H04L43/026

SYSTEMS AND METHODS FOR MATCHING ELECTRONIC ACTIVITIES WITH RECORD OBJECTS BASED ON ENTITY RELATIONSHIPS

The present disclosure relates to systems and methods for matching electronic activities with record objects based on entity relationships. The method can include accessing a plurality of electronic activities, identifying an electronic activity, identifying a first participant associated with a first entity and a second participant associated with a second entity, determining whether a record object identifier is included in the electronic activity, identifying a first record object of the system of record that includes an instance of the record object identifier, and storing an association between the electronic activity and the first record object. The method can include determining a second record object corresponding to the second entity, identifying, using a matching policy, a third record object linked to the second record object and identifying a third entity, and storing, by the one or more processors, an association between the electronic activity and the third record object.

SYSTEMS AND METHODS FOR MATCHING ELECTRONIC ACTIVITIES WITH RECORD OBJECTS BASED ON ENTITY RELATIONSHIPS

The present disclosure relates to systems and methods for matching electronic activities with record objects based on entity relationships. The method can include accessing a plurality of electronic activities, identifying an electronic activity, identifying a first participant associated with a first entity and a second participant associated with a second entity, determining whether a record object identifier is included in the electronic activity, identifying a first record object of the system of record that includes an instance of the record object identifier, and storing an association between the electronic activity and the first record object. The method can include determining a second record object corresponding to the second entity, identifying, using a matching policy, a third record object linked to the second record object and identifying a third entity, and storing, by the one or more processors, an association between the electronic activity and the third record object.

System and method for performing programmable analytics on network data

A system and a method for performing programmable analytics on network data are described. A data layer constructs flow behavior information based on information present within headers of data packets flowing across one or more network devices configured in a computer network. An inline heuristics layer performs one or more inline heuristic operations on the flow behavior information to obtain aggregate statistical information. An integrated analytics layer performs one or more analytical operations on the flow behavior information to obtain network insights. A presentation layer filters and plots information obtained from the data layer, the inline heuristics layer, and the integrated analytics layer, based on a user input.

Network monitoring system, network monitoring method, and program

In the present disclosure, a network monitoring system is provided including an IP network monitoring unit (610) that monitors an IP network to which an IP device is connected; and a non-IP device monitoring unit (630) that monitors a non-IP device. It is possible to monitor both the IP network and the non-IP device in a system that includes the IP network including the IP device and the non-IP device.

Method for identifying application information in network traffic, and apparatus
11582188 · 2023-02-14 · ·

A first correspondence table in a terminal device stores a correspondence between an identifier of a process running on the terminal device and an identifier of a data stream created by the process, a second correspondence table stores a second correspondence between an identifier of an application and an identifier of a process created by the application. The terminal device receives an identifier, sent by a network security device, of a first data stream. The terminal device can find, in the first correspondence table, a first record storing the identifier of the first data stream to obtain an identifier of a process. The terminal device can find in the second correspondence table, a second record storing the identifier of the process in the first record to obtain an identifier of an application from the second record. The identifier of the application is then sent to the network security device.

Multi-level learning for classifying traffic flows on a first packet from DNS response data

Disclosed herein are systems and methods for multi-level classification of data traffic flows based on information in a first packet for a data traffic flow. In exemplary embodiments of the present disclosure, a key can be generated from intercepted DNS data to track data traffic flows by application names and destination IP addresses. Based on these keys, patterns can be discerned to infer data traffic information based on only the information in a first packet, such as destination IP address. The determined patterns can be used to predict classifications of future traffic flows with similar key information. In this way, data traffic flows can be classified and steered in a network based on limited information available in a first packet.

Multi-level learning for classifying traffic flows on a first packet from DNS response data

Disclosed herein are systems and methods for multi-level classification of data traffic flows based on information in a first packet for a data traffic flow. In exemplary embodiments of the present disclosure, a key can be generated from intercepted DNS data to track data traffic flows by application names and destination IP addresses. Based on these keys, patterns can be discerned to infer data traffic information based on only the information in a first packet, such as destination IP address. The determined patterns can be used to predict classifications of future traffic flows with similar key information. In this way, data traffic flows can be classified and steered in a network based on limited information available in a first packet.

INFORMATION PROCESSING METHOD AND APPARATUS, NODE DEVICE, SERVER AND STORAGE MEDIUM
20230037602 · 2023-02-09 ·

The embodiments of the present disclosure provide a method and apparatus for information processing, a node device, a server and a storage medium. The method includes that: characteristic information is extracted from an acquired service packet; and the characteristic information is sent to a server, so that the server generates, according to the characteristic information, a detection instance for detecting a service flow corresponding to the service packet. Thus, by extracting the characteristic information of the service packet, the server generates a detection instance corresponding to the characteristic information, achieving the flexible deployment and application of channel associated performance detection, and reducing the difficulty and cost of manual maintenance.

INFORMATION PROCESSING METHOD AND APPARATUS, NODE DEVICE, SERVER AND STORAGE MEDIUM
20230037602 · 2023-02-09 ·

The embodiments of the present disclosure provide a method and apparatus for information processing, a node device, a server and a storage medium. The method includes that: characteristic information is extracted from an acquired service packet; and the characteristic information is sent to a server, so that the server generates, according to the characteristic information, a detection instance for detecting a service flow corresponding to the service packet. Thus, by extracting the characteristic information of the service packet, the server generates a detection instance corresponding to the characteristic information, achieving the flexible deployment and application of channel associated performance detection, and reducing the difficulty and cost of manual maintenance.

PASSIVE MEASUREMENT OF COMMUNICATION FLOWS

Methods, systems, and devices for communications are described. One or more flows between a node and one or more other nodes in a communication network may be monitored over a time period. During the monitoring, it may be identified that, during a subset of the time period, communications over at least one of the flows were restricted by the communication network based on receiving at least one indicator of congestion for the at least one flow. A quantity of traffic communicated over the one or more flows during the subset of the time period may then be determined, and respective flow rates of the one or more flows may be obtained. The obtained flow rates may be used to calculate a data rate of one or more connections between the node and the one or more other nodes.