converting all network activities into a schedulable discrete event sequence; the network activities comprise packet sending, protocol timeout and attack triggering; the simulation network construction module can construct a simulation network containing complete business logic. The application can convert the MITRE ATT&CK tactical intention into an ordered event stream through the event scheduling module, and can simultaneously perform dynamic decomposition and re-planning on a high-level target through a hierarchical task network planner in the attack and defense simulation module, and can also reconfigure an attack chain in real time by using an ATT&CK technology ID.
Owner:BEIJING ZHANGBA NETWORK SECURITY TECH CO LTD

Methods for non-invasive API discovery, monitoring and exploitation detection in third-party processes

System and method for non-invasive monitoring and exploitation detection in third-party software processes. The system includes modules for scanning process memory to identify sensitive credentials such as application programming interface (API) keys and tokens, monitoring opened file descriptors including files, sockets, and inter-process communication channels, and analyzing network activity including domain name system (DNS) requests and encrypted connections. Runtime metadata such as privileges, environment variables and resource usage is also collected. The system correlates these signals to detect indicators of exploitation, such as unauthorized access, privilege escalation, or injected payloads, without modifying or instrumenting the monitored process. Integration with external security systems may enhance detection accuracy. Alerts and reports are generated in real-time to support incident response and forensic analysis.
Owner:WALLARM INC

Hybrid server-side client-side rendering of medical images

Methods, systems, and computer-readable medium for rendering medical images are provided. In one example, a method includes creating a first rendered image from a set of scan data in response to a request from a client device. The first rendered image is then sent to the client device for display based on a subset of the set of scan data, and after sending the first rendered image to the client device for display, sending the set of scan data to the client device for use to render additional images based on the set of scan data (e.g., rendering additional images from the scan data locally at the client). The set of scan data can be streamed or sent to the client device in the background, during low network activity times, etc., in parallel or after sending the requested medical image.
Owner:FOVIA INC

Honeypot deployment method and device fusing Bayesian attack graph and reinforcement learning algorithm, and computer equipment

The invention relates to a honeypot deployment method and device fusing a Bayesian attack graph and a reinforcement learning algorithm, computer equipment, a computer readable storage medium and a computer program product. The method comprises the following steps: acquiring network observation data associated with an abnormal network activity when detecting that the abnormal network activity exists in a target network; determining updated attack information according to the network observation data and a Bayesian attack graph corresponding to the target network; the updated attack information represents the updated belief state and the updated attack path probability; according to the updated attack information, a defense strategy set for the target network is optimized through a reinforcement learning algorithm, and a honeypot deployment strategy is output based on the updated defense strategy; the attacked probability and the defense efficiency of the target node meet preset conditions; and according to the honeypot deployment strategy, deploying preset honeypot resources on the target node. By adopting the method, the capability of resisting network attack behaviors can be improved.
Owner:CHINA SOUTHERN POWER GRID COMPANY

Payment-accepting entity cyber threat detection

In some aspects, the techniques described herein relate to a method, including: detecting, by a security system on a payment network, an anomaly associated with potential suspect activity in payment network activity associated with a particular merchant; retrieving, by the security system, a merchant identifier corresponding to the particular merchant, a merchant web address associated with the particular merchant, and time information of the anomaly; identifying a source for the potential suspect activity on the payment network by: obtaining IP network traffic data associated with the merchant web address and the time information of the anomaly; evaluating, by the security system, the IP network traffic data for patterns in the IP network traffic data that correspond to the anomaly; and determining, by the security system, a source IP address from the patterns in the IP network traffic data that correspond to the anomaly.
Owner:MASTERCARD INT INC

Threshold Modulation for Efficient Context Implementations

A context-modulated neural network is provided. The network comprises a number of neurons that receive input data, wherein a context modulates network activity by altering a number of network parameters such that network output depends on a combination of the context and the input data. A number of different sets of network parameters govern operation of the network, wherein the context determines which set of parameters is applied to the neurons.
Owner:BOARD OF RGT THE UNIV OF TEXAS SYST

Systems and methods for network policy and parental controls based on spatial awareness

Disclosed are systems and methods that provide a computerized network management framework that provides novel network functionality for devices connected to and / or operating in proximity to wireless networks. The framework provides functionality for leveraging monitored and / or determined spatial awareness related to users and / or their devices in order to create intelligent network-based zones for which network management and / or connectivity can be provided, controlled and managed. The disclosed spatially intelligent zones can correspond to and / or be subject to applied network policies and / or parental controls, for which network activity within such zones can be managed and controlled. Accordingly, the disclosed framework can provide dynamic network capabilities and functionality based on the current position of the user within a location.
Owner:PLUME DESIGN INC

Detecting and protecting claimable non-existent domains

Techniques for detecting and protecting claimable non-existent domains are disclosed. A system, process, and / or computer program product for detecting and protecting claimable non-existent domains includes monitoring network activity using a network security device, detecting that a session is querying a claimable non-existent domain using a domain name system (DNS) security service, and performing an action in response to the session querying the claimable non-existent domain.
Owner:PALO ALTO NETWORKS INC

Systems and methods for online user activity verification and authentication for enhanced network security

Systems and methods of the present disclosure enable improved network security by authenticating the identity of the user initiating the network activities. A network operations center of a wireless communication network system may implement an authentication service to monitor for network activities initiated via communications through a router of the wireless communication network system. The router may identify communications to be authenticated and provide the communication and / or associated data to the authentication service. The authentication service may analyze the data based on usage and performance data associated with the router(s) as well as user profile data associated with the user to verify that the user is the sender of the communication, thus authenticating the identity of the user. The authentication may then be communicated to third-party entities associated with the network activity to enable such third-party entities to confirm or deny the network activity.
Owner:PLUME DESIGN INC

Systems and methods for network policy and parental controls based on spatial awareness

Disclosed are systems and methods that provide a computerized network management framework that provides novel network functionality for devices connected to and / or operating in proximity to wireless networks. The framework provides functionality for leveraging monitored and / or determined spatial awareness related to users and / or their devices in order to create intelligent network-based zones for which network management and / or connectivity can be provided, controlled and managed. The disclosed spatially intelligent zones can correspond to and / or be subject to applied network policies and / or parental controls, for which network activity within such zones can be managed and controlled. Accordingly, the disclosed framework can provide dynamic network capabilities and functionality based on the current position of the user within a location.
Owner:PLUME DESIGN INC

Software-Defined Wide Area Network Self-Service for Service Assurance

The concepts and technologies disclosed herein are directed to software-defined wide-area network (“SD-WAN”) self-service for service assurance. The proposed SD-WAN self-service solution can be used for any policy-driven system that automatically troubleshoots the problems resulting from hybrid SD-WAN network activities, including virtual private network (“VPN”), IP tunnel, IPSec, and security policies. According to one aspect disclosed herein, a method can check network configurations, analyze switch responses, and locate network problems quickly. Moreover, the method can test the functionality of a rules-based troubleshooting software effectively without employing expensive testing equipment and with minimal human intervention. Without the disclosed solution, telecommunications service providers may have to hire more software engineers who understand SDN and cloud technologies to effectively troubleshoot SD-WAN network connectivity issues, including issues caused by virtual network function (“VNF”), virtual machine (“VM”), and SDN switches. Thus, this labor-intensive solution is not only expensive, but also not immune to human error.
Owner:AT&T INTELLECTUAL PROPERTY I L P

Signature reporting system and method

Systems and methods for monitoring network activity. The methods include causing a display of a user interface to a user, wherein the user interface configured to present to the user a classification of a signature, wherein the classification of the signature is made by a firewall, and receive an input from the user to report that the firewall misclassified the signature. The methods also include receiving a report indicating that the firewall misclassified the signature based on the input received from the user; and modifying, using one or more processors executing instructions stored on memory, at least one of the signature and the firewall so that the firewall does not subsequently misclassify the signature.
Owner:SOPHOS LTD

Automated detection of computing system and network activity anomalies using denoising diffusion probabilistic models

Systems and methods for detecting security anomalies in a computing environment. One example system includes an electronic processor configured to receive, via the communication interface, security data for the computing environment and parse the security data to extract a feature set. The electronic processor is configured to apply noise to the feature set to produce a noised feature set and to produce a reduced noise feature set by processing the noised feature set using a neural network trained to remove noise. The electronic processor is configured to compare the reduced noise feature set to the feature set to determine a success score, select a threshold based on the security data, and determine whether the success score exceeds the threshold. The electronic processor is configured to, responsive to determining that the success score does not exceed the threshold, generate a security event based on the security data.
Owner:MOTOROLA SOLUTIONS INC

Security Threat Monitoring for Network-Accessible Devices

Various aspects related to threat management are disclosed. An example method includes monitoring network traffic on a computer network that includes a plurality of endpoints, identifying a software application executing on at least one endpoint from one or more of the sent data or the received data, where execution of the software application is associated with a startup time window and a post-startup time window, determining a security status score for the at least one endpoint based on a comparison of the sent data and the received data with a known pattern of network activity associated with the software application, wherein the known pattern of network activity is based upon the startup time window of the software application, determining a threat status for the at least one endpoint based on the security status score, and, generating an indication of the threat status for the at least one endpoint.
Owner:SOPHOS LTD

Systems and methods for system collusion detection

Systems and methods of generating fraud detection models and controlling network permissions of one or more systems within a network environment are disclosed. A network activity dataset comprising data representative of network activity within a network environment is received and at least one co-controlled system in the network activity dataset is identified by implementing a trained fraud detection model configured to receive the network activity dataset and output a fraud determination for each system having at least a first role in the network activity data. The fraud determination represents a likelihood of a system having the first role engaging in a co-controlled network activity. In response to identifying the at least one co-controlled system, one or more permissions of the at least one co-controlled system for operating within the network environment are modified.
Owner:WALMART APOLLO LLC

Asset operation anomaly determination

Techniques for determining an anomaly in operation of an asset are described. In operation, operation of an asset within an industrial facility is monitored to identify a silence period for the asset, where the silence period is indicative of a time duration when the asset exhibits no network activity. The silence period is then determined to be longer than a reference silence period, where the reference silence period is utilized for determining an anomaly in the operation of the asset. Based on the determination, an alarm indicative of the anomaly in the operation of the asset is generated.
Owner:HONEYWELL INTERNATIONAL INC

Methods, systems, and computer program products for classifying network activity based on classification-specific data patterns

A system, method, and computer program product are described for classifying network activity based on classification-specific data patterns. The method includes receiving training data associated with historical network activities. The method includes training a supervised learning model to output a classification of a plurality of classifications associated with network activity. The method includes training an unsupervised learning model to output an outlier score associated with each classification. The method includes receiving activity data for a subsequent time period, and determining an outlier score for the activity data. Determining the outlier scores includes inputting the activity data to a trained unsupervised learning model and determining the outlier scores based on the trained unsupervised learning model. The method includes, in response to each outlier score satisfying a threshold, generating a classification of the activity data based on the trained supervised learning model.
Owner:VISA INTERNATIONAL SERVICE ASSOCIATION

Detecting and protecting claimed absent domains

Techniques for detecting and protecting claimed non-presence domains are disclosed. A system, process and / or computer program product for detecting and protecting a claimed non-existent domain includes monitoring network activity using a network security device, detecting that a session is querying a claimed non-existent domain using a domain name system (DNS) security service, and performing an action in response to the session querying the claimed non-existent domain.
Owner:PALO ALTO NETWORKS INC