Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

128 results about "Network activity" patented technology

Risk engine that utilizes key performance indicators

Risk engine using key performance indicators, including: monitoring network activity associated with a customer to identify one or more infrastructure risks; calculating, based on the identified one or more infrastructure risks, a key performance indicator (KPI); and presenting, via a user interface, a comparison of a risk metric associated with the customer to one or more other risk metrics corresponding to one or more cohorts of the customer selected based on a variable input to a user interface element of the user interface.
Owner:FORTINET INC

Adaptive anomaly context description

Techniques are disclosed for providing a context-aware description of anomalous behavior in a computer network. According to one embodiment of the present disclosure, a description of an anomaly detected in computer network activity is received. The description includes one or more features of the computer network associated with the anomaly. Contextual information relating to at least one of the features is generated based on a logical network topology. The logical network topology specifies a plurality of network traffic attributes of the computer network. An alert that includes a second description of the anomaly and the contextual information is generated.
Owner:INTELLECTIVE AI INC

Cloud resource risk scenario assessment and remediation

An illustrative method for performing a risk scenario assessment and remediation may include identifying, based on posture data associated with a compute environment, one or more compute resources deployed in the compute environment that are configured to be connected to a network, accessing runtime workload data associated with the one or more compute resources representative of network activity for the one or more compute resources, and performing, based on the posture data and the runtime workload data, a remediation operation associated with the one or more compute resources.
Owner:FORTINET INC

Real-time neural network architecture adaptation through supervised neurogensis during inference operations

A system and method for adaptive neural network architecture with real-time neurogenesis capabilities during inference operations. The system processes data through a core neural network with integrated supervisory and neurogenesis control systems. A hierarchical supervisory network, comprising low-level, mid-level, and high-level nodes, monitors network activity patterns and information flow. The neurogenesis control system maintains continuous activity maps, detects processing bottlenecks, and determines optimal placement of new neurons using geometric optimization. A modification subsystem implements controlled neurogenesis operations while maintaining network stability. The system handles data through adaptive codeword allocation and fusion of dissimilar data types. This sophisticated approach enables neural networks to dynamically expand their processing capacity during operation, responding to detected bottlenecks while maintaining operational stability through carefully managed integration of new neurons.
Owner:ATOMBEAM TECH INC

Anomaly detection in network traffic data

This disclosure relates to systems, methods, and devices for identifying anomalous network activity. In some embodiments, a baseline model is used for identifying anomalous network activity. In some embodiments, anomalous network activity is detected based on a z-score, modified z-score, or both being above respective thresholds when compared to the baseline. In some embodiments, multiple baseline models are used, and anomalous network activity is detected when multiple baseline models identify a network activity session as anomalous. In some embodiments, two baseline models are used.
Owner:ARMIS SECURITY LTD

Intelligent liquid cooling of electronic devices by actively controlled manifolds

A system configured for cooling electronic devices comprises a pair of opposing, active manifolds that control a flow of cooling liquid through pipes or through an immersion tank past the electronic devices. A controller detects and / or predicts localized hotspots and adjusts flow control devices associated with inlets and outlets of the manifolds to direct proportionately more cooling liquid to the hotspots. The flow control devices can be any combination of variable speed pumps and / or adjustable valves, vents, and / or baffles. Manifolds can be placed on two opposing sides of the devices, on four opposing sides, and / or above and / or below the devices. Temperatures proximate the devices can be measured by separate sensors and / or sensors integral to components of the electronic devices. Hotspots can be predicted by monitoring current flows, power flows, and / or voltages of the electronic devices, and / or inferred from network activity and / or from a workload queue.
Owner:FLOWSERVE PTE LTD

Network attack tracing method, device, equipment and medium

The invention discloses a network attack tracing method, device and equipment and a medium, and the method comprises the steps: obtaining a plurality of network flow data packets, a plurality of pieces of weblog data and a plurality of equipment state parameters of a plurality of monitoring nodes in a target network domain; determining an abnormal node with a network attack behavior in the plurality of monitoring nodes based on the plurality of network flow data packets, the plurality of pieces of network log data and the plurality of equipment state parameters; and tracing the network attack behavior based on the abnormal data packet of the abnormal node, the abnormal weblog data and the abnormal equipment state parameter to obtain an attack type, an initial attack node and an attack path of the network attack behavior. The collaborative analysis value of data packet deep features and multi-source equipment information is fully utilized, real threats and normal network activities are accurately distinguished, and the traceability accuracy and reliability are remarkably improved. Meanwhile, through correlation analysis of multi-dimensional data, an attack source positioning range can be converged step by step, and an attack path can be completely reconstructed.
Owner:CHINA DATANG CORPORATION SCIENCE AND TECHNOLOGY GENERAL RESEARCH INSTITUTE

Signature quality evaluation

Systems and methods for scanning network activity. The methods include receiving at an interface connection data regarding a plurality of network connections, wherein the connection data includes a signature used to classify each of the plurality of network connections; determining, using one or more processors executing instructions stored on memory to provide a signature analysis engine configured to analyze the connection data, the signature is prohibitively prone to misclassifying network activity as malicious, wherein the determination is based on the analysis of the connection data; and implementing a signature policy to prevent the signature from misclassifying network activity as malicious.
Owner:SOPHOS LTD

System and method of identifying malicious activity in a network

Disclosed herein are methods and systems for identifying malicious network activity. In an embodiment, a method comprises monitoring, by a computer, network activity of a user having a baseline network activity; executing, by the computer, a machine learning model to determine a network activity score indicating a likelihood of the network activity being malicious activity for the baseline network activity, the machine learning model having been previously trained based on malicious activity and corresponding baseline network activity; and displaying, by the computer, the network activity score.
Owner:MASSACHUSETTS MUTUAL LIFE INSURANCE CO

Network attack and defense simulation engine system based on discrete event driving

The invention belongs to the technical field of network attack and defense simulation, and discloses a network attack and defense simulation engine system based on discrete event driving, which comprises an event scheduling module, a simulation network construction module, an attack and defense simulation module, a simulation kernel module and a panoramic situation awareness module, the event scheduling module is in the form of MITRE ATTamp; the CK is constructed as a theoretical base and is used for converting all network activities into a dispatchable discrete event sequence; the network activities comprise data packet sending, protocol timeout and attack triggering; and the simulation network construction module can construct a simulation network containing complete service logic. According to the application, the MITRE ATTamp is scheduled by the event scheduling module; the CK tactical intention is converted into an ordered event stream, a hierarchical task network planner in the attack and defense simulation module dynamically decomposes and re-plans a high-level target, and ATTamp can be utilized; and the CK technology ID reconstructs an attack chain in real time.
Owner:BEIJING ZHANGBA NETWORK SECURITY TECH CO LTD

Network anomaly detection

A method of identifying anomalous network activity. The method includes identifying, based on network data representative of network activity within a network, at least one instance of a sequence of events that occurred within the network. A probability of the sequence of events occurring during non-anomalous network activity is obtained based on transition probabilities between events in the sequence of events. A frequency characteristic dependent on a frequency at which the sequence of events occurred within the network is determined. A likelihood of the sequence of events occurring within the network at the frequency is determined based on a combination of the probability and the frequency characteristic. It is identified, based on the likelihood, that at least a portion of the network data is anomalous.
Owner:BRITISH TELECOM PLC

Method and system for sensor alarm reporting and UE-to-UE communication in radio access networks

The present disclosure provides a method (100) and a system (200) for reporting a sensor alarm and facilitating UE-to-UE communication in a radio access network (RAN). The method (100) includes the radio access network receiving (102) within a predefined margin, an early notification of the sensor alarm from a first user equipment (UE), terminating (104) one or more scheduled or ongoing network activities impacting call performance of a UE upon receipt of the early notification of the sensor alarm and initiating (106) tracking of reachability of the first UE by the RAN. Further, the method (100) includes continuing (108) tracking of reachability of the first UE by the RAN, where if the first UE remains reachable no further action is taken by the RAN, and if the first UE becomes unreachable send a command from the RAN to one or more surrounding UEs instructing them to activate UE-to-UE wireless communication.
Owner:YAMINE BADAWI

Detecting security threats from logon data

This disclosure describes techniques for analyzing network traffic to generate an actionable insight pertaining to a security threat to a network. In one example, this disclosure describes a method that includes obtaining, by a computing system, historical network activity data that includes information about authentication traffic within a network; determining, by the computing system and based on the historical network activity, a baseline of network activity; collecting, by the computing system, a set of network activity data; applying, by the computing system, an unsupervised algorithm to identify the set of network activity data as anomalous relative to the baseline of network activity; classifying, by the computing system, the network activity data into an identified threat category from among a plurality of threat categories; and taking action, by the computing system and based on the identified threat category, to mitigate a security threat posed by the network activity data.
Owner:WELLS FARGO BANK NA

System and method for mitigating cyber security threats by devices using risk factors

A system and method for mitigating cyber security threats by devices using risk factors. The method includes determining a plurality of risk factors for a device based on a plurality of risk behaviors indicated by network activity and information of the device, wherein the plurality of risk behaviors includes observed risk behaviors and assumed risk behaviors, wherein the observed risk behaviors are indicated by data related to network activity by the device, wherein the assumed risk behaviors are extrapolated based on known contextual information related to the device; determining a risk score for the device based on the plurality of risk factors and a plurality of weights, wherein each of the plurality of weights is applied to one of the plurality of risk factors; and performing at least one mitigation action based on the risk score.
Owner:ARMIS SECURITY LTD

System and method for real-time detection of code integrity violations

A system and method are provided for real-time detection of code integrity violations by combining behavioral stylometry, biometric fingerprinting, and environmental threat analysis. Baseline data of a user's coding style such as indentation, variable naming, and keystroke patterns are stored and compared to live input to calculate deviation scores. Typing behaviors like dwell time, rhythm, and simulated pressure form a biometric fingerprint, while environmental scans detect suspicious network activity, browser extensions, or virtual machine use. A combined risk score is generated, and automated interventions are triggered when it exceeds a threshold, enabling early detection of unauthorized access, AI-generated code, or compromised environments for secure software development.
Owner:BOYLE DANIEL

Unified device identity through correlation of multi-interface network activity

Methods and systems for accurately identifying and tracking electronic devices communicating across heterogeneous networks, even when those devices utilize multiple in-device network interfaces and change identifiers. The system receives network activity indications from various devices, each indication associated with a specific network interface and identifier. A correlation process, potentially employing a machine learning model, analyzes these indications to identify a sub-set originating from a single physical electronic device, spanning at least two different in-device network interfaces (e.g., cellular and Wi-Fi). A unified device identity, a persistent digital representation (or “digital twin”) of the device, is generated based on this correlated sub-set. This unified identity remains associated with the physical device regardless of interface changes, enabling consistent application of security policies, improved network visibility, accurate device tracking, and efficient resource allocation. The system handles both mandatory identifiers, which are associated with specific in-device network interfaces, as well as weak transitory identifiers.
Owner:ONE LAYER LTD

Network security monitoring method

The invention discloses a network security monitoring method, which comprises the following steps of: acquiring full-life-cycle data and attributes of network processes in real time, constructing a process chain table and an associated network, and sorting a relationship between the processes; secondly, matching a network event with a process timeline, dynamically dividing a time window according to a process life cycle, calculating a process time characteristic and a network activity characteristic, comparing a historical normal mode, quantifying a difference by utilizing an algorithm, and identifying an abnormal process; then, inputting the comparison process into a support vector machine to establish a prediction model, and predicting an abnormal process in real time; and finally, abnormal process information is fed back to the security equipment, and abnormal files are positioned and isolation / deletion operation is executed in combination with network behavior data association analysis. According to the method, the abnormal process can be accurately identified, misjudgment is reduced, the sensitivity requirements of different service scenes are met, the abnormal file is positioned by means of network behaviors, and the accuracy and timeliness of network security protection are effectively improved.
Owner:GUIZHOU BLUESKY INNOVATIVE SCI & TECH CO LTD

system

We provide the system. [Solution] Data collection methods for monitoring online activity, AI processing means for analyzing the aforementioned data and detecting anomalies, A notification means for sending an alert to a guardian based on the aforementioned abnormality, A system that includes this.
Owner:SOFTBANK GROUP CORP

Systems, methods, and computer programs (dynamic resource compliance determination for containerized systems)

For crypto assets mounted to pods as files or environment variables, security and compliance can be complex and therefore may be inadequately managed. [Solution] The system may include memory and a processor that communicates with the memory. The processor may be configured to perform operations. The operations may include steps to monitor network actions between resources in a network and steps to extract encrypted data from the network actions. The operations may include steps to detect connection security data from the encrypted data and steps to obtain resource health reports for the resources in the network. The operations may include steps to merge the connection security data with the resource health reports and steps to generate security compliance reports.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Multi-model detection of malicious URL using its network

A URL is input into a virtual browser of a crawler which requests that URL and all of its resource URLs in order to form a network graph. Network features are extracted. An identity stage uses an identity model based upon lexical and host features to determine if the input URL and resource URLs are malicious or benign. A similarity stage uses a similarity model and similarity functions to produce a similarity score between each pair of the input URL and a resource URL. An activity stage uses an activity model to determine if the input URL's network is malicious or benign based upon the network graph and extracted network activity features. Edges of the graph are weights, similarity scores, attributes or network features. A finality stage concludes malicious if the identity stage concluded that the URL was malicious or the activity stage concluded that the URL's network was malicious.
Owner:TREND MICRO INC

Using network traffic data to identify internet of things devices

In one example, a method is described. The method includes: obtaining network traffic data characterizing network activity of devices coupled to a network at a media exposure measurement location, processing the network traffic data to generate, for each of multiple devices: activity parameters, each characterizing a network activity of the device, processing the activity parameters using an IoT classification model that includes a decision tree having: (i) multiple internal nodes, each internal node associated with an activity parameter threshold, and (ii) multiple leaf nodes, each leaf node associated with either the IoT device type or the other device type, based on the decision tree, selecting, from the device identifiers included in the network traffic data, a target device identifier corresponding to a leaf node in the decision tree that is associated with the IoT device type, and outputting the target device identifier.
Owner:THE NIELSEN CO (US) LLC

Network activity deviation detection and remediation

Systems and methods to detect network activity deviations are described. The network activity data can include a set of network activities of a user and can be used to categorize the user into a segment. Deviations in the network activity can be detected based on one or more patterns of previous network activities of the user. For example, a value associated with the network activity can be determined to deviate from an expected value by a threshold value, determined based on the segment. Remediation to prevent the network activity from impacting future activities of the user can be determined based on scores of the network activity's participants, which includes the user. In an example, the network activity can be removed from an account of the user based on the determined remediation.
Owner:CAPITAL ONE SERVICES LLC

Automatic user equipment degradation optimization

A system of a telecommunications network comprising an automatic user equipment (UE) degradation optimization (AUDiO) Optimizer is disclosed. The AUDiO Optimizer collects network performance metrics or network events associated with a UE and retrieves a user profile that includes information indicating the network activity of the subscriber. The AUDiO Optimizer also obtains information about network events or performance metrics associated with the network. Then it determines a threshold performance degradation of the UE based on this information and, in response to the determination, performs an AUDiO action including automatically causing restart of the UE, applying a service credit to an account of the subscriber, or communicating a service degradation-related communication to the subscriber.
Owner:T MOBILE US INC

Microservice architecture-oriented network security detection method and device

The embodiment of the invention provides a micro-service architecture-oriented network security detection method and device. The method comprises the following steps of: respectively acquiring communication flow between virtual machines and a network activity track of a container through a virtual switch port mirror image and a log interface of a container platform; constructing a dynamic baseline model containing a legal communication matrix, a protocol white list and a traffic threshold; comparing the acquired data with the dynamic baseline model by adopting a real-time stream processing technology, and detecting an abnormal behavior of the container or the virtual machine; and executing response measures of different levels according to the seriousness of the abnormal behavior threat. According to the scheme, internal attack behaviors such as container escape and transverse penetration can be effectively identified and coped with.
Owner:NO 15 INST OF CHINA ELECTRONICS TECH GRP

Method for proof-of-authority for highly reliable blockchain network

A method for proof-of-authority for a highly reliable blockchain network according to the present invention comprises the steps in which: a proof-of-authority consensus processing unit selects an extra signer through a preset priority algorithm in a case in which a malfunctioning signer is present when the proof-of-authority consensus processing unit monitors network activities in a blockchain network in which a plurality of approved signers verify a transaction and then include the approved transaction in a chain as a block when the transaction starts at a node; when the new extra signer is approved by majority approvals of the existing signers, the proof-of-authority consensus processing unit replaces the malfunctioning signer with the extra signer; and the new extra signer generates a block or verifies the generated block.
Owner:KUMOH NAT INST OF TECH IND ACADEMIC COOPERATION FOUND

Zero-knowledge secure and private monitoring channel

Systems and methods for securely and privately monitoring risky web activities in an enterprise computing system. A service is provided that communicates with a first client- application deployed on a user device and a second client-application deployed on an administrator device. A secure enclave is deployed by the service that ensures zero-knowledge to store sensitive user data (e.g., activity logs of risky web activity logged by the first client- application). Team-Service Logged-Out keys and Team-Enclave Logged-Out keys are deployed to the user device. When an end user associated with the user device is not logged into the service, the Team-Service Logged-Out keys and Team-Enclave Logged-Out keys are used to authenticate the logged-out end user so that an activity log can be sent to the secure enclave and stored. The activity log can be accessed by the second client-application upon authentication of the administrator using a Device-Enclave key pair associated with the administrator.
Owner:DASHLANE

Comparing network usage against digital model personas

A management server measures network activity of user devices to determine activities of the users associated with each user device. The management server generates digital model personas corresponding to the users based on one or more activities of the user. The management server clusters the digital model personas to generate user groups based on similar activities, and compares a first digital model persona from a first user with at least one second digital model persona.
Owner:CISCO TECHNOLOGY INC

Full-flow threat sensing and tracing system oriented to cloud native environment

The invention belongs to the technical field of cloud native environments, and particularly relates to a cloud native environment-oriented full-flow threat sensing and tracing system, which comprises a data acquisition layer deployed on each computing node of a cloud native cluster and used for acquiring east-west network flow and north-south network flow; the data preprocessing and storage layer is connected with the data acquisition layer, and is used for performing analysis, specification and standardization processing on the acquired original traffic and storing the processed original traffic as a structured traffic log; the dynamic strategy engine is connected with the data preprocessing and storage layer and is used for generating and adjusting a security strategy based on a real-time flow analysis result; and carrying out visualization and traceability analysis. According to the invention, through multi-level data acquisition and fusion, all-around deep monitoring of network activities in a cloud native environment is realized, and specifically, an eBPF probe is deployed on a kernel layer of an operating system in a data acquisition layer, so that basic network connections and data packets of all Pods can be captured without invasion.
Owner:SHAOYANG JINXIN TECHNOLOGY CO LTD

System and methods for sandboxed software analysis with automated vulnerability detection and patch development, deployment and validation

ActiveUS12462016B2FinanceHardware monitoringSoftware analyticsSuspicious behaviour
A system and method for automated software vulnerability detection and patching using sandboxed analysis. The system receives executable machine code files and identifies target device types for execution. A sandbox environment emulates device functionality and executes code while monitoring for suspicious behavior including memory scanning, unauthorized system access, and irregular network activity. Machine learning algorithms analyze execution patterns to detect security vulnerabilities and exploits. Upon identifying threats, the system automatically generates protective patches such as address space layout randomization and data execution prevention measures. These patches are deployed to real devices to prevent exploitation. The system uses reinforcement learning to improve patch effectiveness over time. This automated approach enables proactive cybersecurity protection by responding to emerging threats before malicious exploitation occurs.
Owner:QOMPLX INC

Device anomaly detection based on DNS queries

PCT designated stageWO2026049806A1TransmissionDomain nameNetwork activity
Techniques for providing device anomaly detection based on DNS queries are disclosed. In some embodiments, a system, a process, and / or a computer program product for device anomaly detection based on DNS queries includes receiving Domain Name System (DNS) network activity, wherein the DNS network activity includes a plurality of DNS queries; processing the DNS network activity to generate a plurality of metrics; and automatically detecting anomalies associated with one or more devices for a monitored network.
Owner:INFOBLOX INC