Risk information output device, information output system, risk information output method, and recording medium
US-2024414180-A1 · Dec 12, 2024 · US
US2021058421A1 · US · A1
| Field | Value |
|---|---|
| Publication number | US-2021058421-A1 |
| Application number | US-201916549764-A |
| Country | US |
| Kind code | A1 |
| Filing date | Aug 23, 2019 |
| Priority date | Aug 23, 2019 |
| Publication date | Feb 25, 2021 |
| Grant date | — |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
A number of techniques facilitate generation of data points from observations about network traffic. An inferencing system can use these data points to determine whether a relationship exists between two entities or whether an existing relationship has terminated, without any external knowledge of the existence of or termination of such a relationship.
Opening claim text (preview).
1 - 21 . (canceled) 22 . A method for inferring a relationship between two entities, the method comprising the steps of: receiving at a server, from a network device, composite flow information corresponding to a plurality of flows, wherein each individual flow information comprises a source network identifier and a destination network identifier; determining that for a subset of the plurality of flows: (i) the source network identifier in each flow in the subset belongs to a first set of network identifiers, each of which being associated with a first entity, and (ii) the destination network identifier in each flow in the subset belongs to a second set of network identifiers, each of which being associated with a second entity; and determining that a relationship exists between the first entity and the second entity based on, one or more of: (i) a total number of flows in the subset, (ii) a frequency of the flows in the subset, (iii) a total size of the flows in the subset, (iv) a port associated with the flows in the subset. 23 . The method of claim 1 , wherein determining the existence of the relationship comprises determining that: the total number of the flows in the subset is at least equal to a specified flow-count threshold; or the frequency of the flows in the subset is at least equal to a specified flow-frequency threshold; or the total size of the flow in the subset is at least equal to a specified flow-size threshold. 24 . The method of claim 2 , wherein the flow-count threshold, the flow-frequency threshold, or the flow-size threshold is based on, at least in part, a size of the first entity or a size of the second entity. 25 . The method of claim 1 , wherein determining the existence of the relationship comprises identifying a type of a port associated with the subset of flows. 26 . The method of claim 4 , wherein the port type is a file transfer protocol (FTP) port, or a simple mail transfer protocol (SMTP) port. 27 . The method of claim 1 , wherein the determination of existence of the relationship is based on, at least in part, an additional determination that one or more of the network identifiers in the second set are designated for an entity having a relationship with the second entity. 28 . The method of claim 1 , wherein the network device is associated with an Internet service provider (ISP) or an Internet exchange point (IXP), the ISP or the IXP being different from the first entity and the second entity. 29 . The method of claim 1 , wherein: the network device comprises a domain name system (DNS) resolver; and a first individual flow information comprises a first source network identifier, a first destination network identifier, and a response from a reputation service corresponding to the first source network identifier. 30 . A system for inferring a relationship between two entities, comprising: a processor; a network port in communication with the processor and adapted to receive composite flow information corresponding to a plurality of flows; and a memory coupled to the processor and comprising instructions, which when executed by the processor, program the processor to: receive from a network device, the composite flow information corresponding to a plurality of flows, wherein each individual flow information comprises a source network identifier and a destination network identifier; determine that for a subset of the plurality of flows: (i) the source network identifier in each flow in the subset belongs to a first set of network identifiers, each of which being associated with a first entity, and (ii) the destination network identifier in each flow in the subset belongs to a second set of network identifiers, each of which being associated with a second entity; and determine that a relationship exists between the first entity and the second entity based on, one or more of: (i) a total number of flows in the subset, (ii) a frequency of the flows in the subset, (iii) a total size of the flows in the subset, (iv) a port associated with the flows in the subset. 31 . The system of claim 30 , wherein to determine the existence of the relationship, the instructions program the processor to determine that: the total number of the flows in the subset is at least equal to a specified flow-count threshold; or the frequency of the flows in the subset is at least equal to a specified flow-frequency threshold; or the total size of the flow in the subset is at least equal to a specified flow-size threshold. 32 . The system of claim 31 , wherein the flow-count threshold, the flow-frequency threshold, or the flow-size threshold is based on, at least in part, a size of the first entity or a size of the second entity. 33 . The system of claim 30 , wherein to determine the existence of the relationship, the instructions program the processor to: identify a type of a port associated with the subset of flows. 34 . The system of claim 33 , wherein the port type is a file transfer protocol (FTP) port, or a simple mail transfer protocol (SMTP) port. 35 . The system of claim 30 , wherein to determine the existence of the relationship, the instructions program the processor further to: determine that one or more of the network identifiers in the second set are designated for an entity having a relationship with the second entity. 36 . The system of claim 30 , wherein the network device is associated with an Internet service provider (ISP) or an Internet exchange point (IXP), the ISP or the IXP being different from the first entity and the second entity. 37 . The system of claim 30 , wherein: the network device comprises a domain name system (DNS) resolver; and a first individual flow information comprises a first source network identifier, a first destination network identifier, and a response from a reputation service corresponding to the first source network identifier.
Event detection, e.g. attack signature detection · CPC title
using geographic information, e.g. room number · CPC title
containing mobile subscriber information, e.g. home subscriber server [HSS] · CPC title
Internet protocol version 6 [IPv6] addresses · CPC title
using domain name system [DNS] · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.