Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

381 results about "Source address" patented technology

Public opinion home address standardization method and system

The invention discloses a public opinion home address standardization method and system, and the method comprises the following steps: S1, obtaining and processing multi-source address original data to obtain an address data block, processing the data block based on a pre-trained text embedding model to obtain a corresponding semantic vector, and storing the address data block and the corresponding semantic vector, establishing a multi-source address knowledge base; s2, processing public opinion text data through the text embedding model to obtain a query vector of the public opinion text data; s3, querying the multi-source address knowledge base based on the query vector to obtain a plurality of address data blocks related to the query vector; and S4, constructing a cue word template based on the public opinion text data and the address data blocks, and inputting the cue word template into a large language model to perform public opinion attribution address standardization analysis.
Owner:XIAMEN MEIYABAIKE INFORMATION SECURITY RES INST CO LTD

Industrial AI model security management and control system

The invention discloses an industrial AI model security management and control system, and the system comprises a permission granularity control module which is used for declaring a required minimum permission set when an AI model is registered, and generating a dynamic access token containing a permission list for the model; wherein the identifier is a resource operation authority identifier; the permission mapping table module is used for maintaining a mapping relation from the resource operation permission identifier to the actual resource address; the access verification module is used for verifying the validity and the permission range of the dynamic access token when the model requests the system resources, and refusing the non-permission access; and the dynamic permission recovery module is used for removing the target permission identifier in the authorized permission set of the model in real time to update the permission set, marking that the old token is invalid, and generating a new token containing a timestamp based on the new permission set. According to the method, the industrial AI model can be effectively prevented from abusing the authority, and the system security is improved.
Owner:QKM TECH (DONG GUAN) CO LTD

Data loading method and device, storage medium and equipment

The invention relates to a data loading method and device, a storage medium and equipment, the method is used in an intelligent calculation data processing system comprising a host, a CSD and a SmartNIC, and a PCIe P2P data path is established between the CSD and the SmartNIC; the method comprises the steps that a host generates collaborative descriptors and respectively issues the collaborative descriptors to a CSD and a SmartNIC; the CSD reads source data from a storage medium according to source address information in the collaborative descriptor, executes a processing operation corresponding to the first operator identifier to obtain intermediate data, and directly transmits the intermediate data to a storage area of the SmartNIC through a PCIe P2P data path; and the SmartNIC executes a processing operation corresponding to the second operator identifier on the intermediate data to obtain target data, and transmits the target data to the computing device according to the target address information in the collaborative descriptor.
Owner:GUANGDONG UCAP INTERNET INFORMATION TECH

Low-latency redundant communication protocol based on improved prp

PCT designated stageWO2026020674A1Error preventionFrame sequenceIp address
Provided in the present invention is a low-latency redundant communication protocol based on an improved PRP, which protocol is compatible with the PRP standard of IEC 62439-3-2016 and operates at a link layer. Two redundant ports are connected to an upper-layer protocol by means of a link redundancy entity, and are transparent to the upper-layer protocol; a network-end node has two or three redundant network ports, which are respectively connected to networks that are independent of each other and have the same topological structure, and the networks operate in parallel; and network ports belonging to PRP-supporting end nodes are configured with the same IP address and MAC address. The improvements in the present invention are as follows: a redundancy discarding algorithm is modified to a mode of directly uploading a first-arriving communication frame to an application layer; {source IP address, source MAC address and frame sequence number} is used as a determination condition for a redundant frame; by means of file pre-configuration, the IP address of a single-network-port node in a network is written into a configuration file in advance in a node; and statistics for the number of network port link up / down events, out-of-receive-window statistics, statistics for non-sequential frame sequence numbers, and statistics for the number of out-of-sync redundant frames are added.
Owner:BEIJING AEROSPACE AUTOMATIC CONTROL RES INST

Methods, systems, and computer readable media for providing stream control transmission protocol (SCTP) multihoming between a kubernetes environment and a non-kubernetes environment

A method for providing stream control transmission protocol (SCTP) multihoming between a Kubernetes environment and a non-Kubernetes environment includes receiving, at an SCTP multihoming router (SMR) deployed as a pod within the Kubernetes environment and from a client in the non-Kubernetes environment, an SCTP INIT message for establishing a multi-homed SCTP association between first and second Internet protocol (IP) addresses of the client and first and second local IP addresses of the SMR. The first and second local IP addresses of the SMR are added to an SCTP header of the SCTP INIT message. Source and destination network address translations (NATs) are performed to change a source IP address and a destination IP address in an IP header of an IP datagram carrying the SCTP INIT message to a third local IP address of the SMR and a service IP address of a service in the Kubernetes environment, respectively.
Owner:ORACLE INT CORP

Network security data analysis method and system based on large model, and medium

The invention relates to the technical field of network security, in particular to a network security data analysis method and system based on a large model and a medium. According to the technical scheme, the network security data analysis method based on the large model comprises the following steps: acquiring a multi-source heterogeneous log in real time from a firewall, an intrusion detection system or an intrusion prevention system, a Web application firewall, a server operating system and a service application through a distributed acquisition agent; performing data cleaning on the original log: removing repeated entries, filling missing fields, unifying a timestamp format, and extracting key structured fields including a source IP address, a target IP address, an operation type and a user ID; and performing deep semantic analysis on the cleaned log by using a pre-training large model based on a Transform architecture, and generating vectorized feature representation fused with context semantics. The semantic understanding accuracy of security terminologies is remarkably improved, and the misjudgment defect caused by domain knowledge deficiency of a traditional model is thoroughly overcome.
Owner:STATE GRID HEBEI ELECTRIC POWER CO LTD +1

An object processing method and apparatus, an electronic device, and a storage medium

The application discloses an object processing method and device, electronic equipment and storage medium, and relates to the technical field of network. An object sharing request of an object sharing initiator is received, the object sharing request carries identification information of an object, content information of the object is obtained based on the identification information, the content information of the object is processed by format conversion by using an object processing system, resource address generation and storage processing are performed, activity information is returned to an object sharing acquirer in response to an activity information acquisition request sent by the object sharing acquirer, and a resource address of the object is returned to the object sharing acquirer in response to an object acquisition request sent by the object sharing acquirer. The above method can split the activity information and the content information of the object after format conversion into two data packets to be delivered, reduce the size of a single data packet, and reduce the possibility of being discarded by a long link system.
Owner:TENCENT TECH (CHENGDU) CO LTD

Flow transparent dyeing and full-link dynamic tracking method based on inner layer source MAC address in private cloud VPC environment

The invention discloses a traffic transparent dyeing and full-link dynamic tracking method based on an inner layer source MAC address in a private cloud VPC environment. According to the method, an implicit metadata channel is constructed by utilizing the characteristic that an inner-layer source MAC address does not participate in addressing in Overlay transmission, and tracking is realized through three steps: entry dyeing: replacing the inner-layer source MAC of an original message with a dyeing MAC containing identity information and a dynamic state area on a source end vSwitch data plane; dynamic updating and abnormal marks are transmitted, the intermediate node progressively increases a hop count counter to record a path, and event codes are modified and mirrored and reported when abnormity occurs; and outlet restoration: the target end vSwitch restores the real MAC based on the mapping table and connection tracking, and application transparency is guaranteed. The method has the advantages of zero load, zero overhead, full-link deep perception, high transparency, strong compatibility and the like, and the forwarding path and the real-time state in the virtual network can be accurately obtained on the premise of not invading tenant application.
Owner:CHINA ELECTRONICS CLOUD DIGITAL INTELLIGENCE TECH CO LTD

Vulnerability scanning and attack detection methods, model training methods and devices

This application provides a vulnerability scanning attack detection method, model training method, and apparatus. The method includes: acquiring access logs and extracting key field information from the access logs; generating feature vectors based on the key field information; inputting the feature vectors into a vulnerability scanning attack detection model to obtain the analysis results output by the vulnerability scanning attack detection model; wherein, the vulnerability scanning attack detection model is obtained by pre-generating corresponding training feature vectors based on training logs, and training the model using the training feature vectors and labels used to characterize whether the training source IP address corresponding to the training logs exhibits vulnerability scanning attack behavior; the analysis results are used to characterize whether the behavior corresponding to the access logs is a vulnerability scanning attack behavior. This application improves the accuracy of vulnerability scanning attack behavior identification by analyzing the feature vectors of access logs using a machine learning model.
Owner:QI-ANXIN LEGENDSEC INFORMATION TECH (BEIJING) INC +1

A method and device for forwarding a message in a resilient packet ring

ActiveCN115914116BResilient Packet RingEngineering
The application provides a resilient packet ring message forwarding method and device. The method comprises the following steps: receiving a cross-device link aggregation announcement message through a resilient packet ring network; allocating a RPR cross-device link aggregation identifier for a RPR MAC address of a member node carried by the cross-device link aggregation announcement message; receiving an Ethernet unicast message; when a destination MAC address of the received Ethernet unicast message corresponds to a RPR cross-device link aggregation identifier; performing hash calculation according to the Ethernet unicast message, taking a RPR MAC address of a member node corresponding to a result of the hash calculation as a destination RPR MAC address, taking a RPR MAC address of the current node as a source RPR MAC address, and encapsulating the received Ethernet unicast message into a RPR unicast message; and sending the RPR unicast message through an out port of a shortest RPR path reaching the destination RPR MAC address of the RPR unicast message.
Owner:新华三技术有限公司合肥分公司

Communication method, device, system and storage medium

PCT designated stageWO2025236308A9Connection managementData packTelecommunications
Embodiments of the present disclosure relate to the technical field of communications. Disclosed are a communication method and apparatus and a computer readable storage medium. The communication method comprises: sending first information to a second network function, wherein the first information comprises a first processing rule for determining a received data packet; and receiving second information sent by the second network function, wherein the second information comprises a first data packet conforming to the first processing rule or first address information corresponding to the first data packet, and the first address information is used for identifying source address information of the first data packet.
Owner:BEIJING XIAOMI MOBILE SOFTWARE CO LTD

Network anomaly monitoring method, device and program product based on traffic fingerprint learning

The present disclosure belongs to the technical field of network security, and particularly relates to a network anomaly monitoring method, device and program product based on traffic fingerprint learning, which comprises the following steps: extracting metadata irrelevant to encryption of a target network; the metadata comprises five-tuple, timestamp, length and protocol flag information of a data packet; the metadata is aggregated with a source IP address as a primary key to define a network entity; session feature extraction is performed on a session of the target network entity and other network entities; the extracted session features comprise timing features, operation sequence features and scale distribution features; the operation sequence features comprise Shannon entropy of a continuous request and response type pair; an action fingerprint of the target network entity is constructed according to the session features; and whether the target network and the target network entity are abnormal is judged according to a deviation degree of a current action fingerprint of the target network entity and a fingerprint baseline. The present disclosure can realize accurate identification of network anomalies.
Owner:WUHAN COLLEGE

Method and device for measuring inconsistency of inbound source address verification filtering

The invention relates to the technical field of network measurement, in particular to a method and a device for measuring inconsistency of inbound source address verification filtering, and the method comprises the following steps: fixing all flow identifiers in ICMP (Internet Control Message Protocol) unreachable information messages so as to execute multiple rounds of ICMP unreachable information measurement on each measurable target to obtain a first measurement result; changing a preset flow identifier in the ICMP unreachable message so as to execute multiple rounds of ICMP unreachable message measurement on each measurable target to obtain a second measurement result; and determining whether the load balancing causes instability of the inbound source address verification measurement according to the first measurement result and the second measurement result. Therefore, the problem that the traditional method cannot judge whether the observed filtering inconsistency originates from the real strategy difference in the network or the detection message is distributed to different inlet paths in a load balancing manner is solved.
Owner:TSINGHUA UNIVERSITY

Performance analysis method and device for source address verification, equipment and storage medium

The invention provides a performance analysis method and device for source address verification, equipment and a storage medium, and relates to the technical field of network security. The method comprises the following steps: receiving a source address verification processing program written through a description language; loading an algorithm configuration file; wherein the algorithm configuration file at least comprises a performance model configured for a plurality of preset algorithms, and the performance model is used for calculating the consumed time length of the operation statement based on the operand length of each operation statement; based on the source address verification processing program and the performance model, calculating the consumed time length of each operation statement; and generating a performance analysis report of the source address verification processing program according to the time-consuming duration of all the operation statements in the source address verification processing program. According to the embodiment of the invention, automatic and theoretical performance analysis can be carried out on the source address verification processing flow based on the formalized description language and the predefined algorithm configuration file under the condition of separating from the dependence of specific hardware.
Owner:TSINGHUA UNIVERSITY

Data forwarding method based on outer-layer VLAN tag, network equipment and storage medium

The invention relates to the technical field of optical fiber access networks, in particular to a data forwarding method based on an outer layer VLAN label, network equipment and a storage medium, the method is applied to the network equipment comprising an optical line terminal OLT chip and a switching chip, and the method comprises the following steps: in an uplink direction, obtaining a first GEMPORT ID corresponding to a data stream from an optical network unit ONU through the OLT chip; based on the first GEMPORT ID, generating a first outer layer VLAN label of the uplink data packet; combining the uplink data packet with the first outer-layer VLAN label to form a first double-layer VLAN message; the first double-layer VLAN message is sent to a switching chip; the method comprises the steps of receiving a first double-layer VLAN message through a switching chip, analyzing a first outer-layer VLAN label in the first double-layer VLAN message to obtain a first GEMPORT ID, and creating table items in an initial L2 forwarding table based on the first GEMPORT ID and a source MAC address of the first double-layer VLAN message to obtain an updated L2 forwarding table. According to the invention, the forwarding table pressure of the OLT chip is reduced by using the L2 learning mechanism of the switching chip.
Owner:HANGZHOU RUNZHOU FIBER TECH CO LTD

A message forwarding method and device

This application provides a packet forwarding method and device. The method involves: determining whether to perform Layer 3 forwarding based on the destination MAC address of the Ethernet packet (which is the gateway MAC address); searching the link layer address mapping table based on the destination IP address of the inner IP packet of the Ethernet packet; obtaining a new destination MAC address from the matching link layer address mapping table entry when a matching entry for the destination IP address is found; searching the MAC address table based on the new destination MAC address; obtaining the outgoing port and outgoing VLAN from the matching entry when a matching entry for the new destination MAC address is found; modifying the destination MAC address, source MAC address, and incoming VLAN of the Ethernet packet to the new MAC address, gateway MAC address, and outgoing VLAN, respectively; and sending the modified Ethernet packet through the outgoing port.
Owner:NEW H3C TECH CO LTD

Multi-chip addressing control method, electronic device, storage medium, and program product

PendingCN122285575AAchieving synergyRealize continuous undertaking functionSynchronous controlAddress control
This invention relates to the field of peripheral control technology, specifically to a multi-chip addressing control method, electronic devices, storage media, and program products. The method includes: receiving a control request and generating a command packet containing a source address, a target address, and command data; splitting the command packet and sending it to different target chips under a synchronous control request, and sending the command packet according to the target address under an asynchronous control request; forwarding the command to the master control chip when the slave chip lacks execution capability; executing the command packet when both the master and slave chips receive the same command data; receiving a response packet and determining the responding chip based on the source address, and outputting the control result. This invention enables directional control, collaborative execution, and response differentiation in multi-chip peripherals.
Owner:SHENZHEN XINGSHAN YUEDONG TECH CO LTD

Equipment identification method and device, equipment, medium and program product

The embodiment of the invention provides an equipment identification method and device, equipment, a medium and a program product. The identification method is applied to a gateway, and comprises the following steps: acquiring Coap messages requested by a plurality of discovery devices and / or responded by the plurality of discovery devices; equipment characteristics of the multiple Coap messages and corresponding source MAC addresses are extracted, and the source MAC addresses and the equipment characteristics are in one-to-one or one-to-many correspondence; calculating the similarity between the device features of the same feature type corresponding to different source MAC addresses; and determining different source MAC addresses belonging to the same to-be-identified equipment based on the similarity. The identification information of the equipment can be accurately and efficiently identified. According to the method, the multiple virtual MAC addresses of the same to-be-recognized device are recognized by extracting the device features and calculating and processing the device features, and the virtual MAC addresses are aggregated into one device, so that the detail features of the terminal device are enriched, the complete portrait of the to-be-recognized device is established, and the device is managed more effectively based on the constructed comprehensive and dynamic device digital identity.
Owner:CHINA MOBILEHANGZHOUINFORMATION TECH CO LTD +1

Network anomaly monitoring method and device based on flow fingerprint learning, and program product

The invention belongs to the technical field of network security, and particularly relates to a network anomaly monitoring method and device based on flow fingerprint learning and a program product, and the method comprises the steps: extracting encryption-independent metadata of a target network; the metadata comprises a quintuple of a data packet, a timestamp, a length and protocol mark information; aggregating the metadata by taking a source IP address as a main key, and defining a network entity; performing session feature extraction on sessions between the target network entity and other network entities, the extracted session features including a time sequence feature, an operation sequence feature and a scale distribution feature; wherein the operation sequence feature comprises the Shannon entropy of a continuous request and response type pair; constructing a behavior fingerprint of the target network entity according to the session feature; and judging whether the target network and the target network entity are abnormal or not according to the deviation degree of the current behavior fingerprint of the target network entity and the fingerprint baseline. According to the invention, accurate identification of network anomalies can be realized.
Owner:WUHAN COLLEGE

A method of processing and a routing device for controlling a session

The specification provides a processing method and a routing device for controlling a session, the method comprising: an NPU receiving a first control packet, converting a first source address in the first control packet into a second source address according to a network address translation (NAT) rule, the NPU uploading the first control packet and the second source address to a CPU kernel state, the NPU receiving a second control packet sent by the CPU kernel state, converting a first destination address in the second control packet into a second destination address according to the NAT rule, the NPU uploading the second control packet and the second destination address to the CPU kernel state, and the NPU receiving a takeover notification sent by the CPU kernel state and a control packet converted by a user state to process a session. By the method, the technical problem that the processing logic is limited by the NPU hardware and that the IP can be converted only once in each flow processing and the twice NAT conversion in the NAT hairpin scene cannot be implemented is avoided.
Owner:NEW H3C TECH CO LTD

Method for accessing home intranet, edge access gateway, system, medium and product

The invention discloses a method for accessing a home intranet, an edge access gateway, a system, a medium and a product. The method comprises the following steps: acquiring information of a home terminal obtained by finishing Ethernet point-to-point protocol dialing; an access message sent by the cloud core network equipment is received, and when it is judged that the access message meets a preset condition according to an inner-layer message source IP address in the access message, an inner-layer destination MAC address and a destination IP address in the access message are analyzed to serve as a WAN MAC address and a terminal IP address of a corresponding broadband user; and querying a pre-stored uplink flow forwarding table according to the WAN MAC address and the terminal IP address to obtain a corresponding gateway MAC address and a corresponding terminal MAC address, respectively replacing the source and target MAC addresses of the access message with the gateway MAC address and the terminal MAC address, and then sending the access message to the home terminal. According to the embodiment of the invention, low-cost and high-speed private network accompanying communication can be realized.
Owner:CHINA MOBILEHANGZHOUINFORMATION TECH CO LTD +1

Server access detection method and device, electronic equipment and storage medium

The embodiment of the invention provides a server access detection method and device, electronic equipment and a storage medium, belongs to the technical field of network security, and is applied to the field of financial science and technology and the field of health medical treatment. The method comprises the following steps: performing feature extraction on a network connection log to obtain a network behavior time sequence feature, a log semantic feature and a network behavior topological feature; performing pattern recognition according to the network behavior time sequence features, the log semantic features and the network behavior topological features to obtain a network behavior pattern; constructing a network topological graph according to the source address, the target address, the first sub-network segment and the second sub-network segment, wherein the network topological graph comprises network nodes; performing feature extraction on the network topological graph to obtain node embedding features of network nodes; and performing access detection on the server according to the network behavior pattern and the node embedding feature to obtain an access category, the access category including normal access or abnormal access. According to the embodiment of the invention, the accuracy of server access detection can be improved.
Owner:PING AN TECH (SHENZHEN) CO LTD

Phase-change memory controller, phase-change memory address management method and system

This disclosure provides a controller, address management method, and system for a phase-change memory (PCM). The method includes: determining the address mapping mode of the PCM; if it is a static mapping mode, mapping a first source address to a first destination address based on a preset mapping table; if it is a dynamic mapping mode, matching a corresponding address mapping rule according to a dynamic scenario, and mapping a second source address to a second destination address based on the address mapping rule; if it is a hybrid mapping mode, mapping a third source address to a third destination address based on a preset mapping table, controlling the PCM to perform read operations based on the third destination address; and matching a corresponding address mapping rule according to a dynamic scenario, mapping a fourth source address to a fourth destination address based on the address mapping rule, and controlling the PCM to perform write operations based on the fourth destination address. This application can reduce the read latency of the PCM, improve the write performance and media lifetime of the PCM, and achieve a balance between read and write performance.
Owner:XI AN UNIIC SEMICON CO LTD

An automatic blocking method and system for IPv6 attack based on NAT64

The application provides an IPv6 attack automatic blocking method and system based on NAT64, and relates to the technical field of network security.The method provided by the application comprises the following steps: obtaining traffic data passing through a network boundary, extracting key information of the traffic data in real time and processing the key information in a standardized manner, obtaining general data and constructing a NAT64 database; performing abnormal behavior detection on the general data, marking the general data as potential attack sources, and extracting abnormal information of the potential attack sources; based on NAT64 address mapping, reversely querying the NAT64 database by taking the abnormal information as a query condition, judging whether an IPv4 address of the potential attack sources is converted by NAT64 based on a query result, and obtaining an attack source IPv6 address if the IPv4 address is converted by NAT64; generating a blocking instruction for the attack source IPv6 address based on a blocking policy template, and sending the blocking instruction to a network security device through a device interface protocol to complete automatic blocking; and recording a blocking operation log and sending an alarm notification in real time.The application realizes automatic blocking of IPv6 attacks in combination with an abnormal behavior detection mechanism, an address mapping identification mechanism and an automatic blocking policy.
Owner:JIANGXI KECHEN HONGXING INFORMATION TECH CO LTD

Tensor data transformation method, tensor processing unit, processor, system on chip, and computing device

Provided in the embodiments of the present disclosure are a tensor data transformation method, a tensor processing unit, a processor, a system on a chip, and a computing device. The tensor processing unit comprises: a register array unit, which comprises at least a source address register, a destination address register, and a source tensor parameter register; an instruction decoding unit, which parses an acquired transformation operation instruction, so as to obtain a transformation operation type indicated by an operation type field and obtain respective register serial numbers of the source address register, the destination address register, and the source tensor parameter register; and an instruction execution unit, which accesses the source address register, the destination address register, and the source tensor parameter register on the basis of their respective register serial numbers, reads a source memory address field, a destination memory address field, and a source tensor parameter, reads a source tensor on the basis of the source memory address field, performs, on the source tensor, a transformation operation indicated by the transformation operation type, and writes, on the basis of the source tensor parameter, a destination tensor obtained after the transformation operation into the destination memory address field.
Owner:ALIBABA DAMO (HANGZHOU) TECH CO LTD

Address and Entity Recognition Method and System Based on Large Language Model and Retrieval Enhancement

This disclosure presents an embodiment of a method and system for address and entity recognition based on a large language model and retrieval enhancement. One specific implementation of the method includes: data processing of an acquired multi-source address dataset and a point-of-interest dataset to generate a candidate entry dataset; performing a mixed retrieval on the acquired unstructured text to be processed based on the candidate entry dataset to generate a retrieval candidate entry dataset; constructing a set of instruction prompts from the unstructured text to be processed and the retrieval candidate entry dataset; inputting the instruction prompt set into a preset entity recognition model to obtain a structured entity recognition result; generating a formatted recognition result based on the structured entity recognition result; and, in response to determining that the formatted recognition result represents a successful verification result, identifying the formatted recognition result as the target entity recognition result. This implementation improves anti-interference capability, reduces dependence on labeled data, and lowers data costs.
Owner:TENGYUN TIANYU SCI & TECH BEIJING CO LTD

A method, device and storage medium for automatically establishing a VXLAN VTEP

The application provides a method for automatically establishing a VTEP of a VXLAN, wherein a three-layer network switching device exists between VXLAN devices; a sending end VXLAN device fills a destination address in an Ethernet message header of a VXLAN message as a MAC address of the three-layer network switching device when sending, and sends the message to the three-layer network switching device, which then sends the message to a receiving end VXLAN device; after receiving the VXLAN message, the receiving end VXLAN device binds a source IP in the Ethernet message, a source IP of the VXLAN message and a source MAC address of the VXLAN message as the VTEP; and the receiving end VXLAN device determines a MAC address of a VXLAN tunnel node according to the MAC address in the VTEP when encapsulating the VXLAN. The application enables the VXLAN technology to be applied to any scene, and provides network security communication services for communication messages.
Owner:BEIJING CATHAY INTERNET INFORMATION TECH CO LTD +1

Network request processing method, virtual network card configuration method and virtualized network system

The invention provides a network request processing method, a virtual network card configuration method and a virtualized network system.The virtualized network system comprises a main node and at least one working node which jointly form a virtual machine, and the main node configures a plurality of virtual network cards for the virtual machine. The working node creates a plurality of shadow network cards based on the virtual network card configuration information issued by the main node, and establishes a binding relationship between the shadow network cards and the virtual network cards; when the VCPU on the working node obtains the first network request, the working node extracts the first source MAC address, and determines a first shadow network card bound with the first virtual network card identified by the first source MAC address according to the binding relationship and the first source MAC address; and sending the first network request through the first shadow network card. The shadow network card is introduced, so that the network performance of each node can be fully utilized, the network delay is reduced, and the overall network bandwidth is improved.
Owner:CHINA TELECOM CLOUD TECH CO LTD

Firewall path determination method and device

The invention discloses a firewall path determination method and device, and relates to the technical field of network security. A specific embodiment of the method comprises the following steps: acquiring an access request comprising an access source address and an access destination address; determining a first address set corresponding to the access source address and a second address set corresponding to the access destination address from a plurality of pieces of pre-configured address set information; according to configuration elements included in the address set information, determining a source address set different from the second address set from the first address set, and determining a destination address set different from the first address set from the second address set; and determining a firewall path corresponding to the access request according to the configuration elements respectively corresponding to the source address set and the destination address set. According to the embodiment, automatic analysis of the firewall path is realized, the path analysis efficiency is improved, and the probability of configuration errors and missed configuration caused by manual errors can be reduced.
Owner:THE PEOPLES BANK OF CHINA DIGITAL CURRENCY INST

Method and system for detecting encrypted flood attacks

A system and method for detecting HTTPS flood cyber-attacks. A method includes deriving traffic features from incoming traffic directed to a protected entity; determining if the derived traffic features represent at least one traffic anomaly, wherein the traffic anomaly is a deviation from at least one baseline, wherein the baseline is a normal distribution of traffic features of legitimate incoming traffic; upon determining that the derived traffic features represent at least one anomaly, determining if the anomaly characterizes an on-going HTTPS flood cyber-attack; upon determining that there is the on-going HTTPS flood cyber-attack, populating a list of suspect source internet protocol (IP) addresses of devices triggered detection of the anomaly; challenging each device in the list of suspect source IP addresses to determine if a challenged device is an attack tool; and causing execution of a mitigation action on each client device determined to be an attack tool.
Owner:RADWARE LTD