Disclosed are systems, apparatuses, processes, and computer-readable media for automated certificate-based device enrollment system. For example, a disclosed method includes: scanning, by a controller of a network, one or more workloads to determine a first network endpoint accessing a first AI application based on traffic and logs; matching network traffic from a second network endpoint to a pattern indicative of AI traffic to determine that the network traffic from the second network endpoint is traffic to a second AI application; generating a network map of a pathway from the first network endpoint to the first AI application and a pathway from the second network endpoint to the second AI application; and monitoring traffic on the pathway from the first network endpoint to the first AI application and traffic on the pathway from the second network endpoint to the second AI application based on the network map.
H04L 43/062 - Generation of reports related to network traffic
H04L 41/16 - Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks using machine learning or artificial intelligence
A backscatter communication device assistant may be provided. A computing device may designate a client device as a backscatter communication device assistant. Next, a report indicating a location of a backscatter communication device may be received from the backscatter communication device assistant. Then the backscatter communication device may be caused to receive energy. Data originating from the backscatter communication device may then be received.
G01S 5/00 - Position-fixing by co-ordinating two or more direction or position-line determinationsPosition-fixing by co-ordinating two or more distance determinations
H02J 50/00 - Circuit arrangements or systems for wireless supply or distribution of electric power
H02J 50/20 - Circuit arrangements or systems for wireless supply or distribution of electric power using microwaves or radio frequency waves
H02J 50/30 - Circuit arrangements or systems for wireless supply or distribution of electric power using light, e.g. lasers
One implementation is directed at implementations and deployment of an artificial intelligence (AI) Assistant in an inquiry session with a large language model (LLM). The disclosure provides for appending contextual information to a user input corresponding to a question to be evaluated by the LLM. The user input is received by a graphical user interface (GUI) of a network device of a user. The user input includes the question in the GUI. Contextual metadata are received from content displayed on a display screen of the network device. A prompt for the LLM is generated from the user input and the contextual metadata, and is provided to the LLM. A response is received from the LLM. An answer to the question is displayed in the GUI of the network device of the user.
H04L 51/02 - User-to-user messaging in packet-switching networks, transmitted according to store-and-forward or real-time protocols, e.g. e-mail using automatic reactions or user delegation, e.g. automatic replies or chatbot-generated messages
4.
DELIVERY OF AC POWER WITH HIGHER POWER PoE (POWER OVER ETHERNET) SYSTEMS
A method is provided that includes grouping a plurality of ports at power sourcing equipment receiving pulse power and transmitting power from the group of ports at the power sourcing equipment to a power interface module operable to combine the power and provide an AC (alternating current) outlet configured to provide AC power to one or more devices.
One implementation is directed to implementations of an artificial intelligence (AI) assistant providing in a one-click root cause analysis (RCA). The disclosure provides for receiving a user input via a graphical user interface (GUI) requesting automated performance of a root cause analysis corresponding to an alert due to a triggering event, wherein the triggering event is associated with a time-series data set. A pre-processing may be performed on the time-series data set including performing an anomaly detection and retrieving one or more of traces or logs associated with the time-series data set. A prompt is generated instructing a large language model (LLM) to perform the root cause analysis based on results of the pre-processing and receiving a response to the prompt from the LLM including results of the root cause analysis. The GUI may be revised or updated to display of results of the root cause analysis.
Discovery enhancements for improved roaming may be provided. A client device may discover basic information for each of a plurality of Access Point (APs). Then the client device may select at least one of the plurality of APs as a seamless roaming candidate based on the basic information. Next, the client device may discover full information for the at least one of the plurality of APs.
Systems and methods for dynamic asset monitoring and power management in accordance with embodiments of the disclosure are described herein. An asset tracking device comprises a processor, a motion sensor, a network interface, and an asset monitoring logic that is configured to monitor a power metric associated with the asset tracking device and modify a sensor sampling parameter based on the power metric. The logic applies a linear interpolation algorithm to reconstruct data gaps resulting from reduced sampling frequencies. Furthermore, the logic determines a confidence metric associated with a motion state based on motion data captured by the sensor and activates a specific transmission mode selected from a plurality of transmission modes, such as Bluetooth Low Energy or Ultra-Wideband, based on the confidence metric satisfying a precision condition. Additionally, network devices may utilize environmental zones to determine configuration profiles that govern the sensitivity thresholds and monitoring behavior of the devices.
In some examples, a system creates a requirement including EPG selectors representing EPG pairs, a traffic selector, and a communication operator; determines that EPGs in distinct pairs are associated with different network contexts and, for each pair, which network context(s) contains associated policies; creates first data representing the pair, operator, and traffic selector; when only one network context contains the associated policies, creates second data representing a network model portion associated with the only network context and determines whether the first data is contained in the second data to yield a first check; when both network contexts contain the associated policies, also creates third data representing a network model portion associated with a second network context, and determines whether the first data is contained in the second and/or third data to yield a second check; and determines whether policies for the pairs comply with the requirement based on the checks.
A device is provided that includes a printed circuit board having a top surface, a first trace disposed directly on the top surface of the printed circuit board, and a second trace disposed directly on the top surface of the printed circuit board adjacent the first trace. A first metal dome is positioned over the first trace and is configured to block crosstalk between the first trace and the second trace.
H05K 3/34 - Assembling printed circuits with electric components, e.g. with resistor electrically connecting electric components or wires to printed circuits by soldering
10.
LAZY AND DEMAND-DRIVEN SQL QUERY GENERATION AND OPTIMIZATION
In one implementation, a device obtains information regarding a database. The device uses, based on the information regarding the database, an artificial intelligence model to generate a set of potential queries that could be processed by the database. The device modifies a query sent for processing by the database based on the set of potential queries, to form a valid query. The device sends the valid query to the database for processing.
Techniques for a centralized controller to manage API communications across heterogeneous, federated controllers. The centralized controller provides a unified interface for users to interact with multiple federated controllers. The centralized controller determines the types and/or versions of the federated controllers and identifies existing APIs used to communicate with the federated controllers. The centralized controller maintains an endpoint specification that maps APIs of the centralized controller to different APIs of the federated controllers. The centralized controller calls these different APIs to cause performance of operations requested by users on the federated controllers. The federated controllers return results of the operations to the centralized controller in various formats that are specific to the different federated controllers. The centralized controller uses the endpoint specification to convert, and potentially aggregate, the data back into the centralized controller layer. The centralized controller can then centralized controller may present the final results to the users.
Disclosed are systems, apparatuses, processes, and computer-readable media for detecting and monitoring network traffic associated with machine learning models. For example, a disclosed method includes: accessing, by a controller on a network, traffic data from DNS logs, wherein the traffic data comprises origin addresses and destination addresses; identifying, by the controller, a subset of traffic data associated with AI service traffic based on comparison of the origin addresses and the destination addresses with a list of AI service addresses; routing, by the controller, the AI service traffic through an AI defense gateway, wherein the AI defense gateway collects data associated with the AI service traffic; and generating, by the controller, visualizations of the data associated with the AI service traffic.
H04L 43/045 - Processing captured monitoring data, e.g. for logfile generation for graphical visualisation of monitoring data
H04L 41/16 - Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks using machine learning or artificial intelligence
H04L 43/08 - Monitoring or testing based on specific metrics, e.g. QoS, energy consumption or environmental parameters
13.
PREDICTIVE DATASET REDUCTION FOR OPTIMIZING COMPUTING TASKS IN A NETWORK AND COMPUTE FABRIC
In one implementation, a device obtains performance metrics for a network or compute fabric. The device makes, based on the performance metrics, a prediction that using a full dataset in network or compute fabric to perform a first computing task would lead to contention in the network or compute fabric with respect to a second computing task. The device forms, based on the prediction, a reduced dataset that the device predicts will avoid the contention with respect to the second computing task. The device schedules performance of the first computing task in the network or compute fabric using the reduced dataset.
In one implementation, a device obtains a captured image of application data displayed by an application to a user via an electronic display of an endpoint operated by the user. The device generates a prompt for input to a generative artificial intelligence model that asks the generative artificial intelligence model to summarize the captured image. The device sends the prompt to the generative artificial intelligence model, to generate a summary of the captured image. The device causes the endpoint operated by the user to read the summary of the captured image to the user.
High accuracy roaming with location determination and dynamic bandwidth mechanisms may be provided. High accuracy roaming includes operating, by an access point (AP), at a baseline operating bandwidth. The AP expands from the baseline operating bandwidth to an expanded operating bandwidth for a station (STA) associated with the AP. The AP and the STA perform a location determination procedure at the expanded operating bandwidth to determine location information for the STA. The AP contracts from the expanded operating bandwidth to the baseline operating bandwidth and utilizes the location information to determine one or more candidate target APs for roaming of the STA from the AP to at least one of the one or more candidate target APs. The STA and AP can perform roaming preparation and roaming execution based on the candidate target APs.
Systems and methods for multi-modal occupancy detection using active asset tags are described that utilize existing network infrastructure and battery-powered tags to perform environmental sensing without dedicated motion sensors. An active asset tag equipped with an accelerometer and wireless transceivers monitors its physical state to distinguish between self-motion and environmental occupancy. When stationary, the tag analyzes signal characteristics, such as Bluetooth Low Energy (BLE) attenuation or Ultra-Wideband (UWB) channel impulse responses, using an onboard artificial intelligence engine to detect human presence. The system also employs a bistatic radar framework where access points measure multipath reflections from tag transmissions to locate and count occupants. To optimize power consumption, a hybrid sensing logic utilizes low-power BLE scanning to trigger high-precision UWB ranging only when anomalies are detected. Aggregated data from the distributed sensing nodes is processed by a cloud-based analytics service to generate real-time occupancy maps and utilization insights for facility management.
G01S 13/46 - Indirect determination of position data
G01S 7/41 - Details of systems according to groups , , of systems according to group using analysis of echo signal for target characterisationTarget signatureTarget cross-section
G01S 13/02 - Systems using reflection of radio waves, e.g. primary radar systemsAnalogous systems
17.
HIGHER EFFICIENCY, LONGER HOLDUP TIME DC INPUT FRONT END POWER SUPPLY
A power supply device is provided that an input current circuit and an energy holdup circuit. The input current circuit comprises an input for receiving input power, and an output for providing power to a powered device. The energy holdup circuit is connected to the input current circuit and includes one or more capacitors for storing energy. The energy holdup circuit is configured to couple energy stored in the one or more capacitors to the output when there is a loss of the input power, and to not direct current through the one or more capacitors when the input receives the input power.
H02M 3/07 - Conversion of DC power input into DC power output without intermediate conversion into AC by static converters using resistors or capacitors, e.g. potential divider using capacitors charged and discharged alternately by semiconductor devices with control electrode
18.
SYSTEMS AND METHODS FOR DYNAMIC SYNCHRONIZATION AND INTERFERENCE MITIGATION IN REAL-TIME LOCATION SYSTEMS
Systems and methods for dynamic anchor coordination and interference mitigation within Ultra-Wideband (UWB) real-time location systems are disclosed. The system creates a self-healing infrastructure by continuously monitoring anchor metrics, such as local tag density and packet collision probabilities, to detect impaired primary anchors. When instability is detected, the coordination logic identifies a suitable secondary anchor operating in a cleaner radio frequency environment and dynamically re-assigns it to the primary synchronization role. To further enhance reliability in harsh environments, the system utilizes adaptive repetitive synchronization, wherein critical timing messages are broadcast across multiple, non-consecutive transmission slots within a single ranging round. Additionally, the system aggregates interference data to construct a network-wide map, allowing for the real-time detection of persistent slot collisions. Upon identifying a compromised slot, the logic automatically re-tasks anchors to transmit on clean resources, ensuring robust clock alignment and precise asset tracking despite dynamic congestion.
A method includes receiving an audio signal at a neural network-implemented audio encoder, encoding the audio signal with the neural network-implemented audio encoder according to frequency sub-bands to generate an embedding vector representative of a frame of the audio signal, vector quantizing the embedding vector according to the frequency sub-bands to generate respective codewords for each of the frequency sub-bands, and transmitting, in one or more packets, the respective codewords, or respective indexes thereof, to a remote endpoint.
G10L 19/038 - Vector quantisation, e.g. TwinVQ audio
G10L 25/30 - Speech or voice analysis techniques not restricted to a single one of groups characterised by the analysis technique using neural networks
20.
ASSEMBLING LOW-CODE APPLICATIONS WITH OBSERVABILITY POLICY INJECTIONS
In one embodiment, an illustrative method herein may comprise: determining, by a process, a tenant-specific policy for creation of low-code applications; dynamically computing, by the process and based on the tenant-specific policy and one or more parameters associated with a particular low-code application to be created, one or more injectable low-code tasks for the particular low-code application; determining, by the process, a plurality of selected injectable low-code tasks from the one or more injectable low-code tasks; and creating, by the process, the particular low-code application by injecting the plurality of selected injectable low-code tasks into the particular low-code application for execution.
Techniques for alternating current (AC) powering methods deployed at a power transmitter and a power receiver for line fault detection. AC power is applied to a pair of lines at a power transmitter to transmit the AC power to a power receiver. An occurrence of a predetermined characteristic of an AC voltage waveform or an AC current waveform is detected. The AC power is disconnected from the pair of lines upon detecting occurrence of the predetermined characteristic. Fault detection is performed during a safety check time window upon disconnecting the AC power from the pair of lines. The AC power is reconnected to the pair of lines when a fault is not detected from the fault detection during the safety check time window, and the AC power is maintained disconnected from the pair of lines when a fault is detected during the safety check time window.
The present disclosure is directed to detecting, by a first wireless endpoint device associated with a first basic service set (BSS) neighboring a neighboring overlapping BSS (OBSS), a received data packet from a second wireless endpoint device associated with the OBSS, upon determining the received data packet satisfies a first OBSS threshold and a high-priority data packet is in queue for transmission by the first wireless endpoint device, determining whether the received data packet satisfies a second OBSS threshold, maintaining the high-priority data packet in queue if the received data packet satisfies a second OBSS threshold, and transmitting the high-priority data packet by the first wireless endpoint device if the received data packet does not satisfy the second OBSS threshold.
H04W 72/566 - Allocation or scheduling criteria for wireless resources based on priority criteria of the information or information source or recipient
In one embodiment, a cold tray assembly mounted to a PCB includes a manifold tank, a plurality of baffle walls within the manifold tank, the plurality of baffle walls defining one or more flow paths for a liquid coolant in the manifold tank, and one or more slots within a surface of the manifold tank, the one or more slots corresponding to at least one cold plate thermally coupled to one or more components of the PCB, where the one or more slots are configured to transfer the liquid coolant between the manifold tank and the at least one cold plate to dissipate heat from the one or more components to the liquid coolant.
Techniques for determining whether to send an MFA push notification are described. An indication of a request for a user account to access the application service via a primary device is received at an MFA service from an application service. Using a PAN protocol, determine whether the primary device and the secondary device are within a threshold proximity. When the primary device and the secondary device are within the threshold proximity, allows a push notification to be transmitted to the secondary device requesting authentication to grant access to the user account by the primary device, and when the primary device and the secondary device are not within the threshold, refrain from transmitting the push notification.
H04W 4/80 - Services using short range communication, e.g. near-field communication [NFC], radio-frequency identification [RFID] or low energy communication
Disclosed are systems, apparatuses, processes, and computer-readable media for multicloud gateway with inline natural language prompt inspection. For example, a disclosed method includes decrypting, at a gateway of a multicloud defense system, an application stream from a plurality of packets; inspecting a request or a response in the application stream for natural language content in a payload of the request or the response; requesting, by the gateway of the multicloud defense system, authorization from a defense system to send the natural language content to a destination address; and providing, to the destination address, the plurality of packets based on the authorization from the defense system.
Disclosed are systems, apparatuses, processes, and computer-readable media for identifying usage of compromised AI in a network. For example, a disclosed method includes: building, by a controller, a behavior profile for a user account, where the behavior profile is associated with a model and where the behavior profile includes behavior data based on interactions between the user account and the model; monitoring, by the controller, traffic between a device associated with the user account and an AI service associated with the model, where the traffic includes a prompt; comparing, by the controller, the prompt with the behavior profile for the user account; and implementing, by the controller, a network policy if the prompt deviates from the behavior data of the behavior profile by greater than a predefined threshold.
H04L 41/16 - Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks using machine learning or artificial intelligence
27.
SYSTEMS AND METHODS FOR ONE-CLICK ROOT CAUSE ANALYSIS
One implementation is directed to implementations of an artificial intelligence (AI) assistant providing in a one-click root cause analysis (RCA). The disclosure provides for receiving a user input via a graphical user interface (GUI) requesting automated performance of a root cause analysis corresponding to an alert due to a triggering event, wherein the triggering event is associated with a time-series data set. A pre-processing may be performed on the time-series data set including performing an anomaly detection and retrieving one or more of traces or logs associated with the time-series data set. A prompt is generated instructing a large language model (LLM) to perform the root cause analysis based on results of the pre-processing and receiving a response to the prompt from the LLM including results of the root cause analysis. The GUI may be revised or updated to display of results of the root cause analysis.
Aspects of the present disclosure are directed to enabling, in an environment in which multiple Access Points (APs) with varying privacy and Randomized and Changing MAC (RCM) configurations operate, AP-to-AP RCM in conjunction with Multi-Access Point Coordination (MAPC) between the APs without one adversely affecting the other. In one aspect, a first access point (AP) may determine a Media Access Control (MAC) rotation strategy for a first plurality of access points (APs) of a first wireless network. The MAC rotation strategy may specify use of Basic Service Set Identifiers (BSSIDs) by the first plurality of APs for implementing RCM in presence of a second plurality of APs of a second wireless network. The first AP may perform the RCM based on the MAC rotation strategy. The first AP may perform multi-AP coordination with the second plurality of APs using the BSSIDs.
Embodiments are directed towards managing and tracking item identification of a plurality of items to determine if an item is a new or existing item, where an existing item has been previously processed. In some embodiments, two or more item identifiers may be generated. In one embodiment, generating the two or more item identifiers may include analyzing the item using a small item size characteristic, a compressed item, or for an identifier collision. The two or more item identifiers may be employed to determine if the item is a new or existing item. In one embodiment, the two or more item identifiers may be compared to a record about an existing item to determine if the item is a new or existing item. If the item is an existing item, then the item may be further processed to determine if the existing item has actually changed.
In embodiments, method and systems are provided for facilitating identification of field values based on delimiters. In some implementations, a user selection of a delimiter type to use for identifying values within fields is received. The values within fields are generally separated from one another by delimiters. A first set of one or more values from a plurality of events based on the selected delimiter is identified. Further, a second set of one or more values from the plurality of events is identified based on the selected delimiter. The identified first set of one or more values to a first field and the second set of one or more values to a second field. Additional embodiments are described and/or claimed.
In one embodiment, dynamic resource allocation in open radio access networks (O-RAN) is provided. An example process herein comprises: collecting telemetry data for one or more network slices across a plurality of carriers in an open radio access network; determining per-slice traffic demands of the one or more network slices from a cross-carrier aggregation of the telemetry data; allocating radio resources of the open radio access network for each of the one or more network slices across carriers to support the per-slice traffic demands; and configuring slice-specific parameters for enforcement in the open radio access network based on the radio resources allocated to each of the one or more network slices.
Techniques and architecture are described that provide secondary identifiers or group tags, e.g., security group tags (SGTs). Control security policies may then be provided for entities within a networking arrangement and separate policies per entity may be provided. This results in assigning a primary SGT per entity and secondary SGTs per entity, wherein the secondary SGT categories are the same at each entity. For example, the secondary SGTs may represent a location, a person, an organization, a partner of the organization, a service, a database, a type of record, etc. Generally, the primary SGTs may represent a location, an entity, an organization, a partner of the organization, a person, etc. Utilizing the “hierarchal” SGT arrangement described herein, security may be efficiently enforced once at an ingress network node using primary SGTs and again at the egress network node using secondary SGTs.
Techniques for eliminating double encryption of network traffic between client(s) and protected service(s) based on transport mechanisms utilized by the client(s) and the protected service(s) are disclosed herein. A client-based proxy executing on a client device may receive a request from a browser executing on the client device to access a protected service associated with a network, and the client proxy may intercept the connection of the browser to the service. A gateway associated with the service may require a user of the browser to be authenticated for access to the protected service, and following authentication, the gateway may send a token to the client proxy. Based on whether traffic between the browser and the protected service is transmitted according to a secure transport mechanism, the client proxy may establish one of an unencrypted connection or an encrypted connection with the gateway, and access of the browser may be resumed.
In one embodiment, a visualization process herein: provides a graphical user interface that displays two portions, one of the two portions displaying a physical network topology of a computer network and another of the two portions displaying a logical grouping policy applied within the computer network; detects a user selection of one or more first visual representation components on a first portion of the two portions; maps the one or more first visual representation components on the first portion to one or more second visual representation components on a second portion of the two portions based on how the logical grouping policy relates to the physical network topology; and highlights, on the graphical user interface in response to the user selection, the one or more first visual representation components on the first portion and the one or more second visual representation components on the second portion.
G06F 3/04815 - Interaction with a metaphor-based environment or interaction object displayed as three-dimensional, e.g. changing the user viewpoint with respect to the environment or object
G06F 3/04842 - Selection of displayed objects or displayed text elements
35.
ASSESSING GRAY FAILURES IN REAL TIME LOG UPDATES USING LLMS
In one implementation, a device assesses, by a troubleshooting agent, log data from a monitored system using a large language model. The troubleshooting agent identifies a failure in the monitored system not indicated by the log data. The troubleshooting agent determines, using the large language model, additional data needed to troubleshoot the failure. The troubleshooting agent causes the monitored system to augment the log data with the additional data for assessment by the troubleshooting agent.
H04L 41/16 - Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks using machine learning or artificial intelligence
H04L 43/04 - Processing captured monitoring data, e.g. for logfile generation
36.
UNDERLAY MIGRATION AND INTEROPERABILITY MANAGEMENT
Devices, systems, methods, and processes for managing migration and interoperability between different protocol versions in an underlay network are provided herein. A network device may generate and transmit, while supporting a first Internet Protocol (IP) version type and a second IP version type, a plurality of route advertisements having the same originating router address during a BGP session. Each of the plurality of route advertisements includes a primary next-hop address that conforms to one of the first IP version type or the second IP version type, and a secondary next-hop address that conforms to remaining of the first IP version type or the second IP version type. Since the route advertisements transmitted during the BGP session have the same originating router address that is independent of an IP version type of the primary next-hop address, a route key associated with the network device remains the same.
A method is performed by a controller of a conference device that includes a video camera and a microphone array deployed in a room. The method comprises: receiving video of the room from the video camera; receiving beam-specific audio of the room detected by respective ones of audio beams formed by the microphone array; processing the video to detect face positions of faces in the room; accessing information that pre-defines a region in the room independent from the video and the beam-specific audio; determining one or more first audio beams that each overlaps any face position in the region; and during a video conference session, transmitting, to a remote conference device, first beam-specific audio detected by the one or more first audio beams.
In one implementation, a device may select, based on a task specification associated with a fine-tuning operation for a language model, relevant benchmark datasets from a set of available benchmark datasets to be included in a benchmarking of a language model generated by the fine-tuning operation. The device may select a subset of samples from the relevant benchmark datasets to be included in the benchmarking of the language model generated by the fine-tuning operation. The device may cause the benchmarking of the language model generated by the fine-tuning operation using the subset of samples from the relevant benchmark datasets. The device may provide, based on outputs of the benchmarking of the language model, a summary of results of the benchmarking of the language model generated by the fine-tuning operation.
An example embodiment concisely summarizes impact and dependencies between network devices in order to reduce token counts for providing topology information to an AI model for context. The example embodiment provides a minimal amount of relevant information for context when requesting a generative AI model to produce recommendations with respect to troubleshooting and resolving network issues.
H04L 41/50 - Network service management, e.g. ensuring proper service fulfilment according to agreements
H04L 41/16 - Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks using machine learning or artificial intelligence
40.
PASSWORD AND EMAIL ATTACHMENT LINKAGE FOR THREAT ANALYSIS
This disclosure describes techniques for password linkage to assist with threat detection related to communications across a network. The techniques include receiving a password-protected email attachment. The techniques include storing the password-protected attachment in a password linkage database in association with first metadata from the corresponding email. The techniques may also include detecting a password in a second email that includes second metadata. Responsive to detecting the password, the techniques include automatically creating a linkage between the password-protected attachment and the password. The linkage may be based at least in part on the first metadata and the second metadata. The linkage may allow a security system to investigate the password-protected attachment for a potential threat. As such, password linkage techniques may improve security in network communications.
Devices and methods for context-aware task allocation and reputation management for Artificial Intelligence (AI) agents are provided. Existing task management frameworks may fall short in effectively assigning tasks to AI agents for execution in dynamic, unpredictable, and interdependent environments. Thus, a task management device that can dynamically assign tasks to AI agents is provided. The task management device may receive a task and determine one or more contextual features associated with the task. The task management device may obtain a set of task execution proposals from a subset of AI agents that align with the determined one or more contextual features and evaluate the obtained set of task execution proposals against one or more evaluation parameters. The task management device may select at least one AI agent from the subset of AI agents based on the evaluation and assign the received task to the selected at least one AI agent.
Aspects of the present disclosure are directed to enabling, in an environment in which multiple Access Points (APs) with varying privacy and Randomized and Changing MAC (RCM) configurations operate, AP-to-AP RCM in conjunction with Multi-Access Point Coordination (MAPC) between the APs without one adversely affecting the other. In one aspect, a first access point (AP) may determine a Media Access Control (MAC) rotation strategy for a first plurality of access points (APs) of a first wireless network. The MAC rotation strategy may specify use of Basic Service Set Identifiers (BSSIDs) by the first plurality of APs for implementing RCM in presence of a second plurality of APs of a second wireless network. The first AP may perform the RCM based on the MAC rotation strategy. The first AP may perform multi-AP coordination with the second plurality of APs using the BSSIDs.
Determining location of a Backscatter Devices (BKD) may be provided. A first quadrant of the first AP where the BKD is potentially located based on a first signal level, a second signal level, and a third signal level. A second quadrant of a second AP where the BKD is potentially located may be determined. A third quadrant of a third AP where the BKD is potentially located may be determined. A location of the BKD may be determined at an intersection of the first quadrant, the second quadrant, and the third quadrant.
A system and associated methods outlined herein are directed to improving scaling efficiency for routing devices that service multiple applications through multiple socket interfaces and multiple network segments. In particular, the system aims to reduce memory overhead associated with current methods of network segmentation in Network Stack Instances of a network device by establishing a single namespace that services multiple network segments instead of establishing multiple namespaces where each namespace serves an individual network segment. The system also includes an intercept layer that ensures compatibility with third-party applications that would otherwise expect individual namespaces.
A method for recovering corrupted buckets in a peer cluster is presented. A cluster manager sends a request to peer nodes storing bucket copies corresponding to a corrupted bucket to report bucket health metrics of the respective bucket copies. The peer nodes rebuild the respective bucket copies and report updated bucket health metrics corresponding to the respective rebuilt bucket copies to the cluster manager. The cluster manager elects a bucket copy with a highest searchable event count as the canonical bucket copy. The cluster manager sends all peer nodes having bucket copies with searchable event counts less than the searchable event count of the canonical bucket copy an instruction to discard their respective bucket copies. The cluster manager sends the peer node storing the canonical bucket copy an instruction to replicate the canonical bucket copy to the peer nodes with discarded bucket copies.
This disclosure describes techniques and mechanisms for optimizing configuration management in SD-WAN networks. The techniques may enable optimized configuration management, by maintaining a “single copy of config” that gets pushed across an enterprise network to different device models, consisting of different interface types and other nuances of hardware variations. The techniques also enable delivery of a cloud scale device type agnostic orchestration of network services intent. The techniques may also enable a controller to have the ability to identify the configuration intent of the user and generate a configuration based on what a network device can accept. Further the techniques may enable a controller to identify the relevance of a configuration expressed in user intent with regard to a network device, such that a user can be notified where the user intent cannot be met, thereby reducing configuration mistakes.
Disclosed are systems, apparatuses, methods, computer readable medium, and circuits for sharing multifactor authentication with shared session tokens using an authentication service. According to at least one example, a method includes: in response to receiving a request to check an authentication status from a first application, transmitting a first message to an authentication service including shared information; providing first authentication credentials related to a first authentication to the authentication service; and receiving a message related to a second authentication to bypass the second authentication.
H04L 9/32 - Arrangements for secret or secure communicationsNetwork security protocols including means for verifying the identity or authority of a user of the system
48.
POWER DISTRIBUTION AND COMMUNICATION INFRASTRUCTURE FOR CONNECTED APPLIANCES
Power distribution and communications infrastructure for electric appliances and systems of electric appliances. Specifically, an electric appliance includes a housing, a network interface configured to enable network communications, and at least one primary appliance component that is housed within the housing and that performs a primary function of the electric appliance. The electric appliance further includes at least one server that is housed within the housing and includes at least one processor configured to perform one or more data center functions. The electric appliance further includes a power module that supplies power to the at least one primary appliance component that performs the primary function of the electric appliance and that supplies residual power to the at least one server that performs the one or more data center functions.
The present technology provides solutions for enabling software-defined wide area network (SD-WAN) policies on a cloud security provider. An example method includes collecting, by a SD-WAN controller, contextual data associated with at least one user account of a SD-WAN, wherein the contextual data includes at least one of a virtual private network (VPN) identifier or a security group tag; and transmitting, by the SD-WAN controller, the contextual data over a secure application programming interface to a cloud security engine of a cloud network for enforcement of security policies on the cloud network based on the contextual data. Systems and computer-readable media are also provided.
Techniques and architecture are described that provide secondary identifiers or group tags, e.g., security group tags (SGTs). Control security policies may then be provided for entities within a networking arrangement and separate policies per entity may be provided. This results in assigning a primary SGT per entity and secondary SGTs per entity, wherein the secondary SGT categories are the same at each entity. For example, the secondary SGTs may represent a location, a person, an organization, a partner of the organization, a service, a database, a type of record, etc. Generally, the primary SGTs may represent a location, an entity, an organization, a partner of the organization, a person, etc. Utilizing the "hierarchal" SGT arrangement described herein, security may be efficiently enforced once at an ingress network node using primary SGTs and again at the egress network node using secondary SGTs.
An electro-optical device is provided. The electro-optical device has an electronic integrated circuit (EIC) having a trans-impedance amplifier (TIA) and a driver. The electro-optical device also includes a hybrid photonic integrated circuit (PIC) having a receiver circuit and a transmitter circuit both coupled with the EIC. The receiver circuit has a surface-illuminated photodiode arranged to directly receive incoming optical signals and to convert the incoming optical signals to electrical signals, with the electrical signals being routed to the TIA. The transmitter circuit has a modulator and a grating coupler. The modulator is arranged to convert electrical signals received from the driver to outgoing optical signals, with the outgoing optical signals being routed to the grating coupler for transmission of the outgoing optical signals.
H04B 10/80 - Optical aspects relating to the use of optical transmission for specific applications, not provided for in groups , e.g. optical power feeding or optical transmission through water
52.
VERSION CONTROL FOR STRUCTURED NETWORK CONFIGURATION DATA
In one embodiment, an illustrative method herein comprises: decomposing a primary document composed of structured data into a plurality of subdocuments corresponding to atomic units of the structured data; storing, when the primary document is an initially committed version of the primary document, the primary document as a referenced collection of the plurality of subdocuments each uniquely identified and having an associated version; comparing, when the primary document is an updated version of the primary document, each of the plurality of subdocuments with its own previous version to determine whether there is a difference; storing, for subdocuments where there is a difference, a corresponding updated subdocument version to be referenced for the updated version of the primary document; and establishing, for subdocuments where there is no difference, a reference to a corresponding previously stored subdocument version for the updated version of the primary document.
In one embodiment, a method for optimized access point deployment and blueprint validation can include obtaining, by a process, a floorplan of a given location within which one or more access points are to be installed and determining, by the process and based on historical information, effects of environmental features within the given location on wireless communication coverage based on the floorplan. The method can further include determining, by the process, specific placement of each of the one or more access points within the given location to maximize the wireless communication coverage based on the effects, and producing, by the process, a recommendation of the specific placement on the floorplan.
H04W 16/20 - Network planning tools for indoor coverage or short range network deployment
H04L 41/22 - Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks comprising specially adapted graphical user interfaces [GUI]
54.
ENSEMBLE PRUNING MASKS FOR SEQUENTIAL UNLEARNING IN AN AI SYSTEM
In one implementation, a device performs model unlearning on a trained artificial intelligence model with respect to a first concept by applying a first pruning mask to the trained artificial intelligence model. The device generates a second pruning mask for the trained artificial intelligence model to unlearn a second concept. The device forms an ensemble pruning mask based on the first pruning mask and on the second pruning mask. The device performs model unlearning on the trained artificial intelligence model with respect to the second concept by applying the ensemble pruning mask to the trained artificial intelligence model.
In one implementation, a device identifies capabilities of agents in a multi-agent system in which each agent uses a corresponding artificial intelligence model to perform sub-tasks of a task performed by the multi-agent system. The device obtains metrics regarding interactions between the agents. The device determines a change to the multi-agent system, based on the capabilities and metrics. The device provides an indication of the change to a user interface.
In one implementation, a device receives an input query from a requester. The device uses a multimodal large language model to generate an output based on the input query. The device identifies one or more files by performing a search of an information retrieval index based on the input query. The device provides, to the requester, a response to the input query that is based on the output of the multimodal large language model and on the one or more files.
Embodiments herein describe an interferometric waveguide in a variable optical attenuator (VOA) that includes a phase tuner that introduces a local phase that redirects an optical signal transmitted in the waveguide to an optical absorber or scatterer, thereby attenuating the signal. That is, by controlling the local phase change, the VOA can selectively attenuate an optical signal using the optical absorber or scatterer (or both).
G02F 1/21 - Devices or arrangements for the control of the intensity, colour, phase, polarisation or direction of light arriving from an independent light source, e.g. switching, gating or modulatingNon-linear optics for the control of the intensity, phase, polarisation or colour by interference
G02F 1/025 - Devices or arrangements for the control of the intensity, colour, phase, polarisation or direction of light arriving from an independent light source, e.g. switching, gating or modulatingNon-linear optics for the control of the intensity, phase, polarisation or colour based on semiconductor elements having potential barriers, e.g. having a PN or PIN junction in an optical waveguide structure
G02F 1/225 - Devices or arrangements for the control of the intensity, colour, phase, polarisation or direction of light arriving from an independent light source, e.g. switching, gating or modulatingNon-linear optics for the control of the intensity, phase, polarisation or colour by interference in an optical waveguide structure
Devices, systems, methods, and processes for improving network resiliency using congestion notification within a network are described herein. In UEC enabled (or RDMA) networks, when a communication link gets congested, the packets are buffered and eventually dropped within the switches. Typically, the source device needs to rely on retransmit timeout, which may lead to huge latency. Therefore, the present disclosure presents a solution that leverages congestion signaling or packet trimming techniques for congestion or link failure management. When a switch receives a packet associated with a first entropy value and detects that an egress port associated with the first entropy value is unavailable, the switch modifies the packet and forwards the modified packet via a different port associated with a second entropy value to seek an acknowledgment or a negative acknowledgment for the first packet before a source endpoint of the packet times out.
In one aspect, a method for routing traffic using a multi-tenanted service hub includes: receiving, by the multi-tenanted service hub of a network, a first communication from a first tenant of a shared edge device, where metadata associated with the first communication includes a first source VPN and a service label, determining, by the multi-tenanted service hub, a first tenant ID based on metadata associated with a first tunnel from the shared edge device to the multi-tenanted service hub, querying, by the multi-tenanted service hub, a mapping table using the first source VPN and the first tenant ID to retrieve a device VPN, where the device VPN is a multi-tenanted VPN of the network, and forwarding, by the multi-tenanted service hub, the first communication using the device VPN, where the device VPN corresponds to a service label maps to a service chain.
In one embodiment, a management device receives a request from an accessing device over a computer network to access a specific network device via a local wireless communication link. The management device sends a first nonce along with a shared secret to the accessing device to forward it to the specific network device over the local wireless communication link. The management device receives a second nonce sent by the specific network device in response to validating the shared secret, sent via the local wireless communication link to the accessing device and forwarded over the computer network to the management device. In response to validating the second nonce, the management device sends an acknowledgment message to the accessing device to forward it on to the specific network device to cause it to validate the acknowledgment message and establish a trusted connection with the accessing device over the local wireless communication link.
This disclosure describes techniques for prioritized email security to assist with threat detection related to communications across a network. The techniques include analyzing multiple email communications for potentially malicious content. The techniques may also include determining a priority score for an individual email of the multiple email communications. The priority score may be compared to a predetermined threshold priority value. Based at least in part on the priority score, the individual email may be designated as a prioritized email. The techniques may include using metadata of the prioritized email to identify similar emails from a vector database. Information from the similar emails may be used to assist in classifying the prioritized email with a large language model (LLM) classifier, generating a classification label for the prioritized email. As such, password linkage techniques may improve security in network communications.
Disclosed are systems, methods, and non-transitory computer-readable storage media for monitoring application health via correctable errors. The method includes identifying, by a network device, a network packet associated with an application and detecting an error associated with the network packet. In response to detecting the error, the network device increments a counter associated with the application, determines an application score based at least in part on the counter, and telemeters the application score to a controller. The controller can generate a graphical interface based at least in part on the application score and a timestamp associated with the application score, wherein the graphical interface depicts a trend in correctable errors experienced by the application over a network.
H04L 1/00 - Arrangements for detecting or preventing errors in the information received
H04L 41/22 - Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks comprising specially adapted graphical user interfaces [GUI]
H04L 41/5009 - Determining service level performance parameters or violations of service level contracts, e.g. violations of agreed response time or mean time between failures [MTBF]
H04L 67/10 - Protocols in which an application is distributed across nodes in the network
H04L 41/5003 - Managing SLAInteraction between SLA and QoS
63.
AUTHENTICATION (AUTHN) AND AUTHORIZATION (AUTHZ) BINDING FOR SECURE NETWORK ACCESS
Techniques for combining independent sessions between application(s) and a VPN, proxy service, or similar system, including inner protocol sessions (e.g., such as QUIC, etc.), coming from a single device to form a single logicalsession, where the single logical session could share a single authentication/authorization token are described. The techniques include receiving, from a device within a network, a request for a first application to access a service associated with the proxy service or the VPN, sending, to the device, a first authentication request, and receiving, from the device, a message including a token. The techniques may further include authenticating, by the proxy service or the VPN, the token using a unique identifier associated with the device and enabling, by the proxy service or the VPN, the device to access the service via a first session flow.
Prescriptive advertising of valid security combinations within a Service Set Identifier (SSID) may be provided. A computing device may determine supported security combinations that are supported by the computing device. Next, the computing device may indicate the supported security combinations in an information element. Then the computing device may advertise the information element.
H04L 9/06 - Arrangements for secret or secure communicationsNetwork security protocols the encryption apparatus using shift registers or memories for blockwise coding, e.g. D.E.S. systems
In some implementations, sequences of time series values determined from machine data are obtained. Each sequence corresponds to a respective time series. A plurality of predictive models is generated for a first time series from the sequences of time series values. Each predictive model is to generate predicted values associated with the first time series using values of a second time series. For each of the plurality of predictive models, an error is determined between the corresponding predicted values and values associated with the first time series. A predictive model is selected for anomaly detection based on the determined error of the predictive model. Transmission is caused of an indication of an anomaly detected using the selected predictive model.
G08B 6/00 - Tactile signalling systems, e.g. personal calling systems
B06B 1/06 - Processes or apparatus for generating mechanical vibrations of infrasonic, sonic or ultrasonic frequency making use of electrical energy operating with piezoelectric effect or with electrostriction
G06F 3/01 - Input arrangements or combined input and output arrangements for interaction between user and computer
Disclosed are systems, apparatuses, methods, and computer-readable media for heterogenous network services using platform agnostic extensions. A method includes: instantiating a first service having a first data plane control point; instantiating a second service configured to access the first control point in a data plane; receiving a first packet at the first service in a network path; providing at least one of the first packet and first metadata associated with the first packet to the second service to analyze or process the first packet and the first metadata in conjunction with the first service; processing at least one of the first packet or the first metadata in the second service based on external bytecode and generating at least second metadata based on the processing; receiving second metadata to the first service; and processing the first packet or a second packet.
Presented herein are techniques for preventing an electrical arc upon disconnection of a network cable. A method can include monitoring a network cable connected to a device for faults at a remote location from a connector of the network cable by observing conditions on the network cable of power applied to the network cable, wherein the network cable is for sending data and power. The method can further include detecting a fault on the network cable, wherein the fault was introduced intentionally at the connector prior to disconnecting the connector from the device. The method can further include terminating power at the remote location that is sent over the network cable to prevent an electrical arc upon disconnecting the connector from the device.
H04L 41/0659 - Management of faults, events, alarms or notifications using network fault recovery by isolating or reconfiguring faulty entities
G08B 5/22 - Visible signalling systems, e.g. personal calling systems, remote indication of seats occupied using electric transmissionVisible signalling systems, e.g. personal calling systems, remote indication of seats occupied using electromagnetic transmission
H04L 12/12 - Arrangements for remote connection or disconnection of substations or of equipment thereof
68.
PACKET METADATA CAPTURE IN A SOFTWARE-DEFINED NETWORK
In one embodiment, a switch in a software-defined network receives a packet sent by an endpoint device via the SDN. The switch makes a copy of the packet based on one or more header fields of the packet matching one or more flow table entries of the switch. The switch forms telemetry data for reporting to a traffic analysis service by applying a metadata filter to the copy of the packet. The metadata filter prevents at least a portion of the copy of the packet from inclusion in the telemetry data. The switch sends the formed telemetry data to the traffic analysis service.
This disclosure describes techniques for prioritized email security to assist with threat detection related to communications across a network. The techniques include analyzing multiple email communications for potentially malicious content. The techniques may also include determining a priority score for an individual email of the multiple email communications. The priority score may be compared to a predetermined threshold priority value. Based at least in part on the priority score, the individual email may be designated as a prioritized email. The techniques may include using metadata of the prioritized email to identify similar emails from a vector database. Information from the similar emails may be used to assist in classifying the prioritized email with a large language model (LLM) classifier, generating a classification label for the prioritized email. As such, password linkage techniques may improve security in network communications.
Techniques for implementing centralized authentication and distributed authorization in a system for managing federated controllers. A centralized controller may be used to provide a unified interface for users to manage multiple federated controllers. After users request that the centralized controller unify the management of their network controllers, the federated controllers may perform techniques to register or enroll with the centralized controller. The centralized and federated controllers may establish trust such that the centralized controller may authenticate user identities on behalf of the federated controllers. The centralized controller may obtain access tokens indicating user identities from the federated controllers and may later send the access tokens to the federated controllers along with operation requests for authenticated users. The federated controllers use the access tokens and local access policies to authorize the users to determine if the users can perform operations or access resources.
G06F 21/41 - User authentication where a single sign-on provides access to a plurality of computers
H04L 9/32 - Arrangements for secret or secure communicationsNetwork security protocols including means for verifying the identity or authority of a user of the system
A process for providing a framework for responding to readiness probes is described herein. In embodiments, a virtual machine communicates with one or more external dependencies and generates metrics data which is stored in a cache. In embodiments, an operating system agent transmits readiness probes to the virtual machine, which responds by comparing the metrics to objective values indicated in an external dependency definition. Based on the response, in embodiments, the operating system may remove the virtual machine from service.
H04L 61/4511 - Network directoriesName-to-address mapping using standardised directoriesNetwork directoriesName-to-address mapping using standardised directory access protocols using domain name system [DNS]
72.
Monitoring metrics associated with a user-initiated action in a microservices-based architecture
A method of identifying traces associated with a discrete user-initiated instantiation of a process within a microservices-based application comprises aggregating ingested spans associated with the microservices-based application into traces. The method further comprises identifying a first set of traces from the traces associated with a workflow, wherein the workflow comprises a group of microservices associated with the process implemented by the microservices-based application. Also, the method comprises identifying a second set of traces from the first set of traces, wherein the second set of traces is associated with a discrete user-initiated instantiation of the process.
A computerized method is disclosed that includes operations of obtaining ingested data from a plurality of edge devices, performing analyses of the ingested data from each of the plurality of edge devices, wherein the analyses include performing machine learning modeling on the ingested data from each of the plurality of edges to determine predicted values for data expected to be ingested by each of the plurality of edge devices, and based on results generated from performing the machine learning modeling, determining whether predicted values for data expected to be ingested by each of the plurality of edge devices satisfies a predetermined condition for each of the plurality of edge devices. The machine learning modeling may utilize contextual data corresponding to one or more of the plurality of edge devices, wherein contextual data corresponding to a first edge device is data obtained by a device other than the first edge device.
In one embodiment, a method for controller driven multicast for scalability includes analyzing, by a controller, a plurality of network nodes to determine replication characteristics associated with the plurality of network nodes and identifying, by the controller, a first subset of the plurality of network nodes that are candidates for network node replication. The method can further include identifying, by the controller, a second subset of the plurality of network nodes that are not candidates for network node replication, and initiating, by the controller, one or more path computation element protocol sessions based, at least in part, on identification of the first subset of the plurality of network nodes and the second subset of the plurality of network nodes.
In one embodiment, a method includes collecting, by a device and from each of one or more access points over time within a monitored location, a plurality of hash values, each of the plurality of hash values based on a combination of a plurality of location-related metrics for a respective access point of the one or more access points and calculating, by the device, a baseline hash value for each access point of the one or more access points, each baseline hash value correlated to actual location-related metrics from which each baseline hash value was computed. The method further includes detecting, by the device, an anomalous change in a particular collected hash value of the plurality of hash values from at least one access point of the one or more access points, obtaining, by the device and in response to the anomalous change, a plurality of non-hashed location-related metrics from the at least one access point, and performing, by the device, a security analysis action based on the plurality of non-hashed location-related metrics.
H04L 9/06 - Arrangements for secret or secure communicationsNetwork security protocols the encryption apparatus using shift registers or memories for blockwise coding, e.g. D.E.S. systems
H04W 12/104 - Location integrity, e.g. secure geotagging
76.
Packet Re-Transmisson for Reliable Unordered Delivery
Devices, networks, systems, methods, and processes for detecting packet loss in a digital communication network are provided herein. The digital communication network may include at least one source device. The source device may transmit a set of packets of a flow that has the same Entropy Value (EV) and unique sequence numbers. The source device may further receive an acknowledgment for a delivered packet of the set of packets, where the acknowledgment can include the EV and a sequence number of the delivered packet. Furthermore, the source device may detect, based on the EV and the sequence number, whether a packet loss corresponding to the EV has occurred in the flow. Accordingly, the packet loss may be detected without timing outs or receiving negative acknowledgments. Therefore, the dependency time outs or negative acknowledgments may be suppressed. Consequently, the delays in re-transmission of lost packets may be reduced.
Collaborative geolocation estimation may be provided. A plurality of access points (APs) may receive a geolocation estimation request from a controller. Next, one or more of the plurality of APs may receive signals from a plurality of satellites. The controller may then receive the signals from the plurality of APs. The controller may determine a collaborative geolocation estimation using the signals, wherein, when relative locations of the APs are available, determining the geolocation estimation comprises applying the relative locations. One or more of the plurality of APs may receive the geolocation estimation from the controller.
G01S 19/09 - Cooperating elementsInteraction or communication between different cooperating elements or between cooperating elements and receivers providing processing capability normally carried out by the receiver
G01S 19/14 - Receivers specially adapted for specific applications
G01S 19/45 - Determining position by combining measurements of signals from the satellite radio beacon positioning system with a supplementary measurement
78.
COALESCING PUBLIC INTERNET PACKETS INTO JUMBO FRAMES BETWEEN SD-WAN PROVIDER NETWORK SERVICES
The systems and methods disclosed herein provide for coalescing data packets into jumbo frames in order to maximize the throughputs inside the service provider Local Area Network (LAN), thereby increasing the amount of traffic forwarded between internal services. The systems and methods outlined herein enable a source service on a LAN to receive a plurality of data packets from a public cloud-based network (e.g., the Internet) having a packet size limit less than the MTU limit of the LAN, and coalesce the plurality of data packets into a jumbo frame having a size based on the MTU limit of the LAN. The jumbo frame is then transmitted over the LAN to a destination service on the LAN. The destination service then separates the jumbo frame back into the plurality of data packets for further transmission back to the public cloud-based network.
A system and method are provided for detecting malicious messages using a two-step Bayesian approach. A discrimination engine determines for each of the messages a first score and a second score. The first score represents a likelihood that the respective messages are malicious messages, and the second score represents a likelihood that they were generated by a machine learning (ML) method, such as a large language model (LLM). Using a combination of these two scores, message with a high probability of being malicious message are discriminated and marked as such. For example, messages for which the first and second scores exceed respective thresholds are marked as suspicious.
H04L 41/16 - Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks using machine learning or artificial intelligence
80.
MULTI-AGENT FRAMEWORK FOR SYNTHETIC DATA GENERATION AND VERIFICATION
The disclosure includes a computer-implemented method including generating a dataset of questions that mimic user queries by a multi-agent framework, wherein the multi-agent framework includes deployment of a plurality of artificial intelligence (AI) agents, running a subset of the dataset of questions through a first agent of the plurality of AI agents where each running of a question produces a trajectory which is a sequence of tools that the first agent calls, selecting a most common trajectory (MCT) for each question across all runnings, wherein the MCT for each question is annotated to indicate a correctness of the MCT, reverse engineering alternate questions from the responses for trajectory verification, extracting features from the MCT for each question that has been annotated and the alternate questions, and training a discriminative machine learning model on the features.
81.
DYNAMIC POLICY-BASED ROUTING DURING SESSION RUNTIME
Techniques for dynamic policy-based routing of network traffic through a split-tunnel system after session establishment and during session runtime of a secure access connection. After a secure access connection has been established by an endpoint device, processes running on the endpoint device may attempt to send traffic to a destination by generating a Domain Name Service (DNS) request. According to the techniques described herein, a capture component running in the kernel may intercept the DNS requests (and new connections/sockets) as they are being created by processes. The capture component may instead route the DNS requests to a policy engine that applies various DNS and domain-level policy to the DNS request and returns a verdict back to the endpoint device. Using dynamic, real-time policy-based routing of traffic allows for adaptation to new security threats or changing network conditions without having to update static policies on each endpoint device.
H04L 61/4511 - Network directoriesName-to-address mapping using standardised directoriesNetwork directoriesName-to-address mapping using standardised directory access protocols using domain name system [DNS]
Techniques presented herein generate network visualization(s), such as network topology graphs, in which placement and representation of network components are predicted to mimic users' behavior in a design process. Methods are provided that involve obtaining network topology information including a plurality of attributes related to at least two network devices in a network and generating a plurality of predictions based on the network topology information. The plurality of predictions mimic a user specific placement and a visual representation for each of the at least two network devices. The methods further involve generating a network visualization that includes at least two network components representing the at least two network devices on a canvas, based on the plurality of predictions and providing the network visualization for changing a configuration of the network in a real networking environment or for simulating or emulating operations of the network in a virtual environment.
H04L 41/22 - Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks comprising specially adapted graphical user interfaces [GUI]
H04L 41/16 - Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks using machine learning or artificial intelligence
Techniques for enabling and preventing callback phishing are described herein. An email security system may be configured determine a callback intent of an email containing a phone number. Further, the email security system may determine a domain associated with the email, and retrieve a phone number associated with the domain. Based on a correlation between the email phone number of the email and the domain phone number, the phone number included in the email may be validated, and the email classified accordingly. Further, a telecommunication security service may use the phone number of a callback communication to identify the domain, identify a phone number associated with the sending domain, and correlate the callback phone number with the domain phone number. The phone number may similarly be validated, and the callback classified.
H04L 61/4511 - Network directoriesName-to-address mapping using standardised directoriesNetwork directoriesName-to-address mapping using standardised directory access protocols using domain name system [DNS]
84.
CROSS-DIE HIGH-SPEED ACCESS AND TEST IMPLEMENTATION FOR IN-PACKAGE CHIPLET
In one embodiment, an apparatus includes a main die, a plurality of chiplets including a first chiplet, and an extended Advanced Extensible Interface (AXI) network. The main die includes a first high speed input/output (IO) interface, at least a first main die die-to-die interface, and a main die AXI network. The first chiplet has at least a first chiplet die-to-die interface and a chiplet AXI network, the first chiplet including a first chiplet instance of high speed test logic. The extended AXI network includes the main die AXI network, wherein the extended AXI network includes a physical bus that is arranged between the first main die die-to-die interface and the first chiplet die-to-die interface, and wherein the first chiplet instance of the high speed test logic is accessible through the first high speed IO interface.
In one embodiment, a method for adaptive line key allocation for key expansion modules includes storing, by a process, a list of line keys for a phone that has a line key display and determining, by the process, a first set of line keys from the list of line keys to display on the phone when a key expansion module is paired to the phone and a second set of the line keys to display on the key expansion module. The method further includes determining whether the key expansion module is paired to the phone, displaying the first set of the line keys on the phone when the key expansion module is paired to the phone, and displaying the second set of the line keys on the key expansion module when the key expansion module is paired to the phone.
H04M 1/72466 - User interfaces specially adapted for cordless or mobile telephones with selection means, e.g. keys, having functions defined by the mode or the status of the device
G06F 3/0483 - Interaction with page-structured environments, e.g. book metaphor
G06F 3/04886 - Interaction techniques based on graphical user interfaces [GUI] using specific features provided by the input device, e.g. functions controlled by the rotation of a mouse with dual sensing arrangements, or of the nature of the input device, e.g. tap gestures based on pressure sensed by a digitiser using a touch-screen or digitiser, e.g. input of commands through traced gestures by partitioning the display area of the touch-screen or the surface of the digitising tablet into independently controllable areas, e.g. virtual keyboards or menus
H04M 1/02 - Constructional features of telephone sets
86.
ORCHESTRATING AUTHENTICATION AND AUTHORIZATION OF USERS BETWEEN A CENTRALIZED CONTROLLER AND FEDERATED CONTROLLERS
Techniques for implementing centralized authentication and distributed authorization in a system for managing federated controllers. A centralized controller may be used to provide a unified interface for users to manage multiple federated controllers. After users request that the centralized controller unify the management of their network controllers, the federated controllers may perform techniques to register or enroll with the centralized controller. The centralized and federated controllers may establish trust such that the centralized controller may authenticate user identities on behalf of the federated controllers. The centralized controller may obtain access tokens indicating user identities from the federated controllers and may later send the access tokens to the federated controllers along with operation requests for authenticated users. The federated controllers use the access tokens and local access policies to authorize the users to determine if the users can perform operations or access resources.
This disclosure describes techniques for enabling multiple subnets across multiple fabric sites and associated with multiple network segments (e.g., virtual networks (VNs)) to communicate with each other using a shared network infrastructure, such as a service provider network. In some cases, the techniques described herein include using a common transit VN (e.g., a common transit VN with or without a common firewall) in the shared network infrastructure as well as border devices that enable switching traffic between the common transit VNs and segment VNs (e.g., subscriber VNs) for data transmission to and/or from the common transit VN. In some cases, a border device maintains two types of mapping entries (e.g., map-caches): transit mapping entries and local mapping entries. A transit and a local mapping entry may be configured to represent (e.g., installed to program) forwarding information for packets received on a transit VN and on a segment VN, respectively.
Techniques that include a network that is configured in the first mode of a reactive mode to respond to a client attempting to access an endpoint of the network by providing information to be sent to a map server and by checking whether at least an IP address associated with the client corresponds to a registration produced for the client by a wireless controller. Further, the network is configured in a second mode of a proactive mode to determine based on a count maintained by a wireless controller of a number of client IP addresses whether to allow access or not to allow access to one or more clients to the network.
H04L 47/74 - Admission controlResource allocation measures in reaction to resource unavailability
H04L 41/0604 - Management of faults, events, alarms or notifications using filtering, e.g. reduction of information by using priority, element types, position or time
H04L 47/80 - Actions related to the user profile or the type of traffic
89.
RENDEZVOUS POINT BASIC SERVICE SET IDENTIFIER BASED DISCOVERY FOR WIRELESS NETWORKS
Rendezvous point (RP) Basic Service Set Identifier (BSSID) based discovery for wireless networks may be provided. RP BSSID based discovery processes include transmitting, by a station (STA), an RP request addressed to a predefined RP BSSID corresponding to a RP access point (RPAP) within an access point (AP) cluster. The STA receives an RP response from the RPAP, wherein the RP response includes information enabling the STA to identify one or more BPE-enabled networks accessible through the AP cluster. The STA then establishes a connection with an AP in the AP cluster based on the information received in the RP response, wherein the connection operates with Basic Service Set (BSS) Privacy Enhancement (BPE) mechanisms enabled.
Enhanced Data Privacy (EDP) Association Identifier (AID)-list handling on long power-save scenarios may be provided. A non-access point (AP) multi-link device (MLD) establishes an association with an AP MLD, including receiving an indication of assignment to an epoch group for rotation of frame anonymization parameters at an epoch interval and a list of AIDs to be used in corresponding epochs associated with the epoch group. The maintained association includes rotating frame anonymization parameters at epoch intervals using each AID in the list of AIDs during its corresponding epoch. The non-AP MLD enters a sleep state of a power save mode of operation during the association. Upon entering a wake state, the non-AP MLD determines whether it has a valid AID for a then-current epoch. Responsive to not having the valid AID, the non-AP MLD transmits an AID Assignment Response frame indicating a request for a second list of AIDs.
Network administrators are looking for different ways to better identify and understand what devices are running on their network. Due to privacy and encryption, identifying the devices is becoming increasingly difficult, which can lead to security vulnerabilities and overutilization of resources. The described techniques provide a detection system that improves visibility to a network by utilizing data encoded according to various protocols. The detection system may enrich a network map for better asset and network resource allocation and provide personalized firewall rules based on hardware and operating systems running on the network.
Described herein is a system and method for sensor data device registration. A server receives from a client device, a device identifier associated with a sensor data device. Responsive to determining that the sensor data device is not linked to a respective dashboard, the server transmits to the client device, an indication that the sensor data device is unregistered. The server receives from the client device an indication of a dashboard to which to assign the sensor data device, and thereafter links the sensor device data to the indicated dashboard so that sensor data received from the sensor data device is presented in a user interface corresponding to the indicated dashboard.
In one implementation, a device receives, via a user interface, a selection of a concept to be unlearned by an artificial intelligence model. The device identifies a configuration of a gating network in a mixture of experts layer of the artificial intelligence model that is associated with the concept. The device generates a deactivation matrix to disable the configuration of the gating network associated with the concept. The device updates the artificial intelligence model to unlearn the concept by applying the deactivation matrix to the gating network of the mixture of experts layer of the artificial intelligence model.
Network administrators are looking for different ways to better identify and understand what devices are running on their network. Due to privacy and encryption, identifying the devices is becoming increasingly difficult, which can lead to security vulnerabilities and overutilization of resources. The described techniques provide a detection system that improves visibility to a network by utilizing data encoded according to various protocols. The detection system may enrich a network map for better asset and network resource allocation and provide personalized firewall rules based on hardware and operating systems running on the network.
A system comprising a bus bar that that is configured to support communication of power; a plurality of power receivers coupled to the bus bar, each power receiver configured receive a supplied power and to provide an output power to the bus bar, each power receiver further configured to detect a fault in the output power provided to the bus bar; and one or more power consuming devices connected to the bus bar and configured to receive and consume power provided by a power receiver of the plurality of power receivers.
H02H 7/22 - Emergency protective circuit arrangements specially adapted for specific types of electric machines or apparatus or for sectionalised protection of cable or line systems, and effecting automatic switching in the event of an undesired change from normal working conditions for distribution gear, e.g. bus-bar systemsEmergency protective circuit arrangements specially adapted for specific types of electric machines or apparatus or for sectionalised protection of cable or line systems, and effecting automatic switching in the event of an undesired change from normal working conditions for switching devices
G01R 27/16 - Measuring impedance of element or network through which a current is passing from another source, e.g. cable, power line
H02B 1/20 - Bus-bar or other wiring layouts, e.g. in cubicles, in switchyards
96.
DYNAMIC POLICY-BASED ROUTING DURING SESSION RUNTIME
Techniques for dynamic policy-based routing of network traffic through a split-tunnel system after session establishment and during session runtime of a secure access connection. After a secure access connection has been established by an endpoint device, processes running on the endpoint device may attempt to send traffic to a destination by generating a Domain Name Service (DNS) request. According to the techniques described herein, a capture component running in the kernel may intercept the DNS requests (and new connections/sockets) as they are being created by processes. The capture component may instead route the DNS requests to a policy engine that applies various DNS and domain-level policy to the DNS request and returns a verdict back to the endpoint device. Using dynamic, real-time policy-based routing of traffic allows for adaptation to new security threats or changing network conditions without having to update static policies on each endpoint device.
In one embodiment, a method includes aligning a printed circuit board (PCB) and a connector, and dispensing a plurality of layers of an adhesive material, wherein the plurality of layers of the adhesive material form a structure that attaches the PCB and the connector, wherein the plurality of layers of the adhesive material cooperate with the PCB and the connector to define a clearance or a void. The method also includes curing the plurality of layers of the adhesive material to harden the structure.
Secure communication with a Backscatter Device (BKD) may be provided. A temporal key may be created. The temporal key and a network Identifier (ID) may be encrypted with a public key of a public private key pair associated with the BKD. An excitation frame including the encrypted temporal key and the encrypted network ID may be transmitted to the BKD. The AMP BKD may include a sensor. A BKD frame may be received from the BKD in response to the excitation frame. The BKD frame may include a sensor data encoded with the temporal key and the network ID as a target destination. The BKD frame may be signed using a private key of the public private key pair.
Simultaneous Authentication of Equals (SAE) password identifiers privacy protection may be provided. A client device may receive a set of password Identifiers (IDs) over an Out-of-Band (OOB) connection. Next the computing device may select, from the set of password IDs, a password ID to be seen by an authenticator, and to be applied to an SAE exchange. The computing device may then rotate across the set of password IDs for subsequent SAE exchanges.
Systems and methods are described for unified processing of indexed and streaming data. A system enables users to query indexed data or specify processing pipelines to be applied to streaming data. In some instances, a user may specify a query intended to be run against indexed data, but may specify criteria that includes not-yet-indexed data (e.g., a future time frame). The system may convert the query into a data processing pipeline applied to not-yet-indexed data, thus increasing the efficiency of the system. Similarly, in some instances, a user may specify a data processing pipeline to be applied to a data stream, but specify criteria including data items outside the data stream. For example, a user may wish to apply the pipeline retroactively, to data items that have already exited the data stream. The system can convert the pipeline into a query against indexed data to satisfy the users processing requirements.
G05B 13/00 - Adaptive control systems, i.e. systems automatically adjusting themselves to have a performance which is optimum according to some preassigned criterion
G06F 16/14 - Details of searching files based on file metadata
G06F 16/178 - Techniques for file synchronisation in file systems