Open Access. Powered by Scholars. Published by Universities.®

Digital Commons Network™

Open Access. Powered by Scholars. Published by Universities.®

Articles 9001 - 9030 of 11832

Full-Text Articles in Entire DC Network

Machine-Learning Based Evaluation Of Access Control Lists To Identify Anomalies, Alejo Grigera Sutro Jan 2020

Machine-Learning Based Evaluation Of Access Control Lists To Identify Anomalies, Alejo Grigera Sutro

Defensive Publications Series

Access control lists (ACLs) are a commonly used mechanism to limit the distribution of data in an organization and to protect data from improper access. As ACL size grows one task to be solved is to keep the lists up-to-date and validate that each person in the ACL has appropriate levels of access to data. Currently, managing ACLs and detecting the presence of anomalous individuals in the lists is a manual task. This disclosure describes the application of a trained machine learning model that utilizes as input various factors such as employee roles and organization structure to detect and flag …


Intelligently Locking A Device Based On Contextual Signals, Jonathan D. Hurwitz, Christina Gilbert Jan 2020

Intelligently Locking A Device Based On Contextual Signals, Jonathan D. Hurwitz, Christina Gilbert

Defensive Publications Series

A system is described that enables a computing device (e.g., a mobile phone, smartwatch, tablet computer, etc.) to detect or couple with a companion computing device to detect various contextual signals and automatically lock the computing device based on the various contextual signals. The computing device may use one or more sensors (e.g., infrared cameras, near-field microwave sensors, cameras, microphones, etc.) to detect user inputs, measure wireless signal characteristics, capture images, determine a location of the computing device, etc. as contextual signals. The computing device may analyze these contextual signals to lock the computing device automatically (i.e., change the computing …


Interactively Connecting Corporate Policy And Process To Policy Consumers, Angie Szabo, Swarupa Reddy, Alex Gregory Jan 2020

Interactively Connecting Corporate Policy And Process To Policy Consumers, Angie Szabo, Swarupa Reddy, Alex Gregory

Defensive Publications Series

Connected policy and process techniques are presented herein that facilitate extracting policies from archaic documents and putting them into interactive policy requirements at the fingertips of the people who have to follow them; thereby simplifying their experience and enabling speed to execution. Techniques presented herein may address various prioritization principles including, but not limited to reduction of risk from non-compliance; policy mapping, impact analysis (e.g., new business model, etc.), bi-directional linkages, and policy analytics; tighter controls around policy ownership and editing/approvals/socialization; increased user compliance and ease of consumption; providing improved policy governance and controls; and enhanced analytics.


Reconstruction Of Entity Lifetime Summaries From Autosupport (Asup) Configuration And Logs, Geetha Srikantan Jan 2020

Reconstruction Of Entity Lifetime Summaries From Autosupport (Asup) Configuration And Logs, Geetha Srikantan

Defensive Publications Series

Presented herein are techniques for rapid reconstruction of entity lifetime/ lifecycle summaries (lifetime of entities) from voluminous AutoSupport (ASUP) bundles.


Automatic Linecard (Lc) Capability Detection, Stefano Binetti, Richard Moses S, Davide Sirtori Jan 2020

Automatic Linecard (Lc) Capability Detection, Stefano Binetti, Richard Moses S, Davide Sirtori

Defensive Publications Series

Presented herein are techniques to reduce software development code and allow software to automatically detect and adapt the code to the capabilities of a linecard (LC).


Intent-Aware Flow Redirect Using Single-Hop Internet Control Message Protocol (Icmp) Extension, Carlos M. Pignataro, Nagendra Kumar Nainar Jan 2020

Intent-Aware Flow Redirect Using Single-Hop Internet Control Message Protocol (Icmp) Extension, Carlos M. Pignataro, Nagendra Kumar Nainar

Defensive Publications Series

Techniques presented herein provide for a Control Agent that monitors flow distribution and Smart Network Interface Card (sNIC) capability and utilizes a simple Internet Control Message Protocol (ICMP) extension to instruct upstream node(s) to redirect traffic over other sNIC connected link(s). The techniques may be utilized for both Layer 2 (L2) and Layer 3 (L3) links and may provide a novel mechanism to leverage an sNIC for flow-based/intent-based/capability-aware load balancing and/or policy-balancing.


Methods And Apparatus For Intent And Context-Based Ad-Hoc Data Driven Reporting And Visualization, Plamen Nedeltchev, Madhuri Garikapati, Eric Kroll, Mani Kesavan Jan 2020

Methods And Apparatus For Intent And Context-Based Ad-Hoc Data Driven Reporting And Visualization, Plamen Nedeltchev, Madhuri Garikapati, Eric Kroll, Mani Kesavan

Defensive Publications Series

Existing executive events, investment planning sessions, regular checkups, service reviews, etc. are mainly based on static content such as templates, PDF files and PPT presentations. However, these templates have static dashboard and predefined scenarios that cannot be changed/altered during the presentation and lack the ability to visually-represent relevant ad-hoc content. As such, presented herein are dynamic (ad-hoc) and context-based visualization systems that are more intuitive than conventional arrangements. The techniques presented herein may, for example, facilitate a more natural decision making process by providing content that can dynamically change based, for example, on the current context, such as important in-depth …


Automated And Reactive Mechanism In Connectivity Fault Management (Cfm) With An On-Device Expert System, Karthik Babu Harichandra Babu, Peter Jones, Peter Van Horne, Ananthakrishnan Rajamani Jan 2020

Automated And Reactive Mechanism In Connectivity Fault Management (Cfm) With An On-Device Expert System, Karthik Babu Harichandra Babu, Peter Jones, Peter Van Horne, Ananthakrishnan Rajamani

Defensive Publications Series

Presented herein is an “On-Device Expert System” for implementation at devices operating in accordance with Connectivity Fault Management (CFM). In particular, in addition to fault detection/verification/notification, the techniques presented herein now enable fault device/link identification. The “On-Device Expert System” performs telemetry operations inside the device itself, instead of having the same operations performed in a controller. As such, the techniques presented herein avoid the need for multiple resources usage in the controller for the same telemetry details. With the “On-Device Expert System” providing the needed telemetry details to the controller, the controller now can directly trigger the application associated with …


Using A Cloud-Based Enterprise Network Security System To Provide Decentralized But Unified General Data Protection Regulation (Gdpr) Consent Management, Thomas Vegas, Anirban Karmakar, Giacomo Trifilo Jan 2020

Using A Cloud-Based Enterprise Network Security System To Provide Decentralized But Unified General Data Protection Regulation (Gdpr) Consent Management, Thomas Vegas, Anirban Karmakar, Giacomo Trifilo

Defensive Publications Series

Techniques presented herein provide a decentralized, yet unified, General Data‑Protection Regulation (GDPR) consent management platform functionality that may utilize Domain Name System level (DNS-level) interposing capabilities of a cloud-based enterprise network security system to collect detailed user privacy preferences, which can be stored locally via a user's browser. Thus, websites may not manage consent, but rather may simply process user requests with inline added consent parameters.


Dot Projector Based On Phase Diffuser, John D. Perreault Jan 2020

Dot Projector Based On Phase Diffuser, John D. Perreault

Defensive Publications Series

This disclosure describes low-weight, low-cost, high-efficiency techniques to project coherent infrared dots onto a subject to sense the depth contour of the subject while capturing a photograph. The techniques generate dot patterns of high number and density. A phase diffuser placed in the path of an infrared laser beam causes the wavefront of the laser beam to develop random undulations. The speckle pattern formed at the plane of the subject due to the randomized wavefront serves as a matrix of infrared dots.


Recovery And Upgrade Of A Device Using An Auxiliary Device, Sudha Broslawsky, Jes Klinke, Shelley Chen, Howard Lee, Julius Werner Jan 2020

Recovery And Upgrade Of A Device Using An Auxiliary Device, Sudha Broslawsky, Jes Klinke, Shelley Chen, Howard Lee, Julius Werner

Defensive Publications Series

A laptop or other device that breaks down or freezes, e.g., due to malicious software or malfunction, can be made operational again if it returns to a known healthy state. However, the present state of such a device prevents it from autonomously recovering, upgrading to a stable software version, establishing an internet connection to recover or upgrade, or from reliably identifying itself from the contents of its RAM. Per the techniques of this disclosure, an auxiliary device, e.g., a mobile device, reads the read-only memory of the device-under-repair to determine its make, model, and other parameters. A recent, stable operating …


Airship-Based Security And Monitoring With Machine Learning, Yan Mayster, Brian Shucker Jan 2020

Airship-Based Security And Monitoring With Machine Learning, Yan Mayster, Brian Shucker

Defensive Publications Series

Large open spaces, e.g., beaches, cattle-grazing grounds, etc., often need to be monitored for security or other reasons. In many cases, monitoring from the air provides the widest and most effective coverage. However, due to the cost of air-based monitoring, such aerial monitoring is often not possible, putting individuals or assets at risk or causing loss of revenue. This disclosure describes techniques to deploy small aircraft, e.g., kites, blimps, low-powered drones, etc. to monitor a given area. A video feed from the aircraft is analyzed using a trained machine-learning model to automatically detect situations that meet safety or compliance criteria, …


Protecting Against Malicious Logins On Virtual Machines Using Blockchain, Sarthak Sharma, Lovepreet Singh, Yegappan Lakshmanan Jan 2020

Protecting Against Malicious Logins On Virtual Machines Using Blockchain, Sarthak Sharma, Lovepreet Singh, Yegappan Lakshmanan

Defensive Publications Series

Presented herein are techniques that involve utilizing a blockchain-based methodology that provides a defense against rollback attacks on a virtual machine and is scalable for other application areas. In one example, a solution is provided to avoid rollback attacks during restoration of a virtual machine under the assumption of a malicious host and hypervisor. Techniques presented herein also address problems associated with an untrusted host under certain assumptions.


Tool-Free 3d Printed Threaded Union Method With Removable Tightening Accessory, Hp Inc Jan 2020

Tool-Free 3d Printed Threaded Union Method With Removable Tightening Accessory, Hp Inc

Defensive Publications Series

The process of connecting parts to form a single body is needed when the components have different

materials or when it has been impossible to manufacture the final part in a sole and continuous body. This

process is common in the 3D printing world as the size of the parts that can be printed is limited to the

machine capabilities, and nowadays these are very limited compared to the traditional manufacturing

methods. In powder‐based 3D printing technologies, splitting parts into several components might also

be a convenient strategy to improve the unfused powder removal process or to improve the nesting …


Overhead Collision Alerts And Overhead-Obstacle Aware Navigation Planning Using Onboard Sensors And Vehicle-To-Vehicle Communication, Yan Mayster, Brian Shucker Jan 2020

Overhead Collision Alerts And Overhead-Obstacle Aware Navigation Planning Using Onboard Sensors And Vehicle-To-Vehicle Communication, Yan Mayster, Brian Shucker

Defensive Publications Series

A common type of single-vehicle accident involves a vehicle entering a passageway with insufficient clearance. Variable vehicle dimensions, e.g., oversized trucks, automobiles with roof-mounted bicycles, etc. pose a special challenge since the dimensions of the vehicle are non-standard for just the duration of the trip. Little is done today to alert drivers of impending overhead collisions. Vehicles today utilize no more than clearance lights to signal their oversize dimensions to other vehicles. Navigation tools that account for low-ceiling passageways do not account for non-standard dimensions. This disclosure describes the use of cameras and LiDAR sensors to determine both the dimensions …


Distributed Multi-Bucket Sampling, Richard Steven Farnsworth Jan 2020

Distributed Multi-Bucket Sampling, Richard Steven Farnsworth

Defensive Publications Series

In many contexts, e.g., training of machine learning models, there is a requirement to sample a large dataset that includes data points that are classified as either positive or negative. Per techniques of this disclosure, distributed sampling is performed such that the dataset is read just once and a minimum number of each type of data point is captured without changing the ratio between positive and negative data points. This disclosure describes techniques to sample a large dataset using a mapreduce strategy. During mapping, a data point is one-to-one mapped to a partial result that includes counts of positive and …


Optimized Simultaneous Authentication Of Equals (Sae) Identity Pre-Shared Key (Ipsk), Abhishek Dhammawat, Shreshta Besagarahalli Manu, Namsoo Kim, Mansi Jain Jan 2020

Optimized Simultaneous Authentication Of Equals (Sae) Identity Pre-Shared Key (Ipsk), Abhishek Dhammawat, Shreshta Besagarahalli Manu, Namsoo Kim, Mansi Jain

Defensive Publications Series

Presented here are techniques for the residential deployment of common Wi-Fi® services with an optimized Simultaneous Authentication of Equals (SAE) Identity Pre-Shared Key (iPSK) flow. The techniques presented herein avoid the use of an Authentication, Authorization, and Accounting (AAA) server for clients whose entries are absent through the upfront use of bloom filter information provided by an AAA server. The techniques presented herein can also be used for Wi-Fi Protected Access II (WPA2) iPSK optimization or SAE (Wi-Fi® Protected Access 3 (WPA3) personal), which has more latency sensitive call flow due to SAE auth commit timeouts consideration.


Virtual Reality (Vr) Screenshot, Anonymous Anonymous Jan 2020

Virtual Reality (Vr) Screenshot, Anonymous Anonymous

Defensive Publications Series

The present disclosure describes a method for capturing virtual reality (VR) screenshots of a three-dimensional (3D) scene for a virtual environment. The method is implemented partially on a VR application that is installed on a computing device and partially on a camera rig. The camera rig, housing one or more cameras, is connected to the computing device via a network. The one or more cameras are directed at different angles or at a specific angle to capture the 3D scene from the different angles or the specific angle, respectively. Also, the camera rig is configured to function as a stationary …


A Head Mounted Capture System, Anonymous Anonymous Jan 2020

A Head Mounted Capture System, Anonymous Anonymous

Defensive Publications Series

The present disclosure provides a physical interface (i.e. a serial link cable) for coupling a head mounted capture (HMC) system to a host receiver. The HMC system includes a multi camera aggregator, a plurality of pulse density modulation (PDM) microphones and a hardware (HW) serializer. The multi camera aggregator further includes a plurality of camera sensors. Each of the plurality of camera sensors provides capture data (i.e. images or videos captured by each of the plurality of camera sensors) as an input to the HW serializer via a camera serial interface (CSI). The plurality of PDM microphones provides audio time-division …


On-Demand Content Generation And Insertion During Content Consumption, Victor Carbune, Alex Damian Jan 2020

On-Demand Content Generation And Insertion During Content Consumption, Victor Carbune, Alex Damian

Defensive Publications Series

Consumers of media content such as audio or video often like some parts of the content more compared to other parts. Currently, a user must accept the choices of the content creators regarding the number of different parts of the content that match the user’s preference. This disclosure describes techniques for on-demand generation and/or insertion of media content at the time of media consumption. To this end, users are provided options that can be invoked to generate additional content similar to the content the user is currently consuming.


Authentication Of Application Flows In Software Defined Network Deployments Using A Transaction Model, Niranjan M. M, Nagaraj Kenchaiah Jan 2020

Authentication Of Application Flows In Software Defined Network Deployments Using A Transaction Model, Niranjan M. M, Nagaraj Kenchaiah

Defensive Publications Series

As Software Defined Networking (SDN) enables third party applications to be integrated into the architecture, a malicious application could have as much of a detrimental effect on the network as a compromised controller. In order to avoid the deployment of malicious/compromised applications, controllers and applications should establish a trusted connection and authenticate the identity of applications and their flows before exchanging control messages. Application flows may be considered network configurations sent by applications that are managed by controllers, which install network configurations into switches. Without authentication, applications may inject malicious configurations into network devices at will, which could reduce network …


Node And Service Discovery In Wireless Local Area Network Controller Cluster Architectures Using Hyperledger, Niranjan M. M, Nagaraj Kenchaiah, Vijay Kothamasu, Ramachandra Murthy Jan 2020

Node And Service Discovery In Wireless Local Area Network Controller Cluster Architectures Using Hyperledger, Niranjan M. M, Nagaraj Kenchaiah, Vijay Kothamasu, Ramachandra Murthy

Defensive Publications Series

In the wireless cluster deployments, node discovery is a challenge. Further, it can be more challenging to discover the services running in such deployments. There are existing methods which use "client side discovery" and "server side discovery" that need a centralized "Service Registry" to maintain all available service instances. Presented herein are techniques that provide for the utilization of a private blockchain and HyperLedger in order to discover nodes and their services in wireless cluster deployments. Techniques of this proposal may provide for de‑centralizing node and service discovery in wireless cluster deployments without compromising authentication and security aspects. In one …


Trustworthiness Among Controllers And Switches In Multi-Provider Software Defined Network Deployments Using A Trusted Platform Module (Tpm) And Secure Ledger, Niranjan M. M, Nagaraj Kenchaiah Jan 2020

Trustworthiness Among Controllers And Switches In Multi-Provider Software Defined Network Deployments Using A Trusted Platform Module (Tpm) And Secure Ledger, Niranjan M. M, Nagaraj Kenchaiah

Defensive Publications Series

The OpenFlow® protocol especially OpenFlow® Discovery Protocol (OFDP) utilizes clear text Link Layer Discovery Protocol (LLDP) message exchanges to discover network topology. Such exchanges lack security and may lead to network attacks such as LLDP flooding, link fabrication, etc. Currently, the OpenFlow® protocol both in the case of discovery (OFDP) as well during subsequent communication between a controller and a switch (even with Transport Layer Security (TLS)) does not offer a way to understand whether or not a discovered controller or switch is a trustworthy device. Presented herein are techniques that provide Trusted Platform Module (TPM) and blockchain-based trust establishment …


Secure And Efficient Method To Distribute Configurations In Wireless Cluster Deployments Using Hyper Ledger, Niranjan M. M, Nagaraj Kenchaiah Jan 2020

Secure And Efficient Method To Distribute Configurations In Wireless Cluster Deployments Using Hyper Ledger, Niranjan M. M, Nagaraj Kenchaiah

Defensive Publications Series

An enterprise wireless clustering deployment is comprises of cluster of Wireless Local Area Network (LAN) Controllers (WLCs), intended to provide collaborative services such as load balancing of Access Points (APs), distributed mDNS gateway, etc. Since these cluster deployments are typically very large, configuring individual WLCs is difficult. Presented herein are techniques to incorporate WLC cluster deployments with an authenticated distributed ledger to securely store the configuration and subsequent changes (e.g., only maintain changes from the previous one, using dictionary method: key-value pair to identify the difference). This avoids the use of control Datagram Transport Layer Security (DTLS) connection between AP …


Dynamic And Customer Tailored Consumable Life Projection Messaging, Hp Inc Jan 2020

Dynamic And Customer Tailored Consumable Life Projection Messaging, Hp Inc

Defensive Publications Series

A technique calculates, based on a customer's own typical printing profile, the

approximate number of remaining pages that can be printed using the current remaining

level of individual consumables in the printer, informs the customer when replenishment

is needed, and enables the customer to reorder consumables more cost-effectively.


Customized Printed Handouts For Sales Prospects, Hp Inc Jan 2020

Customized Printed Handouts For Sales Prospects, Hp Inc

Defensive Publications Series

A system captures an image of a prospective customer, records it with related

image in a CRM database, generates content of value to the customer, and prints a

handout for the customer that includes the valued content.


Offline Cable Detection Method, Hp Inc Jan 2020

Offline Cable Detection Method, Hp Inc

Defensive Publications Series

A printer's cable detect information can be read through an external interface,

even when the printer itself is not powered on.


Communication Bus For Embedded Sensor Systems, Hp Inc Jan 2020

Communication Bus For Embedded Sensor Systems, Hp Inc

Defensive Publications Series

A communications bus using features of both I2C and SPI topologies enables

communications between a master and multiple slaves at high data rates over a span of

several feet.


Hardware Security-Based Data Content Protection, Hp Inc Jan 2020

Hardware Security-Based Data Content Protection, Hp Inc

Defensive Publications Series

The method described here, uses a hardware‐based handshaking and

hardware bound policies executed in computing devices, to geo‐fence

contents being viewed in computers.


Pcle Gen4 And Pcle Gen3/Sata Devices Switching Scheme, Hp Inc Jan 2020

Pcle Gen4 And Pcle Gen3/Sata Devices Switching Scheme, Hp Inc

Defensive Publications Series

Disclosed is a way to support PCIe NVMe Gen4 SSD Devices in addition to maintaining support for

PCIe NVMe Gen3 SSD’s and SATA and Hybrid drives like H10. Chipsets are being architected to

support PCIe Gen4 interface in the CPU for higher bandwidth devices such as graphics and high

speed SSDs. However, the I/O controller in the chipset maintains support for PCIe Gen3/SATA and

stops short of supporting PCIe Gen4 devices.