Detecting anomalous network behavior
    112.
    发明申请

    公开(公告)号:US20190238575A1

    公开(公告)日:2019-08-01

    申请号:US16005799

    申请日:2018-06-12

    Applicant: Rapid7, Inc.

    Inventor: Roy Hodgman

    Abstract: Approaches provide for monitoring attempted network activity such as network port connections and corresponding payloads of network data obtained by a network device and, based on the attempted connections and/or payloads, identifying malicious network activity in real time. For example, network activity obtained from a plurality of network devices in a service provider environment can be monitored to attempt to detect compliance with appropriate standards and/or any of a variety of resource usage guidelines (e.g., network behavioral standards or other such rules, guidelines, or network behavior tests) based at least in part on network port connection activity with respect to at least one network device. If it is determined that network activity is not in compliance with the usage guidelines, or other such network behavior test, the system can take one or more remedial actions, which can include generating a notification identifying the malicious network activity.

    AUTOMATIC SERVER CLASSIFICATION IN CLOUD ENVIRONMENTS

    公开(公告)号:US20190199608A1

    公开(公告)日:2019-06-27

    申请号:US15852758

    申请日:2017-12-22

    Abstract: A computer system for classifying one or more servers by server type in a networked computing system to institute server-type based monitoring and or maintenance of the networked computing system. The computer system includes a processor, a memory, a data receiver, a server signature generator, and a server-type tagging service. The data receiver collects server performance data for a first server over a time interval. The server signature generator determines a signature of the first server based on the collected server performance data. The server-type tagging service compares the signature of the first server to a signature of a second server of known server type, determines a similarity of the signature of the first server to the signature of the second server, and, based on the similarity, classifies the first server as being of the same server type as the second server.

    INTELLIGENT NETWORK ACCESS MODE CONFIGURATION BASED ON USAGE CONDITIONS

    公开(公告)号:US20190199586A1

    公开(公告)日:2019-06-27

    申请号:US16289642

    申请日:2019-02-28

    Abstract: A first wireless operating mode of a plurality of wireless operating modes may be selected. The plurality of wireless operating modes may be related to a plurality of antenna configurations and a plurality of wireless radio frequencies. In some implementations, the selecting of the first wireless operating mode may be based on the identified power mode of the first digital device. The first wireless operating mode may be associated with a first antenna configuration of the plurality of antenna configurations. The first wireless operating mode may be associated with a first wireless radio frequency of the plurality of wireless radio frequencies for the data to be accessed by the first digital device over the wireless access device.

    SYSTEM AND METHOD FOR OBTAINING MICRO-SERVICE TELEMETRY DATA

    公开(公告)号:US20190123984A1

    公开(公告)日:2019-04-25

    申请号:US15793557

    申请日:2017-10-25

    Abstract: Systems, methods, and computer-readable media are disclosed for use of an overlay network termination endpoint as a proxy to collect telemetry data for micro-services or specific applications provided by containers in overlay data centers. In one aspect of the present disclosure, a method includes receiving, at a controller, a probe for flow statistics associated with a service path, the probe including corresponding flow identification information, extracting the corresponding flow identification information from the probe, obtaining the flow statistics from an agent based on the flow identification information, the agent being configured to manage a plurality of containers, generating a response packet including the flow statistics obtained from the agent and sending the response packet to an initiator from which the query is received.

Patent Agency Ranking