A data transmission between a connected device and an access point is monitored (102) during a time window to obtain a plurality of network traffic flows. An association between two or more of the plurality of network traffic flows is detected (104) based on one or more of intra-flow features and inter-flow features.
2.
DETERMINING NETWORK USAGE CATEGORIES FOR NETWORK TRAFFIC FLOWS
An encrypted data transmission between a connected device and an access point is monitored during a time window to obtain network data. One or more network traffic flows are detected based on the network data. One or more application-agnostic network usage categories for the one or more network traffic flows are determined based on the network data, wherein one or more unknown applications executing on the connected device cause the encrypted data transmission to be categorized as the one or more network usage categories.
A data transmission between a connected device and an access point is monitored during a time window to obtain a plurality of network traffic flows. An association between two or more of the plurality of network traffic flows is detected based on one or more of intra-flow features and inter-flow features.
An application executing in a connected device generates a unique identifier. The unique identifier is inserted into network traffic transmitted from the connected device to a target network element via an Internet access network element. In response to a monitoring system detecting the unique identifier from the network traffic, the unique identifier is used for a subsequent network-related analysis operation.
H04L 9/06 - Dispositions pour les communications secrètes ou protégéesProtocoles réseaux de sécurité l'appareil de chiffrement utilisant des registres à décalage ou des mémoires pour le codage par blocs, p. ex. système DES
H04L 43/08 - Surveillance ou test en fonction de métriques spécifiques, p. ex. la qualité du service [QoS], la consommation d’énergie ou les paramètres environnementaux
Input data indicative of network conditions, application characteristics, and available differentiation options is received. For evaluated differentiation options, a statistical model generates probabilistic predictions of an application performance outcome for a network-connected device requesting differentiation of network resources and other application performance outcomes for one or more other network-connected devices sharing the network resources. Based on the probabilistic predictions, it is determined whether any of the evaluated differentiation options increases a likelihood of meeting an application performance objective for the network-connected device without causing unacceptable degradation in the other application performance outcomes for the other network-connected devices in accordance with network neutrality principles. In response to determining, it is outputted a recommendation to apply a selected differentiation option for the network-connected device or to deny the differentiation for the network-connected device.
H04L 47/2408 - Trafic caractérisé par des attributs spécifiques, p. ex. la priorité ou QoS pour la prise en charge de différents services, p. ex. services du type services différentiés [DiffServ]
H04L 41/142 - Analyse ou conception de réseau en utilisant des méthodes statistiques ou mathématiques
H04L 41/147 - Analyse ou conception de réseau pour prédire le comportement du réseau
H04L 43/04 - Traitement des données de surveillance capturées, p. ex. pour la génération de fichiers journaux
Wireless data transmissions from a plurality of connected devices of various device types to a plurality of access points are monitored (102). A set of Wi-Fi attributes and corresponding values are extracted (110) from the wireless data transmissions. A maximum set of Wi-Fi attributes and corresponding maximum values are generated (114) for a specific device type of the various device types based on the set of Wi-Fi attributes and corresponding values.
09 - Appareils et instruments scientifiques et électriques
42 - Services scientifiques, technologiques et industriels, recherche et conception
Produits et services
(1) Software for use in monitoring and querying artificial intelligence generated data related to connected devices, applications, contents, threats and privacy; software for use in internal systems, workflow or customer-facing applications; software for use in network security and device protection, detecting, alerting and blocking threats by using artificial intelligence applied to edge network traffic; content control and digital parenting software for use in device management, parental controls and content filtering through usage of artificial intelligence to categorize network traffic; software using artificial intelligence for use in privacy and tracking protection across connected devices through managed broadband or network-deployed gateway; software for use in digital security, anti-virus protection, secure messaging, safe browsing, parental control, software updates, remote device management, messaging, network protection, and privacy protection; machine learning software for use in predicting network device behavior; computer software and firmware for protecting the integrity of computer hardware, software, networks and electronic data; computer software and firmware for analyzing and filtering of network traffic and for the detection, filtering, or removal of computer intrusions, viruses, spam, or other malicious applications or threats, and for providing virtual private networking and security functions; computer software and firmware for monitoring, analyzing or reporting of network information, data and traffic. (1) Software as a service (SaaS) services featuring software for use in the detection, analysis, mitigation and resolution of threats in the field of cyber security; software as a service (SaaS) services featuring software for collecting and analyzing data through machine learning and artificial intelligence; software as a service (SaaS) services featuring software using artificial intelligence for analyzing customer communications; monitoring of computer systems for detecting unauthorized access or data breach; researching, designing, implementing and updating software for use in digital security, anti-virus protection, safe browsing, parental control and remote device management of connected devices in local computer networks; research and design of software for visualization, correlation and analysis of data related to connected devices, applications usage, content access, security threats and privacy protection; domain name system (DNS) management and maintenance services, namely, maintenance of computer software relating to domain name system server computer security and prevention of computer risks to domain name systems.
A coaxial tap is provided. The coaxial tap includes an input port couplable to a feeder coaxial cable carrying a broadband radio frequency (RF) signal and an output port coupled to the input port along a first signal path. A tap is coupled to the first signal path at a location between the input port and the output port. The tap configured to divert a portion of the broadband RF signal from the first signal path to form a tap signal. A signal conditioning network is coupled to the tap along a second signal path. The signal conditioning network includes a plurality of signal conditioning channels corresponding to ones of a plurality of different frequency bands. The signal conditioning network is configured to generate a conditioned tap signal based on a bandwidth of the tap signal.
Network messages in a directly routed local area network (LAN) of a customer-premises equipment (CPE) are subscribed (108) to. The CPE is configured to provide the directly routed LAN for data communication, and an access for the data communication to a wide area network (WAN). The network messages in the directly routed LAN are received (110). The network messages are aggregated (114) to local state objects maintained in the CPE, wherein each local state object contains data of a single connected device. Update data of the local state objects is transmitted (124) via the WAN to remote state objects maintained outside of the CPE.
H04L 9/32 - Dispositions pour les communications secrètes ou protégéesProtocoles réseaux de sécurité comprenant des moyens pour vérifier l'identité ou l'autorisation d'un utilisateur du système
H04L 12/28 - Réseaux de données à commutation caractérisés par la configuration des liaisons, p. ex. réseaux locaux [LAN Local Area Networks] ou réseaux étendus [WAN Wide Area Networks]
H04L 41/12 - Découverte ou gestion des topologies de réseau
12.
CYBERSECURITY BASED ON DOMAIN NAME SYSTEM PROTOCOL PROCESSING
In response to intercepting, by a customer-premises equipment (CPE) a connection request from a connected device to an external encrypted domain name system (DNS) server, blocking, by the CPE, the connection request to cause the connected device to fall back to a use of an unencrypted DNS. And, in response to intercepting, by the CPE, an unencrypted DNS query from the connected device, performing, by the CPE, a cybersecurity operation related to the unencrypted DNS query.
A plurality of machine learning predictions for consecutive sliding windows over a segment of data are obtained (106). Each machine learning prediction comprises probabilities for predicted classes in a single sliding window. 5 One or more machine learning predictions fulfilling a volatility condition are removed (108) from the plurality of machine learning predictions in order to get filtered machine learning predictions. Probabilities for each predicted class of the filtered machine learning predictions are added up (114) to a sum probability for each predicted class of the filtered machine learning predictions. The predicted 10 class of the filtered machine learning predictions having a highest sum probability is selected (126) as a dominant class of the segment.
A customer-premises equipment, CPE receives from a connected device via a first encrypted wireless connection an active media access control, MAC, address and a true MAC address of the connected device. The CPE receives from the connected device via a second wireless connection a data communication that contains the active MAC address of the connected device and omits the true MAC address of the connected device. In response to the CPE detecting that the data communication is addressed to an internal service within the CPE, the CPE associates the true MAC address of the connected device with the data communication, and transmits to the internal service the data communication that contains the active MAC address of the connected device and is associated with the true MAC address of the connected device.
A present carrier frequency of a present radio signal is randomly adjusted within an acceptable tolerance range by a connected device. The present radio signal is transmitted to an access point by the connected device in a present wireless connection.
One or more first device fingerprints are obtained from one or more first wireless connections of a connected device in one or more first wireless networks. One or more second device fingerprints are obtained from one or more second wireless connections of the connected device in one or more second wireless networks. In response to finding a match between the one or more first device fingerprints and the one or more second device fingerprints, an enhanced service is entitled to the connected device.
A plurality of machine learning predictions for consecutive sliding windows over a segment of data are obtained. Each machine learning prediction comprises probabilities for predicted classes in a single sliding window. One or more machine learning predictions fulfilling a volatility condition are removed from the plurality of machine learning predictions in order to get filtered machine learning predictions. Probabilities for each predicted class of the filtered machine learning predictions are added up to a sum probability for each predicted class of the filtered machine learning predictions. The predicted class of the filtered machine learning predictions having a highest sum probability is selected as a dominant class of the segment.
Network messages in a directly routed local area network (LAN) of a customer-premises equipment (CPE) are subscribed to. The CPE is configured to provide the directly routed LAN for data communication, and an access for the data communication to a wide area network (WAN). The network messages in the directly routed LAN are received. The network messages are aggregated to local state objects maintained in the CPE, wherein each local state object contains data of a single connected device. Update data of the local state objects is transmitted via the WAN to remote state objects maintained outside of the CPE.
H04L 41/082 - Réglages de configuration caractérisés par les conditions déclenchant un changement de paramètres la condition étant des mises à jour ou des mises à niveau des fonctionnalités réseau
H04L 41/00 - Dispositions pour la maintenance, l’administration ou la gestion des réseaux de commutation de données, p. ex. des réseaux de commutation de paquets
H04L 41/12 - Découverte ou gestion des topologies de réseau
H04L 41/16 - Dispositions pour la maintenance, l’administration ou la gestion des réseaux de commutation de données, p. ex. des réseaux de commutation de paquets en utilisant l'apprentissage automatique ou l'intelligence artificielle
H04L 43/026 - Capture des données de surveillance en utilisant l’identification du flux
A computing device receives an IP address extracted from an encrypted client hello (ECH) enabled transport layer security (TLS) connection request from a client computing device and identifies, from a list of a plurality of hostnames, a set of hostnames matching the IP address. The device generates a reduced list of the set hostnames matching the IP address and generates a reduced list of the set of hostnames matching the IP address by removing hostnames that do not support an ECH extension of a TLS standard from the set of hostnames matching the IP address. Finally, the device retrieves reputation information related to one or more hostnames of the reduced list for protecting the client computing device and/or a computer network based on the reputation information.
H04L 61/4511 - Répertoires de réseauCorrespondance nom-adresse en utilisant des répertoires normalisésRépertoires de réseauCorrespondance nom-adresse en utilisant des protocoles normalisés d'accès aux répertoires en utilisant le système de noms de domaine [DNS]
H04L 67/02 - Protocoles basés sur la technologie du Web, p. ex. protocole de transfert hypertexte [HTTP]
20.
Processing medium access control (MAC) address in customer-premises equipment (CPE)
After a data packet containing an active medium access control (MAC) address of a connected device enters a customer-premises equipment (CPE), the active MAC address of the connected device is replaced with an earlier MAC address of the connected device. Before the data packet with the earlier MAC address exits the CPE, the earlier MAC address of the connected device is replaced with the active MAC address of the connected device.
G06F 15/16 - Associations de plusieurs calculateurs numériques comportant chacun au moins une unité arithmétique, une unité programme et un registre, p. ex. pour le traitement simultané de plusieurs programmes
A device identifier of a connected device connected to a customer-premises equipment (CPE) is associated with a device context information of the connected device. The CPE is configured to implement a local area network (LAN) for a data communication of the connected device. The device context information and the associated device identifier are passed to a service in the CPE using a communication mechanism. The CPE is configured to implement a platform for the service. The communication mechanism is configured to operate in the CPE.
H04L 41/5054 - Déploiement automatique des services déclenchés par le gestionnaire de service, p. ex. la mise en œuvre du service par configuration automatique des composants réseau
H04L 41/085 - Récupération de la configuration du réseauSuivi de l’historique de configuration du réseau
22.
Passing connected device identity to service in customer-premises equipment
A device identifier is associated with an active medium access control (MAC) address of a connected device connected to a customer-premises equipment (CPE). The CPE is configured to implement a local area network (LAN) for a data communication of the connected device. The device identifier is passed to a service in the CPE using a communication mechanism. The CPE is configured to implement a platform for the service. The communication mechanism is configured to operate in the CPE.
H04L 12/28 - Réseaux de données à commutation caractérisés par la configuration des liaisons, p. ex. réseaux locaux [LAN Local Area Networks] ou réseaux étendus [WAN Wide Area Networks]
H04L 61/103 - Correspondance entre adresses de types différents à travers les couches réseau, p. ex. résolution d’adresse de la couche réseau dans la couche physique ou protocole de résolution d'adresse [ARP]
H04L 61/5007 - Adresses de protocole Internet [IP]
H04L 61/5014 - Adresses de protocole Internet [IP] en utilisant le protocole de configuration dynamique de l'hôte [DHCP] ou le protocole d'amorçage [BOOTP]
H04L 61/5038 - Allocation d'adresse pour une utilisation locale, p. ex. dans des réseaux LAN ou USB, ou dans un réseau de contrôle [CAN]
H04L 101/622 - Adresses de couche 2, p. ex. adresses de contrôle d'accès au support [MAC]
Data communication of a user apparatus via a customer-premises equipment (CPE) is intercepted. The CPE implements a local area network for the data communication of the user apparatus. First network traffic related to a remote access software in the user apparatus is detected in the data communication. Second network traffic related to an online banking software in the user apparatus is detected in the data communication. The first network traffic and the second network traffic are determined to coincide. In response to determining that the first network traffic and the second network traffic coincide, the first network traffic related to the remote access software in the user apparatus is blocked via the CPE.
One or more features of a connected device are determined. A set of websites potentially accessed by the connected device are defined based on the one or more features. Reputation data for the set of websites is determined. The reputation data for the set of websites is stored into a cache. Network traffic between the connected device and an accessed website is intercepted. Reputation data for the accessed website is retrieved from the cache based on the network traffic. A cybersecurity operation related to the connected device is performed based on the reputation data for the accessed website.
A first data communication of a first connected device related to a first target website is intercepted. The first data communication identifies the first target website by a first fully qualified domain name (FQDN), and the first FQDN is mapped to a first Internet protocol (IP) address. A pair of the first FQDN and the first IP address is determined. A second data communication of a second connected device related to a second target website is intercepted. The second data communication comprises a second encrypted FQDN and a second IP address of the second target website. The second IP address is determined to be equal to the first IP address. A cybersecurity reputation of the second target website is retrieved based on the first FQDN. In response to determining that the reputation matches a predetermined alarm condition, a cybersecurity operation is enforced for the second data communication.
H04L 61/4511 - Répertoires de réseauCorrespondance nom-adresse en utilisant des répertoires normalisésRépertoires de réseauCorrespondance nom-adresse en utilisant des protocoles normalisés d'accès aux répertoires en utilisant le système de noms de domaine [DNS]
Information related to data communication between a plurality of connected devices is obtained. A plurality of initiated connections between the plurality of connected devices as directed edges between nodes in a directed graph based on the information are defined. Each initiated connection is represented by a directed edge from a source node to a destination node in the directed graph, and each node comprises an internet protocol (IP) address of the node. The directed graph is explored to determine a plurality of source/destination-pairs, wherein each source/destination-pair contains a source IP address of a source node of a directed edge, and a destination IP address of a destination node of the directed edge. A peer-to-peer (P2P) network including a plurality of P2P devices is detected based on the source/destination-pairs.
A method, apparatus, and a computer-readable medium for a web object reputation processing, especially in Web3. The method includes: intercepting data transmitted in a data connection related to a current decentralized application running in a user apparatus, wherein the current decentralized application comprises a frontend implementing a web user interface for a user of the user apparatus, and a backend implemented as a smart contract; determining a reputation of a web object related to the frontend of the current decentralized application; and in response to determining that the reputation of the web object is malicious, blocking the data connection.
A network apparatus maintains a database of a plurality of virtual private network (VPN) protocols and respective VPN providers. A VPN protocol detection process is performed for determining a VPN protocol used by a computing device based on analyzing network traffic data and the database. In response to detecting the VPN protocol detection process failing or detecting a need to identify a respective VPN provider, an endpoint detection process for determining the VPN usage of the computing device is performed. In response to detecting the endpoint detection process failing or detecting a need to identify VPN usage time information, a traffic pattern search process for determining the VPN usage of the computing device is performed. Further action is taken to protect the computing device in response to detecting the VPN usage on the basis of the VPN protocol detection process, the endpoint detection process, and/or the traffic pattern search process.
A first data communication of a first connected device related to a first target website is intercepted. The first data communication identifies the first target website by a first fully qualified domain name (FQDN), and the first FQDN is mapped to a first Internet protocol (IP) address. A pair of the first FQDN and the first IP address is determined. A second data communication of a second connected device related to a second target website is intercepted. The second data communication comprises a second encrypted FQDN and a second IP address of the second target website. The second IP address is determined to be equal to the first IP address. A cybersecurity reputation of the second target website is retrieved based on the first FQDN. In response to determining that the reputation matches a predetermined alarm condition, a cybersecurity operation is enforced for the second data communication.
H04L 29/12 - Dispositions, appareils, circuits ou systèmes non couverts par un seul des groupes caractérisés par le terminal de données
H04L 61/4511 - Répertoires de réseauCorrespondance nom-adresse en utilisant des répertoires normalisésRépertoires de réseauCorrespondance nom-adresse en utilisant des protocoles normalisés d'accès aux répertoires en utilisant le système de noms de domaine [DNS]
H04L 67/02 - Protocoles basés sur la technologie du Web, p. ex. protocole de transfert hypertexte [HTTP]
G06F 15/16 - Associations de plusieurs calculateurs numériques comportant chacun au moins une unité arithmétique, une unité programme et un registre, p. ex. pour le traitement simultané de plusieurs programmes
G06F 16/901 - IndexationStructures de données à cet effetStructures de stockage
A computing device receives an IP address and a port number related to a transport protocol and an application protocol version and other attributes related to an application protocol extracted from an encrypted client hello (ECH) enabled transport layer security (TLS) connection request from a client computing device and extracts, from the database, a set of all known hostnames matching the IP address. The device generates a reduced list of the set of all hostnames matching the IP address, and assigns a confidence score to each hostname of the reduced list based on an alias count and/or a popularity ranking of the hostname. Finally, a prioritized list of one or more hostnames is generated based on the confidence score, the prioritized list indicating the one or more hostnames in the order of descending probability of being requested in the ECH enabled TLS connection request.
H04L 9/00 - Dispositions pour les communications secrètes ou protégéesProtocoles réseaux de sécurité
H04L 12/22 - Dispositions pour empêcher la prise de données sans autorisation dans un canal de transmission de données
H04L 61/4511 - Répertoires de réseauCorrespondance nom-adresse en utilisant des répertoires normalisésRépertoires de réseauCorrespondance nom-adresse en utilisant des protocoles normalisés d'accès aux répertoires en utilisant le système de noms de domaine [DNS]
H04L 67/02 - Protocoles basés sur la technologie du Web, p. ex. protocole de transfert hypertexte [HTTP]
H04W 12/00 - Dispositions de sécuritéAuthentificationProtection de la confidentialité ou de l'anonymat
A computing device receives an IP address and a port number related to a transport protocol and an application protocol version and other attributes related to an application protocol extracted from an encrypted client hello (ECH) enabled transport layer security (TLS) connection request from a client computing device and extracts, from the database, a set of all known hostnames matching the IP address. The device generates a reduced list of the set of all hostnames matching the IP address, and assigns a confidence score to each hostname of the reduced list based on an alias count and/or a popularity ranking of the hostname. Finally, a prioritized list of one or more hostnames is generated based on the confidence score, the prioritized list indicating the one or more hostnames in the order of descending probability of being requested in the ECH enabled TLS connection request.
H04L 61/4511 - Répertoires de réseauCorrespondance nom-adresse en utilisant des répertoires normalisésRépertoires de réseauCorrespondance nom-adresse en utilisant des protocoles normalisés d'accès aux répertoires en utilisant le système de noms de domaine [DNS]
H04L 67/02 - Protocoles basés sur la technologie du Web, p. ex. protocole de transfert hypertexte [HTTP]
Network device identification is disclosed. A set of data attributes relating to at least two different data types is extracted from network traffic data associated with each user device of a set of user devices. A cluster data set of one or more known device clusters is expanded with the set of data attributes for generating an expanded cluster data set. One or more new device clusters is identified from the expanded cluster data set of the one or more known device clusters by using similarity-based metrics and a weighting factor selected based on the data types of the set of data attributes, and one or more device identification rules is generated based on the one or more new device clusters.
There is provided a method comprising receiving a domain name system (DNS) query from a client computing device, decrypting the DNS query by a DNS resolver device, and requesting reputation information related to the FQDN from an agent device of the router apparatus. If a matching FQDN is not found in a local database, the DNS query is allowed to proceed from the DNS resolver device to a cloud DNS resolver, the IP and MAC address of the client computing device are logged and mapped to the local database, the reputation information related to the FQDN is requested from a cloud FQDN server, and if the reputation information indicates that the FQDN should be blocked, the local database is updated with the reputation information and further queries to the FQDN are blocked.
H04L 61/4511 - Répertoires de réseauCorrespondance nom-adresse en utilisant des répertoires normalisésRépertoires de réseauCorrespondance nom-adresse en utilisant des protocoles normalisés d'accès aux répertoires en utilisant le système de noms de domaine [DNS]
A method, apparatus, and a computer-readable medium for network device protection. The method includes: intercepting present network data related to a present data connection of a user apparatus; analyzing the present network data; and in response to determining that the user apparatus utilizes a privacy feature in the present data connection implemented by a first internet relay and a second internet relay, blocking the present data connection.
A device identification method where a device application usage profile is generated and maintained for each one or more known computing devices of a local network based on network traffic data. In response to detecting an unknown computing device in the local network, network traffic data related to the unknown computing device is collected, and a device application usage profile for the unknown computing device is generated based on the network traffic data related to the unknown computing device. The device application usage profile of the unknown computing device is compared with the device application usage profile of the one or more known computing devices of the local network. In response to detecting a difference between the device application usage profile of the unknown computing device and the device application usage profile of the one or more known computing devices of the local network satisfying a predetermined threshold, the unknown device is identified as one of the known computing devices of the local network.
G06F 15/16 - Associations de plusieurs calculateurs numériques comportant chacun au moins une unité arithmétique, une unité programme et un registre, p. ex. pour le traitement simultané de plusieurs programmes
H04L 43/065 - Génération de rapports liés aux appareils du réseau
H04L 41/16 - Dispositions pour la maintenance, l’administration ou la gestion des réseaux de commutation de données, p. ex. des réseaux de commutation de paquets en utilisant l'apprentissage automatique ou l'intelligence artificielle
H04L 43/0876 - Utilisation du réseau, p. ex. volume de charge ou niveau de congestion
H04L 43/04 - Traitement des données de surveillance capturées, p. ex. pour la génération de fichiers journaux
A device identification method where a device application usage profile is generated and maintained for each one or more known computing devices of a local network based on network traffic data. In response to detecting an unknown computing device in the local network, network traffic data related to the unknown computing device is collected, and a device application usage profile for the unknown computing device is generated based on the network traffic data related to the unknown computing device. The device application usage profile of the unknown computing device is compared with the device application usage profile of the one or more known computing devices of the local network. In response to detecting a difference between the device application usage profile of the unknown computing device and the device application usage profile of the one or more known computing devices of the local network satisfying a predetermined threshold, the unknown device is identified as one of the known computing devices of the local network.
There is provided a method comprising receiving a domain name system (DNS) query from a client computing device, decrypting the DNS query by a DNS resolver device, and requesting reputation information related to the FQDN from an agent device of the router apparatus. If a matching FQDN is not found in a local database, the DNS query is allowed to proceed from the DNS resolver device to a cloud DNS resolver, the IP and MAC address of the client computing device are logged and mapped to the local database, the reputation information related to the FQDN is requested from a cloud FQDN server, and if the reputation information indicates that the FQDN should be blocked, the local database is updated with the reputation information and further queries to the FQDN are blocked.
H04L 61/4511 - Répertoires de réseauCorrespondance nom-adresse en utilisant des répertoires normalisésRépertoires de réseauCorrespondance nom-adresse en utilisant des protocoles normalisés d'accès aux répertoires en utilisant le système de noms de domaine [DNS]
There is provided a method comprising receiving a domain name system (DNS) query from a client computing device, decrypting the DNS query by a DNS resolver device, and requesting reputation information related to the FQDN from an agent device of the router apparatus. If a matching FQDN is not found in a local database, the DNS query is allowed to proceed from the DNS resolver device to a cloud DNS resolver, the IP and MAC address of the client computing device are logged and mapped to the local database, the reputation information related to the FQDN is requested from a cloud FQDN server, and if the reputation information indicates that the FQDN should be blocked, the local database is updated with the reputation information and further queries to the FQDN are blocked..
H04L 61/4511 - Répertoires de réseauCorrespondance nom-adresse en utilisant des répertoires normalisésRépertoires de réseauCorrespondance nom-adresse en utilisant des protocoles normalisés d'accès aux répertoires en utilisant le système de noms de domaine [DNS]
H04L 67/02 - Protocoles basés sur la technologie du Web, p. ex. protocole de transfert hypertexte [HTTP]
An apparatus in a computer network system extracts network traffic metadata related to a client computing device of a local network. The network traffic metadata is required by a device fingerprinting process. In response to detecting a multicast DNS (mDNS) packet query in the network traffic metadata, the apparatus collects an mDNS hostname related to the client computing device from the mDNS packet query. In response to determining, at a first point in time, that a dynamic host configuration protocol (DHCP) hostname related to the client computing device is unavailable in the network traffic metadata, the apparatus assigns the mDNS hostname to the client computing device.
A network gateway apparatus monitors Quic user datagram protocol (UDP) Internet Connection (QUIC) packets between a first device and a second device, extracts a version of the QUIC protocol and a connection identification from an unprotected portion of the protected header in response to detecting a QUIC packet having a protected header in use, determines a salt used in encryption of the protected header based on the version of the QUIC protocol, calculates a client initial secret based on the salt and the connection identification, determines an unprotected payload of the QUIC packet based on the client initial secret, a protected payload of the QUIC packet and the unprotected portion of the protected header, and extracts a server name indication (SNI) from the unprotected payload.
H04L 9/06 - Dispositions pour les communications secrètes ou protégéesProtocoles réseaux de sécurité l'appareil de chiffrement utilisant des registres à décalage ou des mémoires pour le codage par blocs, p. ex. système DES
H04L 9/32 - Dispositions pour les communications secrètes ou protégéesProtocoles réseaux de sécurité comprenant des moyens pour vérifier l'identité ou l'autorisation d'un utilisateur du système
An apparatus in a computer network system extracts network traffic metadata related to a client computing device of a local network. The network traffic metadata is required by a device fingerprinting process. In response to detecting a multicast DNS (mDNS) packet query in the network traffic metadata, the apparatus collects an mDNS hostname related to the client computing device from the mDNS packet query. In response to determining, at a first point in time, that a dynamic host configuration protocol (DHCP) hostname related to the client computing device is unavailable in the network traffic metadata, the apparatus assigns the mDNS hostname to the client computing device.
H04L 61/5014 - Adresses de protocole Internet [IP] en utilisant le protocole de configuration dynamique de l'hôte [DHCP] ou le protocole d'amorçage [BOOTP]
H04L 61/5076 - Mécanismes de mise à jour ou de notification, p. ex. DynDNS
A network apparatus receives a first message relating to a transport layer security (TLS) handshake process for an initialization phase of a Quic user datagram protocol (UDP) Internet Connection (QUIC) connection from a client computing device toward a target computing device, wherein the first message of the TLS handshake process comprises at least a connection identifier. The network apparatus generates a second message relating to the TLS handshake process in response to the first message, wherein a cipher suite value of the second message is set to an invalid cipher suite value for the client computing device and wherein the invalid cipher suite value is unsupported by the client computing device, and sends the second message to the client computing device to cause the client computer device to close the QUIC connection.
H04L 67/02 - Protocoles basés sur la technologie du Web, p. ex. protocole de transfert hypertexte [HTTP]
H04L 101/663 - Adresses de couche transport, p. ex. aspects des ports du protocole de contrôle de transmission [TCP] ou des ports du protocole de datagramme utilisateur [UDP]
A network apparatus receives a first message relating to a transport layer security (TLS) handshake process for an initialization phase of a Quic user datagram protocol (UDP) Internet Connection (QUIC) connection from a client computing device toward a target computing device, wherein the first message of the TLS handshake process comprises at least a connection identifier. The network apparatus generates a second message relating to the TLS handshake process in response to the first message, wherein a cipher suite value of the second message is set to an invalid cipher suite value for the client computing device and wherein the invalid cipher suite value is unsupported by the client computing device, and sends the second message to the client computing device to cause the client computer device to close the QUIC connection.
H04L 9/32 - Dispositions pour les communications secrètes ou protégéesProtocoles réseaux de sécurité comprenant des moyens pour vérifier l'identité ou l'autorisation d'un utilisateur du système
H04L 65/1069 - Établissement ou terminaison d'une session
H04L 69/16 - Implémentation ou adaptation du protocole Internet [IP], du protocole de contrôle de transmission [TCP] ou du protocole datagramme utilisateur [UDP]
H04L 69/326 - Protocoles de communication intra-couche entre entités paires ou définitions d'unité de données de protocole [PDU] dans la couche transport [couche OSI 4]
44.
Network device identification and categorization using behavioral fingerprints
Network device identification is disclosed. A set of data attributes relating to at least two different data types is extracted from network traffic data associated with each user device of a set of user devices. A cluster data set of one or more known device clusters is expanded with the set of data attributes for generating an expanded cluster data set. One or more new device clusters is identified from the expanded cluster data set of the one or more known device clusters by using similarity-based metrics and a weighting factor selected based on the data types of the set of data attributes, and one or more device identification rules is generated based on the one or more new device clusters.
G06F 15/173 - Communication entre processeurs utilisant un réseau d'interconnexion, p. ex. matriciel, de réarrangement, pyramidal, en étoile ou ramifié
H04L 41/085 - Récupération de la configuration du réseauSuivi de l’historique de configuration du réseau
H04L 43/065 - Génération de rapports liés aux appareils du réseau
H04L 41/12 - Découverte ou gestion des topologies de réseau
H04L 41/0893 - Affectation de groupes logiques aux éléments de réseau
An application detection method includes running one or more applications in various application scenarios on one or more user devices for a predetermined time period, capturing network traffic data generated by the one or more applications, labelling the network traffic data according to an application scenario of the one or more applications and with respect to a user device of the one or more user devices, determining an active application usage time in relation to the application scenario during the predetermined time period based on the labelling, training a machine learning model to estimate the active application usage time based on the determining, and using the machine learning model to estimate the active application usage time on the one or more user devices.
H04L 43/08 - Surveillance ou test en fonction de métriques spécifiques, p. ex. la qualité du service [QoS], la consommation d’énergie ou les paramètres environnementaux
There is provided a method that comprises receiving one or more unique passwords for identifying respective one or more user devices of the wireless local area network; associating the one or more unique passwords with the respective one or more user devices and storing the one or more unique passwords to a database; in response to receiving, at an access point of the wireless local area network, a connection request from a user device, requesting, from the user device, a unique password of the user device; and identifying the user device based on the unique password.
H04W 48/04 - Restriction d'accès effectuée dans des conditions spécifiques sur la base des données de localisation ou de mobilité de l'utilisateur ou du terminal, p. ex. du sens ou de la vitesse de déplacement
H04W 8/00 - Gestion de données relatives au réseau
H04W 84/12 - Réseaux locaux sans fil [WLAN Wireless Local Area Network]
A network apparatus maintains a data repository comprising network traffic data related to a plurality of user devices, the network traffic data being collected from a plurality of Network Service Providers (NSPs). A subset of the plurality of user devices are detected to be communicating with one or more same endpoint devices based on analysing the network traffic data. A number of historical connections between each user device of the subset of the plurality of user devices and the one or more endpoint devices is determined based on analysing historical connection data maintained in the data repository, and in response to detecting that the number of historical connections between the subset of the plurality of user devices and the one or more endpoint devices exceeds a predetermined threshold, the one or more endpoint devices are identified as a suspected botnet.
G06F 21/00 - Dispositions de sécurité pour protéger les calculateurs, leurs composants, les programmes ou les données contre une activité non autorisée
A network apparatus maintains a data repository comprising network traffic data related to a plurality of user devices, the network traffic data being collected from a plurality of Network Service Providers (NSPs). A subset of the plurality of user devices are detected to be communicating with one or more same endpoint devices based on analysing the network traffic data. A number of historical connections between each user device of the subset of the plurality of user devices and the one or more endpoint devices is determined based on analysing historical connection data maintained in the data repository, and in response to detecting that the number of historical connections between the subset of the plurality of user devices and the one or more endpoint devices exceeds a predetermined threshold, the one or more endpoint devices are identified as a suspected botnet.
A method includes receiving network traffic data relating to one or more devices of a plurality of home networks, wherein each home network of the plurality of home networks relates to a respective household. The method further includes determining one or more household related features by feature engineering the network traffic data, wherein the one or more household related features are related to one or more of: a device property, a security threat event, and an application usage, associating, in a database, the one or more household related features with identification data assigned to each household, identifying household clusters that represent groups of households comprising a predetermined number of common household related features, and providing a targeted service to a customer based on a household cluster associated with a household of the customer.
H04L 41/5061 - Gestion des services réseau, p. ex. en assurant une bonne réalisation du service conformément aux accords caractérisée par l’interaction entre les fournisseurs de services et leurs clients réseau, p. ex. la gestion de la relation client
H04L 41/12 - Découverte ou gestion des topologies de réseau
H04L 41/16 - Dispositions pour la maintenance, l’administration ou la gestion des réseaux de commutation de données, p. ex. des réseaux de commutation de paquets en utilisant l'apprentissage automatique ou l'intelligence artificielle
H04L 43/045 - Traitement des données de surveillance capturées, p. ex. pour la génération de fichiers journaux pour la visualisation graphique des données de surveillance
H04L 41/0893 - Affectation de groupes logiques aux éléments de réseau
H04L 43/062 - Génération de rapports liés au trafic du réseau
A network apparatus is configured to detect a network connection request on a platform having a hardware accelerator to process network traffic, wherein the hardware accelerator implements computing tasks related to data packets of at least part of the network traffic. The network apparatus is further configured to intercept the network traffic related to the network connection request before the start of the hardware accelerator process, to extract network connection data required by a network traffic analysis function from the network traffic, to allow the hardware accelerator to start acceleration process after the network connection data extraction has finished, and to analyse the network connection based on the extracted network connection data.
A network apparatus is configured to detect a network connection request on a platform having a hardware accelerator to process network traffic, wherein the hardware accelerator implements computing tasks related to data packets of at least part of the network traffic. The network apparatus is further configured to intercept the network traffic related to the network connection request before the start of the hardware accelerator process, to extract network connection data required by a network traffic analysis function from the network traffic, to allow the hardware accelerator to start acceleration process after the network connection data extraction has finished, and to analyse the network connection based on the extracted network connection data.
An application detection method includes receiving, from one or more user devices on a plurality of local networks, first network traffic metadata being related to a client application running on the one or more user devices, receiving, from a plurality of network traffic hubs of the plurality of local networks, second network traffic metadata corresponding to the first network traffic metadata but excluding user device specific data, generating a plurality of combined network traffic metadata datasets for each received first network traffic metadata and the corresponding second network traffic metadata by matching metadata attributes of the first and second network traffic metadata, generating an application detection model by using the plurality of combined network traffic metadata datasets, and using the application detection model for detecting further client applications running on one or more user devices on one or more local networks.
09 - Appareils et instruments scientifiques et électriques
42 - Services scientifiques, technologiques et industriels, recherche et conception
Produits et services
Software for use in monitoring and querying artificial
intelligence generated data related to connected devices,
applications, contents, threats and privacy; software for
use in internal systems, workflow or customer-facing
applications; software for use in network security and
device protection, detecting, alerting and blocking threats
by using artificial intelligence applied to edge network
traffic; content control and digital parenting software for
use in device management, parental controls and content
filtering through usage of artificial intelligence to
categorize network traffic; software using artificial
intelligence for use in privacy and tracking protection
across connected devices through managed broadband or
network-deployed gateway; software for use in digital
security, anti-virus protection, secure messaging, safe
browsing, parental control, software updates, remote device
management, messaging, network protection, and privacy
protection; machine learning software for use in predicting
network device behavior; computer software and firmware for
protecting the integrity of computer hardware, software,
networks and electronic data; computer software and firmware
for analyzing and filtering of network traffic and for the
detection, filtering, or removal of computer intrusions,
viruses, spam, or other malicious applications or threats,
and for providing virtual private networking and security
functions; computer software and firmware for monitoring,
analyzing or reporting of network information, data and
traffic. Software as a service (SaaS) services featuring software for
use in the detection, analysis, mitigation and resolution of
threats in the field of cyber security; software as a
service (SaaS) services featuring software for collecting
and analyzing data through machine learning and artificial
intelligence; software as a service (SaaS) services
featuring software using artificial intelligence for
analyzing customer communications; monitoring of computer
systems for detecting unauthorized access or data breach;
researching, designing, implementing and updating software
for use in digital security, anti-virus protection, safe
browsing, parental control and remote device management of
connected devices in local computer networks; research and
design of software for visualization, correlation and
analysis of data related to connected devices, applications
usage, content access, security threats and privacy
protection; domain name system (DNS) management and
maintenance services, namely, maintenance of computer
software relating to domain name system server computer
security and prevention of computer risks to domain name
systems.
A network apparatus receives a connection request from a client computing device toward a target computing device. Next a target identifier that identifies the target computing device is extracted from the connection request. The connection request is sent to the target computing device and a reputation request with the target identifier is sent to a web resource analyser engine. In response to detecting that a response from the target computing device is received before a response from the web resource analyser engine, the response to the connection request from the target computing device is held by performing a rewrite in a target section of a user-space utility program rule and by using operating system kernel module in user-space memory area of the network apparatus. In response to a receipt of the response from the web resource analyser engine, the response to the connection request is released.
A network apparatus receives a connection request from a client computing device toward a target computing device. Next a target identifier that identifies the target computing device is extracted from the connection request. The connection request is sent to the target computing device and a reputation request with the target identifier is sent to a web resource analyser engine. In response to detecting that a response from the target computing device is received before a response from the web resource analyser engine, the response to the connection request from the target computing device is held by performing a rewrite in a target section of a user-space utility program rule and by using operating system kernel module in user-space memory area of the network apparatus. In response to a receipt of the response from the web resource analyser engine, the response to the connection request is released.
Network device identification. A method includes extracting, from network traffic data of a plurality of user devices in a computer network, one or more data fragments relating to a device model of each user device, associating the one or more data fragments with device identification data assigned to each user device, determining a device model for a specific data fragment based on analyzing one or more data fields associated with the specific data fragment, and generating one or more device model identification rules based on the specific data fragment.
Network device identification. A method includes extracting, from network traffic data of a plurality of user devices in a computer network, one or more data fragments relating to a device model of each user device, associating the one or more data fragments with device identification data assigned to each user device, determining a device model for a specific data fragment based on analyzing one or more data fields associated with the specific data fragment, and generating one or more device model identification rules based on the specific data fragment.
G06F 15/173 - Communication entre processeurs utilisant un réseau d'interconnexion, p. ex. matriciel, de réarrangement, pyramidal, en étoile ou ramifié
G06N 5/025 - Extraction de règles à partir de données
H04L 41/12 - Découverte ou gestion des topologies de réseau
H04L 41/16 - Dispositions pour la maintenance, l’administration ou la gestion des réseaux de commutation de données, p. ex. des réseaux de commutation de paquets en utilisant l'apprentissage automatique ou l'intelligence artificielle
H04L 43/065 - Génération de rapports liés aux appareils du réseau
G06F 18/22 - Critères d'appariement, p. ex. mesures de proximité
Maintaining a database of a plurality of time series data sets, wherein each time series data set is associated to a previously known computer device of a computer network; detecting a connection request from a second computer device of the computer network; collecting one or more new data sets related to the second computer device; comparing the one or more new data sets with one or more time series data sets; calculating one or more value scores related to the plurality of time series data sets based on the comparison; and determining a device association score based on the calculated one or more value scores related to the plurality of time series data sets, wherein the device association score determines an association level between the previously known computer device and the second computer device of the computer network.
There is provided a method comprising: maintaining a database of one or more computer devices registered at a computer network, detecting a connection request from a new computer device, determining a physical location of the new computer device and comparing the physical location of the new computer device with the physical location data stored in the database. In response to detecting a previously registered computer device of the one or more computer devices having at least an approximately same physical location as the new computer device based on the comparison, the method further comprises determining that a change has occurred in network-based identification data of the previously registered computer device and taking further action to protect the computer devices from a security threat caused by the change of the network-based identification data.
A network apparatus detects connection requests and extracts related data. The data is analyzed to determine whether the host is in an active state, whether the host matches a domain referrer and an amount of time from a last connection request. If it is detected that the host is not in an active state, the host is not matching the domain referrer and the amount of time from the last connection request exceeds a predetermined new session threshold, then a connection request is classified as a main request. If the amount of time from the last connection request is below a predetermined continuous session threshold, then any connection requests following the main request are classified as sub-requests. If the domain of host in the active state does not match current host for a sub-request, the sub-request is classified as a third-party request.
An application detection method includes receiving, from one or more user devices on a plurality of local networks, first network traffic metadata being related to a client application running on the one or more user devices, receiving, from a plurality of network traffic hubs of the plurality of local networks, second network traffic metadata corresponding to the first network traffic metadata but excluding user device specific data, generating a plurality of combined network traffic metadata datasets for each received first network traffic metadata and the corresponding second network traffic metadata by matching metadata attributes of the first and second network traffic metadata, generating an application detection model by using the plurality of combined network traffic metadata datasets, and using the application detection model for detecting further client applications running on one or more user devices on one or more local networks.
G06F 15/173 - Communication entre processeurs utilisant un réseau d'interconnexion, p. ex. matriciel, de réarrangement, pyramidal, en étoile ou ramifié
H04L 29/08 - Procédure de commande de la transmission, p.ex. procédure de commande du niveau de la liaison
H04L 12/26 - Dispositions de surveillance; Dispositions de test
09 - Appareils et instruments scientifiques et électriques
Produits et services
Downloadable software for use in monitoring and querying artificial intelligence generated data related to connected devices, applications, contents, threats and privacy; Downloadable software for device profiling, content and application classification, security threat detection and monitoring for use in internal systems, workflow or customer-facing applications; Downloadable software for use in network security and device protection, for detecting, alerting and blocking threats by using artificial intelligence applied to edge network traffic; Downloadable content control and downloadable digital parenting software for use in device management, parental controls and content filtering through usage of artificial intelligence to categorize network traffic; Downloadable software for digital security, anti-virus protection, safe browsing, parental control, network protection; Downloadable machine learning software for predicting network device behavior; Downloadable computer software, namely, firmware for analyzing and filtering of network traffic and for the detection, filtering, or removal of computer intrusions, viruses, spam, or other malicious applications or threats, and for providing security functions; Downloadable computer software, namely, firmware for monitoring, analyzing or reporting of network information, data and traffic
42 - Services scientifiques, technologiques et industriels, recherche et conception
Produits et services
Software as a service (SAAS) services featuring software for use in the detection, analysis, mitigation and resolution of threats in the field of cyber security; Software as a service (SAAS) services featuring software for collecting and analyzing data through machine learning and artificial intelligence for the purpose of device intelligence and device categorization for network monitoring, device profiling, threat detection, building tools providing network visibility for use in local network management; Software as a service (SAAS) services featuring software using artificial intelligence for analyzing customer communications for the purpose of device detection and fingerprinting, application and content access detection, threat detection, privacy tracking detection, network telemetry, netflow data analysis; Monitoring of computer systems for detecting unauthorized access or data breach; Researching, designing, implementing and updating software for use in digital security, anti-virus protection, safe browsing, parental control and remote device management of connected devices in local computer networks; Researching and designing of machine learning and artificial intelligence solutions for network data analysis through visualization, namely, correlation and analysis of data related to connected devices, applications usage, content access, security threats and privacy protection; Domain name system (DNS) management and maintenance services, namely, maintenance of computer software relating to domain name system server computer security and prevention of computer risks to domain name systems
Fully qualified domain name determination is disclosed. A queue of fully qualified domain names (FQDN) is created using a predetermined amount of network domains. Each FQDN is crawled from a plurality of collection agents of a computer network. For each FQDN, data comprising an Internet Protocol (IP) address of the FQDN, IP addresses for resources loaded for the FQDN and load times of the resources loaded for the FQDN are extracted. A correlation model is generated based on the data. An FQDN being accessed by one or more computer devices of the computer network is determined by using the correlation model.
G06N 7/00 - Agencements informatiques fondés sur des modèles mathématiques spécifiques
H04L 61/4511 - Répertoires de réseauCorrespondance nom-adresse en utilisant des répertoires normalisésRépertoires de réseauCorrespondance nom-adresse en utilisant des protocoles normalisés d'accès aux répertoires en utilisant le système de noms de domaine [DNS]
H04L 61/5007 - Adresses de protocole Internet [IP]
A method and system for detecting malicious behavior from smart appliances within a network. Smart appliances have a certain level of intelligence that allows them to perform a specific role more effectively and conveniently. Network traffic data and identification data is collected about smart appliances within a network. The data is sent to a behavior analysis engine, which computes confidence levels for anomalies within the network traffic that may be caused by malicious behavior. If the behavior analysis engine determines that malicious behavior is present in the network, it sends an instruction to a network traffic hub to block network traffic relating to the anomaly. In some embodiments, network traffic is blocked based on source-destination pairs. In some embodiments, network traffic is blocked from a device outside the network that is determined to be malicious.
A network traffic hub receives network traffic from a user device running an application. The network traffic hub aggregates the network traffic into augmented netflows. Based on netflow parameters extracted by the network traffic hub, one or more augmented netflows are associated with the application. The network traffic hub determines whether an augmented netflow is a result of the application being in an active state or a passive state based on, for example, the quantity of data within the netflow. If the quantity of data within the augmented netflow is larger than a data threshold, the augmented netflow can be classified as an active usage, and if the data is less than the data threshold, the augmented netflow can be classified as a passive usage. Thus, by classifying network traffic of an application as active or passive, a record of a user's active usage of the application can be recorded.
A network traffic hub receives network traffic from a user device running an application. The network traffic hub aggregates the network traffic into augmented netflows. Based on netflow parameters extracted by the network traffic hub, one or more augmented netflows are associated with the application. The network traffic hub determines whether an augmented netflow is a result of the application being in an active state or a passive state based on, for example, the quantity of data within the netflow. If the quantity of data within the augmented netflow is larger than a data threshold, the augmented netflow can be classified as an active usage, and if the data is less than the data threshold, the augmented netflow can be classified as a passive usage. Thus, by classifying network traffic of an application as active or passive, a record of a user's active usage of the application can be recorded.
H04L 12/859 - Actions liées à la commande de flux basée sur la nature de l’application, p.ex. contrôle de navigation sur l’Internet ou contrôle du trafic de courrier électronique
H04L 12/851 - Actions liées au type de trafic, p.ex. qualité de service ou priorité
H04L 12/841 - Actions liées à la commande de flux utilisant des données temporelles, p.ex. temps d'aller retour [RTT]
68.
Determining active application usage through a network traffic hub
A network traffic hub receives network traffic from a user device running an application. The network traffic hub aggregates the network traffic into augmented netflows. Based on netflow parameters extracted by the network traffic hub, one or more augmented netflows are associated with the application. The network traffic hub determines whether an augmented netflow is a result of the application being in an active state or a passive state based on, for example, the quantity of data within the netflow. If the quantity of data within the augmented netflow is larger than a data threshold, the augmented netflow can be classified as an active usage, and if the data is less than the data threshold, the augmented netflow can be classified as a passive usage. Thus, by classifying network traffic of an application as active or passive, a record of a user's active usage of the application can be recorded.
A network traffic hub receives network traffic from a user device running an application. The network traffic hub aggregates the network traffic into augmented netflows. Based on netflow parameters extracted by the network traffic hub, one or more augmented netflows are associated with the application. The network traffic hub determines whether an augmented netflow is a result of the application being in an active state or a passive state based on, for example, the quantity of data within the netflow. If the quantity of data within the augmented netflow is larger than a data threshold, the augmented netflow can be classified as an active usage, and if the data is less than the data threshold, the augmented netflow can be classified as a passive usage. Thus, by classifying network traffic of an application as active or passive, a record of a user's active usage of the application can be recorded.
A network traffic hub extracts encryption metadata from messages establishing an encrypted connection between a smart appliance and a remote server and determines whether malicious behavior is present in the messages. For example, the network traffic hub can extract an encryption cipher suite, identified encryption algorithms, or a public certificate. The network traffic hub detects malicious behavior or security threats based on the encryption metadata. These security threats may include a man-in-the-middle attacker or a Padding Oracle On Downgraded Legacy Encryption attack. Upon detecting malicious behavior or security threats, the network traffic hub blocks the encrypted traffic or notifies a user.
G06N 20/20 - Techniques d’ensemble en apprentissage automatique
H04W 12/082 - Sécurité d'accès utilisant la révocation d’autorisation
H04W 12/088 - Sécurité d'accès utilisant des filtres ou des pare-feu
H04B 10/114 - Systèmes d’intérieur ou à courte portée
H04L 12/28 - Réseaux de données à commutation caractérisés par la configuration des liaisons, p. ex. réseaux locaux [LAN Local Area Networks] ou réseaux étendus [WAN Wide Area Networks]
A system and method for intercepting intra-network traffic for smart appliance behavior analysis. A network traffic hub is configured to intercept network traffic between a switch and a router. A smart appliance sends a message to the router, such as a DHCP request when the smart appliance joins the network. The router sends a response to the smart appliance. The network traffic hub intercepts and modifies the response to instruct the smart appliance to send all future intra-network traffic through the network traffic hub and the router. In some embodiments, the network traffic hub alters a network mask in the response message to instruct the smart appliance to send traffic through the network traffic hub. The network traffic hub then extracts data from the network traffic and uses that data for behavior analysis of smart appliances.
H04L 29/06 - Commande de la communication; Traitement de la communication caractérisés par un protocole
H04L 29/08 - Procédure de commande de la transmission, p.ex. procédure de commande du niveau de la liaison
H04L 29/12 - Dispositions, appareils, circuits ou systèmes non couverts par un seul des groupes caractérisés par le terminal de données
H04L 12/707 - Prévention ou récupération du défaut de routage, p.ex. reroutage, redondance de route "virtual router redundancy protocol" [VRRP] ou "hot standby router protocol" [HSRP] par redondance des chemins d’accès
H04L 12/28 - Réseaux de données à commutation caractérisés par la configuration des liaisons, p. ex. réseaux locaux [LAN Local Area Networks] ou réseaux étendus [WAN Wide Area Networks]
A method and system for detecting malicious behavior from smart appliances within a network. Smart appliances have a certain level of intelligence that allows them to perform a specific role more effectively and conveniently. Network traffic data and identification data is collected about smart appliances within a network. The data is sent to a behavior analysis engine, which computes confidence levels for anomalies within the network traffic that may be caused by malicious behavior. If the behavior analysis engine determines that malicious behavior is present in the network, it sends an instruction to a network traffic hub to block network traffic relating to the anomaly. In some embodiments, network traffic is blocked based on source-destination pairs. In some embodiments, network traffic is blocked from a device outside the network that is determined to be malicious.
A method and system for detecting malicious behavior from smart appliances within a network. Smart appliances have a certain level of intelligence that allows them to perform a specific role more effectively and conveniently. Network traffic data and appliance identification data is collected about smart appliances within a network. The data is sent to a behavior analysis engine, which computes confidence levels for anomalies within the network traffic that may be caused by malicious behavior. If the behavior analysis engine determines that malicious behavior is present in the network, it sends an instruction to a network traffic hub to block network traffic relating to the anomaly. In some embodiments, network traffic is blocked based on source-destination pairs. In some embodiments, network traffic is blocked from a device outside the network that is determined to be malicious.
H04L 12/28 - Réseaux de données à commutation caractérisés par la configuration des liaisons, p. ex. réseaux locaux [LAN Local Area Networks] ou réseaux étendus [WAN Wide Area Networks]
H04L 29/06 - Commande de la communication; Traitement de la communication caractérisés par un protocole
G06F 21/56 - Détection ou gestion de programmes malveillants, p. ex. dispositions anti-virus
H04L 12/26 - Dispositions de surveillance; Dispositions de test
H04L 29/12 - Dispositions, appareils, circuits ou systèmes non couverts par un seul des groupes caractérisés par le terminal de données
74.
SECURING PORT FORWARDING THROUGH A NETWORK TRAFFIC HUB
A network traffic hub is configured to receive a request for a port service (i.e., port forwarding or port triggering) from a smart appliance in a local network. The request may be a part of the UPnP protocol, which includes SSDP and IGDP. The request may be transmitted to the network traffic hub directly or the network traffic hub may intercept the request transmitted to a router of the local network. By receiving the request, the network traffic hub prevents automatic establishment of the port service between the smart appliance and the router until an approval or denial of the port sendee is received from, a user. As such, the user is informed of the request and has the ability to approve or deny the port service. Furthermore, the network traffic hub can configure a network to perform a port sendee if the network does not allow for it natively.
G06F 15/173 - Communication entre processeurs utilisant un réseau d'interconnexion, p. ex. matriciel, de réarrangement, pyramidal, en étoile ou ramifié
75.
SECURING PORT FORWARDING THROUGH A NETWORK TRAFFIC HUB
A network traffic hub is configured to receive a request for a port service (i.e., port forwarding or port triggering) from a smart appliance in a local network. The request may be a part of the UPnP protocol, which includes SSDP and IGDP. The request may be transmitted to the network traffic hub directly or the network traffic hub may intercept the request transmitted to a router of the local network. By receiving the request, the network traffic hub prevents automatic establishment of the port service between the smart appliance and the router until an approval or denial of the port sendee is received from, a user. As such, the user is informed of the request and has the ability to approve or deny the port service. Furthermore, the network traffic hub can configure a network to perform a port sendee if the network does not allow for it natively.
G06F 15/173 - Communication entre processeurs utilisant un réseau d'interconnexion, p. ex. matriciel, de réarrangement, pyramidal, en étoile ou ramifié
76.
Securing port forwarding through a network traffic hub
A network traffic hub is configured to receive a request for a port service (i.e., port forwarding or port triggering) from a smart appliance in a local network. The request may be a part of the UPnP protocol, which includes SSDP and IGDP. The request may be transmitted to the network traffic hub directly or the network traffic hub may intercept the request transmitted to a router of the local network. By receiving the request, the network traffic hub prevents automatic establishment of the port service between the smart appliance and the router until an approval or denial of the port service is received from a user. As such, the user is informed of the request and has the ability to approve or deny the port service. Furthermore, the network traffic hub can configure a network to perform a port service if the network does not allow for it natively.
H04L 29/06 - Commande de la communication; Traitement de la communication caractérisés par un protocole
H04L 12/28 - Réseaux de données à commutation caractérisés par la configuration des liaisons, p. ex. réseaux locaux [LAN Local Area Networks] ou réseaux étendus [WAN Wide Area Networks]
H04L 29/12 - Dispositions, appareils, circuits ou systèmes non couverts par un seul des groupes caractérisés par le terminal de données
77.
DETECTING MALICIOUS BEHAVIOR WITHIN LOCAL NETWORKS
A behavior analysis engine and a network traffic hub can identify malicious behavior within a local network con- taining the network traffic hub. The behavior analysis engine can execute executable files that are downloaded by networked de- vices in the local network in a sandbox environment and determine if the executable files are malicious. The behavior analysis engine can also identify malicious network addresses based on features of the network addresses. The behavior analysis engine may iden- tify entities connected to a received entity and determine whether the entity is malicious based on whether the connected entities are malicious, and further may generate condensed versions of ma- chine-learned models to be executed locally on network traffic hubs in local networks.
G06F 21/53 - Contrôle des utilisateurs, des programmes ou des dispositifs de préservation de l’intégrité des plates-formes, p. ex. des processeurs, des micrologiciels ou des systèmes d’exploitation au stade de l’exécution du programme, p. ex. intégrité de la pile, débordement de tampon ou prévention d'effacement involontaire de données par exécution dans un environnement restreint, p. ex. "boîte à sable" ou machine virtuelle sécurisée
78.
DETECTING MALICIOUS BEHAVIOR WITHIN LOCAL NETWORKS
A behavior analysis engine and a network traffic hub can identify malicious behavior within a local network containing the network traffic hub. The behavior analysis engine can execute executable files that are downloaded by networked devices in the local network in a sandbox environment and determine if the executable files are malicious. The behavior analysis engine can also identify malicious network addresses based on features of the network addresses. The behavior analysis engine may identify entities connected to a received entity and determine whether the entity is malicious based on whether the connected entities are malicious, and further may generate condensed versions of machine-learned models to be executed locally on network traffic hubs in local networks.
G06F 21/53 - Contrôle des utilisateurs, des programmes ou des dispositifs de préservation de l’intégrité des plates-formes, p. ex. des processeurs, des micrologiciels ou des systèmes d’exploitation au stade de l’exécution du programme, p. ex. intégrité de la pile, débordement de tampon ou prévention d'effacement involontaire de données par exécution dans un environnement restreint, p. ex. "boîte à sable" ou machine virtuelle sécurisée
79.
Detecting malicious network addresses within a local network
The behavior analysis engine can also detect malicious network addresses that are sent to networked devices in the local network. The network traffic hub identifies network communications that are transmitted through the local network that contain network addresses. The network traffic hub transmits (or sends) the network address to the behavior analysis engine and the behavior analysis engine extracts network address features from the network address. The behavior analysis engine then applies an execution model to the execution features to determine a confidence score for the network address that represents the execution model's certainty that the network address is malicious. The behavior analysis engine uses the confidence score to provide instructions to the network traffic hub as to whether to allow the networked device to receive the network address.
G06F 21/53 - Contrôle des utilisateurs, des programmes ou des dispositifs de préservation de l’intégrité des plates-formes, p. ex. des processeurs, des micrologiciels ou des systèmes d’exploitation au stade de l’exécution du programme, p. ex. intégrité de la pile, débordement de tampon ou prévention d'effacement involontaire de données par exécution dans un environnement restreint, p. ex. "boîte à sable" ou machine virtuelle sécurisée
H04L 43/062 - Génération de rapports liés au trafic du réseau
H04L 43/026 - Capture des données de surveillance en utilisant l’identification du flux
H04L 41/16 - Dispositions pour la maintenance, l’administration ou la gestion des réseaux de commutation de données, p. ex. des réseaux de commutation de paquets en utilisant l'apprentissage automatique ou l'intelligence artificielle
80.
Determining entity maliciousness based on associated entities
The behavior analysis engine can identify malicious entities based on connections between the entity and other entities. The behavior analysis engine receives an entity from the network traffic hub and identifies entities that are connected to the entity within a threshold degree of separation. The behavior analysis engine applies a recursive process to the entity whereby the behavior analysis engine determines whether an entity is malicious based on whether its connections within a threshold degree of separation are malicious. The behavior analysis engine uses the maliciousness of the entities' connections to determine whether the entity is malicious and, if the entity is malicious, the behavior analysis engine may instruct the network traffic hub to block network communications associated with the malicious entity.
G06F 21/55 - Détection d’intrusion locale ou mise en œuvre de contre-mesures
G06F 21/53 - Contrôle des utilisateurs, des programmes ou des dispositifs de préservation de l’intégrité des plates-formes, p. ex. des processeurs, des micrologiciels ou des systèmes d’exploitation au stade de l’exécution du programme, p. ex. intégrité de la pile, débordement de tampon ou prévention d'effacement involontaire de données par exécution dans un environnement restreint, p. ex. "boîte à sable" ou machine virtuelle sécurisée
H04L 43/062 - Génération de rapports liés au trafic du réseau
H04L 43/026 - Capture des données de surveillance en utilisant l’identification du flux
H04L 41/16 - Dispositions pour la maintenance, l’administration ou la gestion des réseaux de commutation de données, p. ex. des réseaux de commutation de paquets en utilisant l'apprentissage automatique ou l'intelligence artificielle
81.
Determining the maliciousness of executable files using a remote sandbox environment
The behavior analysis engine detects malicious executable files that are being downloaded by networked devices in the local network by executing the executable files in a sandboxing environment operating on the behavior analysis engine. The network traffic hub identifies network communications that are transmitted through the local network that contain executable files. The network traffic hub sends the executable file to the behavior analysis engine and the behavior analysis engine executes the executable file in a sandboxing environment that replicates the networked device that was downloading the executable. The behavior analysis engine extracts execution features from the execution of the executable file and applies an execution model to the execution features to determine a confidence score for the executable file. The behavior analysis engine uses the confidence score to provide instructions to the network traffic hub as to whether to allow the networked device to download the executable.
G06F 15/76 - Architectures de calculateurs universels à programmes enregistrés
H04L 12/24 - Dispositions pour la maintenance ou la gestion
G06F 21/55 - Détection d’intrusion locale ou mise en œuvre de contre-mesures
G06F 21/53 - Contrôle des utilisateurs, des programmes ou des dispositifs de préservation de l’intégrité des plates-formes, p. ex. des processeurs, des micrologiciels ou des systèmes d’exploitation au stade de l’exécution du programme, p. ex. intégrité de la pile, débordement de tampon ou prévention d'effacement involontaire de données par exécution dans un environnement restreint, p. ex. "boîte à sable" ou machine virtuelle sécurisée
H04L 12/26 - Dispositions de surveillance; Dispositions de test
82.
Applying condensed machine learned models within a local network
The behavior analysis engine can condense stored machine-learned models and transmit the condensed versions of the machine-learned models to the network traffic hub to be applied in the local networks. When the behavior analysis engine receives new data that can be used to further train a machine-learned model, the behavior analysis engine updates the machine-learned model and generates a condensed-version of the machine-learned model. The condensed-version of the machine-learned model may be more resource efficient than the machine-learned model while capable of making similar or the same decisions as the machine-learned model. The behavior analysis engine transmits the condensed version of the machine-learned model to the network traffic hub and the network traffic hub uses the condensed-version of the machine-learned model to identify malicious behavior in the local network.
G06F 15/76 - Architectures de calculateurs universels à programmes enregistrés
H04L 12/24 - Dispositions pour la maintenance ou la gestion
G06F 21/55 - Détection d’intrusion locale ou mise en œuvre de contre-mesures
G06F 21/53 - Contrôle des utilisateurs, des programmes ou des dispositifs de préservation de l’intégrité des plates-formes, p. ex. des processeurs, des micrologiciels ou des systèmes d’exploitation au stade de l’exécution du programme, p. ex. intégrité de la pile, débordement de tampon ou prévention d'effacement involontaire de données par exécution dans un environnement restreint, p. ex. "boîte à sable" ou machine virtuelle sécurisée
H04L 12/26 - Dispositions de surveillance; Dispositions de test
H04L 43/062 - Génération de rapports liés au trafic du réseau
H04L 43/026 - Capture des données de surveillance en utilisant l’identification du flux
H04L 41/16 - Dispositions pour la maintenance, l’administration ou la gestion des réseaux de commutation de données, p. ex. des réseaux de commutation de paquets en utilisant l'apprentissage automatique ou l'intelligence artificielle
83.
EXTRACTING ENCRYPTION METADATA AND TERMINATING MALICIOUS CONNECTIONS USING MACHINE LEARNING
A network traffic hub extracts encryption metadata from messages establishing an encrypted connection between a smart appliance and a remote server and determines whether malicious behavior is present in the messages. For example, the network traffic hub can extract an encryption cipher suite, identified encryption algorithms, or a public certificate. The network traffic hub detects malicious behavior or security threats based on the encryption metadata. These security threats may include a man-in-the-middle attacker or a Padding Oracle On Downgraded Legacy Encryption attack. Upon detecting malicious behavior or security threats, the network traffic hub blocks the encrypted traffic or notifies a user.
A network traffic hub extracts encryption metadata from messages establishing an encrypted connection between a smart appliance and a remote server and determines whether malicious behavior is present in the messages. For example, the network traffic hub can extract an encryption cipher suite, identified encryption algorithms, or a public certificate. The network traffic hub detects malicious behavior or security threats based on the encryption metadata. These security threats may include a man-in-the-middle attacker or a Padding Oracle On Downgraded Legacy Encryption attack. Upon detecting malicious behavior or security threats, the network traffic hub blocks the encrypted traffic or notifies a user.
A network traffic hub extracts encryption metadata from messages establishing an encrypted connection between a smart appliance and a remote server and determines whether malicious behavior is present in the messages. For example, the network traffic hub can extract an encryption cipher suite, identified encryption algorithms, or a public certificate. The network traffic hub detects malicious behavior or security threats based on the encryption metadata. These security threats may include a man-in-the-middle attacker or a Padding Oracle On Downgraded Legacy Encryption attack. Upon detecting malicious behavior or security threats, the network traffic hub blocks the encrypted traffic or notifies a user.
H04B 10/114 - Systèmes d’intérieur ou à courte portée
H04L 12/28 - Réseaux de données à commutation caractérisés par la configuration des liaisons, p. ex. réseaux locaux [LAN Local Area Networks] ou réseaux étendus [WAN Wide Area Networks]
A system and method for intercepting intra-network traffic for smart appliance behavior analysis. A network traffic hub is configured to intercept network traffic between a switch and a router. A smart appliance sends a message to the router, such as a DHCP request when the smart appliance joins the network. The router sends a response to the smart appliance. The network traffic hub intercepts and modifies the response to instruct the smart appliance to send all future intra-network traffic through the network traffic hub and the router. In some embodiments, the network traffic hub alters a network mask in the response message to instruct the smart appliance to send traffic through the network traffic hub. The network traffic hub then extracts data from the network traffic and uses that data for behavior analysis of smart appliances.
H04L 29/06 - Commande de la communication; Traitement de la communication caractérisés par un protocole
H04L 29/08 - Procédure de commande de la transmission, p.ex. procédure de commande du niveau de la liaison
H04L 29/12 - Dispositions, appareils, circuits ou systèmes non couverts par un seul des groupes caractérisés par le terminal de données
H04L 12/28 - Réseaux de données à commutation caractérisés par la configuration des liaisons, p. ex. réseaux locaux [LAN Local Area Networks] ou réseaux étendus [WAN Wide Area Networks]
H04L 12/707 - Prévention ou récupération du défaut de routage, p.ex. reroutage, redondance de route "virtual router redundancy protocol" [VRRP] ou "hot standby router protocol" [HSRP] par redondance des chemins d’accès
88.
INTERCEPTING INTRA-NETWORK COMMUNICATION FOR SMART APPLIANCE BEHAVIOR ANALYSIS
A system and method for intercepting intra-network traffic for smart appliance behavior analysis. A network traffic hub is configured to intercept network traffic between a switch and a router. A smart appliance sends a message to the router, such as a DHCP request when the smart appliance joins the network. The router sends a response to the smart appliance. The network traffic hub intercepts and modifies the response to instruct the smart appliance to send all future intra-network traffic through the network traffic hub and the router. In some embodiments, the network traffic hub alters a network mask in the response message to instruct the smart appliance to send traffic through the network traffic hub. The network traffic hub then extracts data from the network traffic and uses that data for behavior analysis of smart appliances.
G06F 15/173 - Communication entre processeurs utilisant un réseau d'interconnexion, p. ex. matriciel, de réarrangement, pyramidal, en étoile ou ramifié
A method and system for detecting malicious behavior from smart appliances within a network. Smart appliances have a certain level of intelligence that allows them to perform a specific role more effectively and conveniently. Network traffic data and appliance identification data is collected about smart appliances within a network. The data is sent to a behavior analysis engine, which computes confidence levels for anomalies within the network traffic that may be caused by malicious behavior. If the behavior analysis engine determines that malicious behavior is present in the network, it sends an instruction to a network traffic hub to block network traffic relating to the anomaly. In some embodiments, network traffic is blocked based on source-destination pairs. In some embodiments, network traffic is blocked from a device outside the network that is determined to be malicious.
H04L 12/28 - Réseaux de données à commutation caractérisés par la configuration des liaisons, p. ex. réseaux locaux [LAN Local Area Networks] ou réseaux étendus [WAN Wide Area Networks]
H04L 29/06 - Commande de la communication; Traitement de la communication caractérisés par un protocole
G06F 21/56 - Détection ou gestion de programmes malveillants, p. ex. dispositions anti-virus
H04L 12/26 - Dispositions de surveillance; Dispositions de test
H04L 29/12 - Dispositions, appareils, circuits ou systèmes non couverts par un seul des groupes caractérisés par le terminal de données
A method and system for detecting malicious behavior from smart appliances within a network. Smart appliances have a certain level of intelligence that allows them to perform a specific role more effectively and conveniently. Network traffic data and appliance identification data is collected about smart appliances within a network. The data is sent to a behavior analysis engine, which computes confidence levels for anomalies within the network traffic that may be caused by malicious behavior. If the behavior analysis engine determines that malicious behavior is present in the network, it sends an instruction to a network traffic hub to block network traffic relating to the anomaly. In some embodiments, network traffic is blocked based on source-destination pairs. In some embodiments, network traffic is blocked from a device outside the network that is determined to be malicious.
A method and system for detecting malicious behavior from smart appliances within a network. Smart appliances have a certain level of intelligence that allows them to perform a specific role more effectively and conveniently. Network traffic data and appliance identification data is collected about smart appliances within a network. The data is sent to a behavior analysis engine, which computes confidence levels for anomalies within the network traffic that may be caused by malicious behavior. If the behavior analysis engine determines that malicious behavior is present in the network, it sends an instruction to a network traffic hub to block network traffic relating to the anomaly. In some embodiments, network traffic is blocked based on source-destination pairs. In some embodiments, network traffic is blocked from a device outside the network that is determined to be malicious.
H04L 61/103 - Correspondance entre adresses de types différents à travers les couches réseau, p. ex. résolution d’adresse de la couche réseau dans la couche physique ou protocole de résolution d'adresse [ARP]
A method and system for detecting malicious behavior from smart appliances within a network. Smart appliances have a certain level of intelligence that allows them to perform a specific role more effectively and conveniently. Network traffic data and identification data is collected about smart appliances within a network. The data is sent to a behavior analysis engine, which computes confidence levels for anomalies within the network traffic that may be caused by malicious behavior. If the behavior analysis engine determines that malicious behavior is present in the network, it sends an instruction to a network traffic hub to block network traffic relating to the anomaly. In some embodiments, network traffic is blocked based on source-destination pairs. In some embodiments, network traffic is blocked from a device outside the network that is determined to be malicious.