Geolocating network nodes in attenuated environments for cyber and network security applications
    61.
    发明授权
    Geolocating network nodes in attenuated environments for cyber and network security applications 有权
    在网络和网络安全应用的衰减环境中定位网络节点

    公开(公告)号:US08977843B2

    公开(公告)日:2015-03-10

    申请号:US13114013

    申请日:2011-05-23

    摘要: A system and method for verifying and/or geolocating network nodes in attenuated environments for cyber and network security applications are disclosed. The system involves an origination network node, a destination network node, and at least one router network node. The origination network node is configured for transmitting a data packet to the destination network node through at least one router network node. The data packet contains a security signature portion, a routing data portion, and a payload data portion. The security signature portion comprises a listing of at least one network node that the data packet travelled through from the origination network node to the destination network node. In addition, the security signature portion comprises geolocation information, identifier information, and timing information for at least one network node in the listing.

    摘要翻译: 公开了一种用于在网络和网络安全应用的衰减环境中验证和/或定位网络节点的系统和方法。 该系统涉及始发网络节点,目的地网络节点和至少一个路由器网络节点。 始发网络节点被配置为通过至少一个路由器网络节点将数据分组发送到目的地网络节点。 数据分组包含安全签名部分,路由数据部分和有效载荷数据部分。 安全签名部分包括数据分组从始发网络节点到目的网络节点经过的至少一个网络节点的列表。 此外,安全签名部分包括地理位置信息,标识符信息和用于列表中的至少一个网络节点的定时信息。

    System and method for managing internetwork communications among a plurality of networks
    62.
    发明授权
    System and method for managing internetwork communications among a plurality of networks 有权
    用于管理多个网络之间的互联网通信的系统和方法

    公开(公告)号:US08917626B2

    公开(公告)日:2014-12-23

    申请号:US12505323

    申请日:2009-07-17

    CPC分类号: H04L12/66 H04L45/52 H04L45/64

    摘要: A system for managing internetwork communications among a plurality of networks includes: (a) a plurality of edge network nodes; each respective edge network node being coupled to manage internetwork communications between a respective own network and other networks of the plurality of networks than the respective own network; and (b) at least one gateway-capable edge network node communicatingly coupled with each respective network node. Each respective edge network node includes a native communication network management unit for managing communications by the respective edge network node using a native communication protocol. Each respective edge network node includes an overlay communication network management unit for managing communications by the respective edge network node using an overlay communication protocol.

    摘要翻译: 一种用于管理多个网络之间的网络间通信的系统包括:(a)多个边缘网络节点; 每个相应的边缘网络节点被耦合以管理相对于相应的自己的网络和多个网络中的其他网络之间的互联网络通信,而不是相应的自己的网络; 和(b)与每个相应网络节点通信耦合的至少一个具有网关功能的边缘网络节点。 每个相应的边缘网络节点包括本地通信网络管理单元,用于使用本地通信协议来管理由相应的边缘网络节点进行的通信。 每个相应的边缘网络节点包括覆盖通信网络管理单元,用于使用覆盖通信协议管理相应边缘网络节点的通信。

    METHODS AND SYSTEMS FOR USE IN IDENTIFYING ABNORMAL BEHAVIOR IN A CONTROL SYSTEM
    65.
    发明申请
    METHODS AND SYSTEMS FOR USE IN IDENTIFYING ABNORMAL BEHAVIOR IN A CONTROL SYSTEM 有权
    用于识别控制系统异常行为的方法和系统

    公开(公告)号:US20120304007A1

    公开(公告)日:2012-11-29

    申请号:US13113529

    申请日:2011-05-23

    IPC分类号: G06F11/07

    摘要: Methods and apparatus for use in identifying abnormal behavior in a control system. Operating events associated with a control system are received, and an actual behavior of the control system is determined based on the received operating events. The actual behavior is compared to expected behavior to determine whether the actual behavior differs from the expected behavior. The expected behavior includes a correlation between a plurality of operating events associated with the control system. The expected behavior is updated based on an indication of whether the actual behavior is abnormal from a user.

    摘要翻译: 用于识别控制系统中的异常行为的方法和装置。 接收到与控制系统相关联的操作事件,并且基于所接收的操作事件来确定控制系统的实际行为。 将实际行为与预期行为进行比较,以确定实际行为是否与预期行为不同。 期望的行为包括与控制系统相关联的多个操作事件之间的相关性。 基于用户的实际行为是否异常的指示来更新预期行为。

    System, model and method for evaluating a network
    68.
    发明授权
    System, model and method for evaluating a network 有权
    用于评估网络的系统,模型和方法

    公开(公告)号:US08014371B1

    公开(公告)日:2011-09-06

    申请号:US12466175

    申请日:2009-05-14

    IPC分类号: H04W4/00

    摘要: A system for evaluating a network having a plurality of domains, each domain embodying a respective topology, includes: (a) at least one gateway unit effecting signal handling between adjacent domains; (b) a plurality of communicating nodes coupled with the at least one gateway unit; and (c) at least one respective edge establishing a respective communication link between adjacent respective communicating nodes. At least one first selected communicating node is a unicast node. At least one second selected communicating node is a multicast node. At least one communicating node is a media node. Each unicast node is configured for handling messages addressed to the unicast node. Each multicast node is connected with at least one media node within a domain. Each media node is configured for handling messages addressed to multicast nodes connected with the media node individually or en masse.

    摘要翻译: 一种用于评估具有多个域的网络的系统,每个域体现相应的拓扑,包括:(a)至少一个网关单元,其实现相邻域之间的信号处理; (b)与所述至少一个网关单元耦合的多个通信节点; 和(c)至少一个相应的边缘,在相邻的各个通信节点之间建立相应的通信链路。 至少一个第一选择的通信节点是单播节点。 至少一个第二选择的通信节点是多播节点。 至少一个通信节点是媒体节点。 每个单播节点被配置用于处理寻址到单播节点的消息。 每个多播节点与域内的至少一个媒体节点相连。 每个媒体节点被配置为单独或大量地处理寻址到与媒体节点连接的多播节点的消息。

    QOS provisioning in a network having dynamic link states
    69.
    发明授权
    QOS provisioning in a network having dynamic link states 有权
    具有动态链路状态的网络中的QOS配置

    公开(公告)号:US07936762B2

    公开(公告)日:2011-05-03

    申请号:US12502218

    申请日:2009-07-13

    IPC分类号: H04L12/28

    摘要: A network node for a network having dynamic link states includes a processing unit and computer-readable memory for causing the processing unit to monitor a link state of the network; perform QoS provisioning and make appropriate updates to the QoS provisioning based on changes in the link state and QoS provisioning demands of QoS-aware applications; and provide notification to the QoS-aware applications to allow those applications to dynamically adapt to the link state changes.

    摘要翻译: 具有动态链路状态的网络的网络节点包括处理单元和计算机可读存储器,用于使处理单元监视网络的链路状态; 根据QoS感知应用的链路状态和QoS配置需求的变化,执行QoS配置并对QoS配置进行适当的更新; 并向QoS感知应用程序提供通知,以允许这些应用程序动态地适应链路状态改变。

    System and method for conveying priority associated with a communication among a plurality of networks
    70.
    发明授权
    System and method for conveying priority associated with a communication among a plurality of networks 有权
    用于传送与多个网络中的通信相关联的优先级的系统和方法

    公开(公告)号:US07864783B2

    公开(公告)日:2011-01-04

    申请号:US12249772

    申请日:2008-10-10

    IPC分类号: H04L12/28

    摘要: A system for conveying priority associated with a communication conveyed among networks includes: (a) a first network originating the communication in packets; each respective packet including two segments; a first segment containing a portion of the communication in information payload bits in a first encoding scheme; a second segment containing overhead information relating to the packet in overhead bits in a second encoding scheme; a number of the overhead bits being configured to indicate the priority; and (b) a second network cooperating with the first network to alter encoding of the first segment of a selected packet-set to express the information payload bits in a third encoding scheme that is unreadable in the second network; the second network employing the priority-indicating bits to ascertain priority for handling the communication by the second network; the second network preempting lower priority resources to reserve resources for higher priority packet-sets.

    摘要翻译: 用于传送与网络之间传送的通信相关联的优先级的系统包括:(a)以分组发送通信的第一网络; 每个分组包括两个分段; 第一段,其包含第一编码方案中信息有效载荷比特中的通信的一部分; 第二段,其包含与第二编码方案中的开销比特中的分组有关的开销信息; 多个开销比特被配置为指示优先级; 和(b)与所述第一网络协作的第二网络,以改变所选分组集合的所述第一分段的编码,以在所述第二网络中不可读的第三编码方案中表示所述信息有效载荷比特; 所述第二网络采用所述优先级指示比特来确定由所述第二网络处理所述通信的优先级; 第二个网络抢占较低优先级资源,为更高优先级的数据包集预留资源。