SELF ORGANIZING LEARNING TOPOLOGIES
    81.
    发明申请

    公开(公告)号:US20190334941A1

    公开(公告)日:2019-10-31

    申请号:US16508398

    申请日:2019-07-11

    Abstract: In one embodiment, a networking device at an edge of a network generates a first set of feature vectors using information regarding one or more characteristics of host devices in the network. The networking device forms the host devices into device clusters dynamically based on the first set of feature vectors. The networking device generates a second set of feature vectors using information regarding traffic associated with the device clusters. The networking device models interactions between the device clusters using a plurality of anomaly detection models that are based on the second set of feature vectors.

    DEFEATING MAN-IN-THE-MIDDLE ATTACKS IN ONE LEG OF 1+1 REDUNDANT NETWORK PATHS

    公开(公告)号:US20190289022A1

    公开(公告)日:2019-09-19

    申请号:US15920651

    申请日:2018-03-14

    Abstract: In one embodiment, an elimination point device in a network obtains a master secret from a network controller. The elimination point device assesses, using the master secret, whether an incoming packet received by the elimination point device from a redundant path between the elimination point device and a replication point device in the network includes a valid message integrity check (MIC). The elimination point device determines whether the incoming packet was injected maliciously into the redundant path, based on the assessment of the incoming packet. The elimination point device initiates performance of a mitigation action in the network, when the elimination point device determines that the incoming packet was injected maliciously into the redundant path.

    ROUTING TRAFFIC ACROSS ISOLATION NETWORKS
    88.
    发明申请

    公开(公告)号:US20190199626A1

    公开(公告)日:2019-06-27

    申请号:US15854040

    申请日:2017-12-26

    CPC classification number: H04L45/64 H04L45/245 H04L47/19

    Abstract: In one embodiment, a cloud-based service instructs one or more networking devices in a local area network (LAN) to form a virtual network overlay in the LAN that redirects traffic associated with a particular node in the LAN to a first isolation application instance hosted by the service. The first isolation application instance receives the redirected traffic associated with the particular node. The first isolation application instance determines a routing path for the traffic that comprises one or more other isolation application instances hosted by the cloud-based service. The first isolation application instance tags the traffic to indicate the determined routing path. The first isolation application forwards the tagged traffic to a second isolation application instance along the determined routing path.

    VIRTUAL ACCESS POINT (VAP) FORMATION
    90.
    发明申请

    公开(公告)号:US20190166547A1

    公开(公告)日:2019-05-30

    申请号:US16248108

    申请日:2019-01-15

    CPC classification number: H04W48/14 H04L1/18 H04W24/02 H04W88/08

    Abstract: In one embodiment, a supervisory device in a network receives from a plurality of access points (APs) in the network data regarding a network availability request broadcast by a node seeking to access the network and received by the APs in the plurality. The supervisory device uniquely associates the node with a virtual access point (VAP) for the node and forms a VAP mapping between the VAP for the node and a set of the APs in the plurality selected based on the received data regarding the network availability request. One of the APs in the mapping is designated as a primary access point for the node. The supervisory device instructs the primary AP to send a network availability response to the node that includes information for the VAP. The node uses the information for the VAP to access the network via the set of APs in the VAP mapping.

Patent Agency Ranking