Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

28 results about "Packet payload" patented technology

In computing, a payload is the carrying capacity of a packet or other transmission data unit.

Wire-speed routing and policy enforcement without DPI or decryption

A system and computer-implemented method for routing an encrypted packet through a cloud enforcement network based on a metadata tag. The cloud enforcement network applies policy and routing attributions or tags outside of the encrypted packet payload in such a way as to not require an inner packet to first be decrypted. Traffic prioritization, data protection, and per application policies are achieved by using such metadata tags for internode routing without the need for DPI or decryption. Furthermore, the metadata itself can also be signed or encrypted depending on the provenance of the data. As such, applying meta-tagging external to an encrypted packet, the payload would not be needed to be decrypted during transit of the packet to express end-to-end policy and routing decisions.
Owner:CISCO TECHNOLOGY INC

Identifying malicious network traffic behavior using flow-based packet payload length aggregation

In example embodiments, techniques are provided for identifying malicious network traffic behavior by aggregating packet payload length of packets of a target packet flow that are part of same segments (e.g., same TCP segments) to produce segment payload lengths (e.g., TCP segment payload lengths), and using the segment payload lengths for identification. An encrypted payload analytics (EPA) engine of network detection and response (NDR) software may generate a target image from the segment payload lengths by organizing data points based on the segment payload lengths into a matrix, and converting the data points in the matrix into pixels of the target image. The EPA engine may then apply the target image to a trained machine learning (ML) model to determine a likelihood network traffic behavior is malicious network traffic behavior. In response to the likelihood, the NDR software may perform a remedial action.
Owner:SOPHOS LTD

Apparatus and method for coding of radio programs and multimedia services in television broadcasts

FIG. 1 illustrates an apparatus for decoding according to an embodiment. The apparatus comprises an interface for receiving a plurality of ATSC Link-layer Protocol packets each of which comprising a packet header and a packet payload encapsulating digital content. Moreover, the apparatus comprises a decoding unit. In a first embodiment, the digital content being encapsulated within the packet payload of each of one or more ATSC Link-layer Protocol packets of the plurality of ATSC Link-layer Protocol packets comprises digital radio content, and / or a Distribution and Communications Protocol packet or a portion thereof, and / or Unified Speech and Audio Coding content or extended High Efficiency Advanced Audio Coding content, and / or Journaline content. The decoding unit is configured to decode the packet payload of each one of at least one ATSC Link-layer Protocol packet of the one or more ATSC Link-layer Protocol packets to obtain the digital content of said one of the at least one ATSC Link-layer Protocol packet.
Owner:FRAUNHOFER GESELLSCHAFT ZUR FORDERUNG DER ANGEWANDTEN FORSCHUNG EV

Conditional automatic gain control on single station piconet for bluetooth receiver based on connection state

The present invention relates to a method and apparatus for reducing power consumption in a receiver of a time slotted communication system. An RF front end has power applied after the start of a preamble or after the start of a header, or upon the start of a packet payload based on connection status, signal level, and interference level. Where the signal level is constant, the communication system is in a connected state, and the interference level is low, the system bypasses packet header destination address matching, or optionally, uses only the least significant bits of the header destination address for matching purposes.
Owner:SILICON LABORATORIES INC

Method and apparatus to perform operations on multiple segments of a data packet in a network interface controller

A stacked memory such as a high bandwidth memory (HBM) with a wide data path is used by a streaming pipeline in a network interface controller to buffer segments of a data packet to allow the network interface controller to perform operations on the packet payload. The headers and packet payload can be scanned and classified concurrently with the buffered payload parsed in parallel.
Owner:INTEL CORP

Telemetry restriction mechanism

An apparatus comprising a network interface card (NIC), including packet processing circuitry to determine whether the NIC is to operate according to a first telemetry protection mode to prevent copying of packet data payloads for telemetry or a second telemetry protection mode to enable copying of packet payloads for telemetry.
Owner:INTEL CORP

Systems and methods for processing multiple IP packet types in a network environment

Systems, devices, and methods include receiving, at a first physical port of a network appliance, an IP type A packet. The IP type A packet includes a packet header and a packet payload, and the packet header includes an IP type A destination address. The methods further include determining that the IP type A packet is destined for an IP type B address space; routing the IP type A packet to a virtual port; receiving, the IP type A packet by the virtual port; based at least in part on being received by the virtual port, converting the IP type A address to an IP type B address; and formatting an IP type B packet including an IP type B header and the packet payload from the IP type A packet, wherein the IP type B header includes the IP type B address.
Owner:FORTINET INC

A traffic identification method and device, a storage medium and a computer program product

The application provides a traffic identification method and device, a storage medium and a computer program product, which include: performing feature extraction on first data traffic to obtain a first type of feature vector; the first type of feature vector includes a data packet payload type of feature vector and / or a congestion window type of feature vector; and the first type of feature vector is used to identify the first data traffic to obtain a traffic type of the first data traffic; the traffic type includes an anonymous proxy type and / or a general type. The accuracy of traffic identification can be improved.
Owner:CHINA MOBILE (SUZHOU) SOFTWARE TECH CO LTD +1

Equipment discovery method and system based on hardware buffer, terminal and storage medium

The invention discloses an equipment discovery method and system based on a hardware buffer area, a terminal and a storage medium, and the method comprises the steps: obtaining the equipment information of a server, carrying out the message packaging of the equipment information, obtaining a discovery message, writing the payload of the discovery message into the hardware buffer area of the server, and obtaining the payload of a sent message; performing first message header packaging processing on the message sending payload according to the local port number of the server to obtain a target discovery message, and sending the target discovery message to the client to obtain a server broadcast result; obtaining a response message payload in a hardware buffer area of the client, and performing second message header packaging processing on the response message payload to obtain a target response message; and sending the target response message to the server according to the server broadcast result to obtain a client response result. According to the invention, the sending and response of the CoAP message in the soft bus discovery process are completed through hardware, and the CPU occupancy rate in the soft bus discovery process is reduced.
Owner:深圳开鸿数字产业发展有限公司

Identifying a maximum segment size (MSS) corresponding to a network path

Techniques are disclosed for identifying a maximum segment size (MSS) for a path. For example, a first router includes a routing engine and a packet forwarding engine. The routing engine is configured to identify a path maximum transmission unit (MTU) corresponding to a path between the first router and a second router; and identify a maximum packet overhead size corresponding to a session between a first client device and a second client device over the path between the first router and the second router. Additionally, the routing engine is configured to calculate, based on the path MTU and the maximum packet overhead size, a path maximum segment size (MSS), wherein the path MSS represents a maximum packet payload size corresponding to the path; and control the packet forwarding engine to output information indicative of the path MSS.
Owner:JUNIPER NETWORKS INC

Robust broadcast via relayed retransmission

Systems and methods for broadcasting wireless data via one or more retransmission schemes to increase the packet reception in a wireless system. One or more devices of the system are configured to listen for an initial data packet from a source device. Should one or more devices successfully receive the initial packet, each device that received the packet can unconditionally retransmit a copy of the payload of the initial packet such that any device that failed to receive the initial packet payload has an opportunity to receive it during the respective retransmissions. Similarly, each device of the system can send acknowledgements to the other system devices that indicate whether they received the initial packet. Should one or more of the devices successfully receive the initial packet, the devices can conditionally retransmit a copy of the missing payload when one or more devices indicates they have failed to receive it.
Owner:BOSE CORP

Hardware-based accelerating apparatus for nvme over fabrics target, operation method thereof, and system including the same

A non-volatile memory express over fabrics (NVMe-oF) target accelerating apparatus according to an embodiment of the present disclosure includes: a first offload engine configured to offload a network stack to compute a first network packet and output a first packet payload; and a second offload engine configured to offload an NVMe-oF stack to compute the first packet payload and output data having a first buffer address when the first packet payload is of a first type.
Owner:MANGOBOOST INC

Flexible configurable data analysis device and method based on FPGA

The invention relates to the technical field of network message analysis, and discloses a flexible configurable data analysis device and method based on an FPGA (Field Programmable Gate Array), which can adapt to multi-protocol message analysis by storing a plurality of message analysis templates through an RAM (Random Access Memory) and matching a search module with message frame identification information, and break through the limitation that the existing FPGA analysis mostly aims at a single protocol and is poor in universality. Besides, the analysis module can analyze sub-data in the message load according to the matching template without depending on upper software, so that the problems of low efficiency and poor real-time performance caused by the fact that an existing FPGA only analyzes a frame header fixed field and load data needs to be processed by software are solved; therefore, the flexible and efficient application requirements of a multi-bus heterogeneous high-speed network system on multi-type data processing are met.
Owner:XIAN MICROELECTRONICS TECH INST

Selection of candidate data flows for evaluating performance metrics using passive measurements

Aspects of the subject disclosure may include, for example, identifying a flow of data packets between first and second network addresses of a network, with each packet including respective header and payload portions. The identified flow of data packets is monitored over a number of sample periods to obtain a number of monitored results. A data-flow activity record is generated, having a number of symbols corresponding to the number of monitored results, the symbols including an active symbol value indicative of a presence of an exchange of data and an idle symbol value indicative of an absence of an exchange of data. A suitability of the identified data flow is inferred for estimating a throughput of the network according to the data-flow activity record without interpreting contents of each respective packet payload portion. Other embodiments are disclosed.
Owner:AT&T MOBILITY II LLC +1

A method, system, device and medium for data link layer handover

The application discloses a data link layer switching method, system, device and medium, and relates to the technical field of communication; the method comprises the following steps: in an error correction coding system of a given channel error probability, a wireless channel state is monitored, and an optimal packet length corresponding to a maximum wireless channel throughput is calculated; a data frame of a fiber channel is split based on the optimal packet length, and a wireless data packet payload is obtained; the wireless data packet payload is reconstructed, and a data frame meeting a wireless channel transmission standard is obtained. The application aims to provide a data link layer switching method, system, device and medium, adopts a "direct splitting-repackaging" conversion mode, and effectively improves the switching efficiency of a special network communication data link layer channel.
Owner:BEIJING UNIV OF POSTS & TELECOMM +1

Probe-based virtual network sensitive data traffic detection

The technology disclosed relates to detection of data traffic in computing environments, such as cloud environments. Example systems and methods detect a plurality of workloads in a virtual network in a computing environment and deploy a plurality of probe agents to the plurality of workloads. Each respective probe agent detects network traffic on a respective workload of the plurality of workloads, scans a data packet that is at least one of sent or received by the respective workload, generates a data classification relative to the data packet, and generates a scan result that includes packet payload information and an indication of the data classification. The scan results are received from the plurality of probe agents and a computing action is performed based on scan results.
Owner:PROOFPOINT INC

Statistical behavior sequence-based encrypted malicious traffic characterization method and device

This application provides a method and apparatus for characterizing encrypted malicious traffic based on statistical behavior sequences. The method includes: acquiring and preprocessing a network traffic capture file containing encrypted malicious traffic to obtain an encrypted bidirectional stream with an unparseable payload and anomaly-removed data; extracting flow-level statistical features based on the stream, constructing a standardized behavior sequence through channel clustering and sequence length standardization; performing self-supervised joint training on the encoding and decoding models, optimizing the parameters, and then determining the encoding model as the feature extraction model; constructing the standardized behavior sequence of the traffic to be detected, inputting it into the model to output a behavior representation vector, then inputting it into a machine learning model to output the identification result representing the malicious attributes, category, or abnormal state of the traffic to be detected. This method eliminates the need to parse the packet payload, accurately characterizes the overall behavior pattern of encrypted traffic, improves the stability and generalization of the representation vector, reduces sample labeling dependence, and efficiently adapts to downstream encrypted traffic analysis and detection tasks.
Owner:CHONGQING UNIV

Method and apparatus to perform operations on multiple segments of a data packet in a network interface controller

PendingUS20260205529A1Data packPathPing
A stacked memory such as a high bandwidth memory (HBM) with a wide data path is used by a streaming pipeline in a network interface controller to buffer segments of a data packet to allow the network interface controller to perform operations on the packet payload. The headers and packet payload can be scanned and classified concurrently with the buffered payload parsed in parallel.
Owner:INTEL CORP

Zero-trust network access with user datagram protocol message forwarding

Zero-trust network access (ZTNA) with user datagram protocol (UDP) message forwarding is disclosed. A forwarding rule is determined based on a destination address associated with a received data traffic packet formatted according to a first protocol (e.g., UDP). A bi-directional tunnel is created to forward the traffic based on the determined forwarding rule. A request is generated over a stream having a corresponding stream identifier within the bi-directional tunnel to establish a connection with a proxy device. The traffic packet payload formatted according to the first protocol is wrapped with at least the stream identifier. The wrapped data traffic packet is forwarded to a client device based on the determined forwarding rule to a destination device corresponding to the stream identifier.
Owner:FORTINET INC

Wire-speed routing and policy enforcement without DPI or decryption

A system and computer-implemented method for routing an encrypted packet through a cloud enforcement network based on a metadata tag. The cloud enforcement network applies policy and routing attributions or tags outside of the encrypted packet payload in such a way as to not require an inner packet to first be decrypted. Traffic prioritization, data protection, and per application policies are achieved by using such metadata tags for internode routing without the need for DPI or decryption. Furthermore, the metadata itself can also be signed or encrypted depending on the provenance of the data. As such, applying meta-tagging external to an encrypted packet, the payload would not be needed to be decrypted during transit of the packet to express end-to-end policy and routing decisions.
Owner:CISCO TECHNOLOGY INC

Multiple perspective cross-site scripting detection

An artificial intelligence ensemble has been developed for XSS detection with high accuracy. The artificial intelligence ensemble is created with a deep learning model and a machine learning model, each trained on different perspectives of token sequences extracted from packet payloads. Pre-processing of the raw data (i.e., the packet payload) generates a sequence of tokens that represents the payload and then generates a sequence of abstract tokens from the sequence of tokens. The deep learning model is trained on abstract token sequences to detect XSS from the perspective of patterns of token sequences. The other model is trained on pattern-based features extracted from the sequence of tokens to detect XSS from the perspective of features corresponding to characteristics of tokens sequences corresponding to heuristics gleaned for XSS. After each model is trained, the models are combined and deployed for inline detection of XSS in payload traffic from the different perspectives.
Owner:PALO ALTO NETWORKS INC

Zero-trust network access with user datagram protocol message forwarding

ActiveUS12676772B2Data packEngineering
Zero-trust network access (ZTNA) with user datagram protocol (UDP) message forwarding is disclosed. A forwarding rule is determined based on a destination address associated with a received data traffic packet formatted according to a first protocol (e.g., UDP). A bi-directional tunnel is created to forward the traffic based on the determined forwarding rule. A request is generated over a stream having a corresponding stream identifier within the bi-directional tunnel to establish a connection with a proxy device. The traffic packet payload formatted according to the first protocol is wrapped with at least the stream identifier. The wrapped data traffic packet is forwarded to a client device based on the determined forwarding rule to a destination device corresponding to the stream identifier.
Owner:FORTINET INC

A multifunctional vehicle-mounted TSN testing device and its testing method

ActiveCN121984635BTime domainConsistency test
This invention belongs to the field of automotive testing technology and discloses a multifunctional automotive TSN testing device and its testing method. The testing method includes: enabling all test ports to share the same time base; generating inbound and outbound timestamps for all incoming and outbound frames in a unified time domain; forming a port-level time-aware scheduling matrix; deeply binding the Layer 3 packet payload to a designated physical port and outputting test traffic through the timestamp injection unit of each port; recording the inbound and outbound timestamps of abnormal frames under the same time base; generating TSN consistency verification results based on the inbound and outbound timestamps; and performing cross-protocol delay consistency verification between automotive Ethernet and CAN / LIN. This invention achieves TSN function verification and cross-protocol delay consistency testing under a unified time base, improving the overall testing accuracy and consistency analysis capability in a multi-protocol automotive network environment.
Owner:HONGKE TECH CO LTD

A network congestion control method and system based on TCP message payload truncation

This invention discloses a network congestion control method and system based on TCP packet payload truncation. The method includes: a sending end sending an original TCP packet to a network device; when the network device detects impending congestion, it truncates the payload, retaining only the IP header and TCP header, setting a pre-defined bit in the first field to a truncation flag, and encoding the total length information of the original TCP packet; the network device modifies the Total Length field of the IP header of the TCP packet to the current actual length, calculates and updates the IP checksum, keeps the TCP header and its checksum unchanged, obtains a Cut packet, and sends it to the receiving end; after receiving the TCP packet, the receiving end, when checking that the pre-defined bit in the first field is a truncation flag, ignores TCP checksum errors, extracts the total length information of the original TCP packet, and constructs an ACK acknowledgment packet based on the total length information; after receiving the ACK acknowledgment packet, the sending end retransmits data of the corresponding length according to the total length information. This invention enables rapid congestion recovery of TCP packets.
Owner:YUNHE ZHIWANG (SHANGHAI) TECHNOLOGY CO LTD

Network interface device-based computations

Examples described herein relate to a network interface device. The network interface device can include circuitry that is to: receive a first packet comprising a first packet header and a first packet payload; receive multiple subsequent packets comprising multiple packet headers for respective multiple subsequent packets; update at least one of the multiple packet headers; and construct egress packets. In some examples, the egress packets include respective one of the multiple packet headers and the first packet payload.
Owner:INTEL CORP

Packet payload mapping for robust transmission of data

Systems and methods for packet payload mapping for robust transmission of data are described. For example, methods may include receiving, using a network interface, packets that each respectively include a primary frame and one or more preceding frames from the sequence of frames of data that are separated from the primary frame in the sequence of frames by a respective multiple of a stride parameter; storing the frames of the packets in a buffer with entries that each hold the primary frame and the one or more preceding frames of a packet; reading a first frame from the buffer as the primary frame from one of the entries; determining that a packet with a primary frame that is a next frame in the sequence has been lost; and, responsive to the determination, reading the next frame from the buffer as a preceding frame from one of the entries.
Owner:MIXHALO CORP +1

A malicious encrypted traffic classification method and system based on conversation spatio-temporal feature map

This invention proposes a method and system for classifying malicious encrypted traffic based on session spatiotemporal feature maps. The method includes: using a predefined sliding window to slide across a cleaned encrypted traffic session, extracting statistical features of the encrypted traffic session: packet size features, packet arrival time features, and packet payload α-Renyi entropy; using the packet size and packet arrival time features as the Y-axis and X-axis respectively, and mapping the packet payload α-Renyi entropy into grayscale values ​​to construct a session spatiotemporal feature map; inputting the session spatiotemporal feature map into a ResNet-50 model with a CBAM attention mechanism for malicious encrypted traffic classification. The proposed solution can adapt to different malicious encrypted traffic application scenarios, thereby achieving more efficient and accurate encrypted traffic classification.
Owner:CHINA ACADEMY OF INFORMATION & COMM