Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

40 results about "Packet payload" patented technology

In computing, a payload is the carrying capacity of a packet or other transmission data unit.

Storage type passive covert channel method and system using multiple protocols

ActiveCN120567449AKey distribution for secure communicationPayload (computing)Data pack
The invention discloses a storage type passive covert channel method and system using multiple protocols, a covert transceiver synchronization mechanism and a reversible data hiding mechanism are designed based on an m sequence, and the appointed m sequence is searched for a network data packet load through a sequence matching method to determine a covert carrier data packet. Calculating an allowable maximum matching fault-tolerant bit r to improve the matching probability of the m sequence; in the fault-tolerant bit r, the hidden sender allows the load to be modified so as to embed hidden data; a hidden receiver searches a hidden carrier through an agreed m sequence, extracts hidden data and recovers a data packet to realize reversible data hiding; a kernel module based on an Openwrt system is designed to realize covert channel construction, and the system can be deployed in equipment such as an intelligent router carrying the Openwrt system. According to the invention, while the capacity and the transmission rate of the covert channel are ensured, relatively low calculation storage resources are consumed, and the method has the anti-flow analysis capability.
Owner:BEIJING ELECTRONICS SCI & TECH INST

Wire-speed routing and policy enforcement without DPI or decryption

A system and computer-implemented method for routing an encrypted packet through a cloud enforcement network based on a metadata tag. The cloud enforcement network applies policy and routing attributions or tags outside of the encrypted packet payload in such a way as to not require an inner packet to first be decrypted. Traffic prioritization, data protection, and per application policies are achieved by using such metadata tags for internode routing without the need for DPI or decryption. Furthermore, the metadata itself can also be signed or encrypted depending on the provenance of the data. As such, applying meta-tagging external to an encrypted packet, the payload would not be needed to be decrypted during transit of the packet to express end-to-end policy and routing decisions.
Owner:CISCO TECHNOLOGY INC

Identifying malicious network traffic behavior using flow-based packet payload length aggregation

In example embodiments, techniques are provided for identifying malicious network traffic behavior by aggregating packet payload length of packets of a target packet flow that are part of same segments (e.g., same TCP segments) to produce segment payload lengths (e.g., TCP segment payload lengths), and using the segment payload lengths for identification. An encrypted payload analytics (EPA) engine of network detection and response (NDR) software may generate a target image from the segment payload lengths by organizing data points based on the segment payload lengths into a matrix, and converting the data points in the matrix into pixels of the target image. The EPA engine may then apply the target image to a trained machine learning (ML) model to determine a likelihood network traffic behavior is malicious network traffic behavior. In response to the likelihood, the NDR software may perform a remedial action.
Owner:SOPHOS LTD

High-speed data packet generator

An embodiment may involve executing a set of instructions, where the set of instructions define how to generate outputs that represent one or more data packets, and where segments of the outputs are copied from first parts of respective instructions in the set of instructions. The embodiment may further involve: retrieving, from a plurality of registers, a data packet header; retrieving, from the plurality of registers, a first part of a data packet payload and an increment value; applying the increment value to the first part of the data packet payload to generate a second part of the data packet payload; storing, in the plurality of registers, the first part of the data packet payload with the increment value applied; and providing, as additional segments of the outputs, the data packet header, the first part of the data packet payload, and the second part of the data packet payload.
Owner:FMAD ENG (SNG) PTE LTD

Apparatus and method for coding of radio programs and multimedia services in television broadcasts

FIG. 1 illustrates an apparatus for decoding according to an embodiment. The apparatus comprises an interface for receiving a plurality of ATSC Link-layer Protocol packets each of which comprising a packet header and a packet payload encapsulating digital content. Moreover, the apparatus comprises a decoding unit. In a first embodiment, the digital content being encapsulated within the packet payload of each of one or more ATSC Link-layer Protocol packets of the plurality of ATSC Link-layer Protocol packets comprises digital radio content, and / or a Distribution and Communications Protocol packet or a portion thereof, and / or Unified Speech and Audio Coding content or extended High Efficiency Advanced Audio Coding content, and / or Journaline content. The decoding unit is configured to decode the packet payload of each one of at least one ATSC Link-layer Protocol packet of the one or more ATSC Link-layer Protocol packets to obtain the digital content of said one of the at least one ATSC Link-layer Protocol packet.
Owner:FRAUNHOFER GESELLSCHAFT ZUR FORDERUNG DER ANGEWANDTEN FORSCHUNG EV

Conditional automatic gain control on single station piconet for bluetooth receiver based on connection state

The present invention relates to a method and apparatus for reducing power consumption in a receiver of a time slotted communication system. An RF front end has power applied after the start of a preamble or after the start of a header, or upon the start of a packet payload based on connection status, signal level, and interference level. Where the signal level is constant, the communication system is in a connected state, and the interference level is low, the system bypasses packet header destination address matching, or optionally, uses only the least significant bits of the header destination address for matching purposes.
Owner:SILICON LABORATORIES INC

Gapless Asynchronous Data Recording

An aircraft recording system provides gapless asynchronous data recording. A data acquisition system is connected to a data ingestion interface, such that data acquisition system captures avionics data. An endpoint is associated with the aircraft data acquisition system and located remotely from the aircraft, which persists the plurality of events. An asynchronous messaging platform is provided that is adapted to digest and publish a plurality of packet payload words. A data file caching system is provided that is adapted to cache aircraft data files by ingesting data from the asynchronous messaging platform, writing the ingested data to a cache buffer, and based on a determination that a file descriptor is available, flushing the cache buffer to the file descriptor. A data file persistence system persists the aircraft data files by claiming the file descriptor, flushing the cache buffer to physical storage, and releasing the file descriptor.
Owner:TEXTRON INNOVATIONS INC

Method and apparatus to perform operations on multiple segments of a data packet in a network interface controller

A stacked memory such as a high bandwidth memory (HBM) with a wide data path is used by a streaming pipeline in a network interface controller to buffer segments of a data packet to allow the network interface controller to perform operations on the packet payload. The headers and packet payload can be scanned and classified concurrently with the buffered payload parsed in parallel.
Owner:INTEL CORP

Telemetry restriction mechanism

An apparatus comprising a network interface card (NIC), including packet processing circuitry to determine whether the NIC is to operate according to a first telemetry protection mode to prevent copying of packet data payloads for telemetry or a second telemetry protection mode to enable copying of packet payloads for telemetry.
Owner:INTEL CORP

Apparatus and method for encoding, decoding, transmitting and signaling of flags and icons in television and radio broadcasts

Figure 1 shows an apparatus for decoding according to an embodiment. The apparatus comprises an interface (110) for receiving a plurality of ATSC link layer protocol packets, each ATSC link layer protocol packet comprising a packet header and a packet payload, where the packet payload of an ATSC link layer protocol packet of the plurality of ATSC link layer protocol packets comprises one or more flagged and / or one or more icons of image data. Furthermore, the apparatus comprises a decoding unit (120) for decoding a packet payload of the ATSC link layer protocol packet to obtain image data.
Owner:FRAUNHOFER GESELLSCHAFT ZUR FORDERUNG DER ANGEWANDTEN FORSCHUNG EV

Encrypted traffic classification method, device and medium based on unbalanced data

The present invention provides an encrypted traffic classification method, device and medium based on unbalanced data, the method comprising: performing data packet composite feature extraction and data packet payload feature extraction after segmentation and filtering of the original traffic; setting a baseline after traffic data analysis, sending traffic below the baseline value into the WGAN‑GP network for training, and sending traffic above the baseline value into the OSS algorithm model for downsampling to obtain a balanced data set; dividing the data into a test set and a training set according to a preset ratio, and training the training set through a multi-level spatiotemporal feature extraction model; and then processing the training set through a preset feature fusion module and classification module to obtain a trained multi-level spatiotemporal feature extraction model. This application takes into account the tcp options field in the TCP packet header during data processing to achieve data balance through two sampling methods. The multi-level spatiotemporal feature extraction model adopted enables the model to pay more attention to feature information with discriminability, thereby promoting classification results.
Owner:GUANGZHOU UNIVERSITY

Systems and methods for processing multiple IP packet types in a network environment

Systems, devices, and methods include receiving, at a first physical port of a network appliance, an IP type A packet. The IP type A packet includes a packet header and a packet payload, and the packet header includes an IP type A destination address. The methods further include determining that the IP type A packet is destined for an IP type B address space; routing the IP type A packet to a virtual port; receiving, the IP type A packet by the virtual port; based at least in part on being received by the virtual port, converting the IP type A address to an IP type B address; and formatting an IP type B packet including an IP type B header and the packet payload from the IP type A packet, wherein the IP type B header includes the IP type B address.
Owner:FORTINET INC

A traffic identification method and device, a storage medium and a computer program product

The application provides a traffic identification method and device, a storage medium and a computer program product, which include: performing feature extraction on first data traffic to obtain a first type of feature vector; the first type of feature vector includes a data packet payload type of feature vector and / or a congestion window type of feature vector; and the first type of feature vector is used to identify the first data traffic to obtain a traffic type of the first data traffic; the traffic type includes an anonymous proxy type and / or a general type. The accuracy of traffic identification can be improved.
Owner:CHINA MOBILE (SUZHOU) SOFTWARE TECH CO LTD +1

Packet forwarding method, apparatus, and system

This application discloses a packet forwarding method, an apparatus, and a system, and belongs to the field of communication technologies. The method includes: A first node receives a first packet. The first node sends a second packet to a second node based on the first packet, where a source address of the second packet is obtained by translating a source address of the first packet, a destination address of the second packet is a destination address of the first packet, a packet payload of the second packet is a packet payload of the first packet, the second packet further includes a session identifier, and the session identifier is used by the second node to forward the second packet.
Owner:HUAWEI TECH CO LTD

Equipment discovery method and system based on hardware buffer, terminal and storage medium

The invention discloses an equipment discovery method and system based on a hardware buffer area, a terminal and a storage medium, and the method comprises the steps: obtaining the equipment information of a server, carrying out the message packaging of the equipment information, obtaining a discovery message, writing the payload of the discovery message into the hardware buffer area of the server, and obtaining the payload of a sent message; performing first message header packaging processing on the message sending payload according to the local port number of the server to obtain a target discovery message, and sending the target discovery message to the client to obtain a server broadcast result; obtaining a response message payload in a hardware buffer area of the client, and performing second message header packaging processing on the response message payload to obtain a target response message; and sending the target response message to the server according to the server broadcast result to obtain a client response result. According to the invention, the sending and response of the CoAP message in the soft bus discovery process are completed through hardware, and the CPU occupancy rate in the soft bus discovery process is reduced.
Owner:深圳开鸿数字产业发展有限公司

Identifying a maximum segment size (MSS) corresponding to a network path

Techniques are disclosed for identifying a maximum segment size (MSS) for a path. For example, a first router includes a routing engine and a packet forwarding engine. The routing engine is configured to identify a path maximum transmission unit (MTU) corresponding to a path between the first router and a second router; and identify a maximum packet overhead size corresponding to a session between a first client device and a second client device over the path between the first router and the second router. Additionally, the routing engine is configured to calculate, based on the path MTU and the maximum packet overhead size, a path maximum segment size (MSS), wherein the path MSS represents a maximum packet payload size corresponding to the path; and control the packet forwarding engine to output information indicative of the path MSS.
Owner:JUNIPER NETWORKS INC

Telemetry reporting in vehicle super resolution systems

In one embodiment, a processor of a vehicle detects a difference between a physical characteristic of the vehicle predicted by a first machine learning-based model and a physical characteristic of the vehicle indicated by telemetry data generated by a sub-system of the vehicle. The processor forms a packet payload of an update packet indicative of the detected difference, based in part on a relevancy of the physical characteristic to the first machine learning-based model. The processor applies a synchronization strategy to the update packet, to synchronize the update packet with a second machine learning-based model executed by a receiver. The processor sends the update packet to the receiver via a network, to update the second machine learning-based model.
Owner:CISCO TECHNOLOGY INC

Robust broadcast via relayed retransmission

Systems and methods for broadcasting wireless data via one or more retransmission schemes to increase the packet reception in a wireless system. One or more devices of the system are configured to listen for an initial data packet from a source device. Should one or more devices successfully receive the initial packet, each device that received the packet can unconditionally retransmit a copy of the payload of the initial packet such that any device that failed to receive the initial packet payload has an opportunity to receive it during the respective retransmissions. Similarly, each device of the system can send acknowledgements to the other system devices that indicate whether they received the initial packet. Should one or more of the devices successfully receive the initial packet, the devices can conditionally retransmit a copy of the missing payload when one or more devices indicates they have failed to receive it.
Owner:BOSE CORP

Hardware-based accelerating apparatus for nvme over fabrics target, operation method thereof, and system including the same

A non-volatile memory express over fabrics (NVMe-oF) target accelerating apparatus according to an embodiment of the present disclosure includes: a first offload engine configured to offload a network stack to compute a first network packet and output a first packet payload; and a second offload engine configured to offload an NVMe-oF stack to compute the first packet payload and output data having a first buffer address when the first packet payload is of a first type.
Owner:MANGOBOOST INC

Flexible configurable data analysis device and method based on FPGA

The invention relates to the technical field of network message analysis, and discloses a flexible configurable data analysis device and method based on an FPGA (Field Programmable Gate Array), which can adapt to multi-protocol message analysis by storing a plurality of message analysis templates through an RAM (Random Access Memory) and matching a search module with message frame identification information, and break through the limitation that the existing FPGA analysis mostly aims at a single protocol and is poor in universality. Besides, the analysis module can analyze sub-data in the message load according to the matching template without depending on upper software, so that the problems of low efficiency and poor real-time performance caused by the fact that an existing FPGA only analyzes a frame header fixed field and load data needs to be processed by software are solved; therefore, the flexible and efficient application requirements of a multi-bus heterogeneous high-speed network system on multi-type data processing are met.
Owner:XIAN MICROELECTRONICS TECH INST

Conditional automatic gain control with partial address detection for Bluetooth receiver based on connection state

The present invention relates to a method and apparatus for reducing power consumption in a receiver of a time slotted communication system. An RF front end has power applied after the start of a preamble or after the start of a header, or upon the start of a packet payload based on connection status, signal level, and interference level. Where the signal level is constant, the communication system is in a connected state, and the interference level is low, the system bypasses packet header destination address matching, or optionally, uses only the least significant bits of the header destination address for matching purposes.
Owner:SILICON LABORATORIES INC

Selection of candidate data flows for evaluating performance metrics using passive measurements

Aspects of the subject disclosure may include, for example, identifying a flow of data packets between first and second network addresses of a network, with each packet including respective header and payload portions. The identified flow of data packets is monitored over a number of sample periods to obtain a number of monitored results. A data-flow activity record is generated, having a number of symbols corresponding to the number of monitored results, the symbols including an active symbol value indicative of a presence of an exchange of data and an idle symbol value indicative of an absence of an exchange of data. A suitability of the identified data flow is inferred for estimating a throughput of the network according to the data-flow activity record without interpreting contents of each respective packet payload portion. Other embodiments are disclosed.
Owner:AT&T MOBILITY II LLC +1

A method, system, device and medium for data link layer handover

The application discloses a data link layer switching method, system, device and medium, and relates to the technical field of communication; the method comprises the following steps: in an error correction coding system of a given channel error probability, a wireless channel state is monitored, and an optimal packet length corresponding to a maximum wireless channel throughput is calculated; a data frame of a fiber channel is split based on the optimal packet length, and a wireless data packet payload is obtained; the wireless data packet payload is reconstructed, and a data frame meeting a wireless channel transmission standard is obtained. The application aims to provide a data link layer switching method, system, device and medium, adopts a "direct splitting-repackaging" conversion mode, and effectively improves the switching efficiency of a special network communication data link layer channel.
Owner:BEIJING UNIV OF POSTS & TELECOMM +1

Probe-based virtual network sensitive data traffic detection

The technology disclosed relates to detection of data traffic in computing environments, such as cloud environments. Example systems and methods detect a plurality of workloads in a virtual network in a computing environment and deploy a plurality of probe agents to the plurality of workloads. Each respective probe agent detects network traffic on a respective workload of the plurality of workloads, scans a data packet that is at least one of sent or received by the respective workload, generates a data classification relative to the data packet, and generates a scan result that includes packet payload information and an indication of the data classification. The scan results are received from the plurality of probe agents and a computing action is performed based on scan results.
Owner:PROOFPOINT INC

Statistical behavior sequence-based encrypted malicious traffic characterization method and device

This application provides a method and apparatus for characterizing encrypted malicious traffic based on statistical behavior sequences. The method includes: acquiring and preprocessing a network traffic capture file containing encrypted malicious traffic to obtain an encrypted bidirectional stream with an unparseable payload and anomaly-removed data; extracting flow-level statistical features based on the stream, constructing a standardized behavior sequence through channel clustering and sequence length standardization; performing self-supervised joint training on the encoding and decoding models, optimizing the parameters, and then determining the encoding model as the feature extraction model; constructing the standardized behavior sequence of the traffic to be detected, inputting it into the model to output a behavior representation vector, then inputting it into a machine learning model to output the identification result representing the malicious attributes, category, or abnormal state of the traffic to be detected. This method eliminates the need to parse the packet payload, accurately characterizes the overall behavior pattern of encrypted traffic, improves the stability and generalization of the representation vector, reduces sample labeling dependence, and efficiently adapts to downstream encrypted traffic analysis and detection tasks.
Owner:CHONGQING UNIV

Method and apparatus to perform operations on multiple segments of a data packet in a network interface controller

PendingUS20260205529A1Data packPathPing
A stacked memory such as a high bandwidth memory (HBM) with a wide data path is used by a streaming pipeline in a network interface controller to buffer segments of a data packet to allow the network interface controller to perform operations on the packet payload. The headers and packet payload can be scanned and classified concurrently with the buffered payload parsed in parallel.
Owner:INTEL CORP

Zero-trust network access with user datagram protocol message forwarding

Zero-trust network access (ZTNA) with user datagram protocol (UDP) message forwarding is disclosed. A forwarding rule is determined based on a destination address associated with a received data traffic packet formatted according to a first protocol (e.g., UDP). A bi-directional tunnel is created to forward the traffic based on the determined forwarding rule. A request is generated over a stream having a corresponding stream identifier within the bi-directional tunnel to establish a connection with a proxy device. The traffic packet payload formatted according to the first protocol is wrapped with at least the stream identifier. The wrapped data traffic packet is forwarded to a client device based on the determined forwarding rule to a destination device corresponding to the stream identifier.
Owner:FORTINET INC

Wire-speed routing and policy enforcement without DPI or decryption

A system and computer-implemented method for routing an encrypted packet through a cloud enforcement network based on a metadata tag. The cloud enforcement network applies policy and routing attributions or tags outside of the encrypted packet payload in such a way as to not require an inner packet to first be decrypted. Traffic prioritization, data protection, and per application policies are achieved by using such metadata tags for internode routing without the need for DPI or decryption. Furthermore, the metadata itself can also be signed or encrypted depending on the provenance of the data. As such, applying meta-tagging external to an encrypted packet, the payload would not be needed to be decrypted during transit of the packet to express end-to-end policy and routing decisions.
Owner:CISCO TECHNOLOGY INC

Multiple perspective cross-site scripting detection

An artificial intelligence ensemble has been developed for XSS detection with high accuracy. The artificial intelligence ensemble is created with a deep learning model and a machine learning model, each trained on different perspectives of token sequences extracted from packet payloads. Pre-processing of the raw data (i.e., the packet payload) generates a sequence of tokens that represents the payload and then generates a sequence of abstract tokens from the sequence of tokens. The deep learning model is trained on abstract token sequences to detect XSS from the perspective of patterns of token sequences. The other model is trained on pattern-based features extracted from the sequence of tokens to detect XSS from the perspective of features corresponding to characteristics of tokens sequences corresponding to heuristics gleaned for XSS. After each model is trained, the models are combined and deployed for inline detection of XSS in payload traffic from the different perspectives.
Owner:PALO ALTO NETWORKS INC