Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

156 results about "Packet detection" patented technology

Non-depth flow analysis and streaming matching search analysis method

PendingCN121508886ASecuring communicationSearch analyticsData pack
The invention provides a non-deep traffic analysis streaming matching search analysis method, which comprises the following steps of: constructing a deep data packet detection architecture on the basis of a data platform development kit (DPDK); aiming at the non-encrypted traffic, establishing a multi-mode recognition mechanism combining a regular expression and a feature bit stream mode; aiming at the encrypted traffic, constructing an encrypted traffic feature library according to the statistical features, the protocol features and the behavior features; real-time risk detection of network traffic is realized by adopting a streaming matching search technology; and constructing an intelligent decision and response mechanism, and integrating flow analysis and identification results. According to the non-deep traffic analysis streaming matching search analysis method provided by the invention, real-time analysis, risk identification and supervision of network non-encrypted traffic and encrypted traffic are realized by taking a data platform development kit (DPDK) as a basis and combining a high-performance streaming regular expression engine and a finite-state machine principle; the method can be widely applied to scenes of network communication supervision, data security protection, malicious traffic monitoring and the like.
Owner:BEIJING ACT TECH DEV CO LTD

Method and system for creating sessions in a telecommunication network

The present disclosure provides a method (500) and system (108) for creating sessions in a telecommunication network (106). The method includes receiving session request from the CPE and establishing the CPE session in the telecommunication network (106). Upon successful establishment, an individual HGW session request is received corresponding to HGW child sessions for each of a set of HGW devices connected over the CPE session. A unique Packet Detection Rule (PDR) Identifier (ID) is assigned to each HGW child session based on the respective HGW session request. Subsequently, the HGW child sessions are created using the assigned PDR IDs. The method enables efficient session creation, resource optimization, and independent session handling for multiple HGWs operating behind a common CPE in the telecommunication network (106).
Owner:JIO PLATFORMS LTD

Status event handling associated with a session management function (SMF) node

Apparatuses and methods for DDD status event handling with I-SMF improvement. In one embodiment, a session management function, SMF, node is provided. The SMF node includes processing circuitry configured to receive a subscription request to an event associated with the SMF node where the subscription request includes at least one of a packet detection rule, PDR, information and a Traffic Descriptor, and instruct a user plane function, UPF, node based at least on the subscription request.
Owner:TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)

Method and apparatus for charging

Embodiments of the present disclosure provide method and apparatus for charging. A method performed by a user plane function entity comprises receiving a first message from a control plane function entity. The first message comprises one or more information elements referencing one or more pre-defined packet detection rules (PDRs) configured in the user plane function entity. The one or more pre-defined PDRs specify one or more predefined usage reporting rules (URRs). The method further comprises activating the one or more predefined PDRs. The method further comprises generating a usage report for at least one of the one or more predefined URRs. The usage report comprises information for describing received user traffic which is related to the at least one of the one or more predefined URRs. The method further comprises sending a second message comprising the usage report to the control plane function entity.
Owner:TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)

User equipment route selection policy detection method and related device, storage medium, and program product

A user equipment (UE) route selection policy (URSP) detection method including obtaining first policy section identifier (PSI) information corresponding to a first URSP rule corresponding to a target user equipment, the first URSP rule being matched with a target service flow corresponding to the target user equipment, generating a first packet detection rule based on the first URSP rule that corresponds to the first PSI information, configuring the first packet detection rule to a user plane function (UPF) network element of a first protocol data unit (PDU) session, the first PDU session corresponding to the first URSP rule, and receiving, from the UPF network elements, a first detection result based on the first packet detection rule and indicating whether the target service flow associated with the first PDU session matches the first packet detection rule.
Owner:TENCENT TECHNOLOGY (SHENZHEN) CO LTD

Lightweight encryption method and system for industrial real-time data stream

The invention relates to the technical field of industrial internet security communication, and discloses a lightweight encryption method and system for an industrial real-time data stream, and the method comprises the following steps: intercepting an original data packet, and carrying out the deep packet detection to extract a network layer quintuple and application layer metadata; matching an optimal strategy in a strategy rule set according to the feature vector and generating a scheduling instruction; in response to the instruction, calling a corresponding pre-compilation password operation pipeline to carry out differential encryption processing on the load; and constructing a fixed-length security policy head containing the algorithm template identifier, and packaging and sending the fixed-length security policy head. According to the invention, task fragmentation is carried out by using a consistent Hash technology so as to ensure processing order-preserving. By adopting a lightweight message structure without handshake negotiation and a multi-level strategy scheduling mechanism, content-based fine-grained security protection is realized, and the communication requirements of low delay and high certainty are met while the security of industrial control data is ensured.
Owner:MAINTENANCE & TEST CENTRE CSG EHV POWER TRANSMISSION CO

Data leakage real-time blocking method fusing micro-isolation strategy and context awareness

The invention relates to the technical field of network security, and discloses a data leakage real-time blocking method fusing a micro-isolation strategy and context awareness. According to the method, a micro-isolation strategy engine based on a data sensitivity level is constructed, a logic security domain is defined, and an independent access control rule is configured; collecting a network data flow in real time, identifying sensitive data by using a deep packet detection technology, and extracting context information; dynamically analyzing and generating risk metadata, calculating a real-time risk index, and establishing a behavior baseline model to detect behavior deviation; in combination with behavior deviation, a risk index and a data operation type, an access control rule is adaptively decided and dynamically updated, a high-risk or unauthorized data transmission session is blocked in real time, and the data leakage protection capability is improved.
Owner:JIANGSU MR ZHI INFORMATION TECH CO LTD

PCDN active detection method based on user behavior and traffic feature fusion

The invention discloses a PCDN active detection method based on fusion of user behaviors and traffic features, which belongs to the technical field of active detection, and comprises the following steps: 1.1, building a simulation environment, collecting data, deploying a controllable PCDN service simulation environment comprising mainstream PCDN platform node equipment, a user terminal and detection equipment, the method comprises the following steps: non-inductively collecting network traffic and application layer behavior data through a bypass-deployed deep packet inspection engine and traffic mirroring equipment; according to the method, the specific user behavior characteristics of PCDN platform registration, node testing, settlement query and the like which are strongly associated with commercial settlement are extracted, and flow characteristic fusion judgment is combined, so that identification can be completed at the stage that the user registers and deploys PCDN nodes, and PCDN behaviors are found 7-10 days earlier than that of a traditional flow detection method; the problem of passive detection lagging is solved, and network risks caused by PCDN commercial behaviors in a home broadband can be monitored more timely.
Owner:SHENZHEN BROAD TECH CO LTD

Abnormal traffic identification method, system and device based on deep packet inspection, and medium

The invention discloses an abnormal traffic identification method, system and device based on deep packet inspection, and a medium. The method comprises the following steps: collecting original traffic data in a network through a mirror image port or a probe, obtaining original message data, cleaning and labeling the original message data, and generating a structured data set; performing depth feature extraction on the structured data set to generate a feature vector; training a classification model by using the feature vectors, generating a detection model, analyzing the new flow data through the detection model, and outputting an abnormal probability and grading early warning; positioning an abnormal type according to the abnormal probability and graded early warning, generating a structured report, and linking the safety equipment to execute a blocking operation; and performing incremental training according to the detected feedback data, and updating the detection model. The invention provides an abnormal traffic identification method based on deep packet inspection according to the characteristics of diversified protocol levels and strong concealment and evolution of abnormal behaviors in network traffic.
Owner:YUNNAN POWER GRID CO LTD

A method of data transmission and a communication device

The embodiment of the present application provides a data transmission method and communication device, the method comprises the following steps: a first terminal device acquires first information, the first information is used for a first network device to transmit first data to the first terminal device through a first communication path, and the first information comprises a first packet detection rule (PDR); the first terminal device sends a first message to a second network device through a second communication path, wherein the first message comprises the first information and first indication information, and the first indication information is used for indicating that the first data is transmitted through the first communication path and / or the second communication path. In the method, the transmission of the data through the direct connection path and the non-direct connection path can be realized at the same time, so that the transmission path between the remote terminal device and the data network has diversity, and the service demand can be dynamically met.
Owner:HUAWEI TECH CO LTD

Identification method for malicious remote control shared screen APP in network protection

The invention discloses a method for identifying a malicious remote control shared screen APP in network protection, and relates to the technical field of network security protection, and the method comprises the following steps: collecting the transmission layer network flow of a target APP, and screening out a UDP protocol data packet; detecting a server IP attribution corresponding to the UDP data packet, and judging whether the IP is an overseas or Hong Kong Australian region IP or not; analyzing the interaction logic of the UDP data packets, and verifying whether the conditions of'one-to-one correspondence between request packets and response packets' and'equal number of uplink and downlink UDP data packets' are met; extracting the sizes of the UDP request packet and the response packet and the length of the Payload, and matching at least one of the following corresponding relationships; when all the conditions are met, judging that the target APP is a malicious remote control and shared screen APP based on a RustDesk framework; and feeding back a judgment result to the network security defense system to complete marking and filtering of the target malicious APP.
Owner:望靖坤

Industrial equipment awakening method, electronic equipment and storage medium

The invention provides an industrial equipment awakening method, electronic equipment and a storage medium, and relates to the technical field of communication. The method comprises the following steps: sending an awakening magic packet message detection request to an NEF; receiving a target downlink wake-up magic packet message detection notification sent by the NEF, and extracting the MAC address of the target industrial device; and based on the network resource allocation strategy record, according to the MAC address of the target industrial equipment, requesting to modify the user subscription data of the target UE to the UDM, so as to adjust a preset network slice identifier corresponding to the target UE to a target network slice identifier, and after the UDM completes the modification of the user subscription data, modifying the corresponding PDU session parameter by the SMF, and sending the PDU session parameter to the target industrial equipment. According to the invention, the downlink wake-up magic packet message is transmitted to the target UE through the modified PDU session and is issued to the target industrial device by the target UE to wake up the target industrial device, so that different network resource allocation strategies can be allocated to different UEs, and the flexibility is high.
Owner:SHENZHEN AI LINK CO LTD

Rule issuance methods, message detection methods, devices, network elements and storage media

This application provides a rule issuance method, a packet detection method, an apparatus, a network element, and a storage medium. The rule issuance method includes receiving an Application Authorization Request Initial Message; issuing Policy Control and Charging (PCC) rules based on the Application Authorization Request Initial Message, wherein the PCC rules carry the service media type; and replying to the Network Protocol Multimedia Subsystem (IMS) with an Application Authorization Response Initial Message. The above technical solution reduces the complexity of packet detection and improves packet forwarding performance.
Owner:ULITON COMM SERVICE CO LTD

Packet detection rules derived from ethernet forwarding information

Systems and methods are disclosed herein that relate to obtaining and using Packet Detection Rules (PDRs) in a cellular communications system operating as virtual Ethernet bridge based on Ethernet forwarding information. In one embodiment, a method performed by a User Plane Function (UPF) for enabling a cellular communications system to operate as a virtual Ethernet bridge comprises obtaining a PDR for a Protocol Data Unit (PDU) session in a downlink direction in the cellular communications system. The PDU session is associated with an egress Ethernet port of the virtual Ethernet bridge for the downlink direction, the PDR maps Ethernet packets received at the UPF on an ingress Ethernet port(s) of the virtual Ethernet bridge to the PDU session associated with the egress Ethernet port of the virtual Ethernet bridge, and the PDR is derived from an Ethernet packet forwarding rule of the virtual Ethernet bridge.
Owner:TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)

Reducing listen mode power consumption of wireless local area network (WLAN) devices

This disclosure provides methods, apparatus, and systems for reducing power consumption when a station (STA) operates in a listening mode. In some aspects, to reduce power consumption in listening mode, the STA can alternate between monitoring a radio channel to search for packets and not monitoring the radio channel. When the STA monitors the radio channel to search for packets in listening mode, the STA can configure a packet detection component to a power-on state. When the STA is not monitoring the radio channel in listening mode, the STA can configure the packet detection component to a power-off state. During the power-on state of listening mode, the STA can detect the preamble of packets transmitted on the radio channel. In response to detecting the preamble of the packet, the STA can switch from listening mode to receive mode to process the packet.
Owner:QUALCOMM INC

A power grid dispatching data dynamic perception and protection method based on a commercial secret algorithm

PendingCN122437681AData packData stream
The present application relates to the field of power grid dispatching data security, and more particularly to a power grid dispatching data dynamic perception and protection method based on a commercial secret algorithm. The method captures power grid dispatching network data streams in real time, obtains original service data containing dispatching instructions, measurement data and state information through protocol analysis and deep packet detection; then uses a dynamic data perception engine to identify sensitive data units, and dynamically generates data sensitivity labels according to the business type and the power grid operation state; dynamically matches commercial cryptographic algorithms from the commercial secret algorithm library according to the labels and distributes temporary session keys to generate an encryption strategy; encrypts the sensitive units, adds a security mark containing an algorithm identifier and a key index to the data packet header to form a protected data stream; sends the protected data stream to the target end, updates the session key state and uploads the execution log to the audit center. The present application realizes dynamic, accurate identification and differentiated encryption protection of power grid dispatching sensitive data.
Owner:HAINAN POWER GRID CO LTD

Including packet processing data for deep packet inspection classification rules in a combined lookup table used for packet classification at a network device

Systems and methods for determining whether to perform deep packet inspection (DPI) on packets received at a network device based on shallow packet inspection data are disclosed. Embodiments may include DPI classification data in a combined lookup table that is utilized for shallow packet data based packet classification at a network device. Using the results of lookups in such a combined look table based on received packets, determinations can be made whether to perform DPI on such received packets, and those packets forwarded accordingly.
Owner:ARISTA NETWORKS INC

Dual processor architecture for deterministic forwarding and selective higher order function execution

PendingCN121967319AClearly understand technical solutionsClearly understand the advantagesAssess restrictionSecuring communicationData compressionComputer architecture
The invention relates to an edge system with a dual-processor architecture, which integrates a broadband processor and an enterprise network processor through coordinated function configuration. The service level of the packet flow is divided by the post-provisioning data and the telemetry data, and it is determined whether to transmit the packet by the broadband processor or to selectively perform a high-order function, such as deep packet detection, data encryption, or data compression, by the enterprise network processor. Embodiments include logical coupling of virtual area networks, a signalling mechanism of segment routing / micro identity identification, a transport mechanism of memory sharing and without duplication, and a hybrid coupling combining logical control and data transport entity structures.
Owner:HUANLIAN TECHNOLOGY CO LTD

DNS tunnel flow detection method based on image processing

The invention belongs to the field of computer network security, and discloses a DNS tunnel traffic detection method based on image processing, and the method comprises the steps: in an offline training stage, firstly converting a domain name field and a query type of a DNS data packet into an image according to a preset rule, and carrying out the expansion of a DNS image data set through a deep convolution generative adversarial network; and then shape-color joint robust features of the image are extracted, and unified image vector representation is generated in combination with a bag-of-words model for classification training, so that the generalization ability of the model to various attack forms is effectively improved. In the online deployment stage, incremental expansion is carried out on Open vSwitch source codes, and the incremental expansion comprises embedding of data path processing logic, calling mechanism design of a deep packet inspection interface and parameter adaptation of a starting module. On the premise of not influencing the original forwarding performance and function, seamless integration of the DNS tunnel detection function is realized, and the capability of identifying malicious DNS traffic is enhanced.
Owner:HUNAN UNIV

Data packet detection method and device, electronic equipment and program product

The invention relates to the field of network security and data communication, in particular to a data packet detection method and device, electronic equipment and a program product, and aims to improve the data packet detection speed. The method comprises the steps of obtaining at least one to-be-processed data packet, inputting each to-be-processed data packet into a fine-tuned large language model, and obtaining an output regular expression corresponding to each to-be-processed data packet; for each regular expression, constructing a corresponding automatic detection model based on the detection logic of the regular expression, and migrating the automatic detection model to a first target detection model; and inputting the training data packet with the first label into a preset machine learning model, and performing parameter adjustment on the machine learning model based on the difference between a second label output by the machine learning model and the first label to obtain a second target detection model. According to the method, the large language model is finely adjusted, so that the regular expression library is expanded, and the cost of designing the data packet detection rule is reduced.
Owner:RUIJIE NETWORKS CO LTD

A service awareness method, communication apparatus and communication system

The application provides a service sensing method, a communication device and a communication system. The method comprises the following steps: a session management function network element sends a first request message to a user plane function network element, wherein the first request message comprises a detection rule and a usage reporting rule, the detection rule comprises an application service identifier and packet detection characteristic information, the detection rule is used for detecting a service flow of the application service, the packet detection characteristic information is used for indicating matching characteristics of the service flow of the application service, and the usage reporting rule comprises an event identifier, the event identifier is used for indicating an event of reporting the service flow of the application service, and the event is an application start event or an application end event; and the session management function network element receives a first event report from the user plane function network element, wherein the first event report is used for indicating the event. The technical solution can be used for effectively distinguishing different application service packets.
Owner:HUAWEI TECH CO LTD

Data processing method and apparatus, data storage system, and electronic device

PCT designated stageWO2026114394A1Program controlData packControl store
The present invention relates to the technical field of computers. Disclosed are a data processing method and apparatus, a data storage system, and an electronic device. The method comprises: for any storage controller, performing load demand analysis on an initial data packet to be processed of the storage controller; on the basis of the load analysis result corresponding to each storage controller, performing a first adjustment on the initial data packet to be processed, so that each storage controller obtains an intermediate data packet to be processed; detecting a current data processing capability of each storage controller; and on the basis of the current data processing capability of each storage controller, performing a second adjustment on the intermediate data packet to be processed, so that each storage controller obtains a target data packet to be processed. Two load balancing adjustments are performed on the initial data packet to be processed of each storage controller on the basis of the load demand of data to be processed and the processing capability of a processor itself, respectively, so as to ensure that the data processing load of the storage controllers is balanced, thereby laying a foundation for improving the performance of data storage devices.
Owner:INSPUR SUZHOU INTELLIGENT TECH CO LTD

Data packet hierarchical detection method, system and electronic device

The application discloses a data packet hierarchical detection method, a system and an electronic device, wherein the hierarchical detection method is used when a data packet sent by a terminal or a data packet sent to the terminal is acquired; the current data packet detection level of the terminal is determined; when it is determined that the current data packet detection level of the terminal is a shallow layer detection, shallow layer detection is performed on the data packet; when it is determined that the current data packet detection level of the terminal is a middle layer detection, middle layer detection is performed on the data packet; and when it is determined that the current data packet detection level of the terminal is a deep layer detection, deep layer detection is performed on the data packet. The method can realize data packet detection with different depths according to the data packet detection levels corresponding to the terminals, effectively avoids the problems of high consumption and large delay caused by uniformly using deep packet detection, and is beneficial to improving network throughput, reducing operation and maintenance cost and reducing security policy configuration work.
Owner:SUZHOU MAXNET NETWORK SECURITY TECH CO LTD

Packet detection system, method, apparatus, gateway device and storage medium

This invention relates to a packet inspection system, method, apparatus, gateway device, and storage medium, comprising: a public cloud gateway for encapsulating received raw packets through a first-layer tunnel and sending the encapsulated first packet to a firewall load balancing gateway; a firewall load balancing gateway for encapsulating the first packet through a second-layer tunnel and sending the encapsulated second packet to a cloud server gateway; a cloud server gateway for decapsulating the second packet through the first-layer tunnel and sending it to the target cloud virtual machine where the target firewall resides; and a target firewall for decapsulating the second packet through the second-layer tunnel to obtain the raw packet and performing protection detection on the raw packet. Thus, firewall devices can be integrated into the public cloud gateway, and the encapsulated packets can be distributed to the target firewall for protection detection via a load balancing algorithm through the firewall load balancing gateway, improving the security of the cloud computing environment.
Owner:BEIJING KINGSOFT CLOUD NETWORK TECH CO LTD +1

A packet loss detection method for unmanned surface vessel formations based on adaptive fuzzy membership filtering

PendingCN122316945APacket lossNoise level
This invention discloses a packet loss detection method for unmanned surface vessel (USV) formations based on adaptive fuzzy membership filtering. The method includes: establishing state equations describing the motion of both the leader and follower USVs; linearizing these nonlinear equations to simplify the complex curvilinear motion relationships into linear mathematical expressions, thus obtaining simplified state equations for the entire formation system; introducing an adjustable measurement noise figure based on the simplified formation model, dynamically adjusting the filtering intensity according to the current measurement noise level, thereby more accurately estimating the real-time state of the USVs; and simultaneously detecting packet loss during state updates, combining preset communication quality indicators and real-time calculated noise levels to determine the reliability of received data. This invention achieves good detection results for packet loss in noisy channels and can be widely applied in the field of data detection.
Owner:GUANGDONG UNIV OF TECH

Systems and methods for wireless network management

Disclosed are computerized systems and methods for a decision intelligence (DI)-based framework that automatically and / or dynamically provides mechanisms for managing, optimizing and configuring a WiFi network at a location. The framework provides network management utilizing edge processing capabilities to bridge local WiFi and cloud systems. The framework implements comprehensive device typing through multi-layered analysis combining passive monitoring, deep packet inspection and hybrid deterministic-probabilistic classification methods. State synchronization between local and cloud networks can be achieved through hierarchical data modeling and differential synchronization algorithms. The framework can implement advanced features that include automated channel optimization, QoS management, and security monitoring. The framework incorporates self-healing capabilities using reinforcement learning techniques and maintains operational efficiency through intelligent resource management and workload distribution. The framework can operate autonomously while requiring minimal cloud connectivity, featuring extensible architecture through a plugin system that enables adaptation to evolving network requirements while maintaining stable operation of existing capabilities.
Owner:PLUME DESIGN INC

Methods and devices of packet detection for MIMO systems

Methods and wireless communication devices for MIMO packet detection, include receiving input data by a receiver, performing peak detection by a two-tiered approach including an outer loop and an inner loop to generate candidates composing of detected peaks from correlation outputs, and driving final start of packet and carrier frequency offset measurements from the candidates as a final packet detection result. The outer loop iterates on (Rx, STS) combination pairs, and the inner loop runs peak detection on the input data by one or more correlators for each of the (Rx, STS) combination pairs. Rx is one of the receiving antennas of the receiver and STS is one of space-time streams received by the receiver. In some embodiments, one or more winning candidates are selected from the candidates based on a score computed from information related to the detected peaks for each candidate, and the final packet detection result is derived from the winning candidates.
Owner:MORSE MICRO PTY LTD

A program loading system and method based on USB interface

The present application relates to the technical field of electric digital data processing, and especially relates to a program loading system and method based on a USB interface. The system comprises a source device and N target devices; the source device is connected with the N target devices through a USB interface, the target devices contain block endpoints and interrupt endpoints; after receiving start loading commands fed back by each target device, the source device extracts retransmission detection byte numbers in parallel, establishes a connection with each target device through handshake request packets and handshake response packets, transmits to-be-loaded program codes to each target device through start address request packets and write command packets, detects whether retransmission is performed through check request packets and check response packets in the transmission process, and controls each target device to run the to-be-loaded program codes after the transmission process is completed. The embodiment of the present application can intelligently implement simultaneous loading of programs into multiple electronic devices based on information transmitted through interrupt endpoints and block endpoints, and detect whether retransmission is performed.
Owner:HEFEI HEXAGON SEMICON CO LTD

Deep packet inspection on network devices

Load balancing operations between network devices to perform DPI operations are provided herein. Network devices of a virtualized network device arrangement may load balance network traffic by employing a network link between the network devices to exchange data packets for DPI operations. Further, the network devices may employ dedicated CPUs to offload DPI operations. In this manner, the current techniques may enable preservation of pre-existing networking routing or deterministic routing to be performed on-the-fly by enabling DPI to be performed without constraining network traffic flows to a specified route.
Owner:HEWLETT PACKARD ENTERPRISE DEV LP