Methods that support deterministic random media access control (MAC) address rotation that allows sharing of an address identity with a trusted wireless network infrastructure by generating a next address based on a previously used address and a seed obtained from a previous association with the trusted network infrastructure. In these methods, a computing device obtains a request for a secure connection of an endpoint device to a wireless network. The computing device performs an access authentication for the secure connection and establishes the secure connection of the endpoint device to the wireless network based on successfully performing the access authentication, in which cryptographic information for encrypting one or more network messages is generated. The computing device further generates a subsequent device address for a subsequent secure connection of the endpoint device to the wireless network, based on a current device address obtained from the request and the cryptographic information.
H04L 9/32 - Arrangements for secret or secure communicationsNetwork security protocols including means for verifying the identity or authority of a user of the system
Devices, systems, methods, and processes relate to reducing carbon footprint of running an application, such as a latency-sensitive real-time application, on a computing device without compromising responsiveness of the application. The computing device iteratively performs a reinforcement learning process over a time period for the application, where the application is associated with a plurality of events. The plurality of events comprises network events, operating system events, timer events, communication events, collaboration events, security events, or user input events. The computing device learns, based on the iteratively performed reinforcement learning process, an event scheduling ruleset for the application that defines whether to run an event of the plurality of events on a low-power thread or a standard-power thread, and schedules at least one event of the plurality of events based on the learned event scheduling ruleset. The low-power thread has lower energy consumption compared to the standard-power thread.
In one embodiment, a device in a network generates a feature vector based on traffic flow data regarding one or more traffic flows in the network. The device makes a determination as to whether the generated feature vector is already represented in a training dataset dictionary by one or more feature vectors in the dictionary. The device updates the training dataset dictionary based on the determination by one of: adding the generated feature vector to the dictionary when the generated feature vector is not already represented by one or more feature vectors in the dictionary, or incrementing a count associated with a particular feature vector in the dictionary when the generated feature vector is already represented by the particular feature vector in the dictionary. The device generates a training dataset based on the training dataset dictionary for training a machine learning-based traffic flow analyzer.
Systems, devices, and methods for context-aware, Artificial Intelligence (AI)-driven Network Diagnostics and Troubleshooting (AINDT) are provided. An AINDT system receives a user input indicative of a network issue. The user input includes first logs associated with network devices. For an unclassified network issue, the AINDT system determines a network topology from at least one diagnostic context derived based on the user input, extracts log data from second logs based on the user input, the network topology, or configurable criteria, and identifies a root cause of the issue therefrom. For a classified network issue, the AINDT system runs the user input through a filter pipeline to derive at least one diagnostic context, augments a prompt template based on the diagnostic context(s), and identifies a root cause of the issue based on the prompt template. The AINDT system generates at least one recommendation based on the root cause to address the issue.
H04L 41/0631 - Management of faults, events, alarms or notifications using root cause analysisManagement of faults, events, alarms or notifications using analysis of correlation between notifications, alarms or events based on decision criteria, e.g. hierarchy, tree or time analysis
H04L 41/069 - Management of faults, events, alarms or notifications using logs of notificationsPost-processing of notifications
H04L 41/12 - Discovery or management of network topologies
H04L 41/16 - Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks using machine learning or artificial intelligence
H04L 41/22 - Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks comprising specially adapted graphical user interfaces [GUI]
Techniques, which may be embodied herein as systems, computing devices, methods, algorithms, software, code, computer readable media, or the like, are described herein for generating heatmap visualizations. A heatmap visualization can be a graphical representation of data where the coordinates of a cell in the visualization can be a key that describes a group of data represented by the cell. The colors of a heatmap may indicate information about the data represented by the cell (e.g., the amount of data in the cell). These cells can be rendered by calculating a per-pixel metric rate for each dataset in the heatmap visualization and mapping a dataset's rate onto pixels within the visualization that correspond to the dataset. After this mapping, the maximum rate within the visualization can be used to determine the visualization's colors and the cells can be rendered by coloring each pixel (e.g. pixel row) in its corresponding color.
One implementation of the disclosure is directed to an Information Technology Service Intelligence (ITSI) that provides a method including operations of determining one of (i) a probability that a change in data values across subsequences of a time-series data set over an extended historical time period is representative of data drift, (ii) a difference between data values in an earliest-in-time subsequence and a latest-in-time subsequence, or (iii) a percentage of change between the data values in the earliest-in-time subsequence and the latest-in-time subsequence, performing a threshold comparison including one of comparing the probability to a first threshold, the difference to a second threshold, or the percentage of change to a third threshold, and generating a graphical user interface that indicates a presence of data drift in the time-series data set based on a result of the threshold comparison.
One implementation of the disclosure is directed to an Information Technology Service Intelligence (ITSI) that provides methods including operations of obtaining historical data for a metric over a historical time period in the form of a time-series data set associated with an entity, and an alert, correlating the time-series data set with the alert resulting in an identification of a portion of the time-series data set that corresponds to the alert, performing an adaptive threshold generation procedure resulting in generation of a plurality of severity level thresholds in view of the one or more alerts, determining a severity level of a subset of the time-series data set by comparing the subset of the time-series data set to the plurality of severity level thresholds, and generating a graphical user interface that displays a graphical representation of the time-series data set and the plurality of severity level thresholds
H04L 41/0631 - Management of faults, events, alarms or notifications using root cause analysisManagement of faults, events, alarms or notifications using analysis of correlation between notifications, alarms or events based on decision criteria, e.g. hierarchy, tree or time analysis
H04L 43/045 - Processing captured monitoring data, e.g. for logfile generation for graphical visualisation of monitoring data
8.
PERFORMANCE MEASUREMENT ANALYTICS PLATFORM BASED ON TOPOLOGY STABILITY
In one implementation, a method herein comprises: determining a given time during which a computer network is unstable in response to a topology event within the computer network; causing, in response to the computer network being unstable, a measurement analysis process to perform network performance analysis on the computer network based on the computer network being unstable during the given time; and causing, in response to determining that the computer network is otherwise in a stable state, the measurement analysis process to perform network performance analysis on the computer network based on the computer network being stable.
The present disclosure provides techniques for providing probing data in a privacy enhanced network, including receiving, at a first access point (AP) and from a first wireless station (STA) connected to the first AP, an information request associated with a second AP, where the first AP and the second AP are Basic Service Set (BSS) Privacy Enhancement (BPE) APs. The first AP may determine probing data associated with a first probing BSS identifier (BSSID) of the second AP. The first AP may transmit a first response comprising the probing data to the first wireless STA. The first AP may receive, from a second wireless STA connected to the second AP, a probe request for a second probing BSSID of the first AP, where the probe request comprising an authorization token. Based on successfully validating the probe request, the first AP may transmit a probe response to the second wireless STA.
Techniques for protecting source IPs in a network fabric are described. A binding database may receive an indication of an overlay address-to-underlay address binding for a client device connected to the network fabric. The indication is received in a secure message from a fabric edge node through which the client device is connected. The overlay address-to-underlay address binding indicates a first overlay address and an underlay address associated with the fabric edge node. One or more additional overlay addresses are allocated and associated with the overlay address-to-underlay address binding. Each of the one or more additional overlay addresses is mapped to the first overlay address. A second overlay address is assigned, from the one or more additional overlay addresses, to the client device for an IP flow. The fabric edge node intercepts packet of the IP flow and translates a source IP from the first to the second overlay address.
An example embodiment provides a skills-based registration and routing mechanism across a federation of artificial intelligence (AI) agents based on semantic overlap in a vector space of requests and polytope boundaries representing agent capabilities. The routing mechanism enables each AI agent to register their set of capabilities represented as boundaries of a polytope in the vector space with a directory system (e.g., modified or extended Domain Name System (DNS) servers, etc.). A source agent receives a user request and queries the directory system to identify a remote target agent capable of handling the user request based on overlap of the request with advertised polytope boundaries (representing capabilities of remote target agents). The user request is forwarded from the source agent to the identified remote target agent based on a user intent expressed in the user request.
H04L 61/4511 - Network directoriesName-to-address mapping using standardised directoriesNetwork directoriesName-to-address mapping using standardised directory access protocols using domain name system [DNS]
According to one or more embodiments of the disclosure, an example process herein may comprise: causing, responsive to a triggering event, establishment of a service tree that follows a same path as a multicast parent tree through a data communication network to one or more intended recipient devices; causing a duplication of a particular flow from the multicast parent tree to the service tree; causing a determination of a performance characteristic of the particular flow through the service tree; and causing an association of the performance characteristic with the multicast parent tree.
Buffer Status Report Pole (BSRP) trigger enhancement to query specific feedback may be provided. An initiator Access Point (AP) may send a trigger frame wherein the trigger frame comprises a feedback indicator. Next a receiving device may send a Multi-Station Block Acknowledge (Multi-STA BA) in response to the trigger frame wherein feedback information is included in the Multi-STA BA in response to the trigger frame comprising the feedback indicator. Then the initiator AP may receive the feedback information in the Multi-STA BA.
Systems and methods are described for dividing execution of a pipeline between a first processing system and a second processing system based on a policy. The pipeline definition may include data manipulation operations for execution against input data. An input data pathway may include a route for entry of the input data into a first processing system. The policy may include a ruleset for dividing execution of the data manipulation operations between the first processing system and a second processing system. The data intake and query system may generate instructions for the first processing system to execute a first data manipulation operation of the pipeline against input data and generate output, and also for the second processing system to execute a second data manipulation operation of the pipeline against the output. The data intake and query system may then execute the pipeline against input data from the input data pathway.
An example embodiment provides a skills-based registration and routing mechanism across a federation of artificial intelligence (Al) agents based on semantic overlap in a vector space of requests and polytope boundaries representing agent capabilities. The routing mechanism enables each Al agent to register their set of capabilities represented as boundaries of a polytope in the vector space with a directory system (e.g., modified or extended Domain Name System (DNS) servers, etc.). A source agent receives a user request and queries the directory system to identify a remote target agent capable of handling the user request based on overlap of the request with advertised polytope boundaries (representing capabilities of remote target agents). The user request is forwarded from the source agent to the identified remote target agent based on a user intent expressed in the user request.
The present disclosure provides techniques for providing probing data in a privacy enhanced network, including receiving, at a first access point (AP) and from a first wireless station (STA) connected to the first AP, an information request associated with a second AP, where the first AP and the second AP are Basic Service Set (BSS) Privacy Enhancement (BPE) APs. The first AP may determine probing data associated with a first probing BSS identifier (BSSID) of the second AP. The first AP may transmit a first response comprising the probing data to the first wireless STA. The first AP may receive, from a second wireless STA connected to the second AP, a probe request for a second probing BSSID of the first AP, where the probe request comprising an authorization token. Based on successfully validating the probe request, the first AP may transmit a probe response to the second wireless STA.
The present disclosure provides techniques for identifying and transmitting values related to a capability or operation parameter of an Enhanced Privacy Protection (EPP) access point, including receiving, by a first AP and from a first wireless station associated to the first AP, a protected wireless management request frame, where the request frame includes a request that identifies at least one link of the first AP and at least one capability or operation parameter of the at least one link. The first AP may determine, based on the request, a set of values for the at least one capability or operation parameter of the at least one link. The first AP may encode a protected wireless management response frame, wherein the protected wireless management response frame includes the set of values for the at least one link, and may transmit the protected wireless management frame to the first wireless station.
H04W 12/02 - Protecting privacy or anonymity, e.g. protecting personally identifiable information [PII]
H04L 67/12 - Protocols specially adapted for proprietary or special-purpose networking environments, e.g. medical networks, sensor networks, networks in vehicles or remote metering networks
H04W 8/22 - Processing or transfer of terminal data, e.g. status or physical capabilities
An example embodiment automatically classifies portions of an audio or digital interaction as a good or bad experience based on silence and/or crosstalk. The example embodiment automatically detects silence and crosstalk, and uses this information and a set of criteria to classify an interaction with a user as a good (positive) or bad (negative) experience. The example embodiment combines machine learning (ML) language model analysis of transcripts, silence detection, and crosstalk detection, to classify portions (e.g., silence and crosstalk) of an audio interaction as a good (positive) or bad (negative) experience for the user. A communication may be marked for live coaching or review based on the classifications of the interactions of the agent with users.
A system and method are provided for explaining ontological sub-graphs. The system and method include querying an ontology to determine a match between a query graph and a portion of an ontology graph. When there is a match, a subgraph representing the match is first translated into a simple summary using a simple language (e.g., triplets which include a subject and object corresponding to pairs of connected nodes in the subgraph and a verb/predicate representing a relation/edge in the subgraph that connect the pair nodes). This simple summary is then fed, as part of a prompt, to a large language model (LLM) that generates a human-readable summary based on the prompt.
G06F 21/57 - Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
G06F 11/34 - Recording or statistical evaluation of computer activity, e.g. of down time, of input/output operation
The present disclosure provides techniques for identifying and transmitting future Basis Service Set identifiers (BSSIDs) for access points (APs) in an Extended Service Set (ESS), including implementing, by a first AP, a BSS for one or more wireless stations, where an ESS includes the first AP and a second AP neighboring the first AP, and where the second AP is a basic service set privacy enhancements (BPE) AP. The first AP may encode a wireless management frame including a neighbor report element for the second AP, where the neighbor report element includes data indicating a basic service set identifier (BSSID) for one or more next epochs. Further, the wireless management frame may be transmitted by the first AP to a wireless station of the BSS.
One implementation of the disclosure is directed to an Information Technology Service Intelligence (ITSI) that provides methods for automatically generating one or more severity level thresholds for a metric represented by a time-series data set through adaptive thresholding. One implementation may include operations to retrieve a historical time-series data set that represents a KPI or metric being monitored, perform an adaptive threshold generation process for the time-series data set that includes automatically selecting a seasonality pattern that corresponds to the time-series data set and determining a set of thresholds based thereon. Selecting a seasonality pattern may involve, for each candidate seasonality pattern, computing a silhouette score that indicates how closely a candidate seasonality pattern corresponds to the time-series data set. Based on the selected seasonality pattern, a plurality of severity level thresholds may be determined using a statistical computation such as standard deviation, quantile, percentile, range, etc.
Systems and methods for broadcasting unsolicited management frames after a channel switch in accordance with embodiments of the disclosure are described. A device, such as an access point, can determine to switch from a first channel to a second channel and calculate a max channel switch time. This time represents a delta between the last beacon transmit time on the first channel and the point of service readiness on the second channel. After switching at least one radio to the second channel and confirming physical or regulatory readiness, the network device can schedule an unsolicited management frame for immediate transmission. This frame, which may be an unsolicited probe response, notifies associated stations of availability before the next scheduled beacon interval. Stations can calculate their own ready times based on the signaled switch time to wake up and resume data transmission without performing a full re-association procedure, thereby reducing perceptible latency.
Described herein is a wireless access point that signals when the access point changes bandwidth. The wireless access point includes one or more memories and one or more processors communicatively coupled to the one or more memories. The one or more processors, individually or collectively, perform an operation that includes based on determining that a bandwidth of a channel should be expanded to an expanded bandwidth, determining (i) a first time when the wireless access point will begin expanding the bandwidth and (ii) an amount of time the wireless access point will use to expand the bandwidth starting at the first time, transmitting, before the first time, a first message indicating the first time, transmitting, before the first time, a second message indicating the amount of time, and at the first time, expanding the bandwidth of the channel.
Disclosed are methods, controllers, and computer-readable media that explicitly label data packets and interfaces as trusted or untrusted. The data packet labeling can occur at a centralized security hub or at the enforcement site itself, i.e., at the interface to the trusted or untrusted region. The packet can be labeled with metadata associated with the packet, and that label can be carried through the transport of the packet to avoid overbroad or unnecessary security procedures. Further, a network administrator can designate certain links as trusted or untrusted so that packets designated as trusted can be sent down trusted links, and untrusted traffic can be sent down untrusted links. Network resources are saved while traffic is better separated and allocated down links with trustworthiness that is congruent with that of the packet.
In one implementation, a device may obtain a Simple Two-way Active Measurement Protocol test packet that includes hop-by-hop data collected by the Simple Two-way Active Measurement Protocol test packet along its path. The device may determine whether the Simple Two-way Active Measurement Protocol test packet includes an instruction to reflect the hop-by-hop data back to an originating session sender. The device may copy, based on a determination that the Simple Two-way Active Measurement Protocol test packet includes the instruction, the hop-by-hop data into a type-length-value segment of a reply Simple Two-way Active Measurement Protocol test packet. The device may transmit the reply Simple Two-way Active Measurement Protocol test packet back to the originating session sender.
Optical modules are provided. In one aspect, an optical module includes a printed circuit board (PCB) and a cover having a flange coupled with the PCB. The PCB and the cover are sealed such that when the PCB and the cover are disposed in an immersion fluid the PCB and the cover collectively define a sealed interior that is fluidly isolated from the immersion fluid. The optical module also includes an optical fiber and an electro-optical package disposed in the sealed interior. The electro-optical package has a lens body providing an optical path along which optical signals travel. The optical fiber is in free space optical communication with the optical path of the lens body. A fiber escape is formed by the flange and the PCB, allowing the optical fiber to escape the sealed interior into the immersion fluid.
G02B 6/42 - Coupling light guides with opto-electronic elements
H01L 23/44 - Arrangements for cooling, heating, ventilating or temperature compensation the complete device being wholly immersed in a fluid other than air
H01L 25/16 - Assemblies consisting of a plurality of individual semiconductor or other solid-state devices the devices being of types provided for in two or more different subclasses of , , , , or , e.g. forming hybrid circuits
Methods are provided for a proxy infrastructure that serves as a bridge between an enterprise network and a computing machine of a user, ensuring a chain of trust. The methods involve obtaining, from a client device, a request to navigate to one or more target devices of a remote enterprise network and locally authenticating the client device based on at least one of an identity of the client device and user credentials. The methods further involve generating a connection request for the client device to navigate to the one or more target devices based on the client device being locally authenticated and providing the connection request to a proxy service executing in the remote enterprise network. The proxy service authenticates an access to the one or more target devices based on device credentials while hiding the device credentials from the client device.
The present disclosure provides techniques for identifying and transmitting future association identifiers (AIDs) for wireless stations (STAs) in a Basic Service Set, including identifying, by an access point (AP), a frame to be transmitted. The AP may determine, during a current epoch, a first AID for a first station. The AP may determine a first epoch discriminator, such as an even/odd bit, of the current epoch with respect to the first AID. The AP may transmit the first frame comprising the first AID and the first epoch discriminator, such as transmitting the first frame to the first station.
The present disclosure provides a method for providing real-time delay feedback for triggered uplink (UL) access, including buffering, by a client device, one or more uplink data units for transmission in a first transmit (Tx) queue, determining, by the client device, for each respective buffered uplink data unit of the one or more buffered uplink data units, a respective expiry deadline (ED) based on a respective delay bound associated with the respective buffered uplink data unit, and transmitting, by the client device, delay feedback information to an access point (AP), wherein the delay feedback information is determined based on the respective EDs of the one or more buffered uplink data units.
The present disclosure provides a method for providing real-time delay feedback for triggered uplink (UL) access, including buffering, by a client device, one or more uplink data units for transmission in a first transmit (Tx) queue, determining, by the client device, for each respective buffered uplink data unit of the one or more buffered uplink data units, a respective expiry deadline (ED) based on a respective delay bound associated with the respective buffered uplink data unit, and transmitting, by the client device, delay feedback information to an access point (AP), wherein the delay feedback information is determined based on the respective EDs of the one or more buffered uplink data units.
Systems and methods for broadcasting unsolicited management frames after a channel switch in accordance with embodiments of the disclosure are described. A device, such as an access point, can determine to switch from a first channel to a second channel and calculate a max channel switch time. This time represents a delta between the last beacon transmit time on the first channel and the point of service readiness on the second channel. After switching at least one radio to the second channel and confirming physical or regulatory readiness, the network device can schedule an unsolicited management frame for immediate transmission. This frame, which may be an unsolicited probe response, notifies associated stations of availability before the next scheduled beacon interval. Stations can calculate their own ready times based on the signaled switch time to wake up and resume data transmission without performing a full re-association procedure, thereby reducing perceptible latency.
Described herein is a wireless access point that signals when the access point changes bandwidth. The wireless access point includes one or more memories and one or more processors communicatively coupled to the one or more memories. The one or more processors, individually or collectively, perform an operation that includes based on determining that a bandwidth of a channel should be expanded to an expanded bandwidth, determining (i) a first time when the wireless access point will begin expanding the bandwidth and (ii) an amount of time the wireless access point will use to expand the bandwidth starting at the first time, transmitting, before the first time, a first message indicating the first time, transmitting, before the first time, a second message indicating the amount of time, and at the first time, expanding the bandwidth of the channel.
Reporting traffic feedback in a Multi-Station Block Acknowledge (Multi-STA BA) for Coordinated Time Division Multiple Access (Co-TDMA) may be provided. A sharing Access Point (AP) may send a Buffer Status Report Pole (BSRP) trigger frame. The sharing AP may then receive, from at least one polled AP in a respective at least one Multi-Station Block Acknowledge (Multi-STA BA) in response to the BSRP trigger frame, traffic related feedback information. Next, the sharing AP may determine Transmission Opportunity (TxOP) sharing based on the traffic related feedback information.
One implementation of the disclosure is directed to an Information Technology Service Intelligence (ITSI) that provides methods for automatically generating one or more severity level thresholds for a metric represented by a time-series data set through adaptive thresholding. One implementation may include operations to retrieve a historical time-series data set that represents a KPI or metric being monitored, perform an adaptive threshold generation process for the time-series data set that includes automatically selecting a seasonality pattern that corresponds to the time-series data set and determining a set of thresholds based thereon. Selecting a seasonality pattern may involve, for each candidate seasonality pattern, computing a silhouette score that indicates how closely a candidate seasonality pattern corresponds to the time-series data set. Based on the selected seasonality pattern, a plurality of severity level thresholds may be determined using a statistical computation such as standard deviation, quantile, percentile, range, etc.
The present disclosure provides techniques for identifying and transmitting future association identifiers (AIDs) for wireless stations (STAs) in a Basic Service Set, including identifying, by an access point (AR), a frame to be transmitted. The AR may determine, during a current epoch, a first AID for a first station. The AR may determine a first epoch discriminator, such as an even/odd bit, of the current epoch with respect to the first AID. The AR may transmit the first frame comprising the first AID and the first epoch discriminator, such as transmitting the first frame to the first station.
Systems and methods are described for log data metricization of inherited input data. A data intake and query system may receive a pipeline definition comprising one or more data manipulation operations. The data intake and query system may initiate processing of an input data set with a first data pathway of the pipeline, the first data pathway configured to process the input data set in accordance with the first subset of data manipulation operations and to output to a log destination. The data intake and query system may further cause a second data pathway to inherit the input data set from the first data pathway. The input data set may continue along the first data pathway to the log destination after inheritance. The second data pathway may process the inherited data set in accordance with the second subset of data manipulation operations and output to the metrics destination.
Embodiments are directed towards real time display of event records and extracted values based on at least one extraction rule, such as a regular expression. A user interface may be employed to enable a user to have an extraction rule automatically generate and/or to manually enter an extraction rule. The user may be enabled to manually edit a previously provided extraction rule, which may result in real time display of updated extracted values. The extraction rule may be utilized to extract values from each of a plurality of records, including event records of unstructured machine data. Statistics may be determined for each unique extracted value, and may be displayed to the user in real time. The user interface may also enable the user to select at least one unique extracted value to display those event records that include an extracted value that matches the selected value.
G06F 7/00 - Methods or arrangements for processing data by operating upon the order or content of the data handled
G06F 3/0484 - Interaction techniques based on graphical user interfaces [GUI] for the control of specific functions or operations, e.g. selecting or manipulating an object, an image or a displayed text element, setting a parameter value or selecting a range
Operating modes and unavailability schedules transfer during roaming may be provided. An access point multi-link device (AP MLD) receives a roaming request from a non-AP MLD indicating links to setup with a target AP MLD, information for establishing one or more operating modes and associated operating parameters for the one or more links, and/or information for establishing one or more unavailability periods for the one or more links. The AP MLD transmits to the target AP MLD an indication for establishing the operating modes and associated operating parameters, an indication for establishing the unavailability periods, or both. The AP MLD receives a status indication indicating whether the operating modes and associated operating parameters were successfully established, whether the unavailability periods were successfully established, or both and transmits roaming response comprising the status indication to the non-AP MLD.
The present disclosure provides techniques for identifying and transmitting values related to a capability or operation parameter of an Enhanced Privacy Protection (EPP) access point, including receiving, by a first AP and from a first wireless station associated to the first AP, a protected wireless management request frame, where the request frame includes a request that identifies at least one link of the first AP and at least one capability or operation parameter of the at least one link. The first AP may determine, based on the request, a set of values for the at least one capability or operation parameter of the at least one link. The first AP may encode a protected wireless management response frame, wherein the protected wireless management response frame includes the set of values for the at least one link, and may transmit the protected wireless management frame to the first wireless station.
Systems and methods for modular power characterization and predictive sustainability optimization are described herein. The system includes a testing environment configured to generate a library of modular component characterizations, such as fractional power scaling data for individual radios under controlled thermal stressors. A sustainability logic retrieves this modular data to model a cumulative power sum for a projected network topology, accounting for dynamic variables like signal attenuation across multi-hop paths. The system further integrates heterogeneous platforms by normalizing power data across compute and networking layers into a unified sustainability metric using high-fidelity real-time telemetry. A multifactor optimization engine processes the modeled signal paths against business and environmental needs to determine a return on energy metric. Ultimately, the system automatically identifies specific architectural changes to a customer install base required to meet a predetermined sustainability target, such as a net-zero emissions goal.
H04L 41/0833 - Configuration setting characterised by the purposes of a change of settings, e.g. optimising configuration for enhancing reliability for reduction of network energy consumption
H04L 43/08 - Monitoring or testing based on specific metrics, e.g. QoS, energy consumption or environmental parameters
42.
Facilitating mixed-mode external result provider operations
A search request received at a computer of a search support system is processed by analyzing the received search request to identify request parameters and connecting to a system index of the search support system that is referenced in the request parameters. An external result provider (ERP) process is initiated that establishes communication between the search support system and a data source external to the search support system, for a virtual index referenced in the request parameters. Thus, the ERP process provides an interface between the search support system and external data sources, such as by third parties. The ERP process can operate in a streaming mode (providing real-time search results with minimal processing) and/or a reporting mode (providing results with a greater delay and processing extent) and can switch between modes. The search request results are received from the connected system indexes and the referenced virtual indexes.
Described herein is a wireless network that allows non-AP MLDs and AP MLDs to adjust, negotiate, or renegotiate BA agreements during roaming. A first AP MLD includes one or more memories and one or more processors communicatively coupled to the one or more memories. The one or more processors, individually or collectively, perform an operation that includes receiving a message indicating that (i) a first BA agreement with a non-AP MLD should be maintained when the non-AP MLD roams from the first AP MLD to a second AP MLD and (ii) a second BA agreement with the non-AP MLD should be changed when the non-AP MLD roams from the first AP MLD to the second AP MLD, and based on the message, communicating the first BA agreement to the second AP MLD and refraining from communicating the second BA agreement to the second AP MLD.
Described herein is a network that uses enhanced link reconfiguration requests and link reconfiguration responses to perform seamless roaming. A first AR MLD performs an operation that includes receiving, from a non-AP MLD, a first link reconfiguration request that includes a first multi-link element that indicates a second AP MLD in a SMD of the first AP MLD and that indicates one or more links requested to be added at the second AP MLD for roaming preparation, a first roaming phase indication that indicates a roaming preparation phase, and a roaming request control indicating roaming context information from the non-AP MLD for roaming preparation at the second AP MLD. The operation also includes, based on the first link reconfiguration request, requesting the second AP MLD to initiate roaming preparation using the first multi-link element, the first roaming phase indication, and the roaming request control.
A selection of a Pairwise Master Key (PMK) caching method in a wireless deployment may be provided. One or more PMK caching methods that are supported by a wireless infrastructure may be advertised. A selection of a PMK caching method based on the advertised one or more PMK caching methods may be received from a first station. The first station may be authenticated in the wireless infrastructure. In response to authenticating, a PMK entry in a cache store associated with the PMK caching method may be created for the first station based on the selection.
An optical media converter configured to convert an optical signal with a first modulation scheme to a second optical signal with a second modulation scheme. The optical media converter receives the optical signal and converts the optical signals into electrical signals corresponding to the optical signal with the first modulation scheme. A DSP in the optical media converter modifies the electrical signals to correspond with an optical signal with the second modulation scheme. The optical media converter generates the second optical signal with the second modulation scheme based on the modified electrical signals and transmits the second optical signal out of the optical media converter.
Radio discovery for a mesh Access Point (AP) may be provided. Topology information associated with a first network may be received wherein the first network may comprise a mesh network. A Topology Descriptor Message (TDM) may then be created based on the topology information. The TDM may then be transmitted by a first Access Point (AP).
Techniques for ensuring symmetric forwarding between disparate networks are described herein. In active/standby hub architectures, hub nodes may be configured to convert a preference order (e.g., indicating a preferred hub node), specified by an endpoint on a wide-area network (WAN)-side of a network, into a local-area network (LAN)-side-routing-metric that is distributed to datacenter router(s) on the LAN-side of the network. When an active hub node loses connection to all of the available routing controllers, the active hub may automatically manipulate the LAN-side-routing-metric to make the metric worse than the standby hub to indicate that the routes being advertised by the active hub are “stale,” such that the datacenter routers prefer the standby hub, avoiding traffic asymmetry as a result of the lost connection.
Devices, systems, methods, and processes for facilitating edge-based roaming management are described herein. A roaming management logic, deployed at a network device maintains traffic steering policy information associated with a plurality of client devices. The network device detects a client device roaming from a first edge node in the network and identifies a subset of edge nodes to which the client device may roam to. The identification of the subset of edge nodes is based on a list of neighbor access points associated with an access point associated with the first edge node or a historical roaming pattern of the client device received by the network device. The network device transmits a traffic steering policy context or a group tag context associated with the client device to the identified subset of edge nodes based on the detection of the client device roaming from the first edge node.
H04W 8/02 - Processing of mobility data, e.g. registration information at HLR [Home Location Register] or VLR [Visitor Location Register]Transfer of mobility data, e.g. between HLR, VLR or external networks
50.
STREAM CLASSIFICATION SERVICE RESOURCE RESERVATION AND NEGOTIATION FOR SEAMLESS ROAMING
The present disclosure provides a method for stream classification service (SCS) resource reservation and renegotiation or negotiation for seamless roaming, including receiving, by a serving access point multi-link device (AP MLD) from a station multi-link device (STA MLD) connected with the serving AP MLD, a roaming preparation request identifying a plurality of stream classification service (SCS) streams of the STA MLD, forwarding, by the serving AP MLD, SCS-related information corresponding to one or more SCS streams, among the plurality of SCS streams, to a target AP MLD as part of a roaming preparation procedure, receiving, by the serving AP MLD from the target AP MLD, reservation status information indicating whether resources have been reserved for the one or more SCS streams forwarded by the serving AP MLD, and transmitting, by the serving AP MLD to the STA MLD, a roaming preparation response comprising the reservation status information.
Seamless roaming preparation for a STA to multiple target AR MLDs. An AR MLD that the STA is connected to can receive multiple roaming preparation requests from the STA for different target AR MLDs. The AR MLD transmits the roaming preparation requests to the different target AR MLDs and receives a response from the different target AR MLDs indicating whether each of the different target AR MLDs accepted the roaming preparation request. The AR MLD transmits the responses back to the STA along with roaming information for at least one target AR MLD.
Described herein is a network that allows a non-AP MLD to delete (or cancel) a previous roaming preparation with a target AP MLD. A first AP MLD performs an operation that includes receiving, from a non-AP MLD, a first link reconfiguration request indicating that the non-AP MLD is requesting to perform roaming preparation for a second AP MLD, instructing the second AP MLD to perform roaming preparation for the non-AP MLD based on the first link reconfiguration request, transmitting, to the non-AP MLD, a first link reconfiguration response indicating that the second AP MLD is prepared for roaming, after transmitting the first link reconfiguration response, receiving, from the non-AP MLD, a second link reconfiguration request requesting deletion of the roaming preparation at the second AP MLD, and instructing the second AP MLD to delete the roaming preparation based on the second link reconfiguration request.
H04W 36/28 - Reselection being triggered by specific parameters by agreed or negotiated communication parameters involving a plurality of connections, e.g. multi-call or multi-bearer connections
Multi-link power save (MLPS) indication may be provided. An access point (AP) multi-link device (MLD) establishes a plurality of links with a non-AP MLD. The AP MLD receives, via a link of the plurality of links, an MLPS indication and determines a power management (PM) mode for two or more links of the plurality of links based on the MLPS indication, including determining at least a first link of the two or more links is in an active mode and determining at least a second link of the two or more links is in a power save mode. The AP MLD manages communications with the non-AP MLD based on the PM mode for the two or more links.
Operating modes and unavailability schedules transfer during roaming may be provided. An access point multi-link device (AP MLD) receives a roaming request from a non-AP MLD indicating links to setup with a target AP MLD, information for establishing one or more operating modes and associated operating parameters for the one or more links, and/or information for establishing one or more unavailability periods for the one or more links. The AP MLD transmits to the target AP MLD an indication for establishing the operating modes and associated operating parameters, an indication for establishing the unavailability periods, or both. The AP MLD receives a status indication indicating whether the operating modes and associated operating parameters were successfully established, whether the unavailability periods were successfully established, or both and transmits roaming response comprising the status indication to the non-AP MLD.
Systems and methods are disclosed for generating partition-specific commands. A system may receive a query and identify a partitioned command within the query. The system may identify sets of data processing commands associated with the partitioned command, generate a body for the partitioned command, and process the query using the generated body of the partitioned command. To generate the body for the partitioned command the query system may generate multiple sets of partition-specific commands and sets of partition-specific criteria based on the sets of data processing commands.
A process for facilitating downscaling of data stores in a parallel manner (e.g., in a stateful system) is described herein. In embodiments, a request to scale down a data store is received at the data store. At a ledger manager, an indication of a set of ledgers, associated with the data store, for which to replicate is maintained. Based on the scale down request, a plurality of scale-down jobs is initiated to perform parallel replication of ledgers associated with the data store. The plurality of scale-down jobs replicate at least a portion of the set of ledgers in parallel. Thereafter, it is identified that the plurality of scale-down jobs have completed ledger replication of the set of ledgers associated with the data store. Based on the completion of the replication of the set of ledgers associated with the data store, the data store is terminated.
G06F 16/27 - Replication, distribution or synchronisation of data between databases or within a distributed database systemDistributed database system architectures therefor
Techniques are described for automatically identifying and configuring application connectors relevant to an IT environment by obtaining and analyzing data reflecting activity within the IT environment. The identification of types of assets within the IT environment may be based on analyzing a field value indicating a type of computing asset to which an event relates. The field value might indicate, for example, the presence of various types of computing devices, software applications, network devices, and so forth. Based on the identification of types of assets present in the IT environment, an application automatically configures corresponding connectors for those types of assets.
Scanning techniques are described that assign APs with overlapping detection ranges into groups, and then ensuring those APs use different scanning patterns to scan the channels in a frequency band (e.g., the channels in the 2.4 GHz, 5 GHz, or 6 GHz frequency bands) to identify rogue devices. Because the APs use different scanning patterns (e.g., while a first AP scans for a rogue device in Channel 1 a second AP can scan for a rogue device in Channel 2), this means that two channels can be scanned in the regions where the detections ranges of the APs overlap (rather than the APs scanning the same channels at the same time). This results in the APs being able to identify rogue devices sooner, which provides the technical benefit of being able to mitigate the harmful effects of a rogue device sooner.
A policy enforcement assistant is provided to assist in identifying and implementing configuration changes within a network. The policy enforcement assistant can receive inputs such as administrator inputs, and can determine intent indications based on the inputs, wherein the intent indications indicate configuration change intents affecting the network. The policy enforcement assistant can identify, based on an intent indication, multiple configuration changes under an applicable network policy. The policy enforcement assistant can furthermore identify implementation paths for each of the configuration changes. The implementation paths can use different network management tools to implement the configuration changes. The policy enforcement assistant can either execute the configuration changes via the implementation paths or instruct a user regarding executing the configuration changes.
H04L 41/16 - Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks using machine learning or artificial intelligence
The present disclosure provides techniques for managing association identifier (AID) assignment in enhanced data privacy (EDP) operation. An access point (AP) establishes a wireless communications link with a station, comprising receiving an association request frame from the wireless station, assigning the station to an EDP group, generating a first list of N AIDs for the station, each of the N AIDs to be used in a corresponding epoch of N epochs associated with the EDP group, and transmitting an association response frame to the station, where the response frame comprises information indicating the assigned EDP group and the first list of N AIDs for the wireless station. The AP maintains the wireless communications link with the wireless station based at least in part on the timing information for randomized MAC address rotation for the EDP group, comprising using each AID in the list of N AIDs during corresponding epochs.
Disclosed are systems, apparatuses, methods, and computer-readable media for adaptive preferred scan channels in wireless networks. A method includes: retrieving previous client device information connected to at least one access point (AP), analyzing the previous client device information for at least one property associated with wireless network usage of the at least one AP; and determining whether to configure preferred scan channels with additional channels based on the at least one property associated with the wireless network. Adding preferred scan channels to the default configuration can benefit wireless network performance.
In one embodiment, a method herein comprises: receiving, by a first access point having a transmit opportunity for a wireless channel in a wireless network, information indicative of buffered traffic at two or more other access points operating on the wireless channel; determining, by the first access point, based on spatial isolation information, that the two or more other access points are compatible for concurrent transmissions during a portion of the transmit opportunity; selecting, by the first access point, a coordinated spatial reuse configuration in which the two or more other access points are permitted to communicate concurrently during the portion of the transmit opportunity while the first access point refrains from transmitting user data during the portion; and transmitting, by the first access point, control signaling that causes the two or more other access points to perform the concurrent transmissions during the portion of the transmit opportunity.
Described herein is a wireless network that allows non-AP MLDs and AP MLDs to adjust, negotiate, or renegotiate BA agreements during roaming. A first AP MLD includes one or more memories and one or more processors communicatively coupled to the one or more memories. The one or more processors, individually or collectively, perform an operation that includes receiving a message indicating that (i) a first BA agreement with a non-AP MLD should be maintained when the non-AP MLD roams from the first AP MLD to a second AP MLD and (ii) a second BA agreement with the non-AP MLD should be changed when the non-AP MLD roams from the first AP MLD to the second AP MLD, and based on the message, communicating the first BA agreement to the second AP MLD and refraining from communicating the second BA agreement to the second AP MLD.
Described herein is a network that uses enhanced link reconfiguration requests and link reconfiguration responses to perform seamless roaming. A first AP MLD performs an operation that includes receiving, from a non-AP MLD, a first link reconfiguration request that includes a first multi-link element that indicates a second AP MLD in a SMD of the first AP MLD and that indicates one or more links requested to be added at the second AP MLD for roaming preparation, a first roaming phase indication that indicates a roaming preparation phase, and a roaming request control indicating roaming context information from the non-AP MLD for roaming preparation at the second AP MLD. The operation also includes, based on the first link reconfiguration request, requesting the second AP MLD to initiate roaming preparation using the first multi-link element, the first roaming phase indication, and the roaming request control.
Multi-link power save (MLPS) indication may be provided. An access point (AP) multi-link device (MLD) establishes a plurality of links with a non-AP MLD. The AP MLD receives, via a link of the plurality of links, an MLPS indication and determines a power management (PM) mode for two or more links of the plurality of links based on the MLPS indication, including determining at least a first link of the two or more links is in an active mode and determining at least a second link of the two or more links is in a power save mode. The AP MLD manages communications with the non-AP MLD based on the PM mode for the two or more links.
The present technology provides solutions for performing real-time analytics based on generated telemetry. An example method includes identifying an executable file and one or more actions performed on a host, where the one or more actions are associated with the executable file, generating, by a data processing unit, a behavioral graph having one or more nodes based on the executable file and the one or more actions, and determining, by the data processing unit, that the executable file is a malicious file based on the behavioral graph. Computer-readable media and systems are also provided.
G06F 21/57 - Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
68.
DELIVERY TRAFFIC INDICATION MESSAGE (DTIM) GROUPCAST TECHNIQUES IN MULTI-LINK OPERATION (MLO) AND NON-MLO ENVIRONMENTS
Various Delivery Traffic Indication Message (DTIM) groupcast techniques that may be utilized in multi-link operation (MLO) and non-MLO scenarios for one or more wireless local area networks (WLANs) are provided herein. The techniques can facilitate power saving operations for client devices and/or enhanced Non-Primary Channel Access (NPCA) operations for client devices and AP devices in overlapping basic service set (OBSS) environments.
Techniques for utilizing a language model to mitigate a network vulnerability are described. A language model is deployed that is configured to respond to inputs from network operators. The language model receives a first input from the network operator indicating a description of a network vulnerability. The language model receives a second input including information associated with a configuration of the network. The language model determines a series of actions to execute to mitigate the network vulnerability. Finally, the language model outputs the series of actions to execute to the network operator.
G06F 21/57 - Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
Techniques for providing a language model to understand and recommend product configuration changes, corresponding to specific requirements are described. A language model is deployed to a network controller and is configured to respond to inputs from network administrators. The language model receives an input from the netw ork administrator indicating a description of a requirement for a configuration change. The language model determines a series of actions to execute to implement the configuration change. Finally, the language model outputs the series of actions to execute to the network administrator.
H04L 41/16 - Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks using machine learning or artificial intelligence
71.
CLIENT SIGNALING FOR INDICATING LINKS FOR TARGET ACCESS POINT FOR SEAMLESS ROAMING
Client signaling for indicating links for a target Access Point (AP) to use for seamless roaming may be provided. A target AP establishes one or more links with a client device for roaming to the target AP, wherein the links are configured in a power save mode by default. The target AP receives signaling indicating availability of a link of the one or more links for transmissions to the client device. The target AP determines, based on the signaling, when the link is available for transmissions and initiates one or both of downlink transmissions and triggered uplink transmissions to the client device on the link after determining the link is available.
Techniques for investigating security incident(s) using a multi-agent framework to improve efficiency and accuracy of identifying threats, while reducing costs and resource usage of a system. A system may receive alert(s) corresponding to security incident(s) across customer networks. The system may correlate a subset of the alert(s) with a particular security incident and identify resource(s) available to a customer network associated with the security incident. The system may generate, using agent(s), a summary of the security incident and a dynamic playbook to investigate the security incident. The system may execute, using the agent(s), the tasks and generate output(s). The system may generate and display a recommendation for the security incident based on the outputs. The recommendation may include a status of tire security incident, recommended action(s), supporting evidence, and more.
Client preferences signaling for buffered downlink (DL) data delivery during seamless roaming may be provided. A serving access point (AP) receives a roaming request from a client device, the roaming request indicating an intent to roam from the serving AP to a target AP and including one or more preferences for handling buffered DL data at the serving AP. The serving AP sends a roaming response to the client device, the roaming response indicating parameters for delivering buffered DL data based on the one or more preferences. The serving AP then participates in a buffered DL data delivery phase with the client device based on the parameters indicated in the roaming response, including delivering at least a first portion of the buffered DL data to the client device or forwarding at least a second portion of the buffered DL data to the target AP.
Various Delivery Traffic Indication Message (DTIM) groupcast techniques that may be utilized in multi-link operation (MLO) and non-MLO scenarios for one or more wireless local area networks (WLANs) are provided herein. The techniques can facilitate power saving operations for client devices and/or enhanced Non-Primary Channel Access (NPCA) operations for client devices and AP devices in overlapping basic service set (OBSS) environments.
The present disclosure provides a method for stream classification service (SCS) resource reservation and renegotiation or negotiation for seamless roaming, including receiving, by a serving access point multi-link device (AP MLD) from a station multi-link device (STA MLD) connected with the serving AP MLD, a roaming preparation request identifying a plurality of stream classification service (SCS) streams of the STA MLD, forwarding, by the serving AP MLD, SCS-related information corresponding to one or more SCS streams, among the plurality of SCS streams, to a target AP MLD as part of a roaming preparation procedure, receiving, by the serving AP MLD from the target AP MLD, reservation status information indicating whether resources have been reserved for the one or more SCS streams forwarded by the serving AP MLD, and transmitting, by the serving AP MLD to the STA MLD, a roaming preparation response comprising the reservation status information.
Described herein is a network that allows a non-AP MLD to delete (or cancel) a previous roaming preparation with a target AP MLD. A first AP MLD performs an operation that includes receiving, from a non-AP MLD, a first link reconfiguration request indicating that the non-AP MLD is requesting to perform roaming preparation for a second AP MLD, instructing the second AP MLD to perform roaming preparation for the non-AP MLD based on the first link reconfiguration request, transmitting, to the non-AP MLD, a first link reconfiguration response indicating that the second AP MLD is prepared for roaming, after transmitting the first link reconfiguration response, receiving, from the non-AP MLD, a second link reconfiguration request requesting deletion of the roaming preparation at the second AP MLD, and instructing the second AP MLD to delete the roaming preparation based on the second link reconfiguration request.
A query coordinator can receive a portion of a query from a first distributed data processing system. The query coordinator can identify a second distributed data processing system to execute the portion of the query. Based on identifying the second distributed data processing system, the query coordinator can communicate the portion of the query to a scheme generator. The scheme generator can generate a query processing scheme using the portion of the query and can communicate the query processing scheme to a server associated with the second distributed data processing system. The server can resolve a first portion of the query processing scheme for the second distributed data processing system using a dynamic library as the second distributed data processing system generates a query plan for execution of the portion of the query.
This disclosure describes techniques for mapping local device identifiers used in monitoring data from different sources to a common global identifier to enable correlation of monitoring events related to the same device. The techniques can be used in the context of an Extended Detection and Response (XDR) system architecture for advanced threat detection and response in a computer system. In some cases, the XDR system ingests security data from various monitoring components like Endpoint Detection and Response (EDR), Intrusion Detection Systems (IDSs), Intrusion Prevention Systems (IPSs), firewall engines, and email security systems.
In one aspect, a method for automated creation and management of firewall rules in a network environment, includes obtaining network traffic patterns including data exported from one or more network appliances in the network environment, where the data includes a plurality of network identifiers, automatically generating a first set of firewall rules based on a source and destination of each network identifier, automatically generating a second set of firewall rules based on firewall data including a source and destination of address, and generating a revised set of firewall rules based on the first set of firewall rules and the second set of firewall rules, where the revised set of firewall rules is also based on a detection of a number of times at least one of the second set of rules is invoked at the firewall.
Disclosed herein are systems, methods, and computer-readable media for authentication in a multi-cloud cellular service. In one aspect, a method includes receiving, at a controller of a local site within the multi-cloud cellular service, a network connection request from a device, the cloud-based authentication component being a central network component configured to store device credentials and network policies for authenticating devices connecting to the multi-cloud cellular service across all sites associated with the multi-cloud cellular service. In one aspect, the method also includes locally authenticating, by the controller, the device using stored credential information obtained from the cloud-based authentication component prior to losing the connectivity to the cloud-based authentication component.
Embodiments disclosure herein describe systems, methods, and devices for addressing the challenges of implementing Energy-Efficient Ethernet (EEE) in networks where certain latency-sensitive control protocols are incompatible with EEE or experience degraded performance due to its power-saving mechanisms. Conversely, more devices are being shipped with EEE enabled by default to achieve sustainability-related certifications. In response, various embodiments utilize an EEE management logic that dynamically analyzes network topology data, network traffic data, and EEE settings data to overcome these limitations. By understanding the physical and logical network layout, real-time traffic patterns, and EEE configurations, the system identifies areas where EEE can be safely disabled without negatively affecting critical operations. It can selectively adjust EEE settings to maintain the performance of latency-sensitive protocols while maximizing energy efficiency in less demanding areas. This achieves a desired goal of obtaining reliable operation of latency-sensitive devices, such as industrial control systems, while achieving significant energy savings.
H04L 41/0833 - Configuration setting characterised by the purposes of a change of settings, e.g. optimising configuration for enhancing reliability for reduction of network energy consumption
Systems and methods for Artificial Intelligence (AI)-driven Collaborative Network Event Management (CNEM) are provided. An AI-driven CNEM system includes multiple AI agents operating in a collaborative cycle. The AI-driven CNEM system receives event information associated with a network environment. Using the AI agents, the AI-driven CNEM system receives and evaluates at least one event based on the event information, determines a network management operation based on the evaluation, and triggers at least one action, for example, a recommendation or an execution, associated with the network management operation. The AI agents have designated roles in the collaborative cycle and execute at least one machine learning model for the evaluation of the event(s). The AI-driven CNEM system implements continuous self-learning through previous actions and feedback. The AI-driven CNEM system operates based on an autonomous and collaborative event arbitration cycle that is grounded by local context and domain knowledge.
H04L 41/0659 - Management of faults, events, alarms or notifications using network fault recovery by isolating or reconfiguring faulty entities
H04L 41/22 - Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks comprising specially adapted graphical user interfaces [GUI]
Buffer indication signaling during seamless roaming may be provided. A serving access point (AP) establishes one or more links with a client device, wherein the client device is configured to roam from the serving AP to a target AP. The serving AP transmits buffered downlink (DL) data to the client device during a roaming transition from the serving AP to the target AP. The serving AP determines that the buffered DL data for the client device has been transmitted to the client device and transmits to the client device buffer indication signaling indicating that the serving AP has delivered the buffered DL data for the client device.
This disclosure describes techniques for facilitating communications between users associated with a Security Orchestration, Automation and Response (SOAR) system using a communication platform that is not native to the SOAR system. In some cases, a system is configured to receive a communication provided by a user profile to a communication interface of the native communication platform, determine that the communication interface is associated with a plurality of user profiles, determine that the one of the plurality' of user profiles is associated with the external communication platform, retrieve a set of cross-platform conversion rules for converting communications originating in the native communication platform into communications posted to the external communication platform, determine converted communication data based on the retrieved cross-platform conversion rule(s) and the received communication, and transmit the converted communication to the external communication platform.
The present disclosure provides techniques for managing association identifier (AID) assignment in enhanced data privacy (EDP) operation. An access point (AP) establishes a wireless communications link with a station, comprising receiving an association request frame from the wireless station, assigning the station to an EDP group, generating a first list of N AIDs for the station, each of the N AIDs to be used in a corresponding epoch of N epochs associated with the EDP group, and transmitting an association response frame to the station, where the response frame comprises information indicating the assigned EDP group and the first list of N AIDs for the wireless station. The AP maintains the wireless communications link with the wireless station based at least in part on the timing information for randomized MAC address rotation for the EDP group, comprising using each AID in the list of N AIDs during corresponding epochs.
In one embodiment, a method herein comprises: receiving, by a first access point having a transmit opportunity for a wireless channel in a wireless network, information indicative of buffered traffic at two or more other access points operating on the wireless channel; determining, by the first access point, based on spatial isolation information, that the two or more other access points are compatible for concurrent transmissions during a portion of the transmit opportunity; selecting, by the first access point, a coordinated spatial reuse configuration in which the two or more other access points are permitted to communicate concurrently during the portion of the transmit opportunity while the first access point refrains from transmitting user data during the portion; and transmitting, by the first access point, control signaling that causes the two or more other access points to perform the concurrent transmissions during the portion of the transmit opportunity.
In one embodiment, an apparatus includes an inlet configured to obtain a fluid, an outlet; a manifold, and at least a first port assembly. The manifold includes a first flow chamber and a second flow chamber. The first flow chamber obtains the fluid from the inlet, and the second flow chamber provides the fluid to the outlet. The first port assembly includes a lower first port assembly tunnel, an upper first port assembly tunnel, and a u-turn first port assembly tunnel, wherein the fluid is provided from the first flow chamber to the lower first port assembly tunnel, provided from the lower first port assembly tunnel to the u-turn first port assembly tunnel, and provided from the u-turn first port assembly tunnel to the upper first port assembly tunnel. The fluid is provided from the upper first port assembly tunnel to the second flow chamber.
Apparatuses and methods of fabricating the same are provided. In one aspect, an apparatus includes a substrate, a cladding material disposed on the substrate, a waveguide disposed in the cladding material, and a grating coupler disposed in the cladding material and spaced from the substrate. The grating coupler is arranged to guide an incoming optical signal to the waveguide. The substrate defines a cavity formed, at least in part, by a facet oriented so that a portion of the incoming optical signal that passes through the grating coupler, instead of being guided to the waveguide, reflects off of the facet and is directed away from the grating coupler.
Techniques for providing a language model to understand and recommend product configuration changes, corresponding to specific requirements are described. A language model is deployed to a network controller and is configured to respond to inputs from network administrators. The language model receives an input from the network administrator indicating a description of a requirement for a configuration change. The language model determines a series of actions to execute to implement the configuration change. Finally, the language model outputs the series of actions to execute to the network administrator.
H04L 41/16 - Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks using machine learning or artificial intelligence
91.
AUTOMATED INCIDENT INVESTIGATION USING GENERATIVE MACHINE LEARNING MODELS
This disclosure describes techniques for automatically investigating an incident associated with a monitored computing environment. In some cases, an example method includes providing first data associated with an incident; providing the first data to a first generative machine learning model; receiving, from the first generative machine learning model, second data representing a first query to a first data source system and a second query to a second data source system; receiving a first and a second query response from a first and a second data source system respectively; providing second data determined based on the first query response and the second query response to a second generative machine learning model; receiving, from the second generative machine learning model, third data representing at least one of: (i) a label associated with the incident, or (ii) a recommendation for responding to the incident; and performing an incident response action.
Techniques are described for providing a natural language network security policy assistant for allowing a network administrator to implement network security policies using natural language security policy requests. A natural language request can be received by a user and can be translated using Artificial Intelligence into one or more security policy clauses. If the natural language security policy request leads to ambiguities with regard to intended security policies, one or more clarifying questions can be generated as natural language questions and sent to the user for clarification. One or more security policies can be implemented based on the one or more security policy clauses generated in response to the natural language security policy request and/or the natural language response to the clarifying questions.
In one aspect, the present technology is directed towards providing a self-healing-based auto RRM tuning of a network that allows for a closed-loop and domain specific transition from steady state, or a maintenance, mode to a startup, or a configuration, mode depending on the health score of the network. The ability to switch between network state modes seamlessly upon determining when a startup mode is necessary to improve performance based on the monitoring of a health score, through the monitoring and tracking of the overall network health and performance.
A system and a method to map attack paths in a visualization interface may include storing in a memory asset inventory indicating application assets, attack vector parameters configured to indicate vulnerabilities of one or more of the application assets, and asset mapping information. A processor may determine multiple vulnerable assets in the application assets based at least in part upon the attack vector parameters. Further, the processor may obtain security parameters from a security framework indicating one or more attack techniques, associate each of the vulnerable assets to one or more of the security parameters, and generate a visual interface showing the vulnerable assets and the security parameters. The processor may determine an attack path connecting the vulnerable assets based at least in part upon the asset mapping information, and map the attack path to the application layers and the security parameters in the visual interface.
G06F 21/57 - Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
G06F 9/451 - Execution arrangements for user interfaces
95.
ADAPTABLE MEDIA ACCESS CONTROL ADDRESS ROTATION INTERVALS
Described herein is a system that adjusts how frequently devices rotate MAC addresses. A wireless access point includes one or more memories and one or more processors communicatively coupled to the one or more memories. The one or more processors, individually or collectively, perform an operation that includes assigning a user device to a first group such that the user device rotates a MAC address of the user device based on an epoch duration of the first group, determining that a network security threat level increased, and in response to the network security threat level increasing, reducing the epoch duration to a reduced epoch duration such that the user device rotates the MAC address based on the reduced epoch duration.
Embodiments provide a network device comprising one or more memories and one or more processors communicatively coupled to the one or more memories, wherein the one or more processors are configured to, individually or collectively, perform operations comprising transmitting a stream classification service (SCS) request to a station (STA), the SCS request comprising an SCS identifier (SCSID), a traffic classification (TCLAS) information to identify an SCS flow and a quality of service (QoS) characteristics element that indicates information for the STA to perform QoS classification or prioritization for the SCS flow, and receiving an SCS response from the STA.
Buffer indication signaling during seamless roaming may be provided. A serving access point (AP) establishes one or more links with a client device, wherein the client device is configured to roam from the serving AP to a target AP. The serving AP transmits buffered downlink (DL) data to the client device during a roaming transition from the serving AP to the target AP. The serving AP determines that the buffered DL data for the client device has been transmitted to the client device and transmits to the client device buffer indication signaling indicating that the serving AP has delivered the buffered DL data for the client device.
Client signaling for indicating links for a target Access Point (AP) to use for seamless roaming may be provided. A target AP establishes one or more links with a client device for roaming to the target AP, wherein the links are configured in a power save mode by default. The target AP receives signaling indicating availability of a link of the one or more links for transmissions to the client device. The target AP determines, based on the signaling, when the link is available for transmissions and initiates one or both of downlink transmissions and triggered uplink transmissions to the client device on the link after determining the link is available.
Client preferences signaling for buffered downlink (DL) data delivery during seamless roaming may be provided. A serving access point (AP) receives a roaming request from a client device, the roaming request indicating an intent to roam from the serving AP to a target AP and including one or more preferences for handling buffered DL data at the serving AP. The serving AP sends a roaming response to the client device, the roaming response indicating parameters for delivering buffered DL data based on the one or more preferences. The serving AP then participates in a buffered DL data delivery phase with the client device based on the parameters indicated in the roaming response, including delivering at least a first portion of the buffered DL data to the client device or forwarding at least a second portion of the buffered DL data to the target AP.
Techniques are described for providing a natural language network security policy assistant for allowing a network administrator to implement network security policies using natural language security policy requests. A natural language request can be received by a user and can be translated using Artificial Intelligence into one or more security policy clauses. If the natural language security policy request leads to ambiguities with regard to intended security policies, one or more clarifying questions can be generated as natural language questions and sent to the user for clarification. One or more security policies can be implemented based on the one or more security policy clauses generated in response to the natural language security policy request and/or the natural language response to the clarifying questions.