Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

207 results about "Packet detection" patented technology

Improving classification accuracy in user plane function re-selection scenarios

A method, UPF function / node, computer program, and computer program product to classify traffic of a user equipment, UE by a UPF is provided. A PFCP session establishment request comprising a session ID and a flow information profile is received. Responsive to the flow information profile indicating that flow information is to be stored for sessions by the UE, whether or not there is stored flow information for a session associated with the session ID is determined. UE application traffic is received, the UE application traffic including the session ID. Responsive to there being stored flow information for the session, the UE application traffic is classified based on the stored flow information. Responsive to there not being stored flow information for the session, the UE application traffic for a corresponding packet detection rule of the session; is classified and flow information for the session based on the classifying is stored.
Owner:TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)

Non-depth flow analysis and streaming matching search analysis method

PendingCN121508886ASecuring communicationSearch analyticsData pack
The invention provides a non-deep traffic analysis streaming matching search analysis method, which comprises the following steps of: constructing a deep data packet detection architecture on the basis of a data platform development kit (DPDK); aiming at the non-encrypted traffic, establishing a multi-mode recognition mechanism combining a regular expression and a feature bit stream mode; aiming at the encrypted traffic, constructing an encrypted traffic feature library according to the statistical features, the protocol features and the behavior features; real-time risk detection of network traffic is realized by adopting a streaming matching search technology; and constructing an intelligent decision and response mechanism, and integrating flow analysis and identification results. According to the non-deep traffic analysis streaming matching search analysis method provided by the invention, real-time analysis, risk identification and supervision of network non-encrypted traffic and encrypted traffic are realized by taking a data platform development kit (DPDK) as a basis and combining a high-performance streaming regular expression engine and a finite-state machine principle; the method can be widely applied to scenes of network communication supervision, data security protection, malicious traffic monitoring and the like.
Owner:BEIJING ACT TECH DEV CO LTD

Policy-based transparent packet inspection for last mile zero-trust workload protection

Disclosed are systems, apparatuses, methods, and computer-readable media for policy-based transparent packet inspection for last mile zero-trust workload protection. The method comprises receiving a packet on a network interface of a provisioned resource in a data center or a user device within a network; determining, by a first intercepting agent provisioned within the network interface, whether to inspect the packet based on rules received from a control plane of the network, wherein the network interface comprises a smart network interface card (SmartNIC) or a data processing unit (DPU) and is configured with the first intercepting agent based on the control plane; selectively invoking a deep packet inspection of the packet based on inspection of the packet by the first intercepting agent using the rules from the control plane; and blocking the packet at the network interface based on the deep packet inspection identifying malicious content within the packet.
Owner:CISCO TECHNOLOGY INC

Java background service deployment method and system based on double-node dynamic routing

The invention relates to a Java background service deployment method and system based on double-node dynamic routing, and the method comprises the steps: obtaining the health state of each node based on TCP port activity detection and / or UDP heartbeat packet detection; judging the nodes of which the detection failure times exceed the preset times as fault nodes, and setting the fault nodes to be in an offline state; determining a traffic allocation weight according to the real-time working state of the node; performing routing distribution on the client request based on the traffic distribution weight; route distribution is dynamically adjusted based on the traffic allocation weight, the resource utilization rate of the nodes is improved, and the situation that the load of a single node is too heavy is avoided; when a fault node occurs, the other node is automatically switched to respond to the request, so that the fault switching time is shortened; and the data consistency between the double nodes is adjusted based on the Redis cluster and the MySql cluster. Based on cooperation of the steps, the problems of failure switching delay, low resource utilization and low data consistency in a traditional scheme are solved.
Owner:GUANGZHOU HAOQIN ROBOT TECHNOLOGY CO LTD

Method and system for creating sessions in a telecommunication network

The present disclosure provides a method (500) and system (108) for creating sessions in a telecommunication network (106). The method includes receiving session request from the CPE and establishing the CPE session in the telecommunication network (106). Upon successful establishment, an individual HGW session request is received corresponding to HGW child sessions for each of a set of HGW devices connected over the CPE session. A unique Packet Detection Rule (PDR) Identifier (ID) is assigned to each HGW child session based on the respective HGW session request. Subsequently, the HGW child sessions are created using the assigned PDR IDs. The method enables efficient session creation, resource optimization, and independent session handling for multiple HGWs operating behind a common CPE in the telecommunication network (106).
Owner:JIO PLATFORMS LTD

Status event handling associated with a session management function (SMF) node

Apparatuses and methods for DDD status event handling with I-SMF improvement. In one embodiment, a session management function, SMF, node is provided. The SMF node includes processing circuitry configured to receive a subscription request to an event associated with the SMF node where the subscription request includes at least one of a packet detection rule, PDR, information and a Traffic Descriptor, and instruct a user plane function, UPF, node based at least on the subscription request.
Owner:TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)

Maximum Transmission Unit Size Enforcement

There is provided a method for performing Maximum Transmission Unit size enforcement. The method comprises: receiving at a first node, a first Maximum Transmission Unit size threshold and at least one Packet Detection Rule associated with the first Maximum Transmission Unit size threshold, each of the at least one Packet Detection Rule being associated with one or more enforcement actions for a Protocol Data Unit session; determining at the first node, whether the size of a packet received from a network host exceeds the first Maximum Transmission Unit size threshold; and performing at the first node, an action corresponding to the at least one Packet Detection Rule associated with the first Maximum Transmission Unit size threshold if it is determined that the size of the packet exceeds the first Maximum Transmission Unit size threshold.
Owner:TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)

Method and apparatus for charging

Embodiments of the present disclosure provide method and apparatus for charging. A method performed by a user plane function entity comprises receiving a first message from a control plane function entity. The first message comprises one or more information elements referencing one or more pre-defined packet detection rules (PDRs) configured in the user plane function entity. The one or more pre-defined PDRs specify one or more predefined usage reporting rules (URRs). The method further comprises activating the one or more predefined PDRs. The method further comprises generating a usage report for at least one of the one or more predefined URRs. The usage report comprises information for describing received user traffic which is related to the at least one of the one or more predefined URRs. The method further comprises sending a second message comprising the usage report to the control plane function entity.
Owner:TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)

User equipment route selection policy detection method and related device, storage medium, and program product

A user equipment (UE) route selection policy (URSP) detection method including obtaining first policy section identifier (PSI) information corresponding to a first URSP rule corresponding to a target user equipment, the first URSP rule being matched with a target service flow corresponding to the target user equipment, generating a first packet detection rule based on the first URSP rule that corresponds to the first PSI information, configuring the first packet detection rule to a user plane function (UPF) network element of a first protocol data unit (PDU) session, the first PDU session corresponding to the first URSP rule, and receiving, from the UPF network elements, a first detection result based on the first packet detection rule and indicating whether the target service flow associated with the first PDU session matches the first packet detection rule.
Owner:TENCENT TECHNOLOGY (SHENZHEN) CO LTD

Lightweight encryption method and system for industrial real-time data stream

The invention relates to the technical field of industrial internet security communication, and discloses a lightweight encryption method and system for an industrial real-time data stream, and the method comprises the following steps: intercepting an original data packet, and carrying out the deep packet detection to extract a network layer quintuple and application layer metadata; matching an optimal strategy in a strategy rule set according to the feature vector and generating a scheduling instruction; in response to the instruction, calling a corresponding pre-compilation password operation pipeline to carry out differential encryption processing on the load; and constructing a fixed-length security policy head containing the algorithm template identifier, and packaging and sending the fixed-length security policy head. According to the invention, task fragmentation is carried out by using a consistent Hash technology so as to ensure processing order-preserving. By adopting a lightweight message structure without handshake negotiation and a multi-level strategy scheduling mechanism, content-based fine-grained security protection is realized, and the communication requirements of low delay and high certainty are met while the security of industrial control data is ensured.
Owner:MAINTENANCE & TEST CENTRE CSG EHV POWER TRANSMISSION CO

Data leakage real-time blocking method fusing micro-isolation strategy and context awareness

The invention relates to the technical field of network security, and discloses a data leakage real-time blocking method fusing a micro-isolation strategy and context awareness. According to the method, a micro-isolation strategy engine based on a data sensitivity level is constructed, a logic security domain is defined, and an independent access control rule is configured; collecting a network data flow in real time, identifying sensitive data by using a deep packet detection technology, and extracting context information; dynamically analyzing and generating risk metadata, calculating a real-time risk index, and establishing a behavior baseline model to detect behavior deviation; in combination with behavior deviation, a risk index and a data operation type, an access control rule is adaptively decided and dynamically updated, a high-risk or unauthorized data transmission session is blocked in real time, and the data leakage protection capability is improved.
Owner:JIANGSU MR ZHI INFORMATION TECH CO LTD

PCDN active detection method based on user behavior and traffic feature fusion

The invention discloses a PCDN active detection method based on fusion of user behaviors and traffic features, which belongs to the technical field of active detection, and comprises the following steps: 1.1, building a simulation environment, collecting data, deploying a controllable PCDN service simulation environment comprising mainstream PCDN platform node equipment, a user terminal and detection equipment, the method comprises the following steps: non-inductively collecting network traffic and application layer behavior data through a bypass-deployed deep packet inspection engine and traffic mirroring equipment; according to the method, the specific user behavior characteristics of PCDN platform registration, node testing, settlement query and the like which are strongly associated with commercial settlement are extracted, and flow characteristic fusion judgment is combined, so that identification can be completed at the stage that the user registers and deploys PCDN nodes, and PCDN behaviors are found 7-10 days earlier than that of a traditional flow detection method; the problem of passive detection lagging is solved, and network risks caused by PCDN commercial behaviors in a home broadband can be monitored more timely.
Owner:SHENZHEN BROAD TECH CO LTD

Abnormal traffic identification method, system and device based on deep packet inspection, and medium

The invention discloses an abnormal traffic identification method, system and device based on deep packet inspection, and a medium. The method comprises the following steps: collecting original traffic data in a network through a mirror image port or a probe, obtaining original message data, cleaning and labeling the original message data, and generating a structured data set; performing depth feature extraction on the structured data set to generate a feature vector; training a classification model by using the feature vectors, generating a detection model, analyzing the new flow data through the detection model, and outputting an abnormal probability and grading early warning; positioning an abnormal type according to the abnormal probability and graded early warning, generating a structured report, and linking the safety equipment to execute a blocking operation; and performing incremental training according to the detected feedback data, and updating the detection model. The invention provides an abnormal traffic identification method based on deep packet inspection according to the characteristics of diversified protocol levels and strong concealment and evolution of abnormal behaviors in network traffic.
Owner:YUNNAN POWER GRID CO LTD

A method of data transmission and a communication device

The embodiment of the present application provides a data transmission method and communication device, the method comprises the following steps: a first terminal device acquires first information, the first information is used for a first network device to transmit first data to the first terminal device through a first communication path, and the first information comprises a first packet detection rule (PDR); the first terminal device sends a first message to a second network device through a second communication path, wherein the first message comprises the first information and first indication information, and the first indication information is used for indicating that the first data is transmitted through the first communication path and / or the second communication path. In the method, the transmission of the data through the direct connection path and the non-direct connection path can be realized at the same time, so that the transmission path between the remote terminal device and the data network has diversity, and the service demand can be dynamically met.
Owner:HUAWEI TECH CO LTD

Identification method for malicious remote control shared screen APP in network protection

The invention discloses a method for identifying a malicious remote control shared screen APP in network protection, and relates to the technical field of network security protection, and the method comprises the following steps: collecting the transmission layer network flow of a target APP, and screening out a UDP protocol data packet; detecting a server IP attribution corresponding to the UDP data packet, and judging whether the IP is an overseas or Hong Kong Australian region IP or not; analyzing the interaction logic of the UDP data packets, and verifying whether the conditions of'one-to-one correspondence between request packets and response packets' and'equal number of uplink and downlink UDP data packets' are met; extracting the sizes of the UDP request packet and the response packet and the length of the Payload, and matching at least one of the following corresponding relationships; when all the conditions are met, judging that the target APP is a malicious remote control and shared screen APP based on a RustDesk framework; and feeding back a judgment result to the network security defense system to complete marking and filtering of the target malicious APP.
Owner:望靖坤

Industrial equipment awakening method, electronic equipment and storage medium

The invention provides an industrial equipment awakening method, electronic equipment and a storage medium, and relates to the technical field of communication. The method comprises the following steps: sending an awakening magic packet message detection request to an NEF; receiving a target downlink wake-up magic packet message detection notification sent by the NEF, and extracting the MAC address of the target industrial device; and based on the network resource allocation strategy record, according to the MAC address of the target industrial equipment, requesting to modify the user subscription data of the target UE to the UDM, so as to adjust a preset network slice identifier corresponding to the target UE to a target network slice identifier, and after the UDM completes the modification of the user subscription data, modifying the corresponding PDU session parameter by the SMF, and sending the PDU session parameter to the target industrial equipment. According to the invention, the downlink wake-up magic packet message is transmitted to the target UE through the modified PDU session and is issued to the target industrial device by the target UE to wake up the target industrial device, so that different network resource allocation strategies can be allocated to different UEs, and the flexibility is high.
Owner:SHENZHEN AI LINK CO LTD

Rule issuance methods, message detection methods, devices, network elements and storage media

This application provides a rule issuance method, a packet detection method, an apparatus, a network element, and a storage medium. The rule issuance method includes receiving an Application Authorization Request Initial Message; issuing Policy Control and Charging (PCC) rules based on the Application Authorization Request Initial Message, wherein the PCC rules carry the service media type; and replying to the Network Protocol Multimedia Subsystem (IMS) with an Application Authorization Response Initial Message. The above technical solution reduces the complexity of packet detection and improves packet forwarding performance.
Owner:ULITON COMM SERVICE CO LTD

A wireless mesh adaptive channel selection method and system

The present invention provides a wireless Mesh adaptive channel selection method and system, which relates to the field of channel selection and optimization technology. The present invention first marks the data transmission path and the corresponding channel based on the Mesh network topology, and collects performance parameters such as delay packet loss rate, transmission rate, bandwidth, signal strength, and noise strength at fixed time intervals. The delay packet loss rate and transmission rate are calculated by detecting data packets, and the bandwidth signal strength and noise strength are obtained with the help of tools. Then, the delay packet loss rate, transmission rate, and bandwidth data are extracted to construct a channel quality model. The deep packet inspection engine nDPI is used to identify the service type, and the weight is dynamically adjusted according to the bandwidth ratio. At the same time, a channel signal-to-interference quantization model is constructed based on the signal strength and noise strength. Finally, the signal-to-interference quantization threshold is set to screen out qualified channels, select the channel with the largest channel quality result as the optimal channel and switch to it, effectively improving the rationality of wireless Mesh network channel selection and communication performance.
Owner:CHONGQING LANGYIDI IND CO LTD

Packet detection rules derived from ethernet forwarding information

Systems and methods are disclosed herein that relate to obtaining and using Packet Detection Rules (PDRs) in a cellular communications system operating as virtual Ethernet bridge based on Ethernet forwarding information. In one embodiment, a method performed by a User Plane Function (UPF) for enabling a cellular communications system to operate as a virtual Ethernet bridge comprises obtaining a PDR for a Protocol Data Unit (PDU) session in a downlink direction in the cellular communications system. The PDU session is associated with an egress Ethernet port of the virtual Ethernet bridge for the downlink direction, the PDR maps Ethernet packets received at the UPF on an ingress Ethernet port(s) of the virtual Ethernet bridge to the PDU session associated with the egress Ethernet port of the virtual Ethernet bridge, and the PDR is derived from an Ethernet packet forwarding rule of the virtual Ethernet bridge.
Owner:TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)

Reducing listen mode power consumption of wireless local area network (WLAN) devices

This disclosure provides methods, apparatus, and systems for reducing power consumption when a station (STA) operates in a listening mode. In some aspects, to reduce power consumption in listening mode, the STA can alternate between monitoring a radio channel to search for packets and not monitoring the radio channel. When the STA monitors the radio channel to search for packets in listening mode, the STA can configure a packet detection component to a power-on state. When the STA is not monitoring the radio channel in listening mode, the STA can configure the packet detection component to a power-off state. During the power-on state of listening mode, the STA can detect the preamble of packets transmitted on the radio channel. In response to detecting the preamble of the packet, the STA can switch from listening mode to receive mode to process the packet.
Owner:QUALCOMM INC

ELR communication method and device and readable storage medium

The present application relates to an ELR communication method and device and a readable storage medium, the method comprising: generating and sending an ELR PPDU, the ELR PPDU comprising a first field, the first field being generated based on an ELR identification sequence, the ELR identification sequence being carried on 53 subcarriers with subcarrier indexes from-26 to 26, elements of the ELR identification sequence on subcarriers with subcarrier indexes {-24,-20,-16,-12,-8,-4, 4, 8, 12, 16, 20, 24} being 0. According to the invention, the accuracy of packet detection can be improved. The application supports an IEEE protocol, such as a 802.11 bn / UHR / Wi-Fi 8 protocol, an integrated millimeter wave / IMMW protocol, a UWB protocol, or a perception protocol and the like. The method and the system also support a star flash / spark link / nearlink standard protocol and the like.
Owner:HUAWEI TECH CO LTD

DEB package detection method, device, electronic device and storage medium

Embodiments of the present invention relate to a DEB package detection method, device, electronic device and storage medium, which identify candidate DEB packages from a terminal operating system according to a preset file name pattern; read the file header information of the candidate DEB package and determine the valid DEB package when it matches the preset file header information; read the byte stream information of the valid DEB package and store it in a buffer, and extract target key information from the byte stream information based on a preset template in the buffer; when it is determined that the target key information meets the preset DEB package format specification, read the file structure information of the valid DEB package, extract the file directory tree, and parse each file layer by layer; when it is determined that each file meets the preset DEB package format specification, extract the basic information of each file, and match the basic information with the preset standard information, and determine the integrity and security of the valid DEB package if the match is successful; and implement integrity and security detection of the DEB installation package through a multi-layer verification mechanism.
Owner:BEIJING JINJIUYUAN TECHNOLOGY CO LTD

A power grid dispatching data dynamic perception and protection method based on a commercial secret algorithm

PendingCN122437681AData packData stream
The present application relates to the field of power grid dispatching data security, and more particularly to a power grid dispatching data dynamic perception and protection method based on a commercial secret algorithm. The method captures power grid dispatching network data streams in real time, obtains original service data containing dispatching instructions, measurement data and state information through protocol analysis and deep packet detection; then uses a dynamic data perception engine to identify sensitive data units, and dynamically generates data sensitivity labels according to the business type and the power grid operation state; dynamically matches commercial cryptographic algorithms from the commercial secret algorithm library according to the labels and distributes temporary session keys to generate an encryption strategy; encrypts the sensitive units, adds a security mark containing an algorithm identifier and a key index to the data packet header to form a protected data stream; sends the protected data stream to the target end, updates the session key state and uploads the execution log to the audit center. The present application realizes dynamic, accurate identification and differentiated encryption protection of power grid dispatching sensitive data.
Owner:HAINAN POWER GRID CO LTD

Including packet processing data for deep packet inspection classification rules in a combined lookup table used for packet classification at a network device

Systems and methods for determining whether to perform deep packet inspection (DPI) on packets received at a network device based on shallow packet inspection data are disclosed. Embodiments may include DPI classification data in a combined lookup table that is utilized for shallow packet data based packet classification at a network device. Using the results of lookups in such a combined look table based on received packets, determinations can be made whether to perform DPI on such received packets, and those packets forwarded accordingly.
Owner:ARISTA NETWORKS INC

Dual processor architecture for deterministic forwarding and selective higher order function execution

PendingCN121967319AClearly understand technical solutionsClearly understand the advantagesAssess restrictionSecuring communicationData compressionComputer architecture
The invention relates to an edge system with a dual-processor architecture, which integrates a broadband processor and an enterprise network processor through coordinated function configuration. The service level of the packet flow is divided by the post-provisioning data and the telemetry data, and it is determined whether to transmit the packet by the broadband processor or to selectively perform a high-order function, such as deep packet detection, data encryption, or data compression, by the enterprise network processor. Embodiments include logical coupling of virtual area networks, a signalling mechanism of segment routing / micro identity identification, a transport mechanism of memory sharing and without duplication, and a hybrid coupling combining logical control and data transport entity structures.
Owner:HUANLIAN TECHNOLOGY CO LTD

DNS tunnel flow detection method based on image processing

The invention belongs to the field of computer network security, and discloses a DNS tunnel traffic detection method based on image processing, and the method comprises the steps: in an offline training stage, firstly converting a domain name field and a query type of a DNS data packet into an image according to a preset rule, and carrying out the expansion of a DNS image data set through a deep convolution generative adversarial network; and then shape-color joint robust features of the image are extracted, and unified image vector representation is generated in combination with a bag-of-words model for classification training, so that the generalization ability of the model to various attack forms is effectively improved. In the online deployment stage, incremental expansion is carried out on Open vSwitch source codes, and the incremental expansion comprises embedding of data path processing logic, calling mechanism design of a deep packet inspection interface and parameter adaptation of a starting module. On the premise of not influencing the original forwarding performance and function, seamless integration of the DNS tunnel detection function is realized, and the capability of identifying malicious DNS traffic is enhanced.
Owner:HUNAN UNIV

Data packet detection method and device, electronic equipment and program product

The invention relates to the field of network security and data communication, in particular to a data packet detection method and device, electronic equipment and a program product, and aims to improve the data packet detection speed. The method comprises the steps of obtaining at least one to-be-processed data packet, inputting each to-be-processed data packet into a fine-tuned large language model, and obtaining an output regular expression corresponding to each to-be-processed data packet; for each regular expression, constructing a corresponding automatic detection model based on the detection logic of the regular expression, and migrating the automatic detection model to a first target detection model; and inputting the training data packet with the first label into a preset machine learning model, and performing parameter adjustment on the machine learning model based on the difference between a second label output by the machine learning model and the first label to obtain a second target detection model. According to the method, the large language model is finely adjusted, so that the regular expression library is expanded, and the cost of designing the data packet detection rule is reduced.
Owner:RUIJIE NETWORKS CO LTD

A service awareness method, communication apparatus and communication system

The application provides a service sensing method, a communication device and a communication system. The method comprises the following steps: a session management function network element sends a first request message to a user plane function network element, wherein the first request message comprises a detection rule and a usage reporting rule, the detection rule comprises an application service identifier and packet detection characteristic information, the detection rule is used for detecting a service flow of the application service, the packet detection characteristic information is used for indicating matching characteristics of the service flow of the application service, and the usage reporting rule comprises an event identifier, the event identifier is used for indicating an event of reporting the service flow of the application service, and the event is an application start event or an application end event; and the session management function network element receives a first event report from the user plane function network element, wherein the first event report is used for indicating the event. The technical solution can be used for effectively distinguishing different application service packets.
Owner:HUAWEI TECH CO LTD

Data processing method and apparatus, data storage system, and electronic device

PCT designated stageWO2026114394A1Program controlData packControl store
The present invention relates to the technical field of computers. Disclosed are a data processing method and apparatus, a data storage system, and an electronic device. The method comprises: for any storage controller, performing load demand analysis on an initial data packet to be processed of the storage controller; on the basis of the load analysis result corresponding to each storage controller, performing a first adjustment on the initial data packet to be processed, so that each storage controller obtains an intermediate data packet to be processed; detecting a current data processing capability of each storage controller; and on the basis of the current data processing capability of each storage controller, performing a second adjustment on the intermediate data packet to be processed, so that each storage controller obtains a target data packet to be processed. Two load balancing adjustments are performed on the initial data packet to be processed of each storage controller on the basis of the load demand of data to be processed and the processing capability of a processor itself, respectively, so as to ensure that the data processing load of the storage controllers is balanced, thereby laying a foundation for improving the performance of data storage devices.
Owner:INSPUR SUZHOU INTELLIGENT TECH CO LTD