Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

489 results about "Network segment" patented technology

A network segment is a portion of a computer network. The nature and extent of a segment depends on the nature of the network and the device or devices used to interconnect end stations.

Fault rapid positioning method and device in MGX system

The invention provides a fault rapid positioning method and device in an MGX system, and belongs to the field of server system management and fault diagnosis. The method comprises the following steps: determining an idle universal serial bus interface on a mainboard, and selecting a target USB interface and a fixed IP network segment configuration corresponding to the target USB interface from the idle USB interface; the BMC establishes a physical connection with a device where the HMC is located through the target USB interface, and constructs a virtual local area network channel; in the virtual local area network channel, performing out-of-band communication between the BMC and the HMC; the BMC obtains list information of each component in the MGX system from the HMC, and classifies the list information according to component types; the HMC pre-collects and stores the state information of each category according to the classification result; and the BMC periodically reads the state information based on the Redfish protocol, and identifies the fault in the MGX system according to the state information. According to the method and the device provided by the invention, the fault can be quickly and accurately positioned.
Owner:ENGINETECH COMPUTER CO LTD

Router fluidity using tunneling

The present application describes a system and method for utilizing a tunnel in a networking routing protocol to provide a network segment access to additional servers when certain load balancing trigger events are detected.
Owner:LEVEL 3 COMMUNICATIONS LLC

Asset vulnerability detection method and device, electronic equipment and storage medium

The invention discloses an asset vulnerability detection method and device, electronic equipment and a storage medium, and relates to the technical field of network security, and the method comprises the steps: actively sending a multi-protocol detection packet to scan a target network segment, and obtaining a first asset set; passively monitoring network traffic to extract asset feature information, and obtaining a second asset set to generate an asset list; port scanning tasks of all assets are dispatched to a plurality of scanning nodes in a distributed and parallel mode, dynamic port scanning is carried out according to a descending order of a plurality of key elements in combination with a port scanning optimization model based on risk prediction, and a full-amount port risk map is constructed; the static layer is matched with known vulnerabilities; the dynamic layer identifies suspicious behaviors deviating from a normal behavior baseline through an anomaly detection algorithm, and obtains an asset vulnerability detection result in combination with a cross validation method; according to the invention, the detection requirements of asset full coverage and early threat discovery in a complex network environment are met.
Owner:GUANGDONG ORIENTAL THOUGHT TECH

AI-powered cybersecurity system for regulatory compliance in energy distribution

A system for AI-supported cybersecurity and regulatory compliance in energy distribution networks, consisting of: a hardware-embedded data acquisition module configured to intercept, capture, and time-stamp operational data streams and to control data traffic from SCADA (Supervisory Control and Data Acquisition) systems, AMI (Advanced Metering Infrastructure) systems, and energy management systems (EMS) via multiple communication protocols without operational latency; an FPGA-based deep packet inspection unit coupled with the data acquisition module, wherein the FPGA firmware is configured to perform line rate filtering, protocol decomposition and metadata extraction of the acquired data and forwards preprocessed packet data to an AI processing unit; an AI processing unit consisting of a multi-core central processing unit (CPU), a dedicated AI accelerator selected from a graphics processing unit (GPU) or a tensor processing unit (TPU), and a volatile memory buffer; a response orchestration module that is communicatively coupled with network management devices and operations controllers, wherein the response orchestration module is configured to perform automated security and compliance remediation measures, including network isolation of compromised segments, enforcement of protocol encryption, and privilege revocation; and an immutable audit logging subsystem configured to record all detected events, compliance assessments, and corrective actions in a blockchain-based distributed ledger, with each log entry cryptographically anchored with a secure hash value and digitally signed with keys stored in a secure hardware enclave.
Owner:ALIF MUHAMMAD +11

Method and apparatus for traffic scheduling implementation, device, storage medium, and program product

The present disclosure provides a method of traffic scheduling implementation, including: receiving a domain name resolution request sent by a first business application on a first terminal device, and performing domain name resolution on the domain name resolution request to determine a to-be-resolved domain name; if the to-be-resolved domain name is a target domain name, determining, from a preset network segment, a first virtual network address corresponding to the to-be-resolved domain name, and using the first virtual network address as a first traffic destination address corresponding to the to-be-resolved domain name, where the preset network segment includes a plurality of virtual network addresses; and sending the first traffic destination address to the first business application on the first terminal device, to cause the first business application to perform data transmission based on the first traffic destination address.
Owner:BEIJING VOLCANO ENGINE TECH CO LTD

Method for Configuring Network Address Translation Gateway and Cloud Management Platform

A method for configuring a network address translation NAT gateway based on a public cloud service including: a cloud management platform obtains NAT gateway creation information that is input by a tenant; The cloud management platform creates the NAT gateway in the first VPC based on the NAT gateway creation information; The cloud management platform obtains configuration information that is input by the tenant and applied to the NAT gateway; The cloud management platform sets, based on the identifier of the second VPC, the NAT gateway to be connected to the second VPC, and sends the first NAT rule to the NAT gateway, where the first NAT rule is used to indicate the NAT gateway to: bind a first network segment in the first VPC to a first elastic IP address EIP; and bind the first network segment in the first VPC to a first transit private IP address.
Owner:HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD

Segment scanning type DDoS attack detection method and device, electronic equipment and storage medium

The invention discloses a segment scanning type DDoS attack detection method and device, electronic equipment and a storage medium. The detection method comprises the following steps: for each IP address in a plurality of IP addresses, acquiring a first traffic feature set comprising traffic features of N dimensions of a first traffic set taking the IP address as a destination IP address in a first time period; calculating weights respectively corresponding to the traffic characteristics of the N dimensions based on a historical traffic set; corresponding weights are given to the traffic features of the N dimensions of the IP address, and a second traffic feature set corresponding to the IP address is obtained; clustering the plurality of IP addresses based on a plurality of second traffic feature sets corresponding to the plurality of IP addresses to obtain a clustering result; and determining the IP address network segments subjected to the segment scanning type DDoS attack in the IP address network segments where the plurality of IP addresses are located based on the clustering result. According to the method and the device provided by the embodiment of the invention, the segment scanning type DDoS attack can be effectively detected, the false alarm and the missing alarm are reduced, and the network security is improved.
Owner:BEIJING VOLCANO ENGINE TECH CO LTD

VPN networking system and method, electronic device and computer program product

The invention provides a VPN networking system and method, electronic equipment and a computer program product. Relates to the technical field of communication. In view of the problems of traditional VPN link resource waste and difficult session hot backup, the invention provides a VPN networking system, which comprises a VPN site and a VPN gateway cluster, and the VPN gateway cluster comprises M device nodes based on mesh distribution; a VPN tunnel is established between each device node and the VPN site; the VPN subnet at the local area network side is divided into M subnet segments, and each equipment node bears one subnet segment; every two device nodes in the VPN gateway cluster are in communication connection based on a VPN link, each device node comprises routing information of M device nodes, the routing information is used for indicating a forwarding path of sub-network segment flow when a system breaks down, and the routing information comprises next hop information of a sub-network segment borne by each device node. According to the embodiment of the invention, the method does not depend on session hot backup, achieves the quick and smooth switching of the VPN tunnel, and improves the resource utilization rate.
Owner:TP-LINK

Equipment identification method and device, equipment and medium

ActiveCN120835105ATransmissionAddress Resolution ProtocolMediaFLO
The invention relates to the technical field of Internet of Things, and provides an equipment identification method and device, equipment and a medium, which can start a probe to asynchronously initiate an address resolution protocol broadcast request for a target authorized network segment in a sectional manner to generate an active equipment list, and can avoid congestion, thereby accurately detecting active equipment. Performing port detection on each device in the active device list, performing multi-protocol verification on an open port according to a port-protocol adaptive matching mechanism, and performing organization unique identifier analysis on a media access control address of each device in the active device list; the problem of missing detection caused by single protocol broadcasting and port change and the problem of false alarm caused by only organizing unique identifier analysis are solved; and calculating a confidence score of each device according to the fusion features to generate an identification result of each device, so that device identification can be accurately carried out step by step by integrating multi-dimensional factors, and the false alarm rate is effectively reduced.
Owner:PRIMFORCE TECHNOLOGIES LTD

Flood Suppression of Link-Local Multicast and Broadcast Traffic

Techniques for suppressing the flooding of link-local multicast and broadcast traffic are provided. In certain embodiments, these techniques include receiving, by a network device, a link-local multicast or broadcast message from an endpoint, where the message pertains to a networking protocol that uses link-local multicast and / or broadcast transmissions; dropping, by a data plane of the network device, the message in hardware, such that the message is not flooded on the local network segment of the endpoint; copying, by the data plane, the message to the device's central processing unit (CPU); and processing, by software running on the CPU, the message in accordance with the message's networking protocol (and in a manner that eliminates the need to flood the message).
Owner:ARISTA NETWORKS INC

Efficient split management in a virtual switch using a spanning tree

A network device of a virtual switch, which includes a second network device and operates on a unified control plane, is provided. During operation, the network device maintains a link between its first port and a second port of the second network device. Here, the first link can be distinct from a second link used for exchanging data traffic of the virtual switch. The network device operates a spanning tree protocol to place the first and second ports in respective port states, which include a forwarding state and a blocked state. If the second link becomes unavailable, the network device determines that the virtual switch has split into a first segment comprising the network device and a second segment comprising the second network device. If the first port state is in the blocked state, the network device suspends communication via a respective port of the first segment.
Owner:HEWLETT PACKARD ENTERPRISE DEV LP

Load balancing secure network traffic

Techniques for load balancing secure network traffic are disclosed. A system, process, and / or computer program product for load balancing secure network traffic includes monitoring network traffic for one branch of a plurality of branches for an enterprise network, and splitting the network traffic of the one branch into a plurality of network segments based on a determination that the network traffic exceeds traffic capacity of at least one security processing node (SPN) of a plurality of SPNs using a network load balancer (NLB) in communication with a plurality of Network Processing Nodes (NPNs), the plurality of monitored branches being distributed to the plurality of SPNs via a plurality of tunnels.
Owner:PALO ALTO NETWORKS INC

Voice assistant interaction method and system

The invention discloses a voice assistant interaction method and system, the system comprises an end side device layer, a cloud service layer and a communication interaction layer, the end side device layer comprises at least two terminal devices, and each terminal device is provided with a multi-mode sensor. According to the invention, single-mode noise interference is compensated through multi-mode data fusion, which is significantly superior to the existing voice assistant; a personalized strategy is generated based on a triple of intention, emotion and equipment, so that the interaction experience is improved; local priority synchronization is realized by adopting a double-layer MQTTBroker architecture, the state synchronization delay of cross-network segment equipment is reduced, multi-equipment collaboration is supported, and seamless switching among equipment is realized.
Owner:NANJING HUJU LONGPAN INTELLIGENT TECH CO LTD

Diagnostic service processing method and device based on gateway technology, and electronic equipment

The invention provides a diagnostic service processing method and device based on a gateway technology, and electronic equipment. The method comprises the following steps: carrying out service processing operation on a diagnostic service; determining a diagnostic protocol type corresponding to the diagnostic service; determining whether a diagnosis protocol used by the diagnosis service is consistent with an in-vehicle unified diagnosis protocol; if the diagnosis protocol used by the diagnosis service is consistent with the in-vehicle unified diagnosis protocol, directly sending the diagnosis service to a corresponding target network segment through the in-vehicle gateway; if the diagnosis protocol used by the diagnosis service is not consistent with the in-vehicle unified diagnosis protocol, the diagnosis service is converted into the in-vehicle unified diagnosis protocol format according to the data frame format corresponding to the diagnosis service, and the processed diagnosis request is sent to the corresponding target network segment through the in-vehicle gateway. Through inter-conversion of diagnosis protocols inside and outside a vehicle, the compatibility problem among different diagnosis protocols is solved.
Owner:CHONGQING RUICHI AUTOMOBILE IND CO LTD

Train communication address allocation method, electronic equipment and storage medium

PendingCN121217702ATransmissionMarshallingNetwork addressing
The invention discloses a train communication address allocation method, electronic equipment and a storage medium, and the method comprises the steps: carrying out the detection interaction between train-level backbone network modules of each train to determine a subnet segment corresponding to each train, and receiving an address request of local target equipment based on an Ethernet train composition module of each train, the unique network address is allocated based on the subnet segment, so that the technical problems of low efficiency, easy conflict and incapability of adapting to flexible marshalling requirements caused by manual configuration of the communication address during marshalling adjustment of the existing train are solved, automatic allocation of the train communication address is realized, the marshalling adjustment time is greatly shortened, address conflict is avoided, and the marshalling adjustment efficiency is improved. And meanwhile, different marshalling switching is adapted to meet diversified operation requirements.
Owner:CRRC DALIAN CO LTD

Load balancing secure network traffic

Techniques for load balancing secure network traffic are disclosed. A system, process, and / or computer program product for load balancing secure network traffic includes monitoring network traffic for one branch of a plurality of branches for an enterprise network, and splitting the network traffic of the one branch into a plurality of network segments based on a determination that the network traffic exceeds traffic capacity of at least one security processing node (SPN) of a plurality of SPNs using a network load balancer (NLB) in communication with a plurality of Network Processing Nodes (NPNs), the plurality of monitored branches being distributed to the plurality of SPNs via a plurality of tunnels.
Owner:PALO ALTO NETWORKS INC

Method for implementing zero trust role-based microsegmentation based on network switch and network controller and access switch using the same

There is provided a method for implementing a zero trust role-based microsegmentation based on a network switch. The method includes steps of: (a) registering, by a network controller, the specific network device in a specific segment among preset segments by referring to asset information corresponding to the specific network device; and (b) transmitting, by the network controller, a specific segment ID corresponding to the specific segment to the access switch, to thereby instruct the access switch to assign the specific segment ID as metadata to a specific MAC address of the specific network device by using VACL, and control an access of the specific network device to the network resources based on at least one specific resource access control rule corresponding to the specific segment ID by using IACL.
Owner:PIOLINK

Local area network system and backbone network system

The invention provides a local area network system and a backbone network system, belongs to the technical field of computers, and particularly relates to the technical field of communication, computer networks, routing and fault detection. According to the specific implementation scheme, the regional network system comprises a plurality of network nodes, each network node comprises a plurality of detectors and a plurality of forwarding devices, the detectors are in communication connection with the forwarding devices respectively, and the forwarding devices are in communication connection with the forwarding devices included in the other network nodes respectively; wherein the forwarding equipment is used for receiving a data packet and forwarding the data packet to the detector determined based on a destination address of the data packet under the condition that the destination address of the data packet belongs to a first routing network segment of the forwarding equipment; and the detector obtains fault information based on the received data packet.
Owner:BEIJING BAIDU NETCOM SCI & TECH CO LTD

Method and system for adjusting target depth of disturbance based on dynamic address hopping attack

The application provides a dynamic address hopping attack target depth interference adjustment method and system, and belongs to the technical field of network security.The method comprises the following steps: searching for idle IP addresses of each network segment in a user network area through a network scanning tool; generating a large number of trapping hosts based on the collected idle IP addresses; performing same-side mixed deployment on the generated trapping hosts and real hosts of the user; determining the hopping range of the IP addresses of the trapping hosts, setting specific IP address segments according to network planning, setting the hopping port number range of each trapping host, and dividing different port groups according to the service type; through the deployment of the dynamic address hopping and the large number of trapping hosts, the difficulty of the attacker in identifying and attacking the real host is significantly improved, so that the attack behavior of the attacker is effectively interfered, and the overall network security is improved.
Owner:HANGZHOU TONGWEI INFORMATION TECHNOLOGY CO LTD

Communication protocol for inference of physical slot identifier by baseboard management controller of blade server

ActiveUS12531938B2User identity/authority verificationBroadcast domainEthernet frame
This disclosure describes techniques for interoperability of a blade server in a server chassis, where IOMs of the server chassis do not provide dedicated pins for communicating a physical slot ID to the blade server. BMCs of the blade servers and CMCs of IOMs of the server chassis are mutually configured to broadcast Ethernet frames on layer 2 network segments over a broadcast domain configured by a switch module connected to the blade servers over layer 2 network segments; conduct a slot inference communication protocol using these Ethernet frame broadcasts to enable the CMC to determine a physical slot ID in response to a BMC request, and broadcast that physical slot ID back to the BMC; and use a public certificate-private certificate pair, based in a hardware root of trust, to enforce security of this communication protocol.
Owner:CISCO TECHNOLOGY INC

Agent surveying and mapping method and system for isolated network blind area asset discovery

The invention relates to the technical field of network security and information, in particular to an Agent surveying and mapping method and system for isolating network blind area asset discovery, and the method comprises the steps: deploying an Agent at a terminal, collecting local data including an ARP cache, a network connection table, a hardware fingerprint and a behavior portrait, and encrypting and uploading the local data. The main control center performs asset deduplication and identity verification based on hardware fingerprints, processes connection data by using a time window alignment and session continuity analysis algorithm to solve association ambiguity caused by time sequence dislocation and temporary connection, and establishes a cross-Agent connection relationship with high confidence. And finally fusing the connection relation and behavior portrait data, and incorporating the data into unmanaged assets found by a link layer to synthesize a global asset topology of a cross-logic network segment. According to the method, the coverage rate, the identification accuracy and the real-time performance of asset discovery in a complex isolation network environment are improved, and meanwhile, the interference risk of a scanning process on a service network is eliminated.
Owner:CHINA RAILWAY XIAN GRP CO LTD

Method and device for converting text programming language into graphical programming language

The invention relates to the technical field of programming language conversion, in particular to a method and device for converting a text programming language into a graphical programming language, and the method comprises the steps: converting an input text programming language source code into a structured program-network segment-row-element lattice level data object, generating a text programming language list taking the network segment as a unit; traversing the text programming language list, retrieving a keyword instruction in the text programming language list according to the text programming language protocol, performing region splitting and analysis, generating graphic region information blocks, and storing the graphic region information blocks in a graphic region general list; after processing of all text lines in the current network segment is completed, normalization processing is carried out on the graphic area general table, and conversion of the network segment from a text programming language to a graphic programming language data structure is completed; and summarizing the conversion results of all the network segments to form a complete graphical programming language program. And the conversion efficiency from the text programming language to the graphical programming language is improved.
Owner:JINAN BODOR LASER CO LTD

Resource allocation method and device for secure resource pool, equipment and storage medium

The invention provides a resource allocation method and device for a security resource pool, equipment and a storage medium. The method comprises the following steps: acquiring the type, specification, service logic and address of a security instance required by a tenant; based on an allocable resource group of the resource pool, screening a node matched with the type and the specification, and allocating a security instance of the node for the tenant; constructing a service chain according to the business logic; the diverter creates a VLAN-IF interface for a tenant, binds a service chain and configures a first route and a second route according to a tenant address, a source network segment of the first route is a tenant address, an incoming interface is a first interface of the diverter, an outgoing interface is the VLAN-IF interface, flow flows into the diverter from the first interface and is transferred to the service chain through the VLAN-IF interface, a destination network segment of the second route is the tenant address, and the tenant address is a tenant address. The input interface is a VLAN-IF interface, the output interface is a first interface of the shunt, and the flow processed by the service chain flows into the shunt from the VLAN-IF interface and is returned to the tenant through the first interface.
Owner:HANGZHOU DPTECH TECH

Managing a delay of network segments in an end-to-end communication path

Embodiments of systems and methods for managing a delay of network segments in an end-to-end communication path may include determining an end-to-end time delay measurement of a communication path spanning a first communication network and a second communication network, and transmitting a message comprising the determined end-to-end time delay measurement of the communication path spanning the first communication network and the second communication network to a network element of the first communication network, wherein the message is configured to enable the network element of the first communication network to configure the first communication network to provide sufficient Quality of Service (QoS) to support an end-to-end QoS requirement based on the determined end-to-end time delay.
Owner:QUALCOMM INC

A PLC system communication method and system based on a DCS redundant network

The application provides a PLC system communication method and system based on a DCS redundant network, relates to the technical field of industrial automation control system communication network integration, and comprises the following steps: network architecture reconstruction, direct access of a programmable logic controller (PLC) to a redundant industrial Ethernet of a distributed control system (DCS), and formation of a unified local area network; IP address planning, allocation of addresses of the same preset IP network segment to controllers of the DCS, PLCs, industrial personal computers and optional communication modules, and ensuring direct communication between devices; the application can save special communication modules and supporting equipment, reduce direct hardware cost, reduce cabinet space occupation and wiring cost by fully utilizing the existing redundant network infrastructure of the DCS; for a system containing multiple PLCs, the cost advantage is more obvious, no additional investment in redundant communication hardware is needed, and the overall investment is further reduced.
Owner:YANGCHUN NEW STEEL CO LTD

Intent-based enterprise security using dynamic learning of network segment prefixes

In an example, systems and methods enable automatic implementation of intent-based security policies in a network system, such as a software-defined wide area network system, in which network segment prefixes for network segments at one or more sites are dynamically learned. A service orchestrator controller translates an intent-based security policy input by a user to a security policy for a first site. The security policy for the first site specifies a segment-specific queryable resource associated with a second site. To implement the security policy, a device associated with the first site queries the segment-specific queryable resource associated with the second site, and updates one or more forwarding tables of the device with the network segment prefixes associated with one or more network segments at the second site received in response to the query. The first site forwards network traffic to the second site based on the updated forwarding tables.
Owner:JUNIPER NETWORKS INC

Crown block remote monitoring regulation and control system

The invention provides a crown block remote monitoring and regulating system, and relates to the technical field of crown blocks. The crown block remote monitoring regulation and control system comprises a crown block control system and network bridge equipment, the crown block control system is connected with the network bridge equipment, and the network bridge equipment is configured to establish communication connection with ground terminal equipment when the network bridge equipment and the ground terminal equipment are located in the same network segment. The network bridge equipment is configured to form a sight distance wireless communication path with the ground terminal equipment when the network bridge equipment is in communication connection with the ground terminal equipment; the crown block control system is used for collecting operation data of different crown block assemblies and transmitting the operation data to the ground terminal equipment through the network bridge equipment, so that the ground terminal equipment displays the operation state and fault information of the crown block assemblies in real time according to the operation data. According to the invention, errors and lagging caused by manual reading or single instrument monitoring in the prior art are avoided, and the safety and the working efficiency are greatly improved.
Owner:GUANGXI DEBAO BAIKUANG ALUMINUM CO +3

Method and system for testing optical module by using server

The invention relates to a method and system for testing optical modules by using one server, and the method comprises the following steps: connecting two optical modules to be tested, which need to be streamed, to two Ethernet ports of one server, and connecting the two optical modules to be tested, which need to be streamed, with a switch through optical fibers; aiming at two Ethernet ports connected with two to-be-tested optical modules needing streaming, two independent network namespaces are created on a server, and the two Ethernet ports are respectively distributed to the two network namespaces; allocating an IP (Internet Protocol) for a network card in each network namespace, setting default routes for the two network namespaces, respectively pointing to the IP of the logic port of the butted switch, and configuring the IP of the logic port corresponding to the switch, so that the network namespace in which each Ethernet port is located and the logic port of the butted switch are located in the same network segment; the network segments of the two network namespaces are different from each other, and the switch can forward the traffic of the two network segments; and testing the flow between the two optical modules to be tested.
Owner:WUHAN HUAGONG GENUINE OPTICS TECH CO LTD

Network segment control method and device based on sentry mode, equipment and medium

The invention relates to the technical field of network segment control, and discloses a network segment control method and device for a sentry mode, equipment and a medium, and the method comprises the steps: activating an appointed network management function group corresponding to the sentry mode through a preset network management strategy when the sentry mode of an appointed vehicle is started; after the specified network management function group is activated, determining a first network segment related electronic control unit in a CAN network and a second network segment related electronic control unit in an LIN network which need to be kept in a sentry mode; controlling a related electronic control unit of a third network segment of the CAN network to enter dormancy through the specified network management function group, wherein the third network segment is the other network segments except the first network segment in the CAN network; and controlling a related electronic control unit of a fourth network segment of the LIN network to enter dormancy through the specified network management function group, wherein the fourth network segment is the other network segment except the second network segment in the LIN network.
Owner:GREAT WALL MOTOR CO LTD

Device for autonomous detection of cyber threats

A device for the autonomous detection of cyber threats, consisting of: a housing that encloses a multitude of interconnected hardware components; a network interface unit configured to receive and send data packets from one or more communication networks; a data acquisition unit that is operationally connected to the network interface unit and configured to capture packet-level data, metadata, and system event logs; a preprocessing processor configured to analyze captured data, decodecode protocols, reconstruct communication flows, and generate structured data representations; a feature extraction processor that is operationally coupled with the preprocessing processor and is configured to calculate statistical, temporal and entropy-based features from the structured data representations; a storage unit consisting of volatile memory for real-time processing and non-volatile memory for storing historical data and learned patterns; an inference processor that is operationally coupled with the feature extraction processor and the storage unit, wherein the inference processor is configured to execute a variety of trained models to identify anomalous behavior based on deviations from stored patterns; a classification unit that is operationally coupled with the inference processor and configured to assign detected anomalies to one or more threat categories based on calculated confidence values; a response control unit configured to generate and transmit remedial actions, including blocking network traffic, isolating network segments, and terminating suspicious processes; and a control processor configured to coordinate the data flow between the network interface unit, the data acquisition unit, the preprocessing processor, the feature extraction processor, the inference processor, the classification unit, the response control unit, and the storage unit, with the device operating autonomously to detect and respond to cyber threats in real time.
Owner:ALMOMANI DUAA SHAWKAT +1