Systems and methods for automatically selecting an access control entity to mitigate attack traffic

    公开(公告)号:US10673891B2

    公开(公告)日:2020-06-02

    申请号:US15608568

    申请日:2017-05-30

    IPC分类号: H04L29/06 H04L12/26

    摘要: The methods and system described herein automatically generate network router access control entities (ACEs) that are used to filter internet traffic and more specifically to block malicious traffic. The rules are generated by an ACE engine that processes incoming internet packets and examines existing ACEs and a statistical profile of the captured packets to produce one or more recommended ACEs with a quantified measure of confidence. Preferably, a recommended ACE is identified in real time of the attack, and preferably selected from a library of pre-authored ACEs. It is then deployed automatically or alternatively sent to system personnel for review and confirmation.

    High performance distributed system of record with confidence-based consensus

    公开(公告)号:US20200167779A1

    公开(公告)日:2020-05-28

    申请号:US16697336

    申请日:2019-11-27

    摘要: A high-performance distributed ledger and transaction computing network fabric over which large numbers of transactions are processed concurrently in a scalable, reliable, secure and efficient manner. In one embodiment, the computing network core is configured to support a distributed blockchain network that organizes data in a manner that allows communication, processing and storage of blocks of the chain to be performed concurrently at very high performance and low latency, even when the transactions themselves originate from distant sources. This data organization relies on segmenting a transaction space within autonomous but cooperating computing nodes that are configured as a processing mesh. The system also provides for confidence-based consensus and automated fork resolution. The approach enables the blockchain to continue operating in the presence of an underlying network outage, and to enable clients to make decisions about the disposition of transactions during any period of uncertainty before full consensus has been achieved.

    Multicast overlay network for delivery of real-time video

    公开(公告)号:US20200153882A1

    公开(公告)日:2020-05-14

    申请号:US16747267

    申请日:2020-01-20

    IPC分类号: H04L29/06 H04L29/08

    摘要: A method of multicasting real-time video is described. The method begins by establishing a multicast network of machines capable of ingress, forwarding and broadcasting traffic, together with a mapping infrastructure. The multicast network preferably comprises a portion of an overlay network, such as a content delivery network (CDN). A video stream is published to the multicast network by (a) using the mapping infrastructure to find an ingress node in the multicast network, and then receiving the video stream from a publisher at the ingress node. One or more subscribers then subscribe to the video stream. In particular, and for subscriber, this subscription is carried out by (a) using the mapping infrastructure to find an egress node for the requesting client, and then delivering the video stream to the subscriber from the egress node. Preferably, the publisher and each subscriber use WebRTC to publish or consume the video stream, and video stream is consumed in a videoconference.

    System and method for automated creation of a load test plan

    公开(公告)号:US10606736B1

    公开(公告)日:2020-03-31

    申请号:US15449061

    申请日:2017-03-03

    IPC分类号: G06F11/36 G06F11/30 G06F11/34

    摘要: A computer-implemented method for creation of a test plan for load testing a website includes receiving a set of input parameters, which includes a specified time period range. Beacon data of real user sessions on the website that fall within the specified time period range is retrieved from a data storage repository. A set of peak traffic time periods, which includes a peak day, a peak hour, a peak minute, and a peak second, is identified. User session statistics are calculated for the peak day, the user session statistics including median session duration, session length, and think times. A page group distribution table is generated that includes a list of all page groups and page group hit percentages, relative to all other page groups, for the real user sessions during the peak hour. A set of test scenario paths representative of the page group distribution table is then generated.

    Segmented parallel encoding with frame-aware, variable-size chunking

    公开(公告)号:US10595059B2

    公开(公告)日:2020-03-17

    申请号:US15969563

    申请日:2018-05-02

    发明人: James A. Mutton

    摘要: The subject matter herein generally relates to transcoding content, typically audio/video files though not limited to such, from one version to another in preparation for online streaming or other delivery to end users. Such transcoding may involve converting from one format to another (e.g., changing codecs or container formats), or creating multiple versions of an original source file in different bitrates, frame-sizes, or otherwise, to support distribution to a wide array of devices and to utilize performance-enhancing technologies like adaptive bitrate streaming. A transcoding platform is described herein that, in certain embodiments, leverages distributed computing techniques to transcode content in parallel across a platform of machines that are preferably idle or low-utilization resources of a content delivery network. The transcoding system also utilizes, in certain embodiments, improved techniques for segmenting the original source file so as to enable different segments to be sent to different machines for parallel transcodes.

    Efficiently sanitizing a solid state drive (SSD)

    公开(公告)号:US10589286B2

    公开(公告)日:2020-03-17

    申请号:US14831370

    申请日:2015-08-20

    摘要: A low-cost, portable, destructive sanitization method for solid state drives (SSDs) is provided. Preferably, an SSD is destroyed by disintegration within a given time period (approximately 30 minutes or less) using a blending device operating at a given peak power, e.g., greater than 450 W. A pulverizing agent may be admixed with pieces of an SSD printed circuit board prior to initiating the disintegration process to increase the number of particle collisions in a processing/blending chamber. The pulverizing agent may also contain moisture that mitigates suspension of processed SDD particles in the surrounding air (when the mixing chamber is opened). The overall process may be video-recorded for compliance purposes.

    Reducing false positives in bot detection

    公开(公告)号:US10587629B1

    公开(公告)日:2020-03-10

    申请号:US15805100

    申请日:2017-11-06

    IPC分类号: H04L29/06 G06F21/50

    摘要: This disclosure describes a bot detection system that distinguishes bot transactions from human transactions. The system utilizes an anomaly-based filter process to reduce the number of false positives as determined by the system. The filter process includes maintaining a database of anomaly patterns, wherein the patterns are encoded as anomaly pattern strings. As anomalies are detected, they are encoded in the anomaly pattern strings, and the database is updated by maintaining counts on the occurrences of the strings. When a particular pattern string as reflected in the database has a count that exceeds a threshold, the string is determined to be associated with a bot as opposed to a human user.

    Device Discovery for Cloud-Based Network Security Gateways

    公开(公告)号:US20200053129A1

    公开(公告)日:2020-02-13

    申请号:US16101785

    申请日:2018-08-13

    摘要: Among other things, this document describes systems, methods and devices for discovering and identifying client devices that attempt to access out-of-policy network services via a secure web gateway (or other network security gateway) that lacks visibility into the client network actual IP space. This is a common problem with cloud hosted SWG services that enforce access policy from outside of a customer network (e.g., external to an enterprise network), due to network address translation at the interface between the customer network and the public Internet where the cloud-hosted SWG resides. The teachings hereof address this problem. In one embodiment, a cloud hosted SWG can redirect a client to a bouncer device inside the customer network; that bouncer device can capture the actual client IP address.

    Cloud Based Firewall System and Service
    80.
    发明申请

    公开(公告)号:US20200007506A1

    公开(公告)日:2020-01-02

    申请号:US16266335

    申请日:2019-02-04

    IPC分类号: H04L29/06 H04L29/08

    摘要: A cloud-based firewall system and service is provided to protect customer sites from attacks, leakage of confidential information, and other security threats. In various embodiments, such a firewall system and service can be implemented in conjunction with a content delivery network (CDN) having a plurality of distributed content servers. The CDN servers receive requests for content identified by the customer for delivery via the CDN. The CDN servers include firewalls that examine those requests and take action against security threats, so as to prevent them from reaching the customer site. The CDN provider implements the firewall system as a managed firewall service, with the operation of the firewalls for given customer content being defined by that customer, independently of other customers. In some embodiments, a customer may define different firewall configurations for different categories of that customer's content identified for delivery via the CDN.