Triggering packet capture based on detecting a sequence anomaly

    公开(公告)号:US11240130B2

    公开(公告)日:2022-02-01

    申请号:US16219559

    申请日:2018-12-13

    Abstract: In one embodiment, a method is performed. A device comprising a non-transitory memory and a processor coupled to the non-transitory memory may be in communication with a plurality of network devices. The device may detect an anomaly in a detected sequence of events occurring during a connectivity process for establishing a connection between a first network device and a second network device of the plurality of network devices. The anomaly may comprise a difference between the detected sequence of events and a predetermined sequence of events. The device may determine whether the anomaly satisfies a criterion for triggering a packet capture operation. If so, the device may cause at least one of the first network device or the second network device to capture at least one target packet.

    AP tracking sniffer aware Wi-Fi network

    公开(公告)号:US10700956B2

    公开(公告)日:2020-06-30

    申请号:US15875902

    申请日:2018-01-19

    Abstract: An apparatus, computer program product, and method relating to identifying and configuring an access point (AP) as a network sniffer. A network controller identifies a plurality of sniffer targets for which at least one of a plurality of sniffer candidate access points an act as a network sniffer. The controller receives a desired sniffer target. The controller selects a first AP, of the plurality of sniffer candidate APs, for use as a network sniffer, based on the identified plurality of sniffer targets and the desired sniffer target. The controller configures a radio in the first AP as a network sniffer to monitor network traffic related to the desired sniffer target.

    ANOMALY DETECTION AND CORRECTION IN WIRELESS NETWORKS

    公开(公告)号:US20190319863A1

    公开(公告)日:2019-10-17

    申请号:US15952114

    申请日:2018-04-12

    Abstract: In an embodiment, a computer implemented method comprises receiving, at an edge node in a data communications network, a plurality of digital data packets that have been received via a wireless data interface, wired data interface or data path; filtering, by the edge node, the plurality of digital data packets to produce filtered digital data packets; in the edge node, executing code for a data communications protocol in which one or more of the filtered digital data packets causes the code to transition to different states of the protocol; in the edge node, in parallel with executing the code, executing a protocol state machine comprising a plurality of states and a plurality of transitions between the states to simulate correct execution of a particular data communication protocol; detecting, by the edge node, an anomaly between a first particular state of the protocol during the execution of the code and a second particular state of the protocol state machine, and in response, generating an anomaly event comprising digital data indicating that an anomaly event has occurred; in response to detecting the anomaly event, transmitting, by the edge node, an anomaly event log based on the anomaly event and the filtered digital data packets to a different computing device.

    Wireless configuration diagnosis framework

    公开(公告)号:US11356331B2

    公开(公告)日:2022-06-07

    申请号:US16455163

    申请日:2019-06-27

    Abstract: Wireless configuration diagnosis framework may be provided. A label for a choreography comprising a sequence of frames to be exchanged between a first access point and a first client device may be created by a controller. A reference footprint for the choreography may be created. The reference footprint may comprise, for each frame of the sequence of frames, a frame type, an information element for the frame type, and a bit value for the information element. The reference footprint may be sent to the first access point. A plurality of frames exchanged between the first access point and the first client device associated with the choreography and an outcome for the choreography may be received from the first access point in response to the choreography being triggered.

    Anomaly detection and correction in wireless networks

    公开(公告)号:US10574547B2

    公开(公告)日:2020-02-25

    申请号:US15952114

    申请日:2018-04-12

    Abstract: A plurality of digital data packets may be received via a wireless data interface, wired data interface, or data path. Code may be executed for a data communications protocol in which one or more of the filtered digital data packets causes the code to transition to different states of the protocol. A protocol state machine may be executed comprising a plurality of states and a plurality of transitions between the states to simulate correct execution of a particular data communication protocol. An anomaly may be detected between a first particular state of the protocol during the execution of the code and a second particular state of the protocol state machine, and in response, an anomaly event may be generated comprising digital data indicating that the anomaly has occurred. An anomaly event log based on the anomaly event and the filtered digital data packets may be transmitted to a computing device.

Patent Agency Ranking