Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

8 results about "Web traffic" patented technology

Web traffic is the amount of data sent and received by visitors to a website. This necessarily does not include the traffic generated by bots. Since the mid-1990s, web traffic has been the largest portion of Internet traffic. This is determined by the number of visitors and the number of pages they visit. Sites monitor the incoming and outgoing traffic to see which parts or pages of their site are popular and if there are any apparent trends, such as one specific page being viewed mostly by people in a particular country. There are many ways to monitor this traffic and the gathered data is used to help structure sites, highlight security problems or indicate a potential lack of bandwidth.

Method and system for securing information exchange against ai-based network traffic by using client-side execution-based challenge-response mechanisms

A system and method for defending against AI-driven web traffic interference is provided. The system and method include: receiving, by an agent, a secret device ID and a web token provided by an authentication server; receiving an instruction to modify a request to a web service stored in a web server; embedding within a WebAssembly (WASM) component executed by the agent, a first portion of an encryption key and a second portion of the encryption key; transmitting the second portion of the encryption key to the authentication server; assembling, at runtime within the WASM component, an actual encryption key by combining the first portion and the second portion of the encryption key; encrypting, using the actual encryption key, the web token in the WASM component to generate a plurality of authentication tokens; and sending a request with the generated plurality of authentication tokens to the authentication server.
Owner:CO RADWARE LTD

Website statistical analysis method, device and equipment and storage medium

The invention discloses a website statistical analysis method, device and equipment and a storage medium, one-button deployment is carried out based on a Docker containerization technology, firstly, a lightweight script in a website page is deployed, basic visitor behavior data not related to the personal identity of a user is collected, the volume of the lightweight script is smaller than 3 KB, and the lightweight script is loaded and executed in an asynchronous mode; encrypting and compressing the acquired basic visitor behavior data, sending the data to a server, storing the data in a database configured by a website host, and analyzing and calculating the data stored in the database to obtain a website traffic core index; and displaying the website traffic core indexes through a visual billboard. Quick installation and configuration can be realized by adopting one-button Docker deployment, extremely low influence on website performance is ensured by embedding an asynchronous script smaller than 3KB, and user privacy and data security can be thoroughly protected only by collecting non-personal identity data and encrypting, compressing and transmitting the non-personal identity data.
Owner:TIANFU JIANGXI LAB

An intelligent web application firewall malicious traffic identification method and system based on a CNN-LSTM hybrid neural network

PendingCN122339763AAlgorithmAttack
This invention relates to the field of network security technology and discloses a method and system for identifying malicious traffic in intelligent Web application firewalls based on a CNN-LSTM hybrid neural network, aiming to address the technical shortcomings of traditional WAFs and existing detection models. This invention constructs an end-to-end intelligent Web traffic detection system, achieving malicious payload deobfuscation through adaptive recursive decoding. It employs a hybrid model combining multi-scale CNN and cascaded LSTM to automate the extraction of local features and long-term semantic features. Combined with SMOTE resampling and data augmentation to optimize model training, and a probability threshold policy decision engine, it achieves accurate handling of malicious traffic. The system adopts a five-layer hierarchical architecture, with highly cohesive and loosely coupled modules that can be deployed in an engineered manner. This invention improves the detection capability against obfuscated attacks and unknown attacks, while reducing false positive rates and operational costs, making it suitable for malicious traffic identification scenarios in Web application firewalls.
Owner:JINLING INST OF TECH

Dark web traffic classification method based on gradient boosting tree

The invention discloses a dark network traffic classification method based on a gradient boosting tree. The method comprises the following steps: constructing a feature matrix and a category matrix according to an original dark web traffic data set; initializing a category weight vector and a cumulative prediction confidence value matrix; introducing a category weight item in front of a loss function item of the XGBoost objective function as a multiplication item, and constructing an initial XGBoost objective function based on an initial category weight vector and an initial cumulative prediction confidence value matrix; based on the initial XGBoost objective function, constructing an initial gradient boosting tree; according to the error rate of each category in the previous round, the category weight is dynamically updated and adjusted to update the XGBoost target function, so that the gradient boosting tree is iteratively constructed until the number of iteration rounds reaches a preset value, and the target gradient boosting tree is finally obtained; and classifying the current dark network traffic based on the target gradient boosting tree. According to the method, a dynamic adjustment mechanism is adopted, so that the model can adaptively increase the attention on the difficult-to-classify categories, and the learning progress of each category is continuously balanced in the training process.
Owner:NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP

Flow analysis early warning method and system

The invention relates to the technical field of flow analysis and early warning, and the method comprises the steps that network flow collected by a flow analysis and early warning system is detected and analyzed through an intrusion detection engine and a behavior detection engine, and a platform provides four data security exchange channels and supports intrusion detection and behavior detection. According to the method, a gene detection technology is used for detecting a variety of a known threat, an intelligent detection technology is combined to prevent escape and avoidance, and a host behavior and a network behavior of a malicious code in a sandbox are deeply analyzed to detect an unknown threat. The intrusion detection engine can sense intrusion in content, environment and application layers. The behavior detection engine carries out file restoration and metadata extraction on traffic, the restored file carries out static detection on known threats through a built-in anti-virus engine, artificial intelligence engine detection is carried out, and malicious encrypted traffic, dark network traffic, hidden tunnels and the like can be detected.
Owner:INFORMATION CENT OF YUNNAN POWER GRID CO LTD

Few-sample multi-label website fingerprint identification method and device

The invention relates to the technical field of information security, and provides a few-sample multi-label website fingerprint identification method and device. The method comprises the following steps: acquiring single-label website traffic data, and constructing multi-label website traffic synthetic data based on the single-label website traffic data; pre-training a teacher model based on the multi-label website traffic synthetic data, wherein the pre-trained teacher model can extract universal features of the multi-label website traffic; obtaining few-sample traffic data of the target multi-label website, and based on the few-sample traffic data and the teacher model, performing fine tuning on the student model through comparative distillation to obtain a target student model of the target multi-label website; and based on the target student model and a plurality of historical samples with similar to-be-identified multi-label website flow data features, carrying out fusion to obtain a multi-label website fingerprint identification result. According to the few-sample multi-label website fingerprint identification method and device provided by the invention, the multi-label website identification capability of the model in a few-sample environment can be improved.
Owner:QINGHAI UNIVERSITY

System and method for application traffic control

A system for managing web traffic comprising a meta control operating on a first processor having a first control interface and configured to generate a request for content and to transmit the request for content over a digital data network to a meta control server. The meta control server operating on a second processor and configured to receive the request for content and to select data for one or more second control interfaces as a function of data associated with the first control interface and to transmit the data for the one or more second control interfaces over the digital data network to the first control interface. The first control interface displays the data for the one or more second control interfaces and monitors user activity associated with the data.
Owner:REWARDSTYLE

Distributed defense architecture (DDA) for distributed denial of service (DDOS) attacks

The present disclosure provides various systems, methods, and devices that can be used to defend against distributed denial of service (DDoS) attacks. In one aspect, the present disclosure provides a method for defending against DDoS attacks that can be implemented by a web server. The web server can generate indirect authentication credentials (IACs) based on authentication credentials associated with a user account and share the IACs with an intermediary server. The intermediary server can be, for example, an Internet server provider server or a proxy server. The web server can further detect anomalies based on web traffic directed to the web server and instruct the intermediary server to verify subsequent web traffic directed to the web server based on the IACs. Thereafter, the web server can receive, via the intermediary server, the verified web traffic directed to the web server.
Owner:VISA INTERNATIONAL SERVICE ASSOCIATION