Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

72 results about "Network administrator" patented technology

A network administrator is the person designated in an organization whose responsibility includes maintaining computer infrastructures with emphasis on networking. Responsibilities may vary between organizations, but on-site servers, software-network interactions as well as network integrity/resilience are the key areas of focus.

Intention-driven network management method and system based on large language model

The invention relates to the technical field of network management, and discloses an intent-driven network management method and system based on a large language model (LLM). The method comprises the following steps: receiving a natural language intention of a network administrator, analyzing the intention by utilizing a pre-trained large language model, extracting a key target and constraint, generating a configuration scheme of a TCP / IP or QUIC protocol based on an analysis result and a network protocol knowledge base, and ensuring the effectiveness and safety of configuration through a network constraint verification module. And the configuration passing the verification is applied to the network system. The system comprises an intention input module, an LLM analysis module, a configuration generation module, a verification module, an application module and the like. According to the invention, through conversion from automation intention to configuration, the network management process is simplified, the management efficiency and flexibility are improved, the method is especially suitable for multi-parameter optimization scenes of protocols such as TCP / IP and QUIC, and intelligent network management is realized.
Owner:SICHUAN UNIV

Fine-tuning language models for network devices

Techniques and mechanisms for fine-tuning a language model to be optimized for a network device to which the language model is deployed. A controller for a network may maintain an inventory of network devices in a network, and obtain device information for the network devices. The controller may analyze the device information to determine a device type or role for the network devices. The controller may then select a pre-trained model that is optimal or well-suited for a device type of a particular network device, and perform a distillation function of the language model. Once the language model has been distilled, the controller may augment the language model with locally relevant information such that the language model is contextually relevant for the network device. After fine-tuning the language model, the controller pre-positions the language model on the device so network administrators and other users can access it when necessary.
Owner:CISCO TECHNOLOGY INC

HTTPS flow redirection and authentication control method based on FakeDNS

The invention discloses an HTTPS flow redirection and authentication control method based on a FakeDNS, which can intelligently redirect HTTPS flow based on a domain name to an authentication system without destroying the encryption property of the flow, and redirect an HTTPS request of a user to a preset authentication page by utilizing a DNS spoofing technology so as to realize identity verification of equipment and improve the authentication efficiency. Meanwhile, the security and privacy of communication are kept, the network security is improved, a solution which is high in cost effectiveness and easy to deploy and manage is provided, greater flexibility is provided for a network administrator, seamless network access experience is provided for a user, and the user experience is improved. The problem of redirection authentication of HTTPS access based on the domain name in a bypass deployment environment is solved, and the method has important application value in the field of network security.
Owner:ZHEJIANG YUANWANG INFORMATION CO LTD

Equipment identification method and system based on packet flow semantic feature enhancement, and electronic equipment

The invention provides an equipment identification method and system based on packet traffic semantic feature enhancement, and electronic equipment, and the method comprises the steps: converting the original Internet of Things traffic into a general packet-level traffic semantic feature which can be understood by a large language model, and then carrying out the fine adjustment of the large language model through the packet-level traffic semantic feature, and the large language model can automatically learn potential Internet of Things equipment traffic characteristics and execute equipment classification identification decisions. According to the technical scheme, accurate identification of the Internet of Things equipment is realized, a network administrator can grasp the type and state information of the access equipment in real time, access or abnormal behaviors of unauthorized equipment are effectively identified, safety protection measures are taken in time, and the overall safety of an intelligent environment system is guaranteed.
Owner:NAT UNIV OF DEFENSE TECH +1

System and method for service barring-proces workflow

The system (108) in the present disclosure for service barring workflow is designed to automate and streamline the process of managing service barring actions in a telecommunications network It provides centralized control, efficient processing. and granular control over service restrictions by implementing a method (400) involving various nodes. Tracking Area Code (TAC) and Network administrators. The system (108) offers advantages such as enhanced operational efficiency. accurate enforcement of service barring rules. real-time monitoring. and reporting capabilities. It integrates with network elements and ensures compliance with regulatory requirements. With its flexible and scalable architecture, the system (108) enables administrators and users to efficiently handle service barring requests while maintaining a positive customer experience. Overall, the system (108) for service barring workflow optimizes the service management process. enhances security, and contributes to effective network control and customer satisfaction.
Owner:JIO PLATFORMS LTD

Method and system for NAT (Network Address Translation) optimization engine driven by digital twin network simulation

The invention relates to the technical field of digital twinning technology and network communication optimization, in particular to a method and a system of a digital twinning network simulation driven NAT (Network Address Translation) optimization engine, comprising the following steps: constructing a virtualization mapping model of a physical network; simulating an NAT (Network Address Translation) process in a digital twin environment through a real-time simulation engine; dynamically adjusting an NAT (Network Address Translation) rule and a load balancing strategy of a physical network based on a simulation result; executing safety protection operation in combination with a machine learning algorithm; the method has the beneficial effects that a digital twinning technology and NAT optimization are deeply fused, and a visual and visual management platform is provided for network management personnel. Management personnel can monitor the network state and the NAT performance in real time through the platform and deeply analyze the network problem root by means of a simulation result, and complex field troubleshooting and manual strategy adjustment do not need to be carried out. Therefore, the difficulty and the cost of network management are reduced, the accuracy and the timeliness of management are improved, and the network management is promoted to develop towards the intelligentization and automation directions.
Owner:SHANDONG LANGCHAO YUNTOU INFORMATION TECH CO LTD

Efficient Threat Context-Aware Packet Filtering for Network Protection

A threat intelligence gateway (TIG) may protect TCP / IP networks from network (e.g., Internet) threats by enforcing certain policies on in-transit packets that are crossing network boundaries. The policies may be composed of packet filtering rules with packet-matching criteria derived from cyber threat intelligence (CTI) associated with Internet threats. These CTI-derived packet-filtering rules may be created offline by policy creation and management servers, which may distribute the policies to subscribing TIGs that subsequently enforce the policies on in-transit packets. Each packet filtering rule may specify a disposition that may be applied to a matching in-transit packet, such as deny / block / drop the in-transit packet or pass / allow / forward the in-transit packet, and also may specify directives that may be applied to a matching in-transit packet, such as log, capture, spoof-tcp-rst, etc. Often, however, the selection of a rule's disposition and directives that best protect the associated network may not be optimally determined before a matching in-transit packet is observed by the associated TIG. In such cases, threat context information that may only be available (e.g., computable) at in-transit packet observation and / or filtering time, such as current time-of-day, current TIG / network location, current TIG / network administrator, the in-transit packet being determined to be part of an active attack on the network, etc., may be helpful to determine the disposition and directives that may best protect the network from the threat associated with the in-transit packet. The present disclosure describes examples of methods, systems, and apparatuses that may be used for efficiently determining (e.g., accessing and / or computing), in response to the in-transit packet, threat context information associated with an in-transit packet. The threat context information may be used to efficiently determine the disposition and / or one or more directives to apply to the in-transit packet. This may result in dispositions and / or directives being applied to in-transit packets that better protect the network as compared with solely using dispositions and directives that were predetermined prior to receiving the in-transit packet.
Owner:CENTRIPETAL NETWORKS INC

Double-path automatic planning and transmission implementation method for time-sensitive network equipment

The invention discloses a double-path automatic planning and transmission implementation method for time-sensitive network equipment, which comprises the following steps of: (1) determining identity information of redundant path transmission equipment of current TSN (Time Sensitive Network) equipment, the identity information comprising a transmitting end, a receiving end and a relay transmission end; (2) distributing unique ID identifiers to all TSN devices in the whole network; (3) planning two independent data paths 1 and 2, and determining input and output ports of the two paths; and (4) automatically planning VLAN information on the current path 1 and the current path 2. According to the method, the device configuration under each path in the TSN ring network can be automatically constructed only by determining the identity information of the transmitting end, the relay end and the receiving end equipment and planning the path of the key message by a network administrator; and the redundant path of the key transmission is automatically generated by the TSN equipment according to the transmission node and the path without being configured by a network administrator, so that the configuration workload is reduced, and the fault possibility of network crash caused by configuration is reduced.
Owner:THE 34TH RES INST OF CHINA ELECTRONICS TECH CORP

Intent-based policy configuration using natural language

Techniques are described for providing a natural language network security policy assistant for allowing a network administrator to implement network security policies using natural language security policy requests. A natural language request can be received by a user and can be translated using Artificial Intelligence into one or more security policy clauses. If the natural language security policy request leads to ambiguities with regard to intended security policies, one or more clarifying questions can be generated as natural language questions and sent to the user for clarification. One or more security policies can be implemented based on the one or more security policy clauses generated in response to the natural language security policy request and / or the natural language response to the clarifying questions.
Owner:CISCO TECHNOLOGY INC

Control device, control program, and control method

To allow for paying attention of a manager of a network to timing at which a terminal requested authentication.SOLUTION: A control device 1 comprises: receiving means 12 which receives a signal including a MAC address of an arbitrary terminal 2 from the terminal; reception means 13 which, if the MAC address included in the signal is not included in registered terminal information, outputs a reception time of the signal and the MAC address and accepts an input indicating whether or not the MAC address can be registered; and assignment means 14 which, if the MAC address included in the signal is included in the registered terminal information, executes processing of assigning an IP address to the terminal. In response to an input indicating that the MAC address can be registered, the receiving means adds the MAC address to the registered terminal information and further outputs a warning on the basis of the time.SELECTED DRAWING: Figure 1
Owner:NEC CORP

A method for automatically configuring parameters of a Wi-Fi wireless vibration sensor

The present invention discloses a method for automatically configuring parameters of a Wi-Fi wireless vibration sensor, which is characterized by comprising the following steps: S1, setting an environment for storing second configuration parameters and identifier information in a host computer, and storing the identifier information and first configuration parameters in the environment; S2, arranging wireless sensors for automatically obtaining configuration parameters; S3, obtaining configuration parameters for setting the configuration parameters corresponding to the environment in the sensors; the sensors can be automatically configured when they are put online without manual operation, thereby reducing the risks of information leakage and errors; the sensors do not need to be manually configured before use, and can be automatically configured after installation, thereby reducing the workload of sensor operation and maintenance personnel; network administrators can configure and manage the network parameters of sensors installed at all measuring points on the sensor management system, thereby reducing the risks of leakage and parameter configuration errors.
Owner:HANGZHOU ANMAISHENG INTELLIGENT TECH CO LTD

Intelligent ship network security defense system integrating active defense and path backtracking

The invention discloses an intelligent ship network security defense system integrating active defense and path backtracking, and relates to the technical field of network security. In a ship network system, a network firewall is connected behind a ship wireless communication channel, and meanwhile, a route backtracking module for actively analyzing an abnormal route is connected to a core switch of a ship network; the module records and analyzes all routes on the core switch and gives an alarm for abnormal routes, meanwhile, a virtual network terminal is installed on the network server and used for simulating functional terminal equipment in a ship network to serve as bait of network viruses, and when the viruses invade the virtual terminal, the virtual terminal can send out the network viruses. And the virtual terminal sends a virus intrusion alarm to a network administrator, starts a route backtracking system to carry out route backtracking, and automatically sends a backtracked source to a virus library of the firewall. According to the invention, a passive and active combined method is adopted to carry out network security defense, and the network security can be obviously enhanced compared with a single firewall mode.
Owner:CHINA SHIPPING TELECOMM

System for monitoring optical fiber distribution networks

The system includes a sensor mounted on a passive element of the network, defined by optical boxes or optical fibers, to detect operational parameters of the passive element and periodically produce data packets that represent reference operating conditions and, in real time, data packages that represent anomalous operating conditions detected by the sensor; an input portal maintained in communication with a group of sensors; a server that receives data packets from the input portals, decoding and authenticating them; and a platform receiving, from the server, the data packets of reference operating conditions and of the anomalous operating conditions, storing them and making them available to a network administrator, to be selectively or automatically sent to a field technician, via a mobile computing device.
Owner:FURUKAWA ELECTRIC LATAM SA

A lightweight satellite network security management system and method

The application provides a lightweight satellite network security management system and method. The system realizes unified management of the satellite network security control plane through a centralized network controller. The system has functions such as security authentication of satellite nodes, dynamic security policy generation and distribution, real-time network monitoring, and rapid security event response. The network controller includes multiple modules such as authentication, policy generation, monitoring, and event response, and can customize security policies according to satellite characteristics and adjust them in real time to respond to security threats. The application also includes lightweight design, especially suitable for resource-constrained satellite environments, and a method for continuously optimizing security policies based on monitoring data and event records. In addition, the provided user interface allows satellite network administrators to easily configure policies and handle events. Through centralized management and dynamic adjustment, the system significantly improves the security and efficiency of satellite networks, has advantages such as lightweight, flexibility, and real-time, and meets the security management needs of modern satellite networks.
Owner:BEIJING RES INST OF TELEMETRY

Method and system of securely adding an edge device operating in a public network to an SD-WAN

Some embodiments of the invention provide, for a network manager of a secure SD-WAN (software-defined wide-area network), a method of securely adding an edge device, which operates at a branch location in a public network, to the SD-WAN. The method provides, to an activation service hosted on the public network, a record for the edge device that is to be added to the SD-WAN securely, the record for use by the activation service to authenticate the edge device. The method receives a first notification from the activation service indicating the edge device has been authenticated. The method receives a second notification from a verification service indicating the authenticated edge device has been verified. Based on the first and second notifications, the method provides to the activation service (i) a set of configuration data for the edge device and (ii) a set of authentication data for the edge device. The activation service provides the set of configuration data and the set of authentication data to the edge device to use to join the SD-WAN.
Owner:VELOCLOUD NETWORKS LLC

Cross-device stacking PoE management system and automatic configuration method thereof

The invention relates to the technical field of PoE management, in particular to a cross-device stacking PoE management system and an automatic configuration method thereof, the cross-device stacking PoE management system comprises a master-slave device architecture, the master-slave device architecture comprises a master device and a plurality of slave devices, the master device is used for collecting PoE state information of each slave device and issuing a PoE configuration instruction to the slave devices, the slave device is responsible for executing an instruction of the master device and reporting a state to the master device; the master device configuration module is used for uniformly managing PoE configurations of all slave devices; the slave device execution module is used for receiving and executing a PoE configuration instruction issued by the master device; and the state reporting module is used for reporting the PoE state information to the master device in real time by the slave device. According to the invention, cross-device PoE unified management and control is realized through a master-slave device architecture, and the problem that operation needs to be carried out one by one in a traditional scheme is solved; centralized management, real-time state monitoring and unified configuration of the distributed PoE ports are realized, and the configuration and management process of a network administrator is simplified.
Owner:UNIPOE IOT TECH CO LTD

Operating devices in an operating room

Described are methods and systems for improving cybersecurity of an operating room. A user is prevented from interacting with one or more medical devices connected to an operating room (OR) hub until the user is authenticated through an operations user interface (UI) of the OR hub. The user is authenticated through the operations UI. Authenticating the user through the operations UI includes determining a type of credential possessed by the user. Based on a determination that the user possesses a hospital network administrator credential, the user is permitted to access a plurality of security functions, including enabling and disabling one or more communication ports to which the one or more medical devices are connected. Based on a determination that the user possesses an operator credential, the user is prevented from enabling and disabling the one or more communication ports.
Owner:STRYKER CORP

System and method to allocate and administer guest printing

A system and method is provided for creating and administering a guest user's document processing operations, such as printing, on a host company network sharing the same cloud print service as the guest's company network. The host network administrator generates a list of companies that are pre-approved for users from a guest company. The guest user logs into the host network and views a list of pre-approved companies. The user selects one or more approved companies for which they are already approved. The user selects a PIN which is then associated with their information, approved companies and guest company. The user then submits their job to the cloud print service for release by a host company MFP. The user logs into a selected host company MFP with their PIN and a listing of any related, pending job is displayed. The user may select one or more jobs for release and printing. The PIN may be revoked by the host administrator, timeout or expire when a selected number of printouts has been made.
Owner:TOSHIBA TEC KK

A method for automatic dual-path planning and transmission implementation in time-sensitive network devices

This invention discloses a method for automatic dual-path planning and transmission implementation of time-sensitive network devices, comprising the following steps: (1) determining the identity information of the redundant path transmission devices of the current TSN device, wherein the identity information includes the sender, receiver, and relay transmission end; (2) assigning a unique ID identifier to all TSN devices in the network; (3) planning two independent data paths 1 and 2, and determining the input and output ports of the two paths; (4) automatically planning the VLAN information on the current path 1 and Path 2. This invention only requires the network administrator to determine the identity information of the sender, relay, and receiver devices and plan the path of critical packets, thereby automatically constructing the device configuration under each path in the TSN ring network; the redundant path of critical transmission is automatically generated by the TSN device itself according to the transmission node and path, without the need for network administrator configuration, reducing the configuration workload, thereby reducing the possibility of network crashes caused by configuration.
Owner:THE 34TH RES INST OF CHINA ELECTRONICS TECH CORP

System and method to allocate and administer guest printing

ActiveUS12669966B2Internet privacyEngineering
A system and method is provided for creating and administering a guest user's document processing operations, such as printing, on a host company network sharing the same cloud print service as the guest's company network. The host network administrator generates a list of companies that are pre-approved for users from a guest company. The guest user logs into the host network and views a list of pre-approved companies. The user selects one or more approved companies for which they are already approved. The user selects a PIN which is then associated with their information, approved companies and guest company. The user then submits their job to the cloud print service for release by a host company MFP. The user logs into a selected host company MFP with their PIN and a listing of any related, pending job is displayed. The user may select one or more jobs for release and printing. The PIN may be revoked by the host administrator, timeout or expire when a selected number of printouts has been made.
Owner:TOSHIBA TEC KK

Attack Scene Detection Method Based on Graph Convolutional Neural Network

This invention relates to the field of network security, and more particularly to an attack scenario detection method based on graph convolutional neural networks. With the increasing complexity and diversity of network attacks, the detection of network attack scenarios has become extremely challenging. Typically, administrators deploy monitoring devices, such as intrusion detection systems (IDS), in network nodes. IDS generate a large number of alert messages to reflect potential attack behaviors in the underlying network. Analyzing these intrusion alert messages can reveal corresponding attack scenarios. A common approach is to group similar network security alert messages together using alert message association, thereby discovering similar attack scenarios. This alert message association provides network administrators with an abstract, higher-level view of the network. This patent proposes an attack scenario detection method based on graph convolutional neural networks to discover attack scenarios in network alert messages. By utilizing graph convolutional neural networks, the detection of attack scenarios is transformed into a multi-classification problem of nodes on the alert message graph, achieving relatively accurate detection results.
Owner:ZHEJIANG YUAN INFORMATION TECH CO LTD

Network cutover control method and device, electronic equipment and medium

The invention provides a network cutover control method and device, electronic equipment and a medium, and relates to the technical field of network security. The network cutover control method comprises the following steps: in response to a cutover command issued by a network administrator, verifying the cutover command according to a historical cutover command to obtain a first cutover command; based on the context of the first cutover command and a preset command template, generating a target command set through a large language model; and predicting target execution time of the target cutover command in the target command set, and controlling the target cutover command to run at the target execution time. Through the technical scheme provided by the invention, the problems of high security risk, low flexibility and low efficiency of network cutover in related technologies are solved, and the security, flexibility and efficiency of network cutover are improved.
Owner:CHINA MOBILE COMM CORP TIANJIN +1

Service discovery and flow arrangement method and system based on cooperation of DHCP (dynamic host configuration protocol) and DNS (domain name system)

The embodiment of the invention discloses a DHCP (Dynamic Host Configuration Protocol) and DNS (Domain Name Server) collaboration-based service discovery and flow arrangement method and system, which enable a network administrator to more conveniently manage and discover equipment and services in a network through collaborative planning of an IP (Internet Protocol) address and a domain name, enable a user to identify information such as a department, a position and a function to which the equipment belongs through the domain name, and improve the efficiency of service discovery and flow arrangement. Human errors and query cost in network management are reduced, and efficiency and accuracy of domain name transformation of network management are improved; through the dynamic domain name arrangement, the DHCP server can adjust the domain name and the record value in real time according to the state change of the client, so that the network service can better adapt to different application scenes and user requirements, and the flexibility and expandability of the Internet of Things service are improved; the analysis is arranged and the static configuration is issued at the DHCP server, so that the requirement on the capability of the DNS server is reduced, and the stability of the DNS server is also improved.
Owner:INTERNET DOMAIN NAME SYST BEIJING ENG RES CENT

Wireless Network Access Sharing Based on Presence at a Physical Location

Systems, devices and methods are provided for providing access to secure wireless networks to a user based on the user's physical location. In some embodiments, access to such a network is based on user location information, as determined by a control system. A secure network may be provided based on an inference that the user may be trusted to receive access to the network based on their location. Access to the network may be provided based on the user's physical location and an administrative user of the network providing authorization for the user to join the network, e.g., via a user interface. The user may be recognized at a later time, and provided with access again. The control system may provide access to the network to additional user(s) associated with said user, based on a physical interaction or other behavior indicating a trusted relationship with the additional user(s).
Owner:BECKMAN CHRISTOPHER V

Systems and methods for network monitoring, reporting, and risk mitigation

A network monitoring, reporting and risk mitigation system collects events at a computing device within the local network to provide improved network security. The events are aggregated into alerts, which may be processed according to triggering definitions in order to create ARO (action, recommendations and observations) reports providing required or recommended actions to take or observations to a network administrator. The ARO reports may be processed by a remote server in order to generate contextual feedback for updating the triggering definitions.
Owner:FIELD EFFECT SOFTWARE INC

Fine-tuning language models for network devices

Techniques and mechanisms for fine-timing a language model to be optimized for a network device to which the language model is deployed. A controller for a network may maintain an inventory of network devices in a network, and obtain device information for the network devices. The controller may analyze the device information to determine a device type or role for the network devices. The controller may then select a pre-trained model that is optimal or well- suited for a device type of a particular network device, and perform a distillation function of the language model. Once the language model has been distilled, the controller may augment the language model with locally relevant information such that the language model is contextually relevant for the network device. After fine-tuning the language model, the controller pre-positions the language model on the device so network administrators and other users can access it when necessary.
Owner:CISCO TECHNOLOGY INC

Router affinity in software defined wide area network(s)

ActiveUS12395435B2Digital computer detailsTransmissionService placementEngineering
This disclosure describes techniques and mechanisms for utilizing affinity routing in SDWAN networks. The techniques may enable network administrators to assign and / or configure affinity numbers to hub(s) and / or gateway(s), tunneling interface(s), service(s), etc., as well as affinity-preference-order(s) to edge device(s) within the network. Network administrators may also configure control polic(ies). The techniques enable a scalable and simplified way to automatically load-balance traffic across different gateways within a network, while reducing network resource usage. The techniques may utilize routing affinity to achieve a variety of networking related functionalities, including automatic load-balancing of traffic, provisioning of active and backup gateways, optimal route distribution to routers from routing controllers, optimized service placement for edge routers, without the need for any policy configuration at all, let alone complex policies.
Owner:CISCO TECHNOLOGY INC