Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

8 results about "Protocol Status" patented technology

High-interaction sip honeypot system based on phased interaction control

This invention discloses a highly interactive SIP honeypot system based on phased interactive control, comprising: a message receiving module for receiving external SIP requests; a SIP interactive control module supporting multiple interaction modes and generating corresponding responses according to the current configuration mode; a session state machine module for maintaining the SIP session protocol state; a phase switching control module for maintaining phase state variables and dynamically selecting the interaction mode according to preset trigger conditions; and a recording and statistics module for recording request behavior characteristics, interaction logs, and switching logs. This invention achieves runtime schedulable management of interactive capabilities, enabling low-resource-consumption recording of scanning behavior and deep trapping of advanced attacks and collection of complete attack chain data, providing reliable data support for the detection of encrypted malicious traffic.
Owner:SUN YAT SEN UNIV

An edge intelligence-based low-altitude communication data anomaly detection system and method

PendingCN122293551ADigital dataAlgorithm
This invention belongs to the field of electronic digital data processing technology, specifically relating to a low-altitude communication data anomaly detection system and method based on edge intelligence. The system parses protocol fields from the raw bitstream of the low-altitude communication link layer, extracts type identifiers and payload lengths to construct a protocol state machine transition matrix, and utilizes a Long Short-Term Memory (LSTM) network to extract state transition probability sequence features. Geographically adjacent edge nodes are set as micro-federated learning groups. Each node, after training using local features, only uploads network gating weight parameters to its neighboring nodes for weighted aggregation to update its local model. An alarm is triggered when the real-time state transition probability sequence deviates from the normal transition matrix and exceeds a preset topology threshold. This invention can identify protocol state machine logic errors and transition anomalies, reducing the amount of communication data required for collaborative model updates between edge nodes.
Owner:SHENZHEN UNICAIR COMM TECH CO LTD

An IoT Fuzzy Testing Method Based on LLM Guidance and FSM Dynamic Inference

This invention discloses an IoT fuzzing method based on LLM-guided and FSM dynamic inference, belonging to the field of IoT network security and software testing technology. Addressing the problems of low coverage and inaccurate state machine inference in current IoT protocol fuzzing, this invention first constructs an initial FSM by combining IoT protocol specifications and captured traffic data. Then, it generates a large number of test cases through mutation of seed test cases for fuzzing testing. Features are extracted from device responses, and state identification is performed by calculating similarity. When a new state appears, the FSM and state fingerprint database are updated. When coverage becomes a bottleneck, LLM-guided path inference is used to generate extended sub-FSMs and test cases, which are then executed. The FSM is then corrected based on the test results. This invention enables high-precision automated construction of IoT protocol state FSMs, improving test coverage and enhancing the efficiency and accuracy of vulnerability discovery.
Owner:BEIJING UNIV OF POSTS & TELECOMM

Fine-grained security policy enforcement for applications

Embodiments obtain state elements based on application requests from a client. The state elements may be enqueued in a state queue associated with an application session for an application requests and the application requests may be forwarded to the application. Application responses from the application may be employed to perform further actions, including: obtaining message elements based on the application responses such that the message elements may be enqueued in a message queue associated in the application session; collecting a portion of the state elements in the state queue that may be associated the message elements; updating the portion of the state elements to advance a protocol state based on the message elements such that the application responses may be communicated to the client.
Owner:DELINEA INC

Intelligent detection and defense method and system for industrial control network attacks

The application provides an intelligent detection and defense method and system for industrial control network attacks, and relates to the technical field of industrial control network security. First, the communication data stream of the industrial control network is collected and divided into data frame units, from which the protocol state transition identifier sequence and the control instruction semantic identifier sequence are separated and extracted, and the corresponding control instruction semantic association path is constructed. Then, the constructed control instruction semantic association path is compared with the preset reference path to generate a deviation distribution description. Next, the deviation distribution description is subjected to spatiotemporal coupling disturbance positioning. Finally, a linkage defense instruction set is generated according to the positioning result and sent to the switching device to trigger the port shutdown and flow mirroring analysis operation. The application can actively and intelligently detect and defend industrial control network attacks.
Owner:CHENGDU KANGQIAO ELECTRONICS CO LTD

Intelligent detection and defense method and system for industrial control network attacks

ActiveCN122268687BPathPingData stream
The application provides an intelligent detection and defense method and system for industrial control network attacks, and relates to the technical field of industrial control network security. First, the communication data stream of the industrial control network is collected and divided into data frame units, from which the protocol state transition identifier sequence and the control instruction semantic identifier sequence are separated and extracted, and the corresponding control instruction semantic association path is constructed. Then, the constructed control instruction semantic association path is compared with the preset reference path to generate a deviation distribution description. Next, the deviation distribution description is subjected to spatiotemporal coupling disturbance positioning. Finally, a linkage defense instruction set is generated according to the positioning result and sent to the switching device to trigger the port shutdown and flow mirroring analysis operation. The application can actively and intelligently detect and defend industrial control network attacks.
Owner:CHENGDU KANGQIAO ELECTRONICS CO LTD

Propagating link aggregation control protocol status to single root input / output virtualization virtual function status

PendingUS20260149657A1TransmissionTrunkingEngineering
A system and method of propagating link aggregation control protocol status to single root input / output virtualization virtual function status. The method includes obtaining, by a processing device and using a relay agent executing on the processing device, state information from a Link Aggregation Control Protocol (LACP) speaker of a host machine. The method includes detecting, based on the state information, a communication failure between a physical function (PF) of a network adapter of a host machine and a first network switch of a plurality of network switches. The method includes identifying one or more computing environments that are communicatively coupled to the first network switch through a first virtual function (VF) associated with the PF. The method includes notifying the one or more computing environments about the communication failure by modifying a link state of the first VF.
Owner:RED HAT INC

Method, system, device and medium for MAC layer session asynchronous synchronization of wireless mesh networks

PendingCN122269429ASynchronisation arrangementError preventionWireless mesh networkEngineering
The application discloses a MAC layer session asynchronous synchronization method, system, device and medium of a wireless Mesh network, belongs to the wireless communication technical field, and aims to solve the technical problem of how to quickly and lightly realize MAC / RLC layer state synchronization, reduce high layer intervention, and accelerate link recovery. The technical scheme is as follows: the communication node applied to the Mesh network introduces a globally increasing session token in the MAC layer, and the token is transmitted between nodes through the MAC frame header or control message, so that the token transmission is realized; the receiving end can independently judge whether the local protocol state needs to be reset by comparing the token value, so that the quick synchronization is realized without the participation of the high layer in the complex coordination process; wherein, the node maintains the session token of at least one peer node in the Mesh network; and the session token management and initialization, the communication initiation and token updating, the state synchronization and resetting are as follows.
Owner:INSPUR INTELLIGENT TECHNOLOGY (JIANGSU) CO LTD