Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

151 results about "Transmission Control Protocol" patented technology

The Transmission Control Protocol (TCP) is one of the main protocols of the Internet protocol suite. It originated in the initial network implementation in which it complemented the Internet Protocol (IP). Therefore, the entire suite is commonly referred to as TCP/IP. TCP provides reliable, ordered, and error-checked delivery of a stream of octets (bytes) between applications running on hosts communicating via an IP network. Major internet applications such as the World Wide Web, email, remote administration, and file transfer rely on TCP. Applications that do not require reliable data stream service may use the User Datagram Protocol (UDP), which provides a connectionless datagram service that emphasizes reduced latency over reliability.

Enhancing network resiliency and performance through multipath routing with metasurface-integrated portable transcoder

The technology described herein is directed towards a transcoder device (node) that leverages multipath routing techniques using both terrestrial and satellite links simultaneously. The transcoder device implements the multipath transmission control protocol (MPTCP) along with metasurfaces, such as to support satellite, ethernet, Wi-Fi, and new radio (e.g., 5G) interfaces. The transcoder can decode and reencode data packets at the packet level to facilitate communication between user equipment (UEs) and existing Satcom satellites. A metasurface redirects signals from the satellite to a satellite radio frequency (RF) interface of the transcoder, with the transcoder also coupled by a UE RF interface to a UE, such as a computing device or cellphone. For direct-to-device communications, transcoder conversion is bypassed. Various additional functions facilitate such satellite service, including via frequency conversion, doppler manipulation, a repeater, and frequency equalization / negative-slope compensation.
Owner:DELL PROD LP

Parallel coding and decoding method based on multipath network TCP-UDP

The invention relates to the technical field of network transmission, in particular to a parallel coding and decoding method based on a multi-channel network TCP-UDP (Transmission Control Protocol-User Datagram Protocol). According to the invention, by constructing a multi-path parallel transmission mechanism of a transmission control protocol and a user datagram protocol, the transmission performance of each path can be dynamically evaluated and quantified according to the round-trip time and packet loss rate of the path at the beginning of session establishment, and the initial data distribution proportion is scientifically calculated, so that the initial optimization utilization of network bandwidth resources is realized; in the data transmission process, the actual sending rhythm and the bandwidth utilization condition of each link are continuously monitored, and the evolution trend of the bandwidth load is accurately identified through a time sequence prediction model, so that the path weight is dynamically modulated, the distribution proportion of the data packet is corrected in real time, and the data stream can be continuously and uniformly transmitted on the optimal path. The problems of transmission bottleneck and delay caused by performance fluctuation of a single path are effectively solved, and the reliability, stability and efficiency of data transmission are greatly improved.
Owner:TUOWEI NETWORK (SHENZHEN) CO LTD

5G signaling plane traffic screening method, system and device based on multi-core processing unit, and storage medium

The invention relates to a 5G signaling plane traffic screening method based on a multi-core processing unit, and the method comprises the steps: receiving network mirror image traffic through a physical interface unit, and screening out transmission control protocol traffic; the switching chip unit identifies HTTP / 2 protocol traffic from transmission control protocol traffic according to a target port number or an application layer protocol handshake feature, and forwards the HTTP / 2 protocol traffic to the multi-core processing unit; the binary framing structure of the HTTP / 2 protocol is analyzed, a data frame and a control frame are distinguished, and an HTTP request head is restored; analyzing and decoding an HTTP request header, and extracting a pseudo header field of a uniform resource identifier path in the HTTP request header; generating a traffic filtering rule corresponding to the service signaling traffic bearing the specific network function; and issuing the generated flow filtering rule to a switching chip unit, and outputting specified 5G signaling plane flow. The method automatically adapts to the dynamic change of the 5G network element, and effectively solves the problem of traffic loss or inaccuracy caused by difficult maintenance and untimely updating of the static work parameter data.
Owner:SINO TELECOM TECHNOLOGY CO INC

Method and device for speeding up packet processing

A method for speeding up packet processing is provided. The method includes: receiving, by a hardware acceleration circuitry of a computing device, a packet from an application layer. The method includes determining, by the hardware acceleration circuitry, whether the packet is a transmission control protocol / Internet protocol (TCP / IP) packet. The method includes performing, by the hardware acceleration circuitry, related processing on the TCP / IP packet to obtain a processed TCP / IP packet after the related processing in response to determining that the packet is the TCP / IP packet. The method includes transmitting, by the hardware acceleration circuitry, the processed TCP / IP packet to a lower layer.
Owner:MEDIATEK INC

Methods and systems to reduce delays in VoWi-Fi handover and packet switching registration

ActiveUS12495346B2Wireless network protocolsTransmissionEngineeringPacket switched
The present disclosure refers to methods and systems to reduce delays in VoWI-FI handover and packet switching registration. The method includes triggering a Router Solicitation Router Advertisement (RSRA) procedure to establish a Transmission Control Protocol / Internet Protocol (TCP / IP) interface based on a determination that the VoWi-Fi handover of a user equipment (UE) is to be performed, determining if a router advertisement (RA) is received within a first time interval, and obtaining a full Internet Protocol version 6 (IPv6) address previously used by the UE in response to determining that the RA is not received within the first time interval, the full IPv6 address being for establishing the TCP / IP interface with a network.
Owner:SAMSUNG ELECTRONICS CO LTD

Transmission control protocol acknowledgement shaping

Methods, systems, and devices for wireless communications are described. A user equipment (UE) may generate and transmit at least one TCP ACK message according to a delay timer. A duration for the delay timer may be based on a downlink data pattern associated with downlink data packets for the UE and an uplink scheduling pattern associated with uplink data packets for the UE. The UE may generate and transmit multiple TCP ACK message segments corresponding to the TCP ACK message based on the downlink data pattern and the uplink scheduling pattern. A TCP ACK message segment may correspond to feedback for a respective portion of the quantity of data. The UE may generate and transmit a TCP ACK message associated with the quantity of data based on a transmission blanking pattern.
Owner:QUALCOMM INC

Dynamic Scheme for Customizing TCP Keepalive Idle Interval

A monitoring device and a method are provided for dynamically adjusting an idle interval for a Transmission Control Protocol Keepalive (TCPK) setting in a monitoring device of an electronic monitoring system. The monitoring device is connectable to an access point over a communications network utilizing Transmission Control Protocol (TCP). The initial idle interval for the TCPK of the monitoring device is programmed and a connection between the monitoring device and the access point over the communications network is established. A connection status of the communications network is monitored for failures and a count of the failures is maintained. If the count exceeds threshold, the initial idle interval is reduced by a selected time period to provide an updated idle interval.
Owner:ARLO TECHNOLOGIES INC

Full-duplex remote communication calling method and device and storage medium

The invention discloses a full-duplex remote communication calling method and device and a storage medium, and relates to the technical field of network communication, and the method comprises the steps: responding to a remote calling request sent by a client, and based on the remote calling request, creating a transmission control protocol long connection with the client, the number of the client being one or more; and in response to a remote call request sent by at least one client, creating TCP long connection with the client. According to the invention, real full-duplex remote calling is realized by establishing a single TCP long connection, so that the server can initiatively initiate a calling request to the client, the limitation of unidirectional communication of a traditional RPC framework is broken through, the system architecture is effectively simplified, the complexity that the client plays the server at the same time is avoided, and the resource overhead caused by maintenance of multiple connections is reduced.
Owner:SHENZHEN SHIXI TECH CO LTD

Data processing method, base station, terminal, and storage medium

The application discloses a data processing method, a base station, a terminal and a storage medium. The data processing method comprises the following steps: acquiring a transmission control protocol (TCP) message, backing up a packet data convergence protocol (PDCP) service data unit (SDU) corresponding to the TCP message, generating and saving a sequence number code corresponding to the PDCP SDU; sending the TCP message to a data receiving end; when an acknowledgement (ACK) message carrying an acknowledgement sequence number is received according to the TCP message sent by the data receiving end, determining a sequence number code meeting an acknowledgement condition from the saved sequence number codes according to the acknowledgement sequence number in the ACK message; and deleting the PDCP SDU corresponding to the sequence number code meeting the acknowledgement condition. According to the scheme provided by the embodiment of the application, the sequence number code determined according to the ACK message acknowledgement sequence number is the maximum confirmable sequence number code, the PDCP SDU corresponding to the sequence number code smaller than or equal to the maximum confirmable sequence number code is deleted, the backup file of the PDCP SDU can be deleted more timely, and thus the message quantity of PDCP retransmission is reduced.
Owner:ZTE CORP

Inference system based on large model

The invention provides an inference system based on a large model, and relates to the technical field of data processing, in particular to the technical fields of large models, deep learning, intelligent search and the like. According to the specific implementation scheme, a transmission engine establishes a transmission channel for a pre-filling node and a decoding node of a large model; the pre-filling node and the decoding node are used for processing the same target reasoning request; the pre-filling node is used for storing key value pair information obtained by processing the target reasoning request into a local first video memory; storing the key value pair information in the first video memory into a second video memory of a decoding node through a transmission channel; under the condition of determining that the key value pair information is completely stored in the second video memory, sending a notification message to a decoding node through a transmission control protocol (TCP); and the decoding node responds to the notification message and processes the key value pair information in the second video memory to obtain a processing result of the target reasoning request.
Owner:BEIJING BAIDU NETCOM SCI & TECH CO LTD

Data processing method and terminal

Disclosed in the present application is a data transmission method. The data transmission method includes: establishing a multipath transmission control protocol (MPTCP) connection with a network access point device, the MPTCP connection including a first TCP connection and a second TCP connection, the first TCP connection being constructed according to a first Wi-Fi connection corresponding to a first Wi-Fi module, and the second TCP connection being constructed according to a second Wi-Fi connection corresponding to a second Wi-Fi module; and transmitting network access data to the network access point device by means of the MPTCP connection.
Owner:GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD

One-to-many TCP connection splicing

The invention relates to one-to-many TCP connection splicing. A computing device includes at least one network interface controller (NIC), a memory, and at least one processor including one or more cores. The NIC (s) receive inbound transmission control protocol (TCP) data packets and transmit outbound TCP data packets. The memory stores a program of instructions that the processor executes to divide a data path within the computing device that includes both a receiving endpoint and a transmitting endpoint into a first path and a second path. In response to determining that the first inbound TCP data packet is associated with the established TCP connection and the data stitching group, the processor assigns the first inbound TCP data packet to the first path and assigns a second inbound TCP data packet that is not assigned to the first path to the second path. The processor performs a one-to-many data stitching of payload data from the first inbound TCP data packet to the outbound TCP data packet using the first path.
Owner:NOKIA NETWORKS OY

Throughput enhancements for multi-link operations

Certain aspects of the present disclosure are directed to enhancing throughput of multi-link operations. In general, one example method at a first wireless node includes determining a first ratio of first traffic on each of one or more of a plurality of links between the first wireless node and a second wireless node based on at least one characteristic of the one or more of the plurality of links, the first service comprises a transmission control protocol (TCP) or internet protocol (IP) service; and outputting the first traffic for transmission to the second wireless node according to the first ratio.
Owner:QUALCOMM INC

Method and apparatus for controlling transmission control protocol (TCP) congestion in wireless communication system

PCT designated stageWO2026146951A1Communications systemData transmission
The present disclosure relates to a 5G or 6G communication system for supporting a data transmission rate higher than that of a 4G communication system such as LTE. A method for a server in a wireless communication system, according to one embodiment of the present disclosure, comprises the steps of: receiving acknowledgement (ACK) packets from a base station; determining scheduling characteristics on the basis of the ACK packets; and performing transmission control protocol (TCP) congestion control on the basis of the scheduling characteristics.
Owner:SAMSUNG ELECTRONICS CO LTD +1

Vehicle cloud cooperative vehicle-mounted network fault processing method and system

The invention provides a vehicle-cloud cooperative vehicle-mounted network fault processing method and system, and relates to the technical field of vehicle-mounted network fault processing, and the method comprises the steps: deploying a network probe at a vehicle end, and collecting wireless communication indexes in real time, wherein the wireless communication indexes comprise reference signal receiving power, a signal-to-interference-plus-noise ratio, reference signal receiving quality and TCP / HTTP (Transmission Control Protocol / Hyper Text Transport Protocol) service success rate; a multi-module fault diagnosis mechanism is combined to carry out accurate anomaly detection on various vehicle-mounted services, and context information is uploaded to a cloud end once a fault is found; and the cloud side intelligently generates a recovery strategy such as module reset, neighbor cell forced switching or flow routing optimization by relying on the regional base station load and historical network quality data, issues the recovery strategy to the vehicle side for execution, and receives execution feedback to form closed-loop control at the same time. According to the method, the perception precision, the diagnosis efficiency and the recovery speed of the vehicle-mounted network fault are improved, the vehicle-cloud cooperative operation and maintenance mode from passive response to active prediction, decision making and execution is realized, and the continuity of the vehicle-mounted service and the user experience are effectively guaranteed.
Owner:CHINA FAW CO LTD

Socket interface multi-task coordinated parasitic parameter extraction method and system

The invention provides a parasitic parameter extraction method and system for Socket interface multi-task coordination, and belongs to the technical field of parasitic parameter extraction. The method comprises the following steps: acquiring and analyzing an initial configuration file, and creating a read-write lock mechanism of a process pool and a global task coordination table; establishing non-blocking transmission control protocol monitoring, and mapping a Socket connection handle established by the sub-process and the host process to a global task coordination table; executing parasitic parameter extraction by utilizing the screened sub-processes, and generating a parasitic parameter result data packet after the extraction is completed; and performing Hash abstract verification, and if the Hash abstract verification is passed, marking the task corresponding to the parasitic parameter result data packet as completion and recording the extracted parasitic parameter. According to the method, a traditional file synchronization mechanism is replaced based on non-blocking Socket communication and an event-driven model, so that the inter-process communication efficiency is remarkably improved; and by adopting read-write lock hierarchical control and atomic operation, the utilization rate of hardware resources is effectively improved.
Owner:青岛展诚科技有限公司

Aggregating secured packets in a network device

In one embodiment, a network device includes a network interface to receive secured packets from a remote device over a packet data network, each of the secured packets being secured according to a security protocol and including a respective security protocol header and a Transmission Control Protocol (TCP) packet, which is encrypted according to the security protocol, a host device interface to connect the network device to a host device, and packet processing circuitry to decrypt each of the secured packets based on the respective security protocol header yielding multiple decrypted packets including decrypted TCP packets, aggregate the decrypted TCP packets into a single aggregated packet, and provide the single aggregated packet to software running on a processor of the host device via the host device interface.
Owner:MELLANOX TECHNOLOGIES LTD(IL)

Expression method for Moubus communication data and Ethernet forwarding data

The invention provides a Moubus communication data and Ethernet forwarding data representation method, and relates to the technical field of communication, the method is applied to a household energy storage system, the household energy storage system comprises an energy storage converter, a communication module and an energy management system, and under the condition that the energy storage converter communicates with the energy management system through the communication module, the Ethernet forwarding data is transmitted to the energy management system through the communication module. An energy storage converter is used as a Moubus slave, a communication module is used as a Moubus host, and TCP connection between the Moubus and an energy management system is established; the method comprises the following steps: acquiring communication data of a Moubus slave, representing the communication data as standard communication data in a unified Json data format, mapping the communication data to forwarding data of a TCP (Transmission Control Protocol) when a Moubus host transmits the communication data to an energy management system, and representing the forwarding data as the standard communication data in the unified Json data format. Therefore, based on the standard communication data representing the communication data as the unified Json data format, Modbus host communication is developed at a time, and repeated development is avoided.
Owner:STATE POWER INVESTMENT CORPORATION RESEARCH INSTITUTE +1

Data transmission method and device under automobile open system architecture

The application provides a data transmission method under an automobile open system architecture, which comprises the following steps: creating a complex device driver socket module on a transmission control protocol / internet protocol layer; pre-allocating a random access memory via the complex device driver socket module and locking the pre-allocated random access memory; transmitting data in the locked random access memory via the complex device driver socket module; counting the number of times of transmitting data in the pre-allocated random access memory; in response to the number of times of transmitting data being greater than a predetermined threshold, calling a transmission confirmation function to confirm whether the transmission is completed and releasing the random access memory resource for completing the transmission. The method and interrupt scenario provided by the application can send frames without RAM limitation. In a large data transmission scenario, this mode does not cause frequent in-out interrupts, so that the whole system runs more smoothly.
Owner:ROBERT BOSCH GMBH

Service state detection method and device of service instance, equipment and product

The invention provides a service state detection method and device for a service instance, equipment and a product, and relates to the technical field of micro-service architecture. The method comprises the following steps: acquiring connection state data of a target service instance registered in a registration center; inputting the connection state data into a prediction service state model to obtain a prediction service state abnormal probability value; under the condition that the predicted service state abnormal probability value is smaller than a first preset threshold value, adjusting transmission control protocol stack parameters of the target service instance according to a first preset adjustment strategy; and adjusting the transmission control protocol stack parameter of the target service instance according to a second preset adjustment strategy under the condition that the predicted service state abnormal probability value is greater than a second preset threshold value. And the transmission control protocol stack parameters are adjusted according to the predicted service state abnormal probability value, and low-heartbeat service state management is realized by adopting an event-driven and network layer keep-alive mechanism, so that a registration center CPU and bandwidth resources occupied by a large amount of heartbeat traffic are saved.
Owner:CHINA MOBILE FINANCIAL TECHNOLOGY CO LTD +1

An encrypted traffic restoration system, method, device and storage medium

The application discloses an encrypted traffic restoration system, method and device and a storage medium, relates to the technical field of network security, and comprises a data forwarding plane, a self-defined transmission control protocol stack, a virtual service layer and a virtual service layer. The data forwarding plane is used for receiving encrypted traffic and performing data analysis on the encrypted traffic. The self-defined transmission control protocol stack is used for monitoring the analyzed traffic and determining the connection relationship between a target service end and a target client. The virtual service layer is used for constructing a virtual service end and a virtual client, determining a virtual sender and a virtual receiver, and sequentially transmitting the analyzed traffic to an actual receiver through the virtual sender and the virtual receiver. The virtual service end and the virtual client are both configured with traffic decryption and encryption functions, so that the decrypted traffic obtained through the decryption function can be subjected to data security detection. The plaintext traffic is obtained through the decryption function between the virtual service end and the virtual client, thereby avoiding the problem of changing the original network structure in the encrypted traffic restoration process.
Owner:CETC CYBERSPACE SECURITY TECH CO LTD

Method, device and medium for processing data flow entry

The application provides a data flow table entry processing method, device and medium. The method receives a data packet transmitted by a current network through a transmission control protocol (TCP) session connection; determines a target data flow table entry corresponding to the data packet based on four-tuple information of the data packet; if a data length of the data packet is greater than a preset data length, writes data of the data packet into a data carrying page in the target data flow table entry, and updates table entry data in the target data flow table entry; otherwise, when there is no historical data of a historical data packet in the data carrying page in the target data flow table entry, writes the data of the data packet into the data carrying page, and uploads the data carrying page with the data to a server; or when there is historical data in the data carrying page, uploads the data carrying page with the historical data to the server, and then uploads the data to the server. The method improves the transmission efficiency of the data packet.
Owner:BEIJING ZHUANWEI TECH CO LTD

Resource adjustment method and device, equipment, medium and product

The invention relates to the technical field of network communication management, and provides a resource adjustment method and device, equipment, a medium and a product. The method comprises: obtaining statistical data, the statistical data comprising a first number and a second number, the first number being used for representing the number of connections between a terminal device and a transmission control protocol (TCP) server cluster, and the second number being used for representing the number of instructions of each instruction type between the terminal device and the TCP server cluster; determining a predicted resource usage amount of the TCP server cluster according to the statistical data; and performing resource adjustment on the TCP server cluster according to the predicted resource usage amount. Based on the scheme of the invention, the accuracy of TCP server resource adjustment can be improved.
Owner:CHINA MOBILEHANGZHOUINFORMATION TECH CO LTD +1

Implementation of multipath transmission control protocol and multipath quick user datagram protocol internet connection as opaque to a high-level operating system

Various aspects of the present disclosure generally relate to wireless communication. In some aspects, a user equipment (UE) may detect whether a traffic flow comprises multipath transmission control protocol (MPTCP) traffic or multipath quick user datagram protocol Internet connection (MPQUIC) traffic. The UE may modify one or more packets of the traffic flow based at least in part on a result of detecting whether the traffic flow comprises MPTCP traffic or MPQUIC traffic or based at least in part on an access traffic steering, switching, and splitting (ATSSS) policy configured on a modem processor of the UE. The UE may provide the traffic flow for transmission by the UE in accordance with the ATSSS policy configured on the modem processor of the UE. Numerous other aspects are described.
Owner:QUALCOMM INC

Remote controller capable of displaying and interacting with external equipment on same screen and supporting device for shooting

The utility model relates to the technical field of electronic equipment, in particular to a remote controller capable of displaying and interacting with external equipment on the same screen, which comprises a shell, a circuit board, a power supply unit and a touch screen, the touch screen is arranged on the side surface of the shell, and the circuit board and the power supply unit are both arranged in the shell and are electrically connected with each other; a communication assembly and a master controller are arranged on the circuit board, and the communication assembly is used for being in electric signal connection with external equipment and enabling signals displayed by the touch screen to be the same as signals displayed by the external equipment; the communication assembly comprises a signal transmission unit and at least two types of connection interfaces integrated on the main controller, and each type of connection interface at least supports one transmission control protocol of Harmony Case Engine, Airplay, Miracast, WiDi or DLNA. According to the remote controller, same-screen display can be achieved in terminal devices such as mobile phones and tablet computers of different systems, the remote controller can reversely control the terminal devices, a user can conveniently conduct shooting and live broadcasting independently, and high compatibility is achieved.
Owner:SHENZHEN ZANDIAN TECH CO LTD

Water curtain equipment distributed real-time computing method and device, equipment and storage medium

The application discloses a water curtain equipment distributed real-time calculation method and device, equipment and storage medium, relates to the technical field of distributed computing and load balancing, and the method comprises the steps of adding a plurality of servers to a server list and initializing a current weight; creating a transmission control protocol connection task according to the number of enabled water curtain holes, and executing the task through a load balancing scheduling server; recording the water curtain hole name, the corresponding task and the execution server to a first hash table and a second hash table respectively; decomposing a hydraulics test task into a plurality of subtasks, and scheduling the server to execute in combination with the two hash tables; releasing the server resources, restoring the weight, and determining whether to start a subsequent task according to the execution result after the task is completed, so that when a large amount of water curtain equipment data is processed in real time, the interface is refreshed, and a plurality of hydraulics test processes, the system resource is avoided to be nervous, the performance is reduced or the process is locked due to too many tasks, and the real-time performance and continuity of the data are ensured.
Owner:POWERCHINA ZHONGNAN ENG

New wireless broadcast optimization method, device, equipment, storage medium and program product

PendingCN121173421AError preventionBroadcast service distributionWireless broadcastRTP Control Protocol
The invention provides a new wireless broadcast optimization method, device and equipment, a storage medium and a program product, and belongs to the technical field of wireless communication, and the method comprises the steps that an application function AF is internally provided with an error code corresponding table, and the error code corresponding table is used for storing the corresponding relation between the error rate and the forward error correction FEC coding proportion; receiving a real-time transmission control protocol packet reported by each multicast terminal, wherein the real-time transmission control protocol packet comprises an error rate; performing bit error rate statistics based on the geographic areas to obtain area bit error rates corresponding to the geographic areas; and determining the FEC coding proportion of each geographic area based on the bit error rate of each area and the bit error coding corresponding table. The broadcast channel state is indirectly estimated by means of feedback of the multicast terminal so as to obtain channel measurement, FEC coding is guided according to the corresponding relation between the bit error rate and the FEC coding proportion, and reliability is improved and data transmission efficiency and transmission quality are balanced on the basis of ensuring large capacity and short time delay of broadcast services.
Owner:CHINA MOBILE GRP HAINAN CO LTD +1

APT attack detection method based on traffic context deep mining features

The invention provides an APT (Advanced Persistent Threat) attack detection algorithm based on traffic context deep mining features, which comprises the following steps of: firstly, deeply mining five types of features with distinction degrees, namely packet level features, flow level features, DNS (Domain Name Server) traffic features, TCP (Transmission Control Protocol) traffic features and traffic encryption features of traffic from three dimensions of data packets, data flows and host-level data; then, the overall structure of the SJTU-APT23 data set is recognized in a visual mode through PCA visual correlation analysis and t-SNE visual correlation analysis in sequence, distribution of APT flow data and the relation between the extracted features are known, and the validity of the features is analyzed; and finally, using a random forest model, an SVM (Support Vector Machine) model and a KNN (K Nearest Neighbor) model to identify the APT traffic in the malicious software based on the deep-mined features, trying to classify the organization to which the APT traffic belongs, and proving the effectiveness of the extracted features from the perspective of practice. The invention provides an APT (Advanced Persistent Threat) attack detection method based on traffic context deep mining features, which can accurately identify APT traffic in malicious software traffic.
Owner:YANCHENG POWER SUPPLY CO STATE GRID JIANGSU ELECTRIC POWER CO

Method, apparatus and device for determining result of bright code service and storage medium

The application relates to a method and device for determining the result of a bright code service, an equipment and a storage medium, and relates to the technical field of communication. The method comprises the following steps: determining multiple target transmission control protocol (TCP) sessions of a same user; the multiple target TCP sessions are TCP sessions of the bright code service; sorting the multiple target TCP sessions according to the starting time of each target TCP session, grouping the sorting result obtained through the sorting, and obtaining multiple TCP session groups; the session time interval between two adjacent TCP sessions included in each TCP session group is less than a preset time length; if the session result of any target TCP session in a first TCP session group is failure, determining that the bright code service result corresponding to the first TCP session group is failure; the first TCP session group is any one of the multiple TCP session groups; if the session result of all the target TCP sessions in the first TCP session group is success, determining that the bright code service result corresponding to the first TCP session group is success.
Owner:CHINA UNITED NETWORK COMM GRP CO LTD