Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

112 results about "Overlay network" patented technology

An overlay network is a computer network that is built on top of another network.

Precise synthesis-based graph mapping method

The invention discloses a graph mapping method based on precise synthesis, and the method comprises the steps: constructing a precise synthesis structure library based on NPN equivalence classes, and inputting the precise synthesis structure library into a Boolean network; k-Cut cutting enumeration is carried out on the input Boolean network, a truth table is calculated, cutting is matched with a structure in a precise comprehensive structure library through Boolean matching, and rapid search is realized in combination with NPN classification; the overlay network is generated through multi-round mapping optimization, logic sharing nodes are mined in combination with structural hash, and the multi-round mapping optimization comprises delay-oriented mapping, global area topological optimization and local accurate area optimization; and a new target network is generated based on the optimized overlay network, redundant nodes are removed, and final network construction is completed. According to the method, manual intervention is not needed through full-process automatic mapping and a redundancy removal mechanism, the labor cost of a technical mapping link in chip design is remarkably reduced, and the method is particularly suitable for efficient design of complex circuits and emerging majority of logic base technologies.
Owner:HANGZHOU JIUZHIXING SOFTWARE CO LTD

Combining multiple detection algorithms into a confidence score for bot detection

A bot detection service associated with an overlay network operates to score traffic as a probability of being a bot, as opposed to returning a binary classification (i.e., bot or human). According to the approach herein, scoring is determined through probability estimates, wherein a score (the probability) is based on considering a set of detections concurrently. In one embodiment, all (or substantially all) triggered (current) threat detections contribute to the score. The preferred approach penalizes requests that fail all (or substantially all) combinations of detection algorithms. According to a further feature, an automated tuning (autotuning) is also applied, e.g., using real-time empirical statistical models, to adapt the measurement of false positive probability for one or more threat detection algorithms to suit customer traffic trends. The approach herein is also extensible to include any number of future threat detection algorithms.
Owner:AKAMAI TECHNOLOGIES INC

Policy builder for overlay networks

Embodiments are directed to managing communication over a network. Entities may be determined based on network traffic in an underlay network and classified based on characteristics of the entities, portions of the network traffic in the underlay network, or the like. Policies for an overlay network may be generated based on the classified entities or the portions of the network traffic. Policies may be deployed to gateways that may be associated with the entities such that the gateways facilitate access to the overlay network based on the policies. In response to determining other entities in the underlay network based on other network traffic in the overlay network and the network traffic in the underlay network, the one or more policies may be updated based on the other network traffic in the overlay network, the network traffic in the underlay network, or the one or more other entities.
Owner:TYCO FIRE & SECURITY GMBH

Network threat systematic protection method

PendingCN121966996ASecuring communicationSecurity operations centerData aggregator
The invention discloses a network threat systematic protection method, and belongs to the technical field of network security. According to the method, a unified policy center is constructed, and three layers of security policies of an overlay network, a terminal and an application are defined and issued in a unified manner; network admission control, terminal security management and API risk monitoring systems are deployed to execute strategies respectively; an intelligent linkage mechanism is established, and cross-system automatic co-processing is realized; centralized monitoring, data aggregation and visual analysis are carried out through the unified safety operation center, and support is provided for optimization; and continuously optimizing the strategy and the rule based on the operation data. According to the invention, the problems of isolation, strategy splitting and response lag of a protection system in the prior art are solved, and an active defense system with cooperative linkage and continuous evolution is constructed.
Owner:GUANGZHOU CHANGBENHENG NETWORK TECHNOLOGY CO LTD +1

Efficient multicast source roaming in an overlay network

A first network device operating as a tunnel endpoint in a tunnel fabric is provided. During operation, the first network device can receive, via a local port, a network join request to receive multicast traffic of a multicast group from a second network device. The first network device can store a multicast state for the multicast group in a data structure associated with the control plane. The multicast state can indicate that the network join request is received via a tunnel between the first and second network devices. The first network device can then determine whether a source of the multicast group is coupled to the first network device. If the source is coupled to the first network device, it can program a multicast forwarding entry corresponding to the multicast state in forwarding hardware and forward the multicast traffic to the second network device based on the multicast forwarding entry.
Owner:HEWLETT PACKARD ENTERPRISE DEV LP

EVPN host routing bridging HRB and EVPN cloud native data center

The embodiment of the invention relates to EVPN host routing bridging (HRB) and an EVPN cloud native data center. Techniques are described for an EVPN host routing bridge (HRB) and an EVPN cloud native data center with a host routing bridge (HRB). A host computing device of a data center includes one or more containerized user-level applications. The cloud native virtual router is configured to be dynamically deployed by a datacenter application orchestration engine and operable in a user space of the host computing device. The processing circuitry is configured to execute the containerized user-level application and the cloud native virtual router. The cloud native virtual router includes a containerized routing protocol process configured to operate as a control plane, and a data plane for the containerized router. The data plane is configured to operate an Ethernet virtual private network (EVPN) encapsulated / deencapsulated data path of the overlay network for communicating layer 2 (L2) network traffic of the containerized user application over a switching fabric of the data center.
Owner:JUNIPER NETWORKS INC

Method and apparatus for configuration check of an overlay network

ActiveCN117614814BDomain namePathPing
The application discloses a kind of configuration checking method and device of overlapping network, it is related to computer network technical field, the method includes: obtaining the trouble shooting request of user on overlapping network;When determining that the IP address pair of trouble shooting is cloud load balancing device address, then execute the first checking operation of listener, domain name and URL path of cloud load balancing device;When determining that the IP address pair of trouble shooting is cloud server device address, then execute the second checking operation of security group configuration and port configuration of cloud server device;When determining that the IP address pair of trouble shooting is not cloud load balancing device address and is not cloud server device address, then according to the association between the trouble shooting position information and corresponding third checking operation, determine and execute the third checking operation corresponding to the trouble shooting position information;Generate the notification information with the check result of checking operation.This application is to improve the efficiency of configuration checking of overlapping network.
Owner:CHINA CONSTRUCTION BANK

Zero trust data castle system with security operation methods for active response

The present disclosure relates to attack-tolerant storage system architecture with active response methods against different forms of storage intrusion for data at-rest, under-operation and in-motion as an integrated system design. System is built upon a Storage security controller (SG nodes), USC, overlay network of DTC nodes attached to SG nodes. System security modules are deployed across various geo locations in a Wide Area Network. USC extracts system, security and storage activity telemetry data from Secure Vaults, Storage Gateways and inter-site data transfer systems to orchestrate autonomous security Operations. SG nodes create SP fragments and store in SV nodes or move it across DTC nodes upon data operations. SG nodes are connected to SV nodes which are micro-segmented, data vaults with restricted network reachability. Kill-Data-Service methods and other Active Response security methods are triggered from SG nodes or at DTC nodes, as part of AR operations, orchestrated by USC.
Owner:CHACKO PETER

Methods, systems, and machine storage media for providing secure access to sandboxed user-defined functions

This application relates to secure network access from sandboxed applications. Methods, systems, and computer programs are proposed to enable any sandboxed user-defined function code to securely access the Internet via a cloud data platform. The cloud data platform receives remote procedure calls from user-defined functions (UDFs) executing within a sandboxed process. The UDF includes code associated with at least one operation to be performed. The cloud data platform provides an overlay network to establish a secure exit path for external access to the UDF. The cloud data platform enables the UDF executing within the sandboxed process to initiate network calls.
Owner:SNOWFLAKE INC

Secure blockchain routing technique

Systems and methods for providing secure blockchain routing using an extended blockchain protocol are described herein. In some embodiments, a blockchain routing node can join an overlay network comprising a plurality of blockchain routing nodes. The blockchain routing node can receive a plurality of forwarding tables from the plurality of blockchain routing nodes in accordance with an extended blockchain protocol. The blockchain routing node can determine a routing table for the overlay network based at least in part on the plurality of forwarding tables. In some embodiments, the blockchain routing node can route a payload message to a target blockchain routing node in the overlay network in accordance with the determined routing table.
Owner:VISA INTERNATIONAL SERVICE ASSOCIATION

System and method for accessing k8s based on agent-based heterogeneous computing nodes

The application discloses a system and method for accessing K8s based on an agent, relates to the field of cloud native technology, and realizes the full-process automation of agent initialization registration, node queue allocation, hardware information collection and resource pre-inspection, node environment preparation, K8s cluster access, node label updating and post-validation by deploying an access agent Agent, combining a control plane module, a node controller module, a node access workflow module and a network access module to construct an integrated access architecture; the network environment difference is shielded by using Tailscale to construct an Overlay network, the container runtime and acceleration components are adaptively selected based on the hardware collection results, and the node access full-life cycle closed-loop management is realized through a state machine and a task queue. The application supports the unified automatic access of heterogeneous computing power such as multiple types of GPU, physical machine / virtual machine / edge PC / cloud node and the like, and improves the heterogeneous computing power resource scheduling efficiency.
Owner:TONGFANG YOUYUN (BEIJING) TECH CO LTD

Automatically directing custom compute operational flows through a heterogeneous overlay and cloud compute infrastructure

A heterogeneous overlay network and cloud compute infrastructure comprises different tiers of PoPs that are configurable to provide different amounts of cloud computing. To facilitate the programming (configuration) of compute and caching operations throughout the heterogeneous network, a control mechanism and methodology are provided for automatically directing the flow of custom compute and caching operations using configurable “operations chains.” A representative operation chain comprises a configuration file that specifies a traffic flow, and a set of operations and their relative ordering. A particular operation chain defines an initial operation that typically starts at a given edge machine in the heterogeneous network and then, as needed, one or more additional locations and their associated machines may then be used to facilitate processing of the operation chain.
Owner:AKAMAI TECHNOLOGIES INC

Policy and traffic management in an overlay network

Technique or mechanism in which network security policies are applied close to the source or origin associated with policy decisions. For example. the disclosed technology moves dropped flows from a firewall cluster to a leaf switch based on host location.
Owner:GOOGLE LLC

Selective programming of forwarding hardware in a multi-fabric overlay network

A network device in a first fabric of an overlay network is provided. During operation, the network device can receive a route advertisement from a border device via which the network device communicates outside of the first fabric. The network device can determine, based on an indicator in the route advertisement, whether a host route associated with a host coupled to a second fabric of the overlay network is included in the route advertisement. If the indicator indicates that the host route is included in the route advertisement, the network device can store the host route in a data structure on the network device. The network device can also program, in the local forwarding hardware, a prefix route associated with the host route. If the network device detects a packet destined to the host device, the network device can program the host route in the forwarding hardware.
Owner:HEWLETT PACKARD ENTERPRISE DEV LP

A cloud-native anti-DDoS defense method

The application discloses a cloud native anti-DDoS defense method and belongs to the technical field of network security, and is characterized in that the method comprises the following steps: S1, softwareization, function software of an anti-DDoS system is softwareized into capabilities to form a covering network; S2, strategy automation, the capabilities are connected in the form of a service chain; S3, service chain validation, the corresponding order of execution of each capability is defined through the service chain; and S4, capability deployment, the capabilities existing in the service chain are deployed on cloud servers of an underlying network to form an anti-DDoS strategy. The application can realize automatic anti-DDoS strategy, improve the response speed of the anti-DDoS strategy and the anti-DDoS efficiency.
Owner:UNIV OF ELECTRONICS SCI & TECH OF CHINA

Efficient distribution of multi-destination packets in an overlay network

A network device operating as a tunnel endpoint in an overlay network is provided. During operation, the network device can receive a multi-destination packet associated with a virtual local area network (VLAN) via an edge port of the network device. The network device can determine a multicast group assigned for distributing multi-destination traffic of the VLAN from a data structure in forwarding hardware of the network device. The network device can then forward the multi-destination packet via a root-path multicast tree associated with the multicast group. Subsequently, the network device can receive forwarding information shared by a second network device of the overlay network based on a control packet sent by the second network device. The network device can then program, in the forwarding hardware, a shortest-path multicast tree associated with the multicast group, wherein the shortest-path multicast tree is for distributing traffic belonging to the VLAN.
Owner:HEWLETT PACKARD ENTERPRISE DEV LP

Virtual bootstrap environment for an overlay network

Techniques are disclosed for building a scalable footprint data center using a virtual bootstrap environment. A computing system can implement a virtual bootstrap environment in a host region data center. The computing system can deploy a first service in the virtual bootstrap environment. The first service can have a dependency on a second service. The computing system can then deploy an instance of the second service in the virtual bootstrap environment. The instance of the second service can be configured to receive service traffic from the first service after the instance of the second service is deployed in the virtual bootstrap environment. The first service can be configured to send the service traffic to a corresponding instance of the second service in the host region prior to the instance of the second service being deployed in the virtual bootstrap environment.
Owner:ORACLE INT CORP

Dynamic data signal collection to prevent telemetry spoofing in a bot detection system

The subject matter herein provides a platform and mechanism to enable dynamic control over data signal collection telemetry in a bot detection-based access control system executing, for example, in associated with a multi-tenant shared network infrastructure. The approach herein leverages the ability of a native SDK running in a mobile device application to launch and use a webview that controls the data collection process. The techniques make it harder for bad actors to send spoofed telemetry from their mobile devices to an overlay network edge platform having an associated bot detection system back-end.
Owner:AKAMAI TECHNOLOGIES INC

System and method of providing a loosely-coupled interface model for obtaining underlay transport service

A device transmits, from an overlay service controller associated with an overlay network to an underlay service controller associated with an underlay network and via a semantic structure defined for a service usage API, a request for a service offered by the underlay network. A device may receive, at the overlay service controller, from the underlay service controller and via the service usage API, attachment metadata. A device may map, based on the attachment metadata and via the overlay service controller, an overlay network tunnel to the service in the underlay network to generate an overlay tunnel mapping, wherein the overlay service controller does not have knowledge of details about implementing the service in order to enable the overlay network to consume the service offered by the underlay network. A device may communicate tunneled packets from the overlay network to the underlay network via the overlay tunnel mapping.
Owner:CISCO TECHNOLOGY INC

Service discovery across tunnel endpoints in an overlay network

Embodiments of the present disclosure relate to service discovery across tunnel endpoints in overlay networks. In an example, a network device can receive, from a client device, a multicast query for a service advertised by a host device connected to another network device. The network device is configured as a first virtual tunnel endpoint (VTEP) in an overlay network, while the other network device is configured as a second VTEP. The network device can determine whether a hostname of the host device corresponding to a servicename in the multicast query exists in a resource record. In response to determining that the hostname exists in the resource record, the network device can identify an overlay network path corresponding to the hostname from the resource record. The network device can encapsulate the multicast query based on an overlay encapsulation protocol implemented at the first VTEP, and route the encapsulated multicast query to the host device via the overlay network path.
Owner:HEWLETT PACKARD ENTERPRISE DEV LP

Bot detection and mitigation using dynamic web flows built via machine learning

An overlay network bot detection service is augmented to include a content generation service that dynamically generates dummy web pages that are served (along with real site content) to a requesting user, This content is built using machine learning models trained on a target website's content, or that otherwise leverage generative Al to create site content that mimics the site's real content. The generated content is preferably built dynamically during an actual interaction session with the requesting user, is designed to "look" and "feel" like actual content of the website, and inclusion of the content acts to trap a requesting user's browser in one or more non-productive (fake) navigation loops within the site. This facilitates the overall bot detection because such content and such loops are not actually part of the real site, and thus the navigation of these unproductive pages is highly indicative of bot activity.
Owner:AKAMAI TECHNOLOGIES INC

Overcoming limitations of a virtual private cloud (VPC) implemented on a public cloud in a cloud-native fifth generation (5G) wireless telecommunication network

Example embodiments are directed towards overcoming limitations of a virtual private cloud (VPC) implemented on a public cloud in a cloud-native 5G wireless telecommunication network by overlaying a network of virtual routers (vRouters) across a software defined data center (SDDC) and virtual private cloud (VPC) in such a manner that enables telecommunication network traffic to communicate between one or more telecommunication NFs of the 5G wireless telecommunication network running on a cloud-native platform of the public cloud (e.g., may be workloads that exist in native AWS) and one or more other telecommunication network functions (NFs) of the 5G wireless telecommunication network running in the in the SDDC using the connected VPC (e.g., such as when using VMWare Cloud to implement the SDDC). The connected VPC is a private cloud existing within the public cloud 202 and the overlay network implemented by such vRouters operationally connects the VPC to the host public cloud and other public clouds.
Owner:BOOST SUBSCRIBERCO LLC

Single-node authentication risk detection method and system based on log analysis

The invention provides a single-node authentication risk detection method and system based on log analysis, which can perform real-time analysis based on an actual access log and timely identify a single-node access risk before a fault occurs, thereby effectively avoiding service interruption and improving the reliability of the system. And meanwhile, full-course automatic diagnosis from risk detection to root positioning is realized, the operation and maintenance efficiency is remarkably improved, and the manual troubleshooting cost is reduced. The method supports a plurality of potential fault points such as a plurality of heterogeneous systems, coverage networks, DNS, configurations and the like, can comprehensively monitor and diagnose various faults in a complex environment, is high in applicability, and has good expansibility and adaptability. And a comprehensive risk report and visual display are provided, so that an administrator can quickly understand the system risk condition and timely take effective measures for processing. In addition, the user can customize a risk judgment rule and a diagnosis strategy according to own requirements, and personalized operation and maintenance requirements of different enterprises are met.
Owner:BEIJING YOUTEJIE INFORMATION TECH

Bot detection and mitigation using dynamic web flows built via machine learning

An overlay network bot detection service is augmented to include a content generation service that dynamically generates dummy web pages that are served (along with real site content) to a requesting user, This content is built using machine learning models trained on a target website's content, or that otherwise leverage generative AI to create site content that mimics the site's real content. The generated content is preferably built dynamically during an actual interaction session with the requesting user, is designed to “look” and “feel” like actual content of the website, and inclusion of the content acts to trap a requesting user's browser in one or more non-productive (fake) navigation loops within the site. This facilitates the overall bot detection because such content and such loops are not actually part of the real site, and thus the navigation of these unproductive pages is highly indicative of bot activity.
Owner:AKAMAI TECHNOLOGIES INC

A graph mapping method based on exact synthesis

The application discloses a graph mapping method based on exact synthesis, comprising: constructing an exact synthesis structure library based on NPN equivalence class, and inputting a Boolean network; performing k-Cut cutting enumeration on the input Boolean network and calculating a truth table, matching the cutting with a structure in the exact synthesis structure library through Boolean matching, and realizing fast searching in combination with NPN classification; generating a cover network through multi-round mapping optimization, and mining a logic shared node in combination with structure hashing, wherein the multi-round mapping optimization comprises delay-oriented mapping, global area topology optimization and local exact area optimization; generating a new target network based on the optimized cover network, removing redundant nodes and completing final network construction. Through the automatic mapping and redundant removal mechanism of the whole process, the application does not need manual intervention, significantly reduces the manual cost of the technical mapping link in chip design, and is especially suitable for efficient design of complex circuits and emerging majority logic base technologies.
Owner:HANGZHOU JIUZHIXING SOFTWARE CO LTD

Network reachability verification method and apparatus, and computer storage medium

ActiveUS12676805B2Data packLogical topology
A network reachability verification method and apparatus, and a computer storage medium are provided, and pertain to the field of network technologies. The method includes: obtaining a source interface and a destination interface that correspond to a virtual packet in a target network; and verifying reachability of the virtual packet in an overlay network based on a logical topology of a plurality of forwarding instances of a plurality of network devices in the target network, routing information of the plurality of forwarding instances, a source forwarding instance corresponding to the source interface, and a destination forwarding instance corresponding to the destination interface. In this way, single-layer reachability verification on the overlay network in the target network is implemented, and verification accuracy is high.
Owner:HUAWEI TECH CO LTD

Combining multiple detection algorithms into a confidence score for bot detection

A bot detection service associated with an overlay network operates to score traffic as a probability of being a bot, as opposed to returning a binary classification (i.e., bot or human). According to the approach herein, scoring is determined through probability estimates, wherein a score (the probability) is based on considering a set of detections concurrently. In one embodiment, all (or substantially all) triggered (current) threat detections contribute to the score. The preferred approach penalizes requests that fail all (or substantially all) combinations of detection algorithms. According to a further feature, an automated tuning (autotuning) is also applied, e.g., using real-time empirical statistical models, to adapt the measurement of false positive probability for one or more threat detection algorithms to suit customer traffic trends. The approach herein is also extensible to include any number of future threat detection algorithms.
Owner:AKAMAI TECHNOLOGIES INC

NAT route distribution based on tag information in an SDWAN overlay network

A process can include determining a plurality of Network Address Translation (NAT) routes associated with respective edge routers included in a same virtual private network (VPN) for communicating with a software-defined wide area network (SDWAN). A process can include identifying a first subset of the plurality of NAT routes as mapped to a first public NAT address included in a NAT pool associated with the VPN. A process can include tagging each NAT route of the first subset with a tag value indicative of a preferred router for receiving return traffic of the respective NAT route. A process can include routing traffic on a respective NAT route of the plurality of NAT routes based on applying, at an SDWAN controller, a corresponding control policy matching the tag value of the respective NAT route.
Owner:CISCO TECHNOLOGY INC