Encrypted traffic analytics over a multi-path TCP connection

    公开(公告)号:US11316871B2

    公开(公告)日:2022-04-26

    申请号:US15891708

    申请日:2018-02-08

    摘要: Methods and systems to estimate encrypted multi-path TCP (MPTCP) network traffic include restricting traffic in a first direction (e.g., uplink) to a single path, and estimating traffic of multiple subflows of a second direction (e.g., downlink) based on traffic over the single path of the first direction. The estimating may be based on, without limitation, acknowledgment information of the single path, a sequence of acknowledgment numbers of the single path, an unencrypted initial packet sent over the single path as part of a secure tunnel setup procedure, TCP header information of the unencrypted initial packet (e.g., sequence number, acknowledgment packet, and/or acknowledgment packet length), and/or metadata of packets of the single path (e.g., regarding cryptographic algorithms, Diffie-Helman groups, and/or certificate related data).

    SYSTEMS AND METHODS FOR SCALING DOWN CLOUD-BASED SERVERS HANDLING SECURE CONNECTIONS

    公开(公告)号:US20210126965A1

    公开(公告)日:2021-04-29

    申请号:US17143836

    申请日:2021-01-07

    IPC分类号: H04L29/08 H04L12/26 H04L12/66

    摘要: The disclosed technology relates to systems and methods for automatically scaling down network resources, such as servers or gateway instances, based on predetermined thresholds. A system is configured to detect a reduction in one or more network metrics related to a first server, and instruct the first server to issue a rekey request to a plurality of devices connected to the first server. The system is further configured to instruct a load balancer to route to at least one other server responses from the plurality of devices to the rekey request, and determine a number of connections remaining between the first server and the plurality of devices. The system may be further configured to instruct the load balancer to terminate the first server based on the detected number of connections remaining between the first server and the plurality of devices.

    Identifying anomalies in a network
    10.
    发明授权

    公开(公告)号:US10911475B2

    公开(公告)日:2021-02-02

    申请号:US16434564

    申请日:2019-06-07

    摘要: Various implementations disclosed herein enable identifying anomalies in a network. For example, in various implementations, a method of identifying anomalies in a network is performed by a network node. In various implementations, the network node includes one or more processors, and a non-transitory memory. In various implementations, the method includes generating a characteristic indicator that characterizes a device type based on communications associated with a first device of the device type. In various implementations, the method includes determining, based on communications associated with the first device, a performance indicator that indicates a performance of the first device. In various implementations, the method includes synthesizing an anomaly indicator as a function of the performance indicator in relation to the characteristic indicator.