ADAPTIVE ENFORCEMENT OF SECURITY WITHIN A NETWORK

    公开(公告)号:US20230262093A1

    公开(公告)日:2023-08-17

    申请号:US17672262

    申请日:2022-02-15

    Abstract: A system receives one or more ingress data packets from a client device or a user in a network. The system obtains attributes, via packet inspection, from the one or more ingress data packets, and determines one or more embedding vectors from the attributes. The one or more embedding vectors represent a status of a session during which the ingress data packets are obtained. The system transmits the one or more embedding vectors as inputs to a trained machine learning model. The system infers, using the trained machine learning mode, one or more security policies based on the embedding vectors. The system provides or implementing the one or more security policies.

    SELECTIVE FORMATION AND MAINTENANCE OF TUNNELS WITHIN A MESH TOPOLOGY

    公开(公告)号:US20230136635A1

    公开(公告)日:2023-05-04

    申请号:US17515125

    申请日:2021-10-29

    Abstract: Systems and methods are provided for clustering network devices into cohorts. Next, the systems may determine a subset of the network devices between which tunnels are created, based on any of amounts of available memory, jitter, latency, packet loss, and average round trip time. The selective determination may include, determining to create a first tunnel between a first network device of the first cohort and a second network device within the first cohort, and a second tunnel between the first network device and a third network device within the second cohort, and determining not to create tunnels between first remaining network devices of the first cohort and the second set of network devices of the second cohort. The systems provision the tunnel and the second tunnel to transmit data.

    Managing multicast group traffic
    15.
    发明授权

    公开(公告)号:US11632261B2

    公开(公告)日:2023-04-18

    申请号:US17221816

    申请日:2021-04-04

    Abstract: Some examples relate to managing multicast group traffic. In an example, a switch anchor controller receives a request for a multicast group from an associated network switch in a multicast-capable network. The associated network switch registers to the switch anchor controller in the multicast-capable network. In response to the request, the switch anchor controller selects a non-anchor controller in the multicast-capable network to serve the multicast group to the associated network switch. The switch anchor controller provides the information related to the non-anchor controller to the associated network switch, which in response creates a specific multicast tunnel between the associated network switch and the non-anchor controller to transfer multicast traffic related to the multicast group.

    Uplink selection in a SD-WAN
    16.
    发明授权

    公开(公告)号:US11212223B2

    公开(公告)日:2021-12-28

    申请号:US16735028

    申请日:2020-01-06

    Abstract: An example non-transitory, computer-readable medium includes instructions that cause a device to determine, for uplinks of a branch gateway, a link health baseline. The instructions further cause the device to determine, for a set of criticality classes, a class link health baseline for each link health baseline, based on the link health baseline and a tolerance level of each criticality class. The instructions further cause the device to calculate, based in part on weighted parameters of the class link health baselines and an uplink cost, a path quality threshold score for each application category and for each uplink. The instructions further cause the device to select, for each application category, a primary uplink and a secondary uplink based on the path quality threshold scores. The instructions further cause the device to route network traffic through the primary uplink of the application category assigned to the network traffic.

Patent Agency Ranking