FRAMEWORK FOR INVESTIGATING EVENTS
    2.
    发明公开

    公开(公告)号:US20230421581A1

    公开(公告)日:2023-12-28

    申请号:US18241663

    申请日:2023-09-01

    CPC classification number: H04L63/1416 H04L41/0609 H04L63/1425 H04L63/1433

    Abstract: A method includes accessing events associated with a network and determining an issue based on a correlation of a portion of the events, wherein the issue represents an incident associated with the portion of the events, and wherein the correlation of the portion of the events is based on information associated with the network and at least in part on an event type of the portion of the events. A priority associated with the issue is determined at least based on the event type of the portion of the events. A first event type that is associated with an operational technology (OT) entity has a higher priority than a second event type that is not associated with the OT entity. Data associated with the issue is stored.

    ITERATIVE DEVELOPMENT OF PROTOCOL PARSERS
    3.
    发明公开

    公开(公告)号:US20230198882A1

    公开(公告)日:2023-06-22

    申请号:US17557769

    申请日:2021-12-21

    CPC classification number: H04L43/18 H04L43/04

    Abstract: Systems, methods, and related technologies for determining fields of an unknown protocol are described. One or more packets may be removed from a network traffic capture in response to the one or more packets having a known protocol. The remaining network traffic capture may be grouped into one or more clusters of packets based on similarity. Each of the one or more clusters may be parsed to identify one or more fields of an unknown protocol. The network traffic capture may be modified, including annotating the one or more fields of the unknown protocol.

    ITERATIVE DEVELOPMENT OF PROTOCOL PARSERS

    公开(公告)号:US20250071043A1

    公开(公告)日:2025-02-27

    申请号:US18948155

    申请日:2024-11-14

    Abstract: Systems and methods to determine fields of an unknown protocol are described. The method includes grouping network traffic capture into one or more clusters of packets based on similarity and parsing each of the one or more clusters to identify one or more fields of an unknown protocol. The method further includes generating a description of the unknown protocol comprising the identified one or more fields of the unknown protocol and an order of the identified one or more fields of the unknown protocol. The method further includes compiling the description into a protocol parser.

    Iterative development of protocol parsers

    公开(公告)号:US11777832B2

    公开(公告)日:2023-10-03

    申请号:US17557769

    申请日:2021-12-21

    CPC classification number: H04L43/18 H04L43/04

    Abstract: Systems, methods, and related technologies for determining fields of an unknown protocol are described. One or more packets may be removed from a network traffic capture in response to the one or more packets having a known protocol. The remaining network traffic capture may be grouped into one or more clusters of packets based on similarity. Each of the one or more clusters may be parsed to identify one or more fields of an unknown protocol. The network traffic capture may be modified, including annotating the one or more fields of the unknown protocol.

    ENTITY ATTRIBUTE DESIGNATION BASED ON LOGIC PROGRAMMING

    公开(公告)号:US20230099243A1

    公开(公告)日:2023-03-30

    申请号:US17489890

    申请日:2021-09-30

    Abstract: Systems, methods, and related technologies for entity classification and attribute designation are described. Device property data associated with a device coupled to a network is accessed. One or more features for the device are identified based on the device property data. A first value for an attribute of the device is determined based on a set of rules applied to the one or more features of the device. A first belief value for the attribute is determined based on the set of rules applied to the one or more features of the device. A final value for the attribute of the device is selected based at least in part on the first belief value for the first value of the attribute.

Patent Agency Ranking