Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

55 results about "Network administrator" patented technology

A network administrator is the person designated in an organization whose responsibility includes maintaining computer infrastructures with emphasis on networking. Responsibilities may vary between organizations, but on-site servers, software-network interactions as well as network integrity/resilience are the key areas of focus.

Intention-driven network management method and system based on large language model

The invention relates to the technical field of network management, and discloses an intent-driven network management method and system based on a large language model (LLM). The method comprises the following steps: receiving a natural language intention of a network administrator, analyzing the intention by utilizing a pre-trained large language model, extracting a key target and constraint, generating a configuration scheme of a TCP / IP or QUIC protocol based on an analysis result and a network protocol knowledge base, and ensuring the effectiveness and safety of configuration through a network constraint verification module. And the configuration passing the verification is applied to the network system. The system comprises an intention input module, an LLM analysis module, a configuration generation module, a verification module, an application module and the like. According to the invention, through conversion from automation intention to configuration, the network management process is simplified, the management efficiency and flexibility are improved, the method is especially suitable for multi-parameter optimization scenes of protocols such as TCP / IP and QUIC, and intelligent network management is realized.
Owner:SICHUAN UNIV

Fine-tuning language models for network devices

Techniques and mechanisms for fine-tuning a language model to be optimized for a network device to which the language model is deployed. A controller for a network may maintain an inventory of network devices in a network, and obtain device information for the network devices. The controller may analyze the device information to determine a device type or role for the network devices. The controller may then select a pre-trained model that is optimal or well-suited for a device type of a particular network device, and perform a distillation function of the language model. Once the language model has been distilled, the controller may augment the language model with locally relevant information such that the language model is contextually relevant for the network device. After fine-tuning the language model, the controller pre-positions the language model on the device so network administrators and other users can access it when necessary.
Owner:CISCO TECHNOLOGY INC

Equipment identification method and system based on packet flow semantic feature enhancement, and electronic equipment

The invention provides an equipment identification method and system based on packet traffic semantic feature enhancement, and electronic equipment, and the method comprises the steps: converting the original Internet of Things traffic into a general packet-level traffic semantic feature which can be understood by a large language model, and then carrying out the fine adjustment of the large language model through the packet-level traffic semantic feature, and the large language model can automatically learn potential Internet of Things equipment traffic characteristics and execute equipment classification identification decisions. According to the technical scheme, accurate identification of the Internet of Things equipment is realized, a network administrator can grasp the type and state information of the access equipment in real time, access or abnormal behaviors of unauthorized equipment are effectively identified, safety protection measures are taken in time, and the overall safety of an intelligent environment system is guaranteed.
Owner:NAT UNIV OF DEFENSE TECH +1

System and method for service barring-proces workflow

The system (108) in the present disclosure for service barring workflow is designed to automate and streamline the process of managing service barring actions in a telecommunications network It provides centralized control, efficient processing. and granular control over service restrictions by implementing a method (400) involving various nodes. Tracking Area Code (TAC) and Network administrators. The system (108) offers advantages such as enhanced operational efficiency. accurate enforcement of service barring rules. real-time monitoring. and reporting capabilities. It integrates with network elements and ensures compliance with regulatory requirements. With its flexible and scalable architecture, the system (108) enables administrators and users to efficiently handle service barring requests while maintaining a positive customer experience. Overall, the system (108) for service barring workflow optimizes the service management process. enhances security, and contributes to effective network control and customer satisfaction.
Owner:JIO PLATFORMS LTD

Method and system for NAT (Network Address Translation) optimization engine driven by digital twin network simulation

The invention relates to the technical field of digital twinning technology and network communication optimization, in particular to a method and a system of a digital twinning network simulation driven NAT (Network Address Translation) optimization engine, comprising the following steps: constructing a virtualization mapping model of a physical network; simulating an NAT (Network Address Translation) process in a digital twin environment through a real-time simulation engine; dynamically adjusting an NAT (Network Address Translation) rule and a load balancing strategy of a physical network based on a simulation result; executing safety protection operation in combination with a machine learning algorithm; the method has the beneficial effects that a digital twinning technology and NAT optimization are deeply fused, and a visual and visual management platform is provided for network management personnel. Management personnel can monitor the network state and the NAT performance in real time through the platform and deeply analyze the network problem root by means of a simulation result, and complex field troubleshooting and manual strategy adjustment do not need to be carried out. Therefore, the difficulty and the cost of network management are reduced, the accuracy and the timeliness of management are improved, and the network management is promoted to develop towards the intelligentization and automation directions.
Owner:SHANDONG LANGCHAO YUNTOU INFORMATION TECH CO LTD

Efficient Threat Context-Aware Packet Filtering for Network Protection

PendingUS20250358295A1Securing communicationCyber threat intelligenceAttack
A threat intelligence gateway (TIG) may protect TCP / IP networks from network (e.g., Internet) threats by enforcing certain policies on in-transit packets that are crossing network boundaries. The policies may be composed of packet filtering rules with packet-matching criteria derived from cyber threat intelligence (CTI) associated with Internet threats. These CTI-derived packet-filtering rules may be created offline by policy creation and management servers, which may distribute the policies to subscribing TIGs that subsequently enforce the policies on in-transit packets. Each packet filtering rule may specify a disposition that may be applied to a matching in-transit packet, such as deny / block / drop the in-transit packet or pass / allow / forward the in-transit packet, and also may specify directives that may be applied to a matching in-transit packet, such as log, capture, spoof-tcp-rst, etc. Often, however, the selection of a rule's disposition and directives that best protect the associated network may not be optimally determined before a matching in-transit packet is observed by the associated TIG. In such cases, threat context information that may only be available (e.g., computable) at in-transit packet observation and / or filtering time, such as current time-of-day, current TIG / network location, current TIG / network administrator, the in-transit packet being determined to be part of an active attack on the network, etc., may be helpful to determine the disposition and directives that may best protect the network from the threat associated with the in-transit packet. The present disclosure describes examples of methods, systems, and apparatuses that may be used for efficiently determining (e.g., accessing and / or computing), in response to the in-transit packet, threat context information associated with an in-transit packet. The threat context information may be used to efficiently determine the disposition and / or one or more directives to apply to the in-transit packet. This may result in dispositions and / or directives being applied to in-transit packets that better protect the network as compared with solely using dispositions and directives that were predetermined prior to receiving the in-transit packet.
Owner:CENTRIPETAL NETWORKS INC

Intent-based policy configuration using natural language

Techniques are described for providing a natural language network security policy assistant for allowing a network administrator to implement network security policies using natural language security policy requests. A natural language request can be received by a user and can be translated using Artificial Intelligence into one or more security policy clauses. If the natural language security policy request leads to ambiguities with regard to intended security policies, one or more clarifying questions can be generated as natural language questions and sent to the user for clarification. One or more security policies can be implemented based on the one or more security policy clauses generated in response to the natural language security policy request and / or the natural language response to the clarifying questions.
Owner:CISCO TECHNOLOGY INC

Control device, control program, and control method

To allow for paying attention of a manager of a network to timing at which a terminal requested authentication.SOLUTION: A control device 1 comprises: receiving means 12 which receives a signal including a MAC address of an arbitrary terminal 2 from the terminal; reception means 13 which, if the MAC address included in the signal is not included in registered terminal information, outputs a reception time of the signal and the MAC address and accepts an input indicating whether or not the MAC address can be registered; and assignment means 14 which, if the MAC address included in the signal is included in the registered terminal information, executes processing of assigning an IP address to the terminal. In response to an input indicating that the MAC address can be registered, the receiving means adds the MAC address to the registered terminal information and further outputs a warning on the basis of the time.SELECTED DRAWING: Figure 1
Owner:NEC CORP

Intelligent ship network security defense system integrating active defense and path backtracking

The invention discloses an intelligent ship network security defense system integrating active defense and path backtracking, and relates to the technical field of network security. In a ship network system, a network firewall is connected behind a ship wireless communication channel, and meanwhile, a route backtracking module for actively analyzing an abnormal route is connected to a core switch of a ship network; the module records and analyzes all routes on the core switch and gives an alarm for abnormal routes, meanwhile, a virtual network terminal is installed on the network server and used for simulating functional terminal equipment in a ship network to serve as bait of network viruses, and when the viruses invade the virtual terminal, the virtual terminal can send out the network viruses. And the virtual terminal sends a virus intrusion alarm to a network administrator, starts a route backtracking system to carry out route backtracking, and automatically sends a backtracked source to a virus library of the firewall. According to the invention, a passive and active combined method is adopted to carry out network security defense, and the network security can be obviously enhanced compared with a single firewall mode.
Owner:CHINA SHIPPING TELECOMM

System for monitoring optical fiber distribution networks

The system includes a sensor mounted on a passive element of the network, defined by optical boxes or optical fibers, to detect operational parameters of the passive element and periodically produce data packets that represent reference operating conditions and, in real time, data packages that represent anomalous operating conditions detected by the sensor; an input portal maintained in communication with a group of sensors; a server that receives data packets from the input portals, decoding and authenticating them; and a platform receiving, from the server, the data packets of reference operating conditions and of the anomalous operating conditions, storing them and making them available to a network administrator, to be selectively or automatically sent to a field technician, via a mobile computing device.
Owner:FURUKAWA ELECTRIC LATAM SA

A lightweight satellite network security management system and method

The application provides a lightweight satellite network security management system and method. The system realizes unified management of the satellite network security control plane through a centralized network controller. The system has functions such as security authentication of satellite nodes, dynamic security policy generation and distribution, real-time network monitoring, and rapid security event response. The network controller includes multiple modules such as authentication, policy generation, monitoring, and event response, and can customize security policies according to satellite characteristics and adjust them in real time to respond to security threats. The application also includes lightweight design, especially suitable for resource-constrained satellite environments, and a method for continuously optimizing security policies based on monitoring data and event records. In addition, the provided user interface allows satellite network administrators to easily configure policies and handle events. Through centralized management and dynamic adjustment, the system significantly improves the security and efficiency of satellite networks, has advantages such as lightweight, flexibility, and real-time, and meets the security management needs of modern satellite networks.
Owner:BEIJING RES INST OF TELEMETRY

Cross-device stacking PoE management system and automatic configuration method thereof

The invention relates to the technical field of PoE management, in particular to a cross-device stacking PoE management system and an automatic configuration method thereof, the cross-device stacking PoE management system comprises a master-slave device architecture, the master-slave device architecture comprises a master device and a plurality of slave devices, the master device is used for collecting PoE state information of each slave device and issuing a PoE configuration instruction to the slave devices, the slave device is responsible for executing an instruction of the master device and reporting a state to the master device; the master device configuration module is used for uniformly managing PoE configurations of all slave devices; the slave device execution module is used for receiving and executing a PoE configuration instruction issued by the master device; and the state reporting module is used for reporting the PoE state information to the master device in real time by the slave device. According to the invention, cross-device PoE unified management and control is realized through a master-slave device architecture, and the problem that operation needs to be carried out one by one in a traditional scheme is solved; centralized management, real-time state monitoring and unified configuration of the distributed PoE ports are realized, and the configuration and management process of a network administrator is simplified.
Owner:UNIPOE IOT TECH CO LTD

Operating devices in an operating room

Described are methods and systems for improving cybersecurity of an operating room. A user is prevented from interacting with one or more medical devices connected to an operating room (OR) hub until the user is authenticated through an operations user interface (UI) of the OR hub. The user is authenticated through the operations UI. Authenticating the user through the operations UI includes determining a type of credential possessed by the user. Based on a determination that the user possesses a hospital network administrator credential, the user is permitted to access a plurality of security functions, including enabling and disabling one or more communication ports to which the one or more medical devices are connected. Based on a determination that the user possesses an operator credential, the user is prevented from enabling and disabling the one or more communication ports.
Owner:STRYKER CORP

A method for automatic dual-path planning and transmission implementation in time-sensitive network devices

This invention discloses a method for automatic dual-path planning and transmission implementation of time-sensitive network devices, comprising the following steps: (1) determining the identity information of the redundant path transmission devices of the current TSN device, wherein the identity information includes the sender, receiver, and relay transmission end; (2) assigning a unique ID identifier to all TSN devices in the network; (3) planning two independent data paths 1 and 2, and determining the input and output ports of the two paths; (4) automatically planning the VLAN information on the current path 1 and Path 2. This invention only requires the network administrator to determine the identity information of the sender, relay, and receiver devices and plan the path of critical packets, thereby automatically constructing the device configuration under each path in the TSN ring network; the redundant path of critical transmission is automatically generated by the TSN device itself according to the transmission node and path, without the need for network administrator configuration, reducing the configuration workload, thereby reducing the possibility of network crashes caused by configuration.
Owner:THE 34TH RES INST OF CHINA ELECTRONICS TECH CORP

System and method to allocate and administer guest printing

ActiveUS12669966B2Internet privacyEngineering
A system and method is provided for creating and administering a guest user's document processing operations, such as printing, on a host company network sharing the same cloud print service as the guest's company network. The host network administrator generates a list of companies that are pre-approved for users from a guest company. The guest user logs into the host network and views a list of pre-approved companies. The user selects one or more approved companies for which they are already approved. The user selects a PIN which is then associated with their information, approved companies and guest company. The user then submits their job to the cloud print service for release by a host company MFP. The user logs into a selected host company MFP with their PIN and a listing of any related, pending job is displayed. The user may select one or more jobs for release and printing. The PIN may be revoked by the host administrator, timeout or expire when a selected number of printouts has been made.
Owner:TOSHIBA TEC KK

Attack Scene Detection Method Based on Graph Convolutional Neural Network

This invention relates to the field of network security, and more particularly to an attack scenario detection method based on graph convolutional neural networks. With the increasing complexity and diversity of network attacks, the detection of network attack scenarios has become extremely challenging. Typically, administrators deploy monitoring devices, such as intrusion detection systems (IDS), in network nodes. IDS generate a large number of alert messages to reflect potential attack behaviors in the underlying network. Analyzing these intrusion alert messages can reveal corresponding attack scenarios. A common approach is to group similar network security alert messages together using alert message association, thereby discovering similar attack scenarios. This alert message association provides network administrators with an abstract, higher-level view of the network. This patent proposes an attack scenario detection method based on graph convolutional neural networks to discover attack scenarios in network alert messages. By utilizing graph convolutional neural networks, the detection of attack scenarios is transformed into a multi-classification problem of nodes on the alert message graph, achieving relatively accurate detection results.
Owner:ZHEJIANG YUAN INFORMATION TECH CO LTD

Network cutover control method and device, electronic equipment and medium

The invention provides a network cutover control method and device, electronic equipment and a medium, and relates to the technical field of network security. The network cutover control method comprises the following steps: in response to a cutover command issued by a network administrator, verifying the cutover command according to a historical cutover command to obtain a first cutover command; based on the context of the first cutover command and a preset command template, generating a target command set through a large language model; and predicting target execution time of the target cutover command in the target command set, and controlling the target cutover command to run at the target execution time. Through the technical scheme provided by the invention, the problems of high security risk, low flexibility and low efficiency of network cutover in related technologies are solved, and the security, flexibility and efficiency of network cutover are improved.
Owner:CHINA MOBILE COMM CORP TIANJIN +1

Wireless Network Access Sharing Based on Presence at a Physical Location

Systems, devices and methods are provided for providing access to secure wireless networks to a user based on the user's physical location. In some embodiments, access to such a network is based on user location information, as determined by a control system. A secure network may be provided based on an inference that the user may be trusted to receive access to the network based on their location. Access to the network may be provided based on the user's physical location and an administrative user of the network providing authorization for the user to join the network, e.g., via a user interface. The user may be recognized at a later time, and provided with access again. The control system may provide access to the network to additional user(s) associated with said user, based on a physical interaction or other behavior indicating a trusted relationship with the additional user(s).
Owner:BECKMAN CHRISTOPHER V

Systems and methods for network monitoring, reporting, and risk mitigation

A network monitoring, reporting and risk mitigation system collects events at a computing device within the local network to provide improved network security. The events are aggregated into alerts, which may be processed according to triggering definitions in order to create ARO (action, recommendations and observations) reports providing required or recommended actions to take or observations to a network administrator. The ARO reports may be processed by a remote server in order to generate contextual feedback for updating the triggering definitions.
Owner:FIELD EFFECT SOFTWARE INC

Fine-tuning language models for network devices

Techniques and mechanisms for fine-timing a language model to be optimized for a network device to which the language model is deployed. A controller for a network may maintain an inventory of network devices in a network, and obtain device information for the network devices. The controller may analyze the device information to determine a device type or role for the network devices. The controller may then select a pre-trained model that is optimal or well- suited for a device type of a particular network device, and perform a distillation function of the language model. Once the language model has been distilled, the controller may augment the language model with locally relevant information such that the language model is contextually relevant for the network device. After fine-tuning the language model, the controller pre-positions the language model on the device so network administrators and other users can access it when necessary.
Owner:CISCO TECHNOLOGY INC

A non-stress measurement method for the availability of network agent services, and system thereof

The present invention belongs to the technical field of network management, and relates to a non-stress measurement method for the availability of network agent service (s), and system thereof. By adopting advanced data sampling, time series prediction and machine learning technology, the present invention can evaluate the availability of proxy services in real time and accurately, which is helpful for network administrators to better monitor, maintain and optimize proxy services and improve the overall security and stability of the network.
Owner:INSTITUTE OF INFORMATION ENGINEERING CHINESE ACADEMY OF SCIENCES

A routing optimization method for distributed training cluster communication

ActiveCN119743401Breduce overheadEnable non-blocking traffic communicationTransmissionEngineeringNetwork topology
This invention discloses a routing optimization method for distributed training cluster communication. The method comprises two parts: a traffic analysis component and a routing optimization component, both implemented in the centralized control plane of a software-defined network. The traffic analysis component needs to perceive the specific communication mode adopted by the application layer and the node allocation configured by the network administrator to obtain relevant traffic information, including the origin, destination, and amount of data transmitted for each flow, as well as the dependencies between flows. The routing optimization component then performs non-blocking route allocation based on the obtained task traffic information and network topology. This invention, targeting distributed machine learning data center training clusters, achieves overall non-blocking traffic communication by perceiving task cluster communication traffic and optimizing routes, reducing training communication overhead and further improving task completion time. It has application value in current mainstream large-scale model training scenarios.
Owner:ZHEJIANG UNIV

Intelligent electric energy meter verification method and system based on Bundy system parallel computing acceleration

The invention relates to an intelligent electric energy meter verification method and system based on federated parallel computing acceleration, and belongs to the field of intelligent electric energy meter verification. According to the method, a network administrator identifies and establishes equipment with computing and networking capabilities, node roles are distributed by using an MPI protocol, and a stable associate system private computing group is formed; the task distribution and scheduling module decomposes a complex verification task into sub-tasks, intelligently distributes the sub-tasks to each node based on a real-time resource monitoring and load balancing algorithm, and dynamically adjusts the sub-tasks to cope with changes; the central coordinator monitors the task progress and the system health of each node in real time, records execution data, quickly responds to faults and optimizes resource allocation; the system adopts a distributed computing mode to execute a complex algorithm, such as a deep learning model, and ensures computing efficiency and result accuracy through parallel processing and result integration. According to the invention, the computing power of edge equipment is fully utilized, and a supervision and coordination mechanism is combined, so that an efficient and stable electric energy meter verification solution is provided.
Owner:STATE GRID TIANJIN ELECTRIC POWER COMPANY +1

Implementing configuration changes using language models

PCT designated stageWO2026178104A1Linguistic modelSoftware engineering
Techniques for providing a language model to understand and recommend product configuration changes, corresponding to specific requirements are described. A language model is deployed to a network controller and is configured to respond to inputs from network administrators. The language model receives an input from the netw ork administrator indicating a description of a requirement for a configuration change. The language model determines a series of actions to execute to implement the configuration change. Finally, the language model outputs the series of actions to execute to the network administrator.
Owner:CISCO TECHNOLOGY INC

Cross-environment generalization network traffic optimization method based on large model agent

The application relates to the field of network traffic optimization, and particularly relates to a cross-environment generalization network traffic optimization method based on a large model agent. The technical scheme comprises the following steps: data collection, collecting a historical traffic matrix, network topology and capacity information and a natural language instruction from a network administrator; the collected historical traffic matrix, network topology and capacity information are sent to a feature decoupling module for cross-environment feature decoupling, and the natural language instruction is sent to a large model agent for strategy understanding and embedding; then, a pre-trained network traffic engineering head decoding is used to generate network routing allocation; finally, the routing allocation is issued through a network model context protocol of the large model, and network feedback and performance indexes are monitored, which are used as inputs of the next round of optimization to form a closed loop control. The application is suitable for network traffic optimization.
Owner:THE CHINESE UNIV OF HONG KONG (SHENZHEN) +1

Systems and methods for network monitoring, reporting, and risk mitigation

A network monitoring, reporting and risk mitigation system collects events at a computing device within the local network to provide improved network security. The events are aggregated into alerts, which may be processed according to triggering definitions in order to create ARO (action, recommendations and observations) reports providing required or recommended actions to take or observations to a network administrator. The ARO reports may be processed by a remote server in order to generate contextual feedback for updating the triggering definitions.
Owner:FIELD EFFECT SOFTWARE INC

Alarm processing method and device, electronic equipment and storage medium

The invention provides an alarm processing method and device, electronic equipment and a storage medium, and relates to the technical field of security. According to the method, multiple pieces of alarm information generated by one attack activity in the same time can be aggregated through the feature codes and the generation time, so that alarm redundancy can be removed, the number of alarms is effectively reduced, the processing speed of a network administrator is improved, and the network administrator can process network threat events more conveniently and effectively.
Owner:QI AN XIN TECHNOLOGY GROUP INC

Secured network switch and method for secure and configurable filtering

A secured network switch is configured to enforce security between devices on a home network to ensure vulnerable devices do not compromise assets on privileged devices. The secured switch operates at the data link layer and is configured to enforce security based on device management and enforcement. The switch is configured to only allow devices that have been classified to allow communication with each other to forward packets to each other. The switch is configured to use broadcast, multicast, and network neighbor management to control the device discovery through the switch. The secured switch will also gather device information by snooping various sources of device ‘broadcast’ information and present this information via a user interface to aid network administrators in classifying devices and creating device to device relationships.
Owner:SILICONDUST USA INC

Method, system, and computer program product for address translation

The present disclosure relates to a method, system, and computer program product for address translation. The method includes receiving an access request from the outside of a cluster service to the inside by an ingress control service. The method further includes generating a callback for the access request in response to receiving the access request. The method further includes translating a source address of the callback to a network address of the ingress control service by an egress container group, wherein the network address of the ingress control service is a destination address of the access request. According to embodiments of the present disclosure, by this method of translating the source address of the callback to the destination address of the access request, it is possible to enhance the security of network communication and improve the convenience of network management, which enhances the management experience of a network administrator.
Owner:DELL PROD LP