Patents
Literature
Hiro is an intelligent assistant for R&D personnel, combined with Patent DNA, to facilitate innovative research.
Hiro

45 results about "Packet sampling" patented technology

Packet sampling flow-based detection of network intrusions

A flow-based intrusion detection system for detecting intrusions in computer communication networks. Data packets representing communications between hosts in a computer-to-computer communication network are processed and assigned to various client / server flows. Statistics are collected for each flow. Then, the flow statistics are analyzed to determine if the flow appears to be legitimate traffic or possible suspicious activity. A concern index value is assigned to each flow that appears suspicious. By assigning a value to each flow that appears suspicious and adding that value to the total concern index of the responsible host, it is possible to identify hosts that are engaged in intrusion activity. When the concern index value of a host exceeds a preset alarm value, an alert is issued and appropriate action can be taken.
Owner:CISCO TECH INC

Scalable traffic classifier and classifier training system

A traffic classifier has a plurality of binary classifiers, each associated with one of a plurality of calibrators. Each calibrator trained to translate an output score of the associated binary classifier into an estimated class probability value using a fitted logistic curve, each estimated class probability value indicating a probability that the packet flow on which the output score is based belongs to the traffic class associated with the binary classifier associated with the calibrator. The classifier training system configured to generate a training data based on network information gained using flow and packet sampling methods. In some embodiments, the classifier training system configured to generate reduced training data sets, one for each traffic class, reducing the training data related to traffic not associated with the traffic class.
Owner:AT&T INTPROP I L P

Packet communications unit

To analyze traffic at an application level, a stream according to TCP or SCTP is required to be reconstructed and to be analyzed. When a packet is transferred to analyzing equipment using a port mirroring function with which a router and a switch are provided, transferred traffic volume increases and exceeds the throughput of the analyzing equipment. As only a part of packets configuring a stream is transferred to the analyzing equipment in transfer to the analyzing equipment using a packet sampling function, analysis at the application level is impossible. To solve the problem, when a packet communication unit recognizes a stream start packet, samples a stream initiated by the packet on a condition and at a rate respectively determined beforehand and generates a condition for copying the packet based upon information of both ends of the stream included in the packet, packets sampled in units of stream can be transferred to the analyzing equipment.
Owner:ALAXALA NETWORKS

Detection method for abnormal traffic and packet relay apparatus

InactiveUS20070115850A1Efficient detectionMakes the resources of the target consumedError preventionTransmission systemsTraffic capacityByte
The present invention provides a technology including, for example, a packet relay processing section to carry out packet relay, a packet sampling section to carry out packet sampling, a flow statistics counting section to take statistics of each flow, and a flow statistics generating section to generate a NetFlow export datagram, wherein the flow statistics counting section collectively counts the number of the packets or bytes received per unit time when the number does not exceed a threshold value and individually counts the number for each flow when the number exceeds the threshold value, and thereby a flow of abnormal traffic which is suspected to be DoS attack is efficiently detected with small amounts of resources (mainly memories).
Owner:ALAXALA NETWORKS

Scalable traffic classifier and classifier training system

A traffic classifier has a plurality of binary classifiers, each associated with one of a plurality of calibrators. Each calibrator trained to translate an output score of the associated binary classifier into an estimated class probability value using a fitted logistic curve, each estimated class probability value indicating a probability that the packet flow on which the output score is based belongs to the traffic class associated with the binary classifier associated with the calibrator. The classifier training system configured to generate a training data based on network information gained using flow and packet sampling methods. In some embodiments, the classifier training system configured to generate reduced training data sets, one for each traffic class, reducing the training data related to traffic not associated with the traffic class.
Owner:AT&T INTPROP I LP

Detection method for abnormal traffic and packet relay apparatus

InactiveUS7729271B2Efficient detectionMakes the resources of the target consumedError preventionTransmission systemsTraffic capacityByte
The present invention provides a technology including, for example, a packet relay processing section to carry out packet relay, a packet sampling section to carry out packet sampling, a flow statistics counting section to take statistics of each flow, and a flow statistics generating section to generate a NetFlow export datagram, wherein the flow statistics counting section collectively counts the number of the packets or bytes received per unit time when the number does not exceed a threshold value and individually counts the number for each flow when the number exceeds the threshold value, and thereby a flow of abnormal traffic which is suspected to be DoS attack is efficiently detected with small amounts of resources (mainly memories).
Owner:ALAXALA NETWORKS

Method and apparatus for one-way passive loss measurements using sampled flow statistics

A packet loss estimation technique is disclosed that utilizes the sampled flow level statistics that are routinely collected in operational networks, thereby obviating the need for any new router features or measurement infrastructure. The technique is specifically designed to handle the challenges of sampled flow-level aggregation such as information loss resulting from packet sampling, and generally comprises: receiving a first record of sampled packets for a flow from a first network element; receiving a second record of sampled packets for the flow from a second network element communicating with the first network element; correlating sampled packets from the flow at the first network element and the second network element to a measurement interval; and estimating the packet loss using a count of the sampled packets correlated to the measurement interval.
Owner:AT&T INTPROP I L P

System and method for producing dynamic credit updates for time based packet sampling

A method is provided in one example embodiment and includes receiving a packet flow from a data source at a network element; determining a control value for controlling a sample rate for the packet flow; and recalculating the control value based on a number of packets received and a number of sampled packets. In more particular embodiments, the method can include assigning a particular identifier to a particular packet of the packet flow; generating an input access control list for the data source; and matching the particular identifier to an output port of the network element. In yet other embodiments, the method can include generating a copy of a particular packet of the packet flow; and forwarding the copy of the particular packet to an output access control list based on an assigned quality of service (QoS) group.
Owner:CISCO TECH INC

Scalable traffic classifier and classifier training system

A traffic classifier has a plurality of binary classifiers, each associated with one of a plurality of calibrators. Each calibrator trained to translate an output score of the associated binary classifier into an estimated class probability value using a fitted logistic curve, each estimated class probability value indicating a probability that the packet flow on which the output score is based belongs to the traffic class associated with the binary classifier associated with the calibrator. The classifier training system configured to generate a training data based on network information gained using flow and packet sampling methods. In some embodiments, the classifier training system configured to generate reduced training data sets, one for each traffic class, reducing the training data related to traffic not associated with the traffic class.
Owner:AT&T INTPROP I LP

Data packet sampling statistic method and apparatus

InactiveCN101119246AIncrease sampling distortionSampling Distortion ReductionData switching networksSpecial data processing applicationsDistortionComputer engineering
The present invention discloses a data package sampling statistics method, wherein, the method comprises the following steps: distill the key words of the received data package to obtain the type of the data package; plus the aforesaid type data package counter value with one and delivery the latest counter value according to the preplaced sample alternation; sampling stat the data package if the counter value delivered result is the system preplaced sample value. The present invention samples the data package by classification, samples each type by bags or by time to make sure that each type of the data package can be chosen, which deoxidizes the true flux distributing circus as far as possible and decreases the sampling distortion degree. The present invention, corresponding to the aforesaid method, also provides a data package sampling statistics device.
Owner:NEW H3C TECH CO LTD

Egress Port Overload Protection For Network Packet Forwarding Systems

Systems and methods are disclosed to provide egress port overload protection for network packet forwarding systems. Input packets are received at one or more ingress ports and load balanced among a plurality of egress ports for the packet forwarding system. Load balanced packets associated with each egress port are then sampled to generate sampled load balanced packets that are output from the egress port. For certain embodiments, a sampling percentage is used for the packet sampling, and the sampling percentage for each egress port is set based upon a comparison of a current traffic rate for the egress port to a threshold rate for the egress port. The threshold rates for the egress ports are allowed to be configured through a user interface. Further, session and non-session traffic can be identified, and session aware load balancing and / or per-port packet sampling can be applied.
Owner:KEYSIGHT TECH SINGAPORE (SALES) PTE LTD

Network flow identification system and method based on dynamic data packet sampling

The invention provides a network flow identification system and method based on dynamic data packet sampling. The system comprises a network flow identification server, a data packet analysis module and a behavior analysis module which are successively in unidirectional connection. A traditional network flow identification method can not timely adjust an identification strategy according to continuously changing flow environment, and the conflict is solved in the invention; in a network flow identification process, the system and method of the invention can adjust a current network flow identification strategy through sensing data packet change, and select a first packet information combination protocol identification method, a data packet analysis combination protocol identification method or a network behavior analysis combination protocol identification method; the system and method can automatically select a network flow protocol identification strategy suitable for current flow features according to operation environment change, thereby guaranteeing network flow identification accuracy and treatment efficiency under any flow environment.
Owner:NAT COMP NETWORK & INFORMATION SECURITY MANAGEMENT CENT

Packet switch equipment and bandwidth control method using the same

Disclosed is a packet switch equipment and a band control method using same. In accordance with one embodiment of the invention, a number of packets are sampled by using a packet sampling function provided by a packet switch chip, and the sampled packets are transmitted to a CPU. By using the transmitted sample packets, the total amount of bandwidth used by a corresponding user is estimated based on the source MAC address or the source IP address. If the estimated value exceeds a predetermined threshold, a bandwidth limitation function is applied to the user that is providing packets that exceed the bandwidth. A number of users can be dynamically recognized even when they are undefined, and a dynamic bandwidth limitation function is performed by tracking the bandwidth used by a corresponding user.
Owner:SAMSUNG ELECTRONICS CO LTD

Pseudo-random n-out-of-N packet sampling

A method for sampling n-out-of-N packets in a network. Initially, the packet index corresponding to the N packets is pseudo-randomly shuffled. The shuffle function rearranges a set of numbers pseudo-randomly with a one-to-one mapping and no overlap. One way to perform the pseudo-random shuffle function is to use a linear feedback shift register (LFSR). The LFSR supports N being a power of two. However, the LFSR approach can be adapted to support N being any positive integer value. Based on the results of the shuffle function, sampling points are pseudo-randomly selected. By pseudo-randomly selecting the sample points, n-out-of-N sampling greatly minimizes biases.
Owner:CISCO TECH INC

Cigarette packet sampling-inspection method capable of avoiding unloading of trays from conveying line

The invention discloses a cigarette packet sampling-inspection method capable of avoiding unloading of trays from a conveying line. The cigarette packet sampling-inspection method comprises the steps of cigarette packet ex-warehouse, cigarette packet conveying, cigarette packet sampling-inspection, empty tray stacking, empty tray detection, empty tray return and the like. The cigarette packet sampling-inspection method disclosed by the invention has no need of forking trays off from the conveying line, and is capable of guaranteeing automatic conveying for the trays, reducing the investment of auxiliary equipment, reducing the damage of the trays during a manual operation process, and lowering the production running cost of an enterprise.
Owner:CHINA TOBACCO ZHEJIANG IND

Space-time classification-based dynamic background differential detection method, system and device

The invention discloses a space-time classification-based dynamic background differential detection method, a system and a device. The method comprises the steps of establishing a background model corresponding to each pixel in an image through packet sampling in a time sequence, classifying pixels in the background model according to to-be-detected pixels and obtaining a rough foreground mask image; with a foreground pixel point in the rough foreground mask image as a center, classifying pixel points in a preset neighboring domain range of the central pixel point, and correcting the central pixel point to be a background pixel point or still maintaining the central pixel point as a foreground pixel point according to the number of pixel points the same type with the central pixel point within the preset neighboring domain range of the central pixel point and belonging to background pixel points. According to the invention, the packet sampling method is adopted, so that the ability ofthe dynamic background description is enhanced. Only pixel points the same type of the central pixel point are adopted to judge whether a foreground pixel point is a real foreground pixel point or not. Therefore, the accuracy of detection is improved. The method can be widely applied to the field of moving target detection.
Owner:SUN YAT SEN UNIV

Method, system and device of packet sampling

A method and a system for sampling a packet as well as a device are disclosed herein. The method includes the following steps: a notification node of an LSP sends obtained information about the protocol type of a packet to a specific netflow sampling entity; the netflow sampling entity determines the protocol type of the packet according to the information about the protocol type after receiving the packet, and samples the packet according to the determined protocol type. Through the embodiments of the present invention, the accuracy of netflow sampling is improved significantly.
Owner:HUAWEI TECH CO LTD

Automatic control method for burst luminous power

ActiveCN104579495ASolve the problem of loss of optical power detectionElectromagnetic transmissionAutomatic controlTransmitted power
The invention is applied to the field of luminous power control, and provides an automatic control method for burst luminous power. The automatic control method comprises the following steps: when a laser is in a working state, outputting backlight current which is respectively obtained by a short packet sampling circuit and a medium-long packet sampling circuit, wherein the short packet sampling circuit can sample and maintain the backlight current at the current moment; when a trigger signal is turned into being valid from being invalid, triggering interruption for one time; in the interruption process, judging whether the trigger signal is valid or not; if the trigger signal is determined to be invalid, judging that the data packet transmitted by the laser is a short packet, then jumping out of interruption, triggering computing of the sampled luminous power according to the backlight current stored by the short packet sampling circuit, and adjusting the light transmitting power of the laser according to the comparative analysis result with the targeted luminous power. According to the automatic control method disclosed by the invention, the short time storage characteristic of the short packet sampling circuit is utilized, and the short packet current is stored, so that the problem that in the prior art the short packet luminous power adjustment cannot be processed can be solved.
Owner:WUHAN TELECOMM DEVICES

Hybrid collection method of finite times of high and low frequency signals based on multichannel analog-to-digital converter

ActiveCN106849951AMeet the collection frequency requirementsReasonable useAnalogue-digital convertersHardware structureEngineering
The invention discloses a hybrid collection method of finite times of high and low frequency signals based on a multichannel analog-to-digital converter. Rational configuration of channels is collected within the finite times to realize hybrid collection of waveforms of the high and low frequency signals. The method comprises the following steps: firstly dividing collected signals into low frequency signals or high frequency signals, and determining sampling frequency of the low frequency signals and the high frequency signals; then performing packet sampling on each signal according to the set sampling frequency and parameters according to the limitation of the maximum sampling rate of the analog-to-digital converter and the total number of sampling channels to obtain a set of sampling data points; finally, synthesizing signal waveforms by all data points in the set according to a set rule; and in the case of a fault, judging a sampling group of a fault signal according to mutation data point values, then the signal period data where the packet sampling is located do not participate in the superposition synthesis of previous and successive signal period data. The method disclosed by the invention has the advantages of simple hardware structure and high cost performance ratio.
Owner:ZHEJIANG UNIV

Overall packing method for secondary packaging equipment of particle drugs

The invention provides an overall packing method for secondary packaging equipment of particle drugs. The method can be divided into a packet finishing process, a packet sampling process, a packet collection and grouping process and a packet collection filling-sealing-cutting process. The processes are needed to be tightly matched and smoothly transited, so that equipment is guaranteed to operate continuously, stably and efficiently.
Owner:浙江大学江阴机械装备研发和测试中心

Cigarette packet sampler

The invention discloses a cigarette packet sampler, relates to an automatic sampler for detecting the density, humidity and other indexes of the cigarette packet, which belongs to field of tobacco machinery. The invention provides a cigarette packet sampler which exerts a short-term pressure onto the top of the cigarette packet to avoid the lifting of the cigarette and the damage at the top layer when a sampling rod withdraws. The cigarette packet sampler comprises a machine frame, a cigarette packet transmission device, and a sampling device, wherein, the cigarette packet transmission device is provided with a cigarette packet sampling stay position, the sampling device comprises a driving oil cylinder, a main pressing head, the sampling rod, and a damping pressing packet device, the damping pressing packet device comprises a damping mechanism, and a follow-up pressing plate supported by the damping mechanism; the follow-up pressing plate is arranged above the cigarette packet stay position on the cigarette packet transmission device, and the position on follow-up pressing plate which corresponds to the position of the sampling rod in the sampling device is provided with a through hole which leads the sampling rod to pass through freely. The invention has advantages that: the structure is simple, and the sampling efficiency can be greatly increased.
Owner:YANGZHOU TIANBAO BUSBAR ELECTRICAL

Adaptive protocol sampling method and device

The invention provides an adaptive protocol sampling method and an adaptive protocol sampling device. The method comprises the following steps of presetting a transmission protocol priority according to a transmission protocol type distribution used by virus transmission, wherein each priority corresponds to one priority list; detecting performance parameters of a sampling device and determining a sampling width; receiving and parsing a data packet and obtaining the transmission protocol type of the data packet; determining the priority of the data packet, and determining a sampling rate of the data packet according to the corresponding priority list and sampling width; collecting data in the data packet according to the sampling rate; and sending the collected data to the data processing part. The device comprises a configuration unit, a detecting unit, a data receiving unit, an analysis unit, a data collecting unit and a sending unit. According to the method and the device provided by the invention, when massive data are processed, the priority is determined through the protocol type, and the data with a low degree of importance are abandoned, so that both the equipment performance and result of handling can be ensured.
Owner:BEIJING ANTIY NETWORK SAFETY TECH CO LTD

Method and device for processing data packets

The embodiment of the invention provides a method and a device for processing data packets. The method and the device can be applied to an LVS (Linux Virtual Server). The method comprises the following steps: acquiring all to-be-sent data packets by the LVS; determining sampling data packets, in which IP (Internet Protocol) addresses of corresponding client sides require to be written, of all thedata packets according to a preset data packet sampling rate; writing the IP addresses of the corresponding client sides in the sampling data packets, thus obtaining all target data packets; sending all the target data packets to a preset back-end server, and carrying out service analysis on the client sides corresponding to all the data packets according to the IP addresses of the client sides inall the target data packets by the back-end server based on the processing.
Owner:BEIJING QIYI CENTURY SCI & TECH CO LTD

SDN based user-defined data packet sampling method

The invention discloses an SDN based user-defined data packet sampling method. The SDN based user-defined data packet sampling method comprises the step of 1) setting a sampling module in a controller, and configuring an appointed switch by the controller based on sampling configuration information sent by an upper-layer application; 2) when the controller receives a sampling start instruction sent by the upper-layer application, sending the sampling start instruction to the appointed switch; 3) when the switch receives the sampling start instruction, starting a set timer, sieving each data packet based on configuration to obtain data packets meeting a matching rule, then extracting needed content from the sieved data packets according to a configured sampling mode and outputting the needed content to an appointed port; and 4) when the controller receives a sampling stop instruction sent by the upper-layer application, sending the sampling stop instruction to the appointed switch based on the sampling start instruction, and when the switch receives the sampling stop instruction, stopping sampling and cancelling the timer. The SDN based user-defined data packet sampling method not only guarantees more accurate sampling content, but also can reduce the size of the data packets to the maximum extent.
Owner:INST OF INFORMATION ENG CAS

Second Pulse Synchronization Method Based on Merging Unit SV Packet Sampling Number Learning

The invention discloses a pulse per second synchronization method based on merging unit SV message sampling sequence number learning, which does not rely on an external clock synchronization apparatus and is suitable for pulse per second synchronization of a protection measurement and control apparatus (including a protection apparatus, a measurement and control apparatus, a protection and measurement and control integrated apparatus, and a station domain protection control apparatus). According to the continuity and interval time of a merging unit sampling sequence number, validity is determined, under the condition of the validity, actual pulse per second generating time is calculated through subtracting rated delay time and transmission time from message receiving time of a merging unit sampling sequence number of zero, and a pulse per second width is calculated through the multi-frame message receiving time of the merging unit sampling sequence number of zero; and the protection measurement and control apparatus, according to a merging unit sampling message synchronization sign, automatically selects a merging unit as a reference time source and at least calculates the pulse per second of two merging units for realizing seamless switching of the reference time source of the merging unit when the reference source merging unit is converted from synchronization to desynchronizing or has broken link abnormities.
Owner:STATE GRID CORP OF CHINA +4

Data packet sampling method and device

ActiveCN104219110AAchieving Fair SamplingData switching networksTraffic capacityBloom filter
The invention discloses a data packet sampling method and device. The data packet sampling method comprises determining whether data traffic of data packets sent by a user belong to a high traffic, if so, performing traffic length counting on the traffic of the data packets through a Hash counter, and if not, performing traffic length counting through a content-addressing-based counter; determining whether the traffic lengths of the data packets inside the content-addressing-based counter exceed a preset threshold value, if so, transferring the traffic of the data packets and the corresponding traffic lengths into the Hash counter and meanwhile updating a Bloom filter, calculating the sampling probability of the data packets by referring to a preset inversely-proportional traffic length and sampling probability function, and determining whether to sample the data packet according to the sampling probability. According to data packet sampling method, the volumes of the traffics containing the data packets are determined, for the high traffics containing a relatively large number of the data packets, the sampling possibility can smaller than that of the small traffics containing a relatively small number of the data packets, so that fair sampling for the large-traffic data packets and the small-traffic data packets can be achieved.
Owner:THE PLA INFORMATION ENG UNIV

Egress port overload protection for network packet forwarding systems

Systems and methods are disclosed to provide egress port overload protection for network packet forwarding systems. Input packets are received at one or more ingress ports and load balanced among a plurality of egress ports for the packet forwarding system. Load balanced packets associated with each egress port are then sampled to generate sampled load balanced packets that are output from the egress port. For certain embodiments, a sampling percentage is used for the packet sampling, and the sampling percentage for each egress port is set based upon a comparison of a current traffic rate for the egress port to a threshold rate for the egress port. The threshold rates for the egress ports are allowed to be configured through a user interface. Further, session and non-session traffic can be identified, and session aware load balancing and / or per-port packet sampling can be applied.
Owner:KEYSIGHT TECH SINGAPORE (SALES) PTE LTD

A method, system and device for dynamic background differential detection based on spatiotemporal classification

The invention discloses a space-time classification-based dynamic background differential detection method, a system and a device. The method comprises the steps of establishing a background model corresponding to each pixel in an image through packet sampling in a time sequence, classifying pixels in the background model according to to-be-detected pixels and obtaining a rough foreground mask image; with a foreground pixel point in the rough foreground mask image as a center, classifying pixel points in a preset neighboring domain range of the central pixel point, and correcting the central pixel point to be a background pixel point or still maintaining the central pixel point as a foreground pixel point according to the number of pixel points the same type with the central pixel point within the preset neighboring domain range of the central pixel point and belonging to background pixel points. According to the invention, the packet sampling method is adopted, so that the ability ofthe dynamic background description is enhanced. Only pixel points the same type of the central pixel point are adopted to judge whether a foreground pixel point is a real foreground pixel point or not. Therefore, the accuracy of detection is improved. The method can be widely applied to the field of moving target detection.
Owner:SUN YAT SEN UNIV
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Patsnap Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Patsnap Eureka Blog
Learn More
PatSnap group products