Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

32 results about "Web traffic" patented technology

Web traffic is the amount of data sent and received by visitors to a website. This necessarily does not include the traffic generated by bots. Since the mid-1990s, web traffic has been the largest portion of Internet traffic. This is determined by the number of visitors and the number of pages they visit. Sites monitor the incoming and outgoing traffic to see which parts or pages of their site are popular and if there are any apparent trends, such as one specific page being viewed mostly by people in a particular country. There are many ways to monitor this traffic and the gathered data is used to help structure sites, highlight security problems or indicate a potential lack of bandwidth.

Aggregation of select network traffic statistics

Disclosed herein are network information collectors, methods, computer-readable media, and systems for generating network traffic statistics. For example, the network appliance is to receive, via a network, an accumulating map from a network appliance device, wherein the accumulating map comprises a condensed and aggregated version of web traffic flow information to the network appliance device; receive, via the network, additional accumulating maps from other network appliance devices; populate an accumulation map database with the accumulating map and the additional accumulating maps; and generate a report of the network traffic statistics hosted by the network appliance device and the other network appliance devices.
Owner:HEWLETT PACKARD ENTERPRISE DEV LP

System and method for automated universal resource locator creation

A system and method for automated bulk creation of Universal Resource Locators (URLs) with embedded Urchin Tracking Module (UTM) parameters is disclosed. The method processes input data, including endpoint URLs and UTM parameters, through pre-processing steps such as data cleansing and format standardization. The method appends UTM parameter-value pairs to endpoint URLs, optionally encoding the parameters. The generated tracking URLs are stored in a structured database for seamless integration with analytics tools, enabling reliable tracking and actionable insights into web traffic and user behavior.
Owner:SMALLMAN GABRIEL LANG

Method and System for Generating Technical Barriers to Trade Questionnaire Based on Big Data

The present invention discloses a method and system for generating a technical trade measure questionnaire based on big data, including obtaining and preprocessing information text data and web traffic data of a trade service platform, performing keyword analysis on the information text data to obtain keyword semantic importance, performing interest analysis on the web traffic data to obtain user interest, constructing a bias analysis function based on the keyword semantic importance and user interest, constructing a question sequence model, embedding the bias analysis function into the question sequence model, simulating the question sequence model, calculating the contribution degree of questions based on the simulation results, determining a questionnaire generation scheme according to the contribution degree of questions, and generating a questionnaire based on the questionnaire generation scheme. This method can not only improve the generation efficiency and quality of the questionnaire, but also has good interpretability and can be directly applied to the technical trade measure questionnaire evaluation system.
Owner:CHINA NAT INST OF STANDARDIZATION

Method and system for securing information exchange against ai-based network traffic by using client-side execution-based challenge-response mechanisms

A system and method for defending against AI-driven web traffic interference is provided. The system and method include: receiving, by an agent, a secret device ID and a web token provided by an authentication server; receiving an instruction to modify a request to a web service stored in a web server; embedding within a WebAssembly (WASM) component executed by the agent, a first portion of an encryption key and a second portion of the encryption key; transmitting the second portion of the encryption key to the authentication server; assembling, at runtime within the WASM component, an actual encryption key by combining the first portion and the second portion of the encryption key; encrypting, using the actual encryption key, the web token in the WASM component to generate a plurality of authentication tokens; and sending a request with the generated plurality of authentication tokens to the authentication server.
Owner:CO RADWARE LTD

Dark web website identification method and device in multiple tab concurrent access scenario

This invention discloses a method and apparatus for identifying dark web websites in scenarios with concurrent access across multiple tabs. The method includes: acquiring network traffic packets of a website being viewed and extracting directional sequence features from the network traffic packets; dividing the directional sequence features into multiple sub-sequence features based on a multi-sliding window, and inputting the multiple sub-sequence features into a neural network model to extract preset pattern features; analyzing the correlation of the preset pattern features using a target website identification model to obtain a probability calculation result of the target website being accessed; and obtaining the target website identification result from the website being identified based on the probability calculation result and a preset classification model. This invention can effectively extract key information of accessed dark web websites from obfuscated dark web traffic, achieve accurate website identification across multiple tabs, and exhibit good robustness in dynamic and defensive scenarios.
Owner:TSINGHUA UNIVERSITY

Detection of domain names generated by a domain generation algorithm using a wide and deep learning architecture

A computer-implemented method for detecting malicious content is disclosed that includes operations of: receiving a character set as an input, converting the input into an integer array containing indexes of each character, and creating an input vector from the integer array, the input vector being a dense numerical representation of the character set. The input vector is passed to a machine learning model to generate a plurality of features based on the character set, the plurality of features comprising at least two of: a length of the character set, a Shannon Entropy of the character set, n-gram similarity score of the character set with English dictionary words, n-gram similarity score of the character set with a set of legitimate domains, and an online web traffic ranking service. A dense input vector is formed by concatenating the plurality of features to the input vector, and then processed to obtain a comparison score.
Owner:CISCO TECHNOLOGY INC

Rerouting suspicious web traffic

In one embodiment, a method includes receiving a first request message associated with the online application, where the online application is provided by one or more application servers within the network domain, where the online application manages data, determining that a first suspicion score associated with the first request message exceeds a pre-determined threshold, inserting an indication into the first request message in response to the determination, where the indication specifies that the first request message is to be routed to a sandbox environment that is configured to mimic the one or more application servers, and where the sandbox environment is configured to not update the data managed by the online application, determining first routing policies based at least on the first suspicion score, and forwarding the indication-inserted first request message to a first computing device in the network domain based on the first routing policies.
Owner:BOLT FINANCIAL INC

Darknet traffic classifier based on natural scene statistics for defense against adversarial attacks

The application provides a dark web traffic classifier based on natural scene statistics and an anti-attack defense method, and belongs to the technical field of network security. The method comprises the following steps: obtaining dark web traffic original data to form an original data set; using four attack algorithms to attack each data in the original data set to obtain four kinds of adversarial attack samples; using a natural scene statistics method to characterize the dark web traffic original data and the adversarial attack samples generated by one of the four attack algorithms to obtain a parameter set of a generalized Gaussian distribution and an asymmetric generalized Gaussian distribution; training a detector using each parameter set; adding Gaussian noise to the data in the original data set, and training an autoencoder using the data after the Gaussian noise is added; combining the detector and the autoencoder into a two-layer defense mechanism; and identifying unknown traffic data by using the two-layer defense mechanism, feeding unknown traffic data with a classification result of attack traffic to the autoencoder for reconstruction to obtain benign data.
Owner:NINGXIA UNIVERSITY

Web abnormal traffic detection method and system capable of being adaptively updated

The invention provides an adaptive updating Web abnormal traffic detection method and system. The method comprises the following steps: 1) collecting and extracting target domain name traffic data from a Web application program; 2) obtaining three types of features including category features, statistical features and abnormal score features through traffic field contents; 3) training an abnormal traffic detection baseline model for the target domain name by using a multi-class machine learning fusion algorithm; 4) setting an event triggering mechanism, and realizing self-adaptive updating of the detection model based on an integrated learning framework; and 5) performing classification detection on the Web flow data of the target domain name by using the detection model. According to the method, the defect of insufficient adaptability of a traditional detection method is overcome, continuous learning and dynamic updating of abnormal traffic detection are realized, and the system can adapt to a new attack mode.
Owner:联通西部创新研究院有限公司

Enhancing the effectiveness of firewall applications with machine learning techniques

The invention concerns increasing the efficiency of the traditional rule-based WAF (200) (Web Application Firewall - Web Application Firewall) by detecting anomalies in web traffic in real time, thus reducing the frequently produced false positives, integrating machine learning algorithms for real-time web traffic anomaly detection, reduction of false positives, and effective detection of new attack vectors, thereby enhancing the efficiency of WAF (200).
Owner:MEDIANOVA INTERNET HIZMETLERI VE TICARET ANONIM SIRKETI

Malicious enumeration attack detection

PendingGB2637830AData packInternet traffic
A computer system, method, or program includes receiving flow data associated with web traffic from one or more requesters for a website, analyzing the flow data associated with the web traffic for the website 510, determining whether the flow data associated with the web traffic for the website indicates a likelihood of a malicious enumeration attack, and alerting (450, fig.4) an administrator of the website of the likelihood of the malicious enumeration attack. Flow data can be stored in a da tabase (420, fig.4). The likelihood of enumeration attack can be calculated based on agent name 570, number or volume of requests in a time period 540, and threshold percentage of requests matching a word list of common web pages 560, or on a weighted combination of these factors (fig.6). Analysis may be performed at predetermined intervals 580. Preferably the system does not perform deep packet analysis, i.e. packet inspection, when determining if there is an enumeration attack. Instead relying on metadata such as IP address, MAC address, host names, web page names, packet headers and the like. Such a system may protect internet-of-things (IoT) devices.
Owner:SOPHOS LTD

A load balancer-based website traffic management method and system

The application relates to the technical field of data analysis, and discloses a website traffic management method and system based on a load balancer, which comprises the following steps: acquiring real-time state information and real-time load information of a plurality of servers, inputting the real-time state information and the real-time load information into a preset load decision model to obtain real-time load decision data; configuring the load balancer according to the real-time load decision data to determine network traffic borne by each server; periodically acquiring performance index data of a website system under the real-time load decision data, and evaluating and optimizing the performance of the preset load decision model based on the performance index data of the website system. The preset load decision model is used to dynamically adjust the configuration of the load balancer, the load balancing accuracy and the resource utilization rate are improved, the decision and implementation results are periodically evaluated and optimized, the efficiency and robustness of the system are ensured, and the traffic load balancing demand of effectively managing a large website or application is met.
Owner:CHINA TELECOM CLOUD TECH CO LTD

Access control policy for proxy services

Systems and methods to manage and efficiently perform authorization of multiple proxy clients are disclosed. Furthermore, systems and methods to measure and check whether the web traffic of one or more client devices has reached a permissible limit of web traffic assigned by the proxy service provider. Specifically, a proxy is configured to gather and save authorization information of one or more clients within its memory. Therefore, the proxy server can verify and authorize one or more clients by utilizing the data from its memory. Furthermore, the proxy is configured to measure and report the utilized web traffic of one or more client devices to a messaging platform. In another aspect, systems and methods to check whether one or more client devices have reached a permissible amount of web traffic limit are disclosed.
Owner:OXYLABS UAB

Method to randomize online activity

A computer-implemented method for digital fingerprint obfuscation is disclosed. The computer-implemented method includes training a machine learning model to classify web traffic data into one or more personas. The computer-implemented method further includes identifying, using the trained machine learning model, a particular persona of a user based, at least in part, on a user's real traffic data generated during a current user session. The computer-implemented method further includes generating synthetic traffic data based, at least in part, on the identified particular persona of the user.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Deep learning approach for real-time scanning attack URLS detection using innocent until proven guilty learning framework (IUPG) and custom web traffic volume features

PendingUS20260254819A1Internet trafficEngineering
Techniques for a deep learning approach for real-time scanning attack Uniform Resource Locaters (URLs) detection using Innocent Until Proven Guilty (IUPG) learning framework and custom web traffic volume features are disclosed. In some embodiments, a method for a deep learning approach for real-time scanning attack URLs detection using an IUPG learning framework and custom web traffic volume features includes pre-filtering network traffic associated with a URL for an inline scanning attack detection service, determining a plurality of features for the URL, applying the plurality of features for the URL to an IUPG-trained deep learning model for inline detection of scanning URLs, and performing an action in response to a determination that the URL is a scanning URL is disclosed herein.
Owner:PALO ALTO NETWORKS INC

Website statistical analysis method, device and equipment and storage medium

The invention discloses a website statistical analysis method, device and equipment and a storage medium, one-button deployment is carried out based on a Docker containerization technology, firstly, a lightweight script in a website page is deployed, basic visitor behavior data not related to the personal identity of a user is collected, the volume of the lightweight script is smaller than 3 KB, and the lightweight script is loaded and executed in an asynchronous mode; encrypting and compressing the acquired basic visitor behavior data, sending the data to a server, storing the data in a database configured by a website host, and analyzing and calculating the data stored in the database to obtain a website traffic core index; and displaying the website traffic core indexes through a visual billboard. Quick installation and configuration can be realized by adopting one-button Docker deployment, extremely low influence on website performance is ensured by embedding an asynchronous script smaller than 3KB, and user privacy and data security can be thoroughly protected only by collecting non-personal identity data and encrypting, compressing and transmitting the non-personal identity data.
Owner:TIANFU JIANGXI LAB

Access control policy for proxy services

Systems and methods to manage and efficiently perform authorization of multiple proxy clients are disclosed. Furthermore, systems and methods to measure and check whether the web traffic of one or more client devices has reached a permissible limit of web traffic assigned by the proxy service provider. Specifically, a proxy is configured to gather and save authorization information of one or more clients within its memory. Therefore, the proxy server can verify and authorize one or more clients by utilizing the data from its memory. Furthermore, the proxy is configured to measure and report the utilized web traffic of one or more client devices to a messaging platform. In another aspect, systems and methods to check whether one or more client devices have reached a permissible amount of web traffic limit are disclosed.
Owner:OXYLABS UAB

An intelligent web application firewall malicious traffic identification method and system based on a CNN-LSTM hybrid neural network

PendingCN122339763AAlgorithmAttack
This invention relates to the field of network security technology and discloses a method and system for identifying malicious traffic in intelligent Web application firewalls based on a CNN-LSTM hybrid neural network, aiming to address the technical shortcomings of traditional WAFs and existing detection models. This invention constructs an end-to-end intelligent Web traffic detection system, achieving malicious payload deobfuscation through adaptive recursive decoding. It employs a hybrid model combining multi-scale CNN and cascaded LSTM to automate the extraction of local features and long-term semantic features. Combined with SMOTE resampling and data augmentation to optimize model training, and a probability threshold policy decision engine, it achieves accurate handling of malicious traffic. The system adopts a five-layer hierarchical architecture, with highly cohesive and loosely coupled modules that can be deployed in an engineered manner. This invention improves the detection capability against obfuscated attacks and unknown attacks, while reducing false positive rates and operational costs, making it suitable for malicious traffic identification scenarios in Web application firewalls.
Owner:JINLING INST OF TECH

Network server security partition configuration method and system

The invention provides a network server security partition configuration method and system, and the method comprises the steps: receiving an access request, and determining the type of the access request; if the type is Web traffic, controlling the first network architecture to determine an IP address of the access request; if the type of the access request is non-Web traffic, controlling a second network architecture to determine an IP address of the access request; obtaining a request identifier of the IP address; and if the request identifier is in the preset white list, sending the access request to the first convergence switch and / or the second convergence switch to access the intranet server. According to the invention, the first network architecture and the second network architecture which are connected in parallel are arranged, and the optimal communication link is dynamically selected based on the type of the access request and according to the request type, so that the efficiency and the security of network communication are improved, and the problems of overhigh firewall load and large delay caused by access of more Web traffic and non-Web traffic are solved.
Owner:HUANENG XINDIAN POWER GENERATION CO LTD

System for identifying and predicting trends

A system and method that automates trending data collection and timeseries predictions based on a coordinated system of emerging topics across social media, forums, news, media, search engine, web traffic, and other data sources. Using machine learning and natural language processing, trending data counts are cross referenced across each platform to inform representative conversational data collection, cultural classification, and timeseries predictions in order to identify emerging trends and predict trend trajectory over time. User interfaces provided by the system may be used to aid in evaluating emerging cultural trends as they may relate to business activity, law enforcement, and financial and other personal decisions, for example. The system may provide such data based on upon user configured searches that might focus the results on topics such as key consumer, economic, or political topics.
Owner:NICHEFIRE INC

Method, system, device, medium and product for anti-noise identification of encrypted website traffic

The application discloses an encrypted website traffic anti-noise identification method, system, device, medium and product, and relates to the field of digital information transmission. The method comprises the following steps: obtaining encrypted traffic generated when a user accesses a website, and saving the encrypted traffic into a PCAP file containing multiple data packets according to a set rule; cleaning the data packets in the PCAP file to obtain cleaned encrypted traffic; recombining the cleaned encrypted traffic based on the five-tuple information of the data packets to obtain multiple data streams; extracting website features from each data packet in each data stream to obtain website fingerprint extraction results; generating graph structure data based on the website fingerprint extraction results; performing a graph classification task on the graph structure data, and completing prediction of the user's access to the website according to the classification result. The application can effectively implement identification of website traffic on the premise that there is background noise.
Owner:HARBIN ENG UNIV

Dark web traffic classification method based on gradient boosting tree

The invention discloses a dark network traffic classification method based on a gradient boosting tree. The method comprises the following steps: constructing a feature matrix and a category matrix according to an original dark web traffic data set; initializing a category weight vector and a cumulative prediction confidence value matrix; introducing a category weight item in front of a loss function item of the XGBoost objective function as a multiplication item, and constructing an initial XGBoost objective function based on an initial category weight vector and an initial cumulative prediction confidence value matrix; based on the initial XGBoost objective function, constructing an initial gradient boosting tree; according to the error rate of each category in the previous round, the category weight is dynamically updated and adjusted to update the XGBoost target function, so that the gradient boosting tree is iteratively constructed until the number of iteration rounds reaches a preset value, and the target gradient boosting tree is finally obtained; and classifying the current dark network traffic based on the target gradient boosting tree. According to the method, a dynamic adjustment mechanism is adopted, so that the model can adaptively increase the attention on the difficult-to-classify categories, and the learning progress of each category is continuously balanced in the training process.
Owner:NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP

Flow analysis early warning method and system

The invention relates to the technical field of flow analysis and early warning, and the method comprises the steps that network flow collected by a flow analysis and early warning system is detected and analyzed through an intrusion detection engine and a behavior detection engine, and a platform provides four data security exchange channels and supports intrusion detection and behavior detection. According to the method, a gene detection technology is used for detecting a variety of a known threat, an intelligent detection technology is combined to prevent escape and avoidance, and a host behavior and a network behavior of a malicious code in a sandbox are deeply analyzed to detect an unknown threat. The intrusion detection engine can sense intrusion in content, environment and application layers. The behavior detection engine carries out file restoration and metadata extraction on traffic, the restored file carries out static detection on known threats through a built-in anti-virus engine, artificial intelligence engine detection is carried out, and malicious encrypted traffic, dark network traffic, hidden tunnels and the like can be detected.
Owner:INFORMATION CENT OF YUNNAN POWER GRID CO LTD

Rearranging tags on a graphical user interface (GUI) based on known and unknown levels of web traffic

Systems and methods for rearranging tags on a graphical user interface (GUI) based on known and unknown levels of web traffic are disclosed. To provide users with real estate listings that have popular home attributes with respect to a given region, the system uses known user interaction information to determine predicted user interaction information for real estate listing phrases (e.g., tags) that are associated with unknown user interaction information. The system then ranks the real estate listing phrases based on each real estate listing phrase's user interaction information. Based on the ranked real estate listing phrases, the system generates for display the highest ranked real estate listing phrase in association with a real estate listing being associated with the real estate listing phrase.
Owner:MFTB HOLDCO INC

GAN-based website traffic authenticity measurement method, system and storage medium

A GAN-based website traffic authenticity measurement method, system, and storage medium, the method includes collecting website click event data; using the website click event data to construct a behavior sequence; training a generative adversarial network model, using the generator in the generative adversarial network model to continuously generate simulated behavior sequences, and the discriminator to continuously learn how to judge whether the sequence is real or fake, until the loss of the generator and the discriminator no longer decreases, terminating the training to obtain a trained generative adversarial network model; using the discriminator of the trained generative adversarial network model to perform a discriminant measurement on the authenticity of the constructed behavior sequence. The system includes a data collection module, a behavior sequence construction module, a network model training module, and a authenticity discrimination module. The present invention can achieve more accurate recognition, use machine learning methods to learn user behavior patterns, can discover some patterns that cannot be discovered manually, and can adapt to different websites.
Owner:BEIJING XINGHEZHIXING NETWORK TECH CO LTD

Few-sample multi-label website fingerprint identification method and device

The invention relates to the technical field of information security, and provides a few-sample multi-label website fingerprint identification method and device. The method comprises the following steps: acquiring single-label website traffic data, and constructing multi-label website traffic synthetic data based on the single-label website traffic data; pre-training a teacher model based on the multi-label website traffic synthetic data, wherein the pre-trained teacher model can extract universal features of the multi-label website traffic; obtaining few-sample traffic data of the target multi-label website, and based on the few-sample traffic data and the teacher model, performing fine tuning on the student model through comparative distillation to obtain a target student model of the target multi-label website; and based on the target student model and a plurality of historical samples with similar to-be-identified multi-label website flow data features, carrying out fusion to obtain a multi-label website fingerprint identification result. According to the few-sample multi-label website fingerprint identification method and device provided by the invention, the multi-label website identification capability of the model in a few-sample environment can be improved.
Owner:QINGHAI UNIVERSITY

System and method for application traffic control

A system for managing web traffic comprising a meta control operating on a first processor having a first control interface and configured to generate a request for content and to transmit the request for content over a digital data network to a meta control server. The meta control server operating on a second processor and configured to receive the request for content and to select data for one or more second control interfaces as a function of data associated with the first control interface and to transmit the data for the one or more second control interfaces over the digital data network to the first control interface. The first control interface displays the data for the one or more second control interfaces and monitors user activity associated with the data.
Owner:REWARDSTYLE

Systems, methods, and computer-readable storage media for extracting data from web applications

Systems, methods, and computer-readable media are disclosed for extracting data from web applications. An exemplary embodiment includes monitoring web traffic between a client terminal and a server, the web traffic corresponding to a user's interaction with a web browser to send a request for data, such as a web page, from the client terminal to the server. A data log is created reflecting the monitored web traffic, and processed to extract the request for data. A command is generated for accessing the server based on the request for the data that was extracted from the data log. When the generated command is executed, it downloads the data from the server to the client terminal. Some embodiments are able to specify a pattern to search for in the downloaded web page, search the downloaded data for the pattern to identify data of interest and provide the identified data to a user.
Owner:FREDDIE MAC

Distributed defense architecture (DDA) for distributed denial of service (DDOS) attacks

The present disclosure provides various systems, methods, and devices that can be used to defend against distributed denial of service (DDoS) attacks. In one aspect, the present disclosure provides a method for defending against DDoS attacks that can be implemented by a web server. The web server can generate indirect authentication credentials (IACs) based on authentication credentials associated with a user account and share the IACs with an intermediary server. The intermediary server can be, for example, an Internet server provider server or a proxy server. The web server can further detect anomalies based on web traffic directed to the web server and instruct the intermediary server to verify subsequent web traffic directed to the web server based on the IACs. Thereafter, the web server can receive, via the intermediary server, the verified web traffic directed to the web server.
Owner:VISA INTERNATIONAL SERVICE ASSOCIATION

Method and device for automatically adjusting card extraction probability and medium

The invention discloses a method and device for automatically adjusting the card extraction probability and a medium. The method comprises the steps that page view data of a website are monitored in real time, and the page view data comprise website traffic and user behaviors; performing normalization processing on the page view data to obtain normalized page view data; calculating an adjustment factor of a preset reference probability according to the normalized page view data; adjusting the reference probability according to the adjustment factor, and determining a final card extraction probability; and carrying out random lottery drawing according to the final card drawing probability to obtain a lottery drawing result.
Owner:ANRUI DIGITAL INFORMATION TECH CO LTD