System and method for real-time analysis of network traffic

    公开(公告)号:US09955023B2

    公开(公告)日:2018-04-24

    申请号:US15783446

    申请日:2017-10-13

    摘要: A system for monitoring a live-data flow through a network includes at least one server communicating with the network. A processor within each of the at least one server implements a first processing node for monitoring a mirrored live-data flow of the live-data flow passing through at least one selected point within the network in a non-intrusive manner that does not affect the live-data flow passing through the at least one selected point. The first processing node decodes data within the mirrored live-data flow according to each protocol associated with the data. The first processing node detects at least one predetermined or deduced condition defined by at least one of a plurality of applications implemented on a second processing node and executes at least one predetermined or deduced response responsive to an indication of occurrence of the at least one predetermined or deduced condition within the decoded data. The first processing node also forwards data from the first processing node to a second processing node data from at least one of the plurality of simultaneous live-data flows based upon occurrence of the at least one predetermined or deduced condition. The processor within the at least one server the processor further implements the second processing node for accessing from the second processing node, external data from an external data source. The second processing node also processes at least a portion of the data forwarded from the first processing node using at least one of the plurality of applications implemented on the second processing node and the external data. The processing of the data by the at least one of the plurality of applications and the external data causes execution of the at least one predetermined or deduced response to determine a manner for controlling an operation of the network at a same time the live-data flow is in active transmission between the endpoints in the network. The operation of the network is controlled in response to the executed at least one predetermined or deduced response while events associated with the live-data flow are occurring within the network.

    System and method for real-time analysis of network traffic

    公开(公告)号:US10701214B2

    公开(公告)日:2020-06-30

    申请号:US16372141

    申请日:2019-04-01

    摘要: A system for monitoring a live-data flow through a network includes at least one server communicating with the network. A processor within each of the at least one server implements a first processing node for monitoring a mirrored live-data flow of the live-data flow passing through at least one selected point within the network in a non-intrusive manner that does not affect the live-data flow passing through the at least one selected point. The first processing node decodes data within the mirrored live-data flow according to each protocol associated with the data. The first processing node detects at least one predetermined or deduced condition defined by at least one of a plurality of applications implemented on a second processing node and executes at least one predetermined or deduced response responsive to an indication of occurrence of the at least one predetermined or deduced condition within the decoded data. The first processing node also forwards data from the first processing node to a second processing node data from at least one of the plurality of simultaneous live-data flows based upon occurrence of the at least one predetermined or deduced condition. The processor within the at least one server the processor further implements the second processing node for accessing from the second processing node, external data from an external data source. The second processing node also processes at least a portion of the data forwarded from the first processing node using at least one of the plurality of applications implemented on the second processing node and the external data. The processing of the data by the at least one of the plurality of applications and the external data causes execution of the at least one predetermined or deduced response to determine a manner for controlling an operation of the network at a same time the live-data flow is in active transmission between the endpoints in the network. The operation of the network is controlled in response to the executed at least one predetermined or deduced response while events associated with the live-data flow are occurring within the network.

    System and method for real-time analysis of network traffic
    5.
    发明授权
    System and method for real-time analysis of network traffic 有权
    实时分析网络流量的系统和方法

    公开(公告)号:US09529621B2

    公开(公告)日:2016-12-27

    申请号:US15180496

    申请日:2016-06-13

    摘要: A system for monitoring live-data flow through a network includes a processor implementing a first processing node including an ingestor virtual machine (ingestor VM) for monitoring a mirrored live-data flow of the live-data flow passing through a selected point within the network in a non-intrusive manner that does not affect the live-data flow of at least one live data flow passing through the selected point. The ingestor VM further decodes each packet within the mirrored data flow according to each protocol associated with a packet and manages processes occurring within and between the first processing node and a second processing node. A time dependent buffer virtual machine (TDB VM) allocates a time dependent buffer (TDB) within the memory for executing the processes performed within and between the first processing node and a second processing node, and releasing the allocated TDB after completion of the processes. A governor virtual machine (governor VM) allocates memory resources within the memory between the first processing node and the second processing node for the processes performed within and between the first processing node and a second processing node. A grid virtual machine (grid VM) controls communications within and between the first processing nodes and between the first processing node and the second processing node.

    摘要翻译: 用于监视通过网络的实时数据流的系统包括执行第一处理节点的处理器,该第一处理节点包括摄取器虚拟机(摄取器VM),用于监视通过网络内的选定点的实时数据流的镜像实时数据流 以不侵入的方式,不影响通过所选点的至少一个实时数据流的实时数据流。 摄取器VM根据与分组相关联的每个协议进一步解码镜像数据流中的每个分组,并管理在第一处理节点和第二处理节点之间发生的进程。 时间相关缓冲器虚拟机(TDB VM)在存储器内分配时间相关缓冲器(TDB),用于执行在第一处理节点和第二处理节点之间执行的处理,并且在完成处理之后释放所分配的TDB。 调控器虚拟机(调控器VM)在第一处理节点和第二处理节点之间的存储器内为在第一处理节点和第二处理节点之间执行的处理分配内存资源。 网格虚拟机(网格VM)控制第一处理节点内和第一处理节点之间以及第一处理节点和第二处理节点之间的通信。

    System and method for an automated system for continuous observation, audit and control of user activities as they occur within a mobile network

    公开(公告)号:US10700976B2

    公开(公告)日:2020-06-30

    申请号:US15989962

    申请日:2018-05-25

    摘要: A method for detecting a fraudulent attempt to activate a new PIN, SIM Card or mobile device includes monitoring, at a first processing node associated with a network interconnecting a first network point and a second network point, a mirrored live-data flow of a live data flow passing through the first processing node in a non-intrusive manner that does not affect the first live-data flow passing through the first processing node. The live-data flow comprises data that is in active transmission between the first network point and the second network point and prior to storage of the data in a database. The first processing node detects that a transaction within the monitored live-data flow relates to an activation of the new PIN, SIM card or mobile device and compares the detected transaction to a list of known fraud situations stored in the first processing node to determine if the detected transaction relates to a known fraud situation. The first processing node generates an alert indication responsive to a determination the detected data relates to one of a plurality of known fraud situations. The first processing node identifies the detected transaction as a potential fraud situation responsive to a determination the detected data does not relate to one of the plurality known fraud situations. An automatically generated dialog verification with a party requesting the new PIN, SIM Card or mobile device is performed to verify identity of the party requesting the new PIN, SIM Card or mobile device for the detected transaction identified as the potential fraud situation.

    SYSTEM AND METHOD FOR REAL-TIME ANALYSIS OF NETWORK TRAFFIC

    公开(公告)号:US20190281167A1

    公开(公告)日:2019-09-12

    申请号:US16372141

    申请日:2019-04-01

    摘要: A system for monitoring a live-data flow through a network includes at least one server communicating with the network. A processor within each of the at least one server implements a first processing node for monitoring a mirrored live-data flow of the live-data flow passing through at least one selected point within the network in a non-intrusive manner that does not affect the live-data flow passing through the at least one selected point. The first processing node decodes data within the mirrored live-data flow according to each protocol associated with the data. The first processing node detects at least one predetermined or deduced condition defined by at least one of a plurality of applications implemented on a second processing node and executes at least one predetermined or deduced response responsive to an indication of occurrence of the at least one predetermined or deduced condition within the decoded data. The first processing node also forwards data from the first processing node to a second processing node data from at least one of the plurality of simultaneous live-data flows based upon occurrence of the at least one predetermined or deduced condition. The processor within the at least one server the processor further implements the second processing node for accessing from the second processing node, external data from an external data source. The second processing node also processes at least a portion of the data forwarded from the first processing node using at least one of the plurality of applications implemented on the second processing node and the external data. The processing of the data by the at least one of the plurality of applications and the external data causes execution of the at least one predetermined or deduced response to determine a manner for controlling an operation of the network at a same time the live-data flow is in active transmission between the endpoints in the network. The operation of the network is controlled in response to the executed at least one predetermined or deduced response while events associated with the live-data flow are occurring within the network.

    System and method for an automated system for continuous observation, audit and control of user activities as they occur within a mobile network
    10.
    发明授权
    System and method for an automated system for continuous observation, audit and control of user activities as they occur within a mobile network 有权
    用于在移动网络内发生的用户活动的连续观察,审核和控制的自动化系统的系统和方法

    公开(公告)号:US09532227B2

    公开(公告)日:2016-12-27

    申请号:US15162159

    申请日:2016-05-23

    摘要: A system and method monitors for fraudulent transactions relating to a mobile device. Either of first and second processing nodes places a hold on a transaction associated with the first live-data flow and the second live-data flow responsive to detection of a potentially fraudulent condition. A third processing node generates an interactive verification communication responsive to the first data associated with the first live-data flow and the second data associated with the second live-data flow to establish a validity of the transaction. The third processing node releases the hold on the transaction responsive to the interactive verification communication determining the potentially fraudulent condition relates to a non-fraudulent transaction and generates a fraud detection response responsive to the interactive verification communication determining the potentially fraudulent condition relates to a fraudulent transaction before the transaction completes.

    摘要翻译: 系统和方法监视涉及移动设备的欺诈交易。 第一处理节点和第二处理节点之一响应于对潜在的欺诈条件的检测,对与第一实时数据流和第二实时数据流相关联的事务进行保持。 第三处理节点响应于与第一实时数据流相关联的第一数据和与第二实时数据流相关联的第二数据来产生交互验证通信,以建立交易的有效性。 第三处理节点响应于交互验证通信释放事务的保留,确定潜在的欺诈条件涉及非欺诈性交易,并且响应于交互验证通信产生欺诈检测响应,确定潜在的欺诈条件涉及欺诈交易 在交易完成之前。