Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

139 results about "Packet filtering" patented technology

Neuro-Generative Adversarial System for real-time detection and combating of malware morphing in high-density edge networks

ActiveDE202025106911U1Platform integrity maintainanceData packEmbedded security
A system for real-time detection and mitigation of morphing malware in high-density edge networks, consisting of: a data acquisition unit configured to receive, normalize, and encode multimodal telemetry data streams originating from at least one of the following domains: network traffic, process behavior, system call sequences, binary instruction traces, and control flow graphs; the data acquisition unit is further configured to compute feature embeddings over sliding time windows and apply privacy-preserving redactions prior to storage; a generative neural processor that is operationally coupled to the data acquisition unit and configured to generate synthetic morphing malware variants by learning probabilistic transformations of previously observed malicious data representations, maintaining semantic functionality while varying structural and behavioral features; a discriminative neural processor trained adversarially with the generative neural processor, wherein the discriminative neural processor is configured to detect morphing malware by evaluating a probability distribution over multimodal telemetry embeddings and classifying anomalous process and flow behaviors in real time; a coordination processor that is communicatively connected to both the generative neural processor and the discriminative neural processor and is configured to orchestrate adversarial co-training, regulate detection thresholds, calculate reinforcement-based penalties for false negative results, and trigger countermeasures as soon as a detection confidence level exceeds a predefined adaptive threshold; a secure, system-integrated inference and enforcement unit configured to perform low-latency countermeasures at the network edge, including selective packet filtering, flow isolation, process interruption, or system microsegmentation, based on instructions from the coordinating processor; and a hardware-embedded security enclave that is embedded in the system and configured to store cryptographic keys, neural model parameters, and integrity affirmation data to ensure the confidentiality, authenticity, and immutability of model artifacts and policy configurations.
Owner:ANAJAVADIDHODDI RAMACHANDRA NAIK CHAYAPATHI BENGALURU +7

Server-free dynamic management and control method based on extended Berkley packet filter

The invention provides a server-free dynamic management and control method based on an extended Burkley packet filter, and the method comprises the steps: mounting an eBPF program to a kernel cgroup subsystem, monitoring a function instance creation / destruction event in real time, extracting metadata, dynamically generating a fine-grained network strategy, compiling the fine-grained network strategy into an eBPF byte code, and injecting the eBPF byte code into a Map format strategy table, realizing data packet level allowing / discarding control by using a flow control hook; and when the instance is destroyed, the strategy table rule is automatically cleared through a cgroprease event. Through kernel-level dynamic management and control, precise security protection, zero-trust micro-isolation and kernel layer malicious behavior interception of the function instance in the full life cycle are realized, and the security efficiency and the resource utilization rate of the cloud native environment are remarkably improved.
Owner:BEIJING PACTERA JINXIN TECH LTD

Network communication dynamic encryption method, encryption and decryption system, equipment, medium and product

The invention discloses a network communication dynamic encryption method, an encryption and decryption system, equipment, a medium and a product, and relates to the technical field of communication. The method comprises the steps that a dynamic factor is obtained through a Berkley packet filter function, a key is generated based on the dynamic factor, the key generated based on the dynamic factor has high randomness and unpredictability, and the problem that a fixed key is adopted in a traditional encryption mode, and consequently the key is prone to being cracked can be solved; moreover, by using the execution environment of the Berkley packet filter function in the kernel mode, the risk that the key is stolen in the transmission and storage process is reduced, the influence on the network communication performance is small, and the network communication encryption efficiency and the network communication security are improved. Moreover, the information of network communication is used as the basis of key generation, additional key distribution and storage management processes are not needed, complex key exchange and certificate management mechanisms are not needed, the key management process is simplified, and the operation and maintenance cost of the system is reduced.
Owner:LANGCHAO ELECTRONIC INFORMATION IND CO LTD

Performance detection method and device for AI infrastructure and storage medium

The invention discloses an AI infrastructure performance detection method and device and a storage medium, and belongs to the technical field of data processing. The method comprises the steps that according to chip information of container nodes, dynamic instrumentation is conducted on a kernel layer and a calculation layer by expanding a Burkley packet filter, first performance indexes of the kernel layer and the calculation layer are collected, a hardware management library function is called, second performance indexes of a chip hardware layer are collected, and on the basis of a control group mechanism, the kernel layer and the calculation layer are subjected to dynamic instrumentation; and obtaining meta-information of the business process group in the container node, constructing an association relationship between the first performance index and the business process group and between the second performance index and the business process group through association marking according to the meta-information, and performing association analysis on the first performance index and the second performance index based on the association relationship to obtain a performance detection result of the business process group. According to the method, the performance parameters are collected through a non-intrusive scheme, the performance indexes of different service processes are determined through a service association mode, and the accuracy of AI performance problem positioning is improved.
Owner:CHINA MERCHANTS BANK

Packet filtering strategy management method and data packet filtering method and device

The invention provides a management method of a packet filtering strategy and a data packet filtering method and device, and the management method comprises the steps: enabling the packet filtering strategy to be matched with a strategy template, and storing the matched packet filtering strategy to the strategy template of a corresponding type; each category of strategy template is configured with value ranges of parameters of at least two dimensions, and the combination modes of the dimensions of the parameters of different strategy templates are different; screening out candidate packet filtering strategies from the packet filtering strategies which are not matched with the strategy template, wherein the candidate packet filtering strategies are packet filtering strategies which coincide with the value range of the parameters of the strategy template; splitting a value range of a parameter coinciding with the strategy template from the candidate packet filtering strategy, generating a new packet filtering strategy, and storing the new packet filtering strategy in the corresponding strategy template; and taking the value range of the residual parameter which is not overlapped with the strategy template in the candidate packet filtering strategy as another new packet filtering strategy, and storing the new packet filtering strategy and other packet filtering strategies which are not matched with the strategy template in the strategy tree together.
Owner:HANGZHOU DPTECH TECH

Network data flow relation graph generation method and device, electronic equipment and readable medium

The embodiment of the invention discloses a network data flow relation graph generation method and device, electronic equipment and a readable medium. A specific embodiment of the method comprises the following steps: acquiring preset network data packet capturing information and network data packet filtering information; capturing each initial network data packet among the servers, and filtering each initial network data packet in parallel based on the network data packet filtering information; analyzing the target network data packet to obtain data packet analysis information corresponding to the target network data packet; based on the obtained analysis information of each data packet, generating information of each communication connection edge between the servers; based on the preset network data packet capture information, storing the information of each communication connection side to a preset database; and in response to the detected data flow query request information sent by the user side, generating a network data flow relation graph corresponding to the at least one piece of communication connection side information. According to the embodiment, waste of computing power resources of a computer is reduced.
Owner:HUAQING RONGTIAN (BEIJING) SOFTWARE CO LTD

Token injection in packet headers to support high volume packet filtering

A class of network packets can be labeled by inserting a token into a packet header field. Preferably the header field is available to intermediary devices in cleartext. A packet filter examines the packets, allowing packets with the token to pass while dropping others. For example, the token can indicate that the packet is part of a “trusted” class. The token can be calculated from a secret, shared between the sender and receiver, and a rotating value. In some embodiments, the token may be placed in all packets associated with a trusted sender or for some time before trust must be re-established. Alternatively, the token can be placed in an initial one or more packets of a particular flow, and the packet filter can look for such packet(s), deciding whether to allow or block them. The packet filter then treats subsequent packets in the same flow in the same way.
Owner:AKAMAI TECHNOLOGIES INC

Full-stack observability method of unified platform

The invention provides a full-stack observability method for a unified platform, which comprises the following steps of: respectively acquiring logs, indexes and link tracking data by using an application performance monitoring agent, an extended Berkley packet filter agent and an index acquisition agent, and storing and distributing the logs, the indexes and the link tracking data, and performing data association processing by using the request tracking identifier and the timestamp to obtain an original data set which is stored uniformly and is in cross-data association, and performing format standardization and full-stack tracking integration processing respectively to obtain a standardized time sequence index and full-stack link tracking data respectively. By summarizing the data into the same observation system and associating the observation data by using the specific field, all observability data can be observed on the same platform, and the same user interface is used, so that switching among a plurality of system pages is not needed, the problem of data islands is solved, and a user-friendly observable platform is created.
Owner:JIANGXI TONGRUI INFORMATION TECH CO LTD

Systems and methods for testing sandboxed in-kernel programs

Systems and methods for testing sandboxed in-kernel programs are provided. A method of testing a program includes: obtaining a Berkeley Packet Filter (BPF) program to test; obtaining a test to run on the BPF program; performing the test on the BPF program for a plurality of Linux kernels and reporting a result of performing the test on the BPF program for a plurality of Linux kernels. This enables a generic testing solution for black box testing of BPF programs. The embodiments can integrate with existing testing suites and frameworks and can integrate into CI / CD pipelines. Some embodiments allow testing using any kernel from user space. Host kernel testing of BPF programs is enabled by a developer using the developer's own workstation and version of the Linux kernel. Guest kernel testing of BPF programs is enabled using specific kernel versions by providing the framework a specification of the target kernel environment.
Owner:TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)

Edge computing and distributed zero-trust architecture system and data processing method

The invention discloses an edge computing and distributed zero-trust architecture system and a data processing method. The system comprises an edge computing device cluster, a distributed zero-trust control center, an edge security gateway and a block chain identity infrastructure. The edge computing node collects hardware state, vulnerability and behavior data through the terminal security agent module; the block chain identity infrastructure provides distributed identity identification and verifiable credential service; the edge security gateway executes data packet filtering and single packet authentication; and the distributed zero-trust control center calculates a real-time security coefficient and generates a differentiation strategy, and the log is synchronized to the alliance chain for evidence storage. According to the data processing method, security access is realized through access request initiation, single packet authentication, data acquisition, trust evaluation, strategy execution and log evidence storage. According to the method, the edge device state and distributed zero trust are deeply fused, the problems of incomplete identity authentication and static permission control in an edge scene are solved, and the security and traceability of an edge computing network are improved.
Owner:BEIJING ANCHEN INFORMATION TECHNOLOGY CO LTD

GOTO action in network traffic policies

A traffic policy includes policy rules that specify branch actions in their action fields. A branch action specifies another policy rule in the traffic policy. Packet filters generated from the traffic policy represent the traffic policy rules and execution order semantics of the branch rules.
Owner:ARISTA NETWORKS INC

Data packet filtering method and device

The invention relates to a data packet filtering method and device. The method comprises the following steps: extracting dimension information of a data packet, wherein the dimension information comprises at least one of a source IP address, a destination IP address, a source port, a destination port and a protocol type; sending the data packet to a corresponding virtual system; the virtual system matches the dimension information of the data packet with a pre-configured strategy template; when the matching is successful, filtering the data packet according to a filtering rule corresponding to the strategy template; and when the matching is unsuccessful, filtering the data packet through a strategy tree. According to the data packet filtering method and device, the packet filtering strategy analysis and matching efficiency can be improved, and the network attack protection efficiency of packet filtering is improved.
Owner:HANGZHOU DPTECH TECH

Network-packet filtering system and method

A network-packet filtering system is provided. The system includes one or more end hosts and a network-packet filtering device communicable with the end hosts and an external network. Each end host obtains its host-performance vector by executing a first neural network model based on its system-performance information. The network-packet filtering device determines whether to drop a packet from the external network or to pass the packet by executing a second neural network model based on the host-performance vectors and the packet.
Owner:NUVOTON

Data packet real-time filtering method and device of vehicle-mounted host firewall

The invention provides a data packet real-time filtering method and device for a vehicle-mounted host firewall, and relates to the technical field of vehicle-mounted host firewall application, and the method comprises the steps: receiving a preset rule set sent by an upper computer; monitoring the current vehicle state in real time, determining a first filtering rule of the current network traffic data packet from a preset rule set based on the first vehicle state of the current vehicle, and analyzing and filtering each protocol layer data of the current network traffic data packet; if the current vehicle is switched from the first vehicle state to a second vehicle state, determining an application layer data filtering rule and / or a transmission layer data filtering rule corresponding to the second vehicle state from a preset rule set, and updating the first filtering rule to generate a second filtering rule, and analyzing and filtering each protocol layer data of the current network flow data packet based on the second filtering rule. The technical problem that a vehicle-mounted host firewall in the prior art cannot enable the filtered data packet to accurately meet the requirements of a complex vehicle application scene is solved.
Owner:NEUSOFT REACH AUTOMOBILE TECH (SHENYANG) CO LTD

Hypercall method and apparatus for kernel-mode program of extended berkeley packet filter

A hypercall method and apparatus for a kernel-mode program of an enhanced Berkeley packet filter are disclosed. The method is applied to a virtual machine monitor, comprises: acquiring, in response to a virtualization page fault triggered by the kernel-mode program, a memory address where the virtualization page fault is triggered; determining whether the memory address of the virtualization page fault is consistent with a memory address corresponding to a page fault key in a mapping table; reading, from the mapping table, a page fault value mapped by the page fault key if the memory address of the virtualization page fault is consistent with the memory address corresponding to the page fault key, wherein the page fault value comprises a function type of a hypercall written by the kernel-mode program; and executing, based on the function type indicated by the page fault value, the hypercall of the function type.
Owner:CLOUD INTELLIGENCE ASSETS HOLDING (SINGAPORE) PTE LTD

Semantic monitoring and causal delimiting method for affairs of electricity consumption information acquisition terminal

PendingCN121880064AAchieve non-intrusive depth observationIncrease the level of automationFault responseTimestampPower usage
The invention discloses an electricity consumption information acquisition terminal transaction semantic monitoring and causal delimiting method, which comprises the following steps: acquiring an application protocol data unit by utilizing an eBPF probe, generating a cross-layer unique transaction fingerprint based on extracted sessions, objects, businesses and calling identifiers, and generating a transaction event record by utilizing a pairing state machine; constructing a transaction observation window containing front and back extensions by taking a transaction observation timestamp as a reference, and screening and aggregating kernel events associated with the transaction fingerprint to obtain a transaction evidence set; and constructing a directed evidence graph based on the set, and calculating the confidence coefficient of each root cause category by using a scoring rule and an index normalization algorithm. According to the invention, non-intrusive deep observation of power acquisition business affairs is realized, and the automation level and fault diagnosis precision of power terminal operation and maintenance are improved.
Owner:NANJING XINLIAN ELECTRONICS CO LTD

Filter element, related filter assembly and filter package

The present disclosure relates to: a flexible filter media pack arranged in a tubular manner about an axis; a first open end cap connected in a fluid-tight manner to the first axial end of the filter media pack; and a second open end cap connected in a fluid-tight manner to the second axial end of the filter media pack, characterized in that the first end cap is flexible and non-destructively deformable between a first shape and a second, different shape; and related filter packages and filter assemblies.
Owner:DONALDSON CO INC

Hash and tcam based combined packet classifier and method

The application discloses a kind of combination packet classifier and method based on hash and TCAM, adopt the combination of imperfect hash classification module and TCAM classification module, the complement of imperfect hash classification and TCAM classification on input key value space is realized;Compared with the traditional TCAM packet classification solution based on, the application reduces hardware resource utilization, system power consumption;Compared with the packet classification solution based on perfect hash, the application reduces the design cost of hash function and the time complexity of generation process under the premise of guaranteeing the function of classifier.The application can consider low space resource consumption, low power consumption and low delay in the classification stage, saves design cost in the classifier generation stage, and reduces the time complexity of generation process;Meanwhile, the application can better balance different types of hardware resources on reconfigurable hardware platforms such as FPGA, and provides a new way of thinking for the design of classifier in network tasks such as firewall packet filtering and routing table lookup.
Owner:XIAN MICROELECTRONICS TECH INST

Method for monitoring and enforcing secure policies in a device

A method for monitoring and enforcing secure policies in a device includes collecting kernel data from a kernel space by a packet filtering module operating in a user space. The kernel data is processed into events that are transmitted to a data bus, where the events are stored and provided to a policy enforcement module. The policy enforcement module evaluates the events with an algorithm to detect potential threat events. When a threat event is identified, one or more secure policies are selected and executed in the device as corresponding actions or commands. The method enables real-time monitoring of kernel activity and enforcement of security policies while maintaining the architecture in user space.
Owner:EXEIN SPA

Systems and methods for cyber threat detection based on new and / or updated cyber threat intelligence

Systems, methods, and apparatuses are described for detection and / or analysis of cyber threats based on updated cyber threat intelligence associated with cyber threats. Packet filtering output data such as logs of packet communications and / or copies of packets may be generated based on first cyber threat intelligence associated with a cyber threat. Updated criteria based on subsequent updated cyber threat intelligence may then be applied to the packet filtering output data.
Owner:CENTRIPETAL NETWORKS INC

Efficient Threat Context-Aware Packet Filtering for Network Protection

A threat intelligence gateway (TIG) may protect TCP / IP networks from network (e.g., Internet) threats by enforcing certain policies on in-transit packets that are crossing network boundaries. The policies may be composed of packet filtering rules with packet-matching criteria derived from cyber threat intelligence (CTI) associated with Internet threats. These CTI-derived packet-filtering rules may be created offline by policy creation and management servers, which may distribute the policies to subscribing TIGs that subsequently enforce the policies on in-transit packets. Each packet filtering rule may specify a disposition that may be applied to a matching in-transit packet, such as deny / block / drop the in-transit packet or pass / allow / forward the in-transit packet, and also may specify directives that may be applied to a matching in-transit packet, such as log, capture, spoof-tcp-rst, etc. Often, however, the selection of a rule's disposition and directives that best protect the associated network may not be optimally determined before a matching in-transit packet is observed by the associated TIG. In such cases, threat context information that may only be available (e.g., computable) at in-transit packet observation and / or filtering time, such as current time-of-day, current TIG / network location, current TIG / network administrator, the in-transit packet being determined to be part of an active attack on the network, etc., may be helpful to determine the disposition and directives that may best protect the network from the threat associated with the in-transit packet. The present disclosure describes examples of methods, systems, and apparatuses that may be used for efficiently determining (e.g., accessing and / or computing), in response to the in-transit packet, threat context information associated with an in-transit packet. The threat context information may be used to efficiently determine the disposition and / or one or more directives to apply to the in-transit packet. This may result in dispositions and / or directives being applied to in-transit packets that better protect the network as compared with solely using dispositions and directives that were predetermined prior to receiving the in-transit packet.
Owner:CENTRIPETAL NETWORKS INC

Data packet filtering method and device, storage medium and electronic equipment

The invention relates to a data packet filtering method and device, a storage medium and electronic equipment. The method comprises the following steps: acquiring mobile data of equipment and signal data of the equipment; determining a data filtering rule of the equipment according to the mobile data and the signal data; and filtering the transmission data packet of the equipment according to the data filtering rule. The technical problem that the data packet is not safely filtered is solved.
Owner:FIBOCOM AUTO INC

Methods and Systems for Efficient Encrypted SNI Filtering for Cybersecurity Applications

A packet-filtering system described herein may be configured to filter packets with encrypted hostnames in accordance with one or packet-filtering rules. The packet-filtering system may resolve a plaintext hostname from ciphertext comprising an encrypted Server Name Indication (eSNI) value. The packet-filtering system may resolve the plaintext hostname using a plurality of techniques. Once the plaintext hostname is resolved, the packet-filtering system may then use the plaintext hostname to determine whether the packets are associated with one or more threat indicators. If the packet-filtering system determines that the packets are associated with one or more threat indicators, the packet-filtering system may apply a packet filtering operation associated with the packet-filtering rules to the packets.
Owner:CENTRIPETAL NETWORKS INC

System and method for obtaining instrumentation data

A computing environment determines, by an initialization process, a monitor instance identifier of an instance of an application, wherein the initialization process initializes monitoring of the instance of the application. The computing environment generates, by the initialization process, a system call argument based on a pseudo-randomly generated identifier. The computing environment makes, by the initialization process, a system call comprising the system call argument. The computing environment determines, by a kernel-space Berkeley packet filter (BPF), to monitor the instance of the application based on the system call. The computing environment extracts, by the kernel-space BPF, the pseudo-randomly generated identifier from the system call argument to obtain the monitor instance identifier. The computing environment stores, in a watch list, the monitor instance identifier and the pseudo-randomly generated identifier. The computing environment obtains instrumentation data using the monitor instance identifier and the pseudo-randomly generated identifier.
Owner:RAPIDFORT INC

Network control method, device, equipment, medium and program product

The embodiment of the invention provides a network control method and device, equipment, a medium and a program product, and relates to the technical field of terminal intelligent control. The method comprises the steps of obtaining a unique identifier of a target application program; constructing a network access control list containing the target application program; and configuring a network filtering rule for the target application program based on the network access control list and the unique identifier. Based on the method, the accuracy of network filtering rule configuration can be improved through the uniqueness of the unique identifier of the target application program, and misjudgment caused by factors such as address or port overlapping is avoided. And the network filtering rule is configured for the target application program based on the network access control list and the unique identifier, so that data packet filtering can be forcibly processed, and the forcibility and uniformity of the rule are ensured. Therefore, through the method, the accuracy, uniformity and mandatory of network control can be improved.
Owner:SHENZHEN TAILIWEI INTELLIGENT TECHNOLOGY CO LTD

Data packet filtering method and device, equipment, storage medium and vehicle

The invention relates to a data packet filtering method and device, equipment, a storage medium and a vehicle, the method is suitable for a network interface layer in a processor, and the method comprises the following steps: extracting first attribute information from a to-be-processed data packet; calculating target verification information corresponding to the to-be-processed data packet based on the first attribute information; target verification information is searched in all pieces of verification information obtained in advance, and all the pieces of verification information are obtained through calculation according to attribute information, collected in advance, of the expected data packet; when the target verification information is found, forwarding the to-be-processed data packet to a network protocol stack; and when the target verification information is not found, discarding the to-be-processed data packet. By calculating the target verification information corresponding to the to-be-processed data packet, whether the to-be-processed data packet is the expected data packet or not can be verified before the to-be-processed data packet is uploaded to the network protocol stack, so that inflow of an unexpected data packet is blocked, the calculation overhead of a processor is reduced, and the bandwidth utilization rate is improved.
Owner:BEIJING CO WHEELS TECH CO LTD

Duplicate message filtering system for industrial wireless networks

This invention relates to the technical field of industrial wireless communication. Specifically, it provides a duplicate packet filtering system for industrial wireless networks. The system includes: a packet feature extraction module, a hash value calculation module, a dynamic filter module, and a filtering decision and execution module. The packet feature extraction module extracts features from the current wireless packet. The hash value calculation module calculates the corresponding hash value based on the source MAC address of a first terminal. The dynamic filter module queries the hash RAM table based on the hash value to obtain the SA RAM index. The dynamic filter module retrieves the current entry corresponding to the SA RAM based on the SA RAM index. The dynamic filter module determines whether the current wireless packet is a duplicate packet based on the current entry corresponding to the SA RAM. The filtering decision and execution module filters out the current wireless packet when it is a duplicate packet. This invention reduces network resource waste, significantly reduces terminal processing load, and ensures real-time and reliable communication.
Owner:SHENYANG BONCHREE TECHNOLOGY CO LTD +1

User login auditing method, device and equipment, medium and product

The invention discloses a user login auditing method, device and equipment, a medium and a product. The method comprises the following steps: mounting an extension packet filter program to a target trigger point related to user login; under the condition that the target trigger point is triggered, acquiring a system call event of the target trigger point through the extension packet filter program, and transmitting to-be-audited event data associated with the system call event to a login audit daemon process of a user space; and performing user login auditing based on the to-be-audited event data through the login auditing daemon process, and generating a user login auditing result. According to the scheme, the system call event is acquired through the extension packet filter program mounting to perform user login auditing, so that the event call can be monitored in real time, and the real-time performance is high; the auditing process does not depend on log files, and the log tampering risk is avoided; kernel source codes, system configuration and the like do not need to be modified, the original authentication process and system stability are not influenced, the invasiveness is low, and the compatibility is high.
Owner:SHANGHAI JIACHE INFORMATION TECH CO LTD

Methods and systems for efficient adaptive logging of cyber threat incidents

A packet-filtering network appliance such as a threat intelligence gateway (TIG) protects TCP / IP networks from Internet threats by enforcing certain policies on in-transit packets that are crossing network boundaries. The policies are composed of packet filtering rules derived from cyber threat intelligence (CTI). Logs of rule-matching packets and their associated flows are sent to cyberanalysis applications located at security operations centers (SOCs) and operated by cyberanalysts. Some cyber threats / attacks, or incidents, are composed of many different flows occurring at a very high rate, which generates a flood of logs that may overwhelm computer, storage, network, and cyberanalysis resources, thereby compromising cyber defenses. The present disclosure describes incident logging, in which a single incident log efficiently incorporates the logs of the many flows that comprise the incident, thereby potentially reducing resource consumption while improving the informational / cyberanalytical value of the incident log for cyberanalysis when compared to the component flow logs. Incident logging vs. flow logging can be automatically and adaptively switched on or off depending on the combination of resource consumption and informational / cyberanalytical value.
Owner:CENTRIPETAL NETWORKS INC

Operating system fingerprint simulation method, device, equipment, medium and product

The invention discloses an operating system fingerprint simulation method and device, equipment, a medium and a product. The method comprises the following steps: capturing a plurality of first detection messages received by a detection host by using an eBPF program through an eBPF virtual machine in a kernel mode; feature information corresponding to the multiple first detection messages is extracted, a second detection message in the multiple first detection messages is determined according to the feature information, and the second detection message belongs to an Nmap operating system fingerprint detection packet in any detection stage in Nmap operating system fingerprint scanning; filtering the second detection message; generating a performance event according to attribute information of an Nmap operating system fingerprint detection packet corresponding to the second detection message, and storing the performance event in an eBPF map data structure; and the user mode program reads the corresponding performance event through the file descriptor so as to simulate the fingerprint of the Nmap operating system. According to the embodiment of the invention, the influence on the performance of the operating system can be reduced to the minimum while the fingerprint of the operating system is disguised.
Owner:NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP +1