Method and system for cloaked observation and remediation of software attacks
    2.
    发明授权
    Method and system for cloaked observation and remediation of software attacks 有权
    隐藏观察和软件攻击修复的方法和系统

    公开(公告)号:US08566941B2

    公开(公告)日:2013-10-22

    申请号:US13408980

    申请日:2012-02-29

    IPC分类号: G06F21/00

    摘要: A method and system provide security for a communication network and for one or more nodes within the network. Software can be distributed throughout the network from a centralized location or administrative console. The software can be made resident in the kernel of the operating system of a receiving node. The software can provide an observation functionality, an analysis functionality, a reporting functionality and a remediation functionality or some subset of those functionalities.

    摘要翻译: 一种方法和系统为通信网络和网络内的一个或多个节点提供安全性。 软件可以从集中的位置或管理控制台分布在整个网络中。 该软件可以驻留在接收节点的操作系统的内核中。 该软件可以提供观察功能,分析功能,报告功能和修复功能或这些功能的某些子集。

    METHOD AND SYSTEM FOR CLOAKED OBSERVATION AND REMEDIATION OF SOFTWARE ATTACKS
    3.
    发明申请
    METHOD AND SYSTEM FOR CLOAKED OBSERVATION AND REMEDIATION OF SOFTWARE ATTACKS 有权
    解决方法和系统软件攻击和解决方案

    公开(公告)号:US20080320592A1

    公开(公告)日:2008-12-25

    申请号:US11767173

    申请日:2007-06-22

    IPC分类号: G06F11/00 G06F21/20

    摘要: A method and system provide security for a communication network and for one or more nodes within the network. Software can be distributed throughout the network from a centralized location or administrative console. The software can be made resident in the kernel of the operating system of a receiving node. The software can provide an observation functionality, an analysis functionality, a reporting functionality and a remediation functionality or some subset of those functionalities.

    摘要翻译: 一种方法和系统为通信网络和网络内的一个或多个节点提供安全性。 软件可以从集中的位置或管理控制台分布在整个网络中。 该软件可以驻留在接收节点的操作系统的内核中。 该软件可以提供观察功能,分析功能,报告功能和修复功能或这些功能的某些子集。

    METHOD AND SYSTEM FOR CLOAKED OBSERVATION AND REMEDIATION OF SOFTWARE ATTACKS
    4.
    发明申请
    METHOD AND SYSTEM FOR CLOAKED OBSERVATION AND REMEDIATION OF SOFTWARE ATTACKS 有权
    解决方法和系统软件攻击和解决方案

    公开(公告)号:US20120167214A1

    公开(公告)日:2012-06-28

    申请号:US13408980

    申请日:2012-02-29

    IPC分类号: G06F21/00 G06F11/00

    摘要: A method and system provide security for a communication network and for one or more nodes within the network. Software can be distributed throughout the network from a centralized location or administrative console. The software can be made resident in the kernel of the operating system of a receiving node. The software can provide an observation functionality, an analysis functionality, a reporting functionality and a remediation functionality or some subset of those functionalities.

    摘要翻译: 一种方法和系统为通信网络和网络内的一个或多个节点提供安全性。 软件可以从集中的位置或管理控制台分布在整个网络中。 该软件可以驻留在接收节点的操作系统的内核中。 该软件可以提供观察功能,分析功能,报告功能和修复功能或这些功能的某些子集。

    NETWORK TRAFFIC ANALYSIS USING A DYNAMICALLY UPDATING ONTOLOGICAL NETWORK DESCRIPTION
    5.
    发明申请
    NETWORK TRAFFIC ANALYSIS USING A DYNAMICALLY UPDATING ONTOLOGICAL NETWORK DESCRIPTION 有权
    使用动态更新本体网络的网络流量分析

    公开(公告)号:US20100077078A1

    公开(公告)日:2010-03-25

    申请号:US12626872

    申请日:2009-11-27

    IPC分类号: G06F15/173

    摘要: Network traffic analysis is performed by deploying, across a network having a plurality of network nodes, at least one data collection agent, on at least two of the plurality of network nodes. Each data collection agent may monitor at each network node, a plurality of network connections instantiated during a monitoring time period. Data resulting from the monitoring is acquired from the data collection agents and an ontological description of the network is automatically created from the acquired data. The ontological description is dynamically updated and network traffic analysis is performed using the dynamically updating ontological description.

    摘要翻译: 通过在多个网络节点中的至少两个网络节点上跨越具有多个网络节点的网络部署至少一个数据收集代理来执行网络流量分析。 每个数据采集代理可以在每个网络节点处监视在监视时间段期间实例化的多个网络连接。 从数据采集代理获取监视产生的数据,并从所获取的数据自动创建网络的本体描述。 本体描述是动态更新的,并且使用动态更新本体描述来执行网络流量分析。

    Network traffic analysis using a dynamically updating ontological network description
    6.
    发明授权
    Network traffic analysis using a dynamically updating ontological network description 有权
    网络流量分析采用动态更新本体网络描述

    公开(公告)号:US08429748B2

    公开(公告)日:2013-04-23

    申请号:US12626872

    申请日:2009-11-27

    IPC分类号: G06F21/00

    摘要: Network traffic analysis is performed by deploying, across a network having a plurality of network nodes, at least one data collection agent, on at least two of the plurality of network nodes. Each data collection agent may monitor at each network node, a plurality of network connections instantiated during a monitoring time period. Data resulting from the monitoring is acquired from the data collection agents and an ontological description of the network is automatically created from the acquired data. The ontological description is dynamically updated and network traffic analysis is performed using the dynamically updating ontological description.

    摘要翻译: 通过在多个网络节点中的至少两个网络节点上跨越具有多个网络节点的网络部署至少一个数据收集代理来执行网络流量分析。 每个数据采集代理可以在每个网络节点处监视在监视时间段期间实例化的多个网络连接。 从数据采集代理获取监视产生的数据,并从所获取的数据自动创建网络的本体描述。 本体描述是动态更新的,并且使用动态更新本体描述来执行网络流量分析。

    Method and apparatus for high resolution passive network latency measurement
    7.
    发明授权
    Method and apparatus for high resolution passive network latency measurement 有权
    用于高分辨率无源网络延迟测量的方法和装置

    公开(公告)号:US08243599B2

    公开(公告)日:2012-08-14

    申请号:US11555484

    申请日:2006-11-01

    IPC分类号: H04L12/26

    CPC分类号: H04L43/0858 H04L43/12

    摘要: A method includes receiving a first capture time corresponding to a first time that a data packet is received at a first probe and a second capture time corresponding to a second time that the data packet is received at a second probe. The data packet is from existing network traffic transmitted over a data network. The first and second probes can be configured to capture the data packet in response to a capture instruction. The first capture time and second capture time are different and are used to calculate the latency of at least a portion of a data network.

    摘要翻译: 一种方法包括:接收第一次捕获时间,该第一捕获时间对应于在第一探测时接收到数据分组的第一捕获时间;以及第二捕获时间,该第二捕获时间对应于在第二探测时接收到数据分组的第二时间。 数据包来自通过数据网络传输的现有网络流量。 可以将第一和第二探针配置为响应于捕获指令捕获数据分组。 第一捕获时间和第二捕获时间是不同的,并且用于计算数据网络的至少一部分的等待时间。