Generating network system maps based on network traffic

    公开(公告)号:US11792093B2

    公开(公告)日:2023-10-17

    申请号:US17384458

    申请日:2021-07-23

    IPC分类号: G06F15/173 H04L43/045

    CPC分类号: H04L43/045

    摘要: Systems, methods, and related technologies for generating a network system map based on network traffic and possibly additional data are described. Network traffic may be received and parsed to obtain metadata associated with the network traffic. A network system may be identified based on the metadata. A network system map may be generated for the network system based on one or more of the metadata or the additional data.

    ROGUE DEVICE DETECTION INCLUDING MAC ADDRESS SPOOFING DETECTION

    公开(公告)号:US20240356966A1

    公开(公告)日:2024-10-24

    申请号:US18761048

    申请日:2024-07-01

    摘要: Systems, methods, and related technologies including media access control (MAC) address spoofing detection are described. The MAC address spoofing detection and response may include accessing a first media access control (MAC) address associated with a first communication on a first port of a first network device coupled to a network, accessing a second media access control (MAC) address associated with a second communication on a second port of a second network device coupled to the network, and determining that the second MAC address matches the first MAC address The method further includes identifying a device associated with the first or second communication as being associated with a spoofing event based on the second port differing from the first port and based on the first and second timestamps being within a threshold amount of time from one another and performing an action associated with the first or second port.

    NAME TRANSLATION MONITORING
    3.
    发明申请

    公开(公告)号:US20210367960A1

    公开(公告)日:2021-11-25

    申请号:US17391820

    申请日:2021-08-02

    IPC分类号: H04L29/06 H04L29/12

    摘要: Systems, methods, and related technologies for analyzing traffic based on naming information are described. In certain aspects, name information and address information from a name translation response are stored. The name information is associated with a device based on the device sending a communication to an address associated with the name information.

    Name translation monitoring
    4.
    发明授权

    公开(公告)号:US11108799B2

    公开(公告)日:2021-08-31

    申请号:US16752289

    申请日:2020-01-24

    IPC分类号: H04L29/06 H04L29/12

    摘要: Systems, methods, and related technologies for analyzing traffic based on naming information are described. In certain aspects, name information and address information from a name translation response are stored. The name information is associated with a device based on the device sending a communication to an address associated with the name information.

    ROGUE DEVICE DETECTION INCLUDING MAC ADDRESS SPOOFING DETECTION

    公开(公告)号:US20220255960A1

    公开(公告)日:2022-08-11

    申请号:US17732358

    申请日:2022-04-28

    摘要: Systems, methods, and related technologies including media access control (MAC) address spoofing detection are described. The MAC address spoofing detection and response may include accessing a first MAC address associated with a first communication on a first port of a first network device and accessing a second MAC address associated with a second communication on a second port of a second network device. Whether the first MAC address and the second MAC address match may be determined. Information associated with a third communication associated with the first MAC address on the first port of the first network device and information associated with a fourth communication associated with the second MAC address on the second port of the second network device may be accessed. An action may be performed associated with the second port of the second network device based on the second MAC address matching the first MAC address.

    ROGUE DEVICE DETECTION INCLUDING MAC ADDRESS SPOOFING DETECTION

    公开(公告)号:US20200213352A1

    公开(公告)日:2020-07-02

    申请号:US16237229

    申请日:2018-12-31

    摘要: Systems, methods, and related technologies including media access control (MAC) address spoofing detection are described. The MAC address spoofing detection and response may include accessing a first MAC address associated with a first communication on a first port of a first network device and accessing a second MAC address associated with a second communication on a second port of a second network device. Whether the first MAC address and the second MAC address match may be determined. Information associated with a third communication associated with the first MAC address on the first port of the first network device and information associated with a fourth communication associated with the second MAC address on the second port of the second network device may be accessed. An action may be performed associated with the second port of the second network device based on the second MAC address matching the first MAC address.

    NAME TRANSLATION MONITORING
    7.
    发明申请

    公开(公告)号:US20180167405A1

    公开(公告)日:2018-06-14

    申请号:US15377119

    申请日:2016-12-13

    IPC分类号: H04L29/06 H04L29/12

    摘要: Systems, methods, and related technologies for analyzing traffic based on naming information are described. In certain aspects, name information and address information from a name translation response are stored. The name information is associated with a device based on the device sending a communication to an address associated with the name information.

    GENERATING NETWORK SYSTEM MAPS BASED ON NETWORK TRAFFIC

    公开(公告)号:US20230421466A1

    公开(公告)日:2023-12-28

    申请号:US18464361

    申请日:2023-09-11

    IPC分类号: H04L43/045

    CPC分类号: H04L43/045

    摘要: Systems, methods, and related technologies for generating a network system map based on network traffic and possibly additional data are described. Network traffic may be received and parsed to obtain metadata associated with the network traffic. A network system may be identified based on the metadata. A network system map may be generated for the network system based on one or more of the metadata or the additional data.

    Rogue device detection including mac address spoofing detection

    公开(公告)号:US11349867B2

    公开(公告)日:2022-05-31

    申请号:US16237229

    申请日:2018-12-31

    摘要: Systems, methods, and related technologies including media access control (MAC) address spoofing detection are described. The MAC address spoofing detection and response may include accessing a first MAC address associated with a first communication on a first port of a first network device and accessing a second MAC address associated with a second communication on a second port of a second network device. Whether the first MAC address and the second MAC address match may be determined. Information associated with a third communication associated with the first MAC address on the first port of the first network device and information associated with a fourth communication associated with the second MAC address on the second port of the second network device may be accessed. An action may be performed associated with the second port of the second network device based on the second MAC address matching the first MAC address.