Open Access. Powered by Scholars. Published by Universities.®
- Publication Year
- File Type
Articles 9001 - 9030 of 11832
Full-Text Articles in Entire DC Network
Machine-Learning Based Evaluation Of Access Control Lists To Identify Anomalies, Alejo Grigera Sutro
Machine-Learning Based Evaluation Of Access Control Lists To Identify Anomalies, Alejo Grigera Sutro
Defensive Publications Series
Access control lists (ACLs) are a commonly used mechanism to limit the distribution of data in an organization and to protect data from improper access. As ACL size grows one task to be solved is to keep the lists up-to-date and validate that each person in the ACL has appropriate levels of access to data. Currently, managing ACLs and detecting the presence of anomalous individuals in the lists is a manual task. This disclosure describes the application of a trained machine learning model that utilizes as input various factors such as employee roles and organization structure to detect and flag …
Intelligently Locking A Device Based On Contextual Signals, Jonathan D. Hurwitz, Christina Gilbert
Intelligently Locking A Device Based On Contextual Signals, Jonathan D. Hurwitz, Christina Gilbert
Defensive Publications Series
A system is described that enables a computing device (e.g., a mobile phone, smartwatch, tablet computer, etc.) to detect or couple with a companion computing device to detect various contextual signals and automatically lock the computing device based on the various contextual signals. The computing device may use one or more sensors (e.g., infrared cameras, near-field microwave sensors, cameras, microphones, etc.) to detect user inputs, measure wireless signal characteristics, capture images, determine a location of the computing device, etc. as contextual signals. The computing device may analyze these contextual signals to lock the computing device automatically (i.e., change the computing …
Interactively Connecting Corporate Policy And Process To Policy Consumers, Angie Szabo, Swarupa Reddy, Alex Gregory
Interactively Connecting Corporate Policy And Process To Policy Consumers, Angie Szabo, Swarupa Reddy, Alex Gregory
Defensive Publications Series
Connected policy and process techniques are presented herein that facilitate extracting policies from archaic documents and putting them into interactive policy requirements at the fingertips of the people who have to follow them; thereby simplifying their experience and enabling speed to execution. Techniques presented herein may address various prioritization principles including, but not limited to reduction of risk from non-compliance; policy mapping, impact analysis (e.g., new business model, etc.), bi-directional linkages, and policy analytics; tighter controls around policy ownership and editing/approvals/socialization; increased user compliance and ease of consumption; providing improved policy governance and controls; and enhanced analytics.
Reconstruction Of Entity Lifetime Summaries From Autosupport (Asup) Configuration And Logs, Geetha Srikantan
Reconstruction Of Entity Lifetime Summaries From Autosupport (Asup) Configuration And Logs, Geetha Srikantan
Defensive Publications Series
Presented herein are techniques for rapid reconstruction of entity lifetime/ lifecycle summaries (lifetime of entities) from voluminous AutoSupport (ASUP) bundles.
Automatic Linecard (Lc) Capability Detection, Stefano Binetti, Richard Moses S, Davide Sirtori
Automatic Linecard (Lc) Capability Detection, Stefano Binetti, Richard Moses S, Davide Sirtori
Defensive Publications Series
Presented herein are techniques to reduce software development code and allow software to automatically detect and adapt the code to the capabilities of a linecard (LC).
Intent-Aware Flow Redirect Using Single-Hop Internet Control Message Protocol (Icmp) Extension, Carlos M. Pignataro, Nagendra Kumar Nainar
Intent-Aware Flow Redirect Using Single-Hop Internet Control Message Protocol (Icmp) Extension, Carlos M. Pignataro, Nagendra Kumar Nainar
Defensive Publications Series
Techniques presented herein provide for a Control Agent that monitors flow distribution and Smart Network Interface Card (sNIC) capability and utilizes a simple Internet Control Message Protocol (ICMP) extension to instruct upstream node(s) to redirect traffic over other sNIC connected link(s). The techniques may be utilized for both Layer 2 (L2) and Layer 3 (L3) links and may provide a novel mechanism to leverage an sNIC for flow-based/intent-based/capability-aware load balancing and/or policy-balancing.
Methods And Apparatus For Intent And Context-Based Ad-Hoc Data Driven Reporting And Visualization, Plamen Nedeltchev, Madhuri Garikapati, Eric Kroll, Mani Kesavan
Methods And Apparatus For Intent And Context-Based Ad-Hoc Data Driven Reporting And Visualization, Plamen Nedeltchev, Madhuri Garikapati, Eric Kroll, Mani Kesavan
Defensive Publications Series
Existing executive events, investment planning sessions, regular checkups, service reviews, etc. are mainly based on static content such as templates, PDF files and PPT presentations. However, these templates have static dashboard and predefined scenarios that cannot be changed/altered during the presentation and lack the ability to visually-represent relevant ad-hoc content. As such, presented herein are dynamic (ad-hoc) and context-based visualization systems that are more intuitive than conventional arrangements. The techniques presented herein may, for example, facilitate a more natural decision making process by providing content that can dynamically change based, for example, on the current context, such as important in-depth …
Automated And Reactive Mechanism In Connectivity Fault Management (Cfm) With An On-Device Expert System, Karthik Babu Harichandra Babu, Peter Jones, Peter Van Horne, Ananthakrishnan Rajamani
Automated And Reactive Mechanism In Connectivity Fault Management (Cfm) With An On-Device Expert System, Karthik Babu Harichandra Babu, Peter Jones, Peter Van Horne, Ananthakrishnan Rajamani
Defensive Publications Series
Presented herein is an “On-Device Expert System” for implementation at devices operating in accordance with Connectivity Fault Management (CFM). In particular, in addition to fault detection/verification/notification, the techniques presented herein now enable fault device/link identification. The “On-Device Expert System” performs telemetry operations inside the device itself, instead of having the same operations performed in a controller. As such, the techniques presented herein avoid the need for multiple resources usage in the controller for the same telemetry details. With the “On-Device Expert System” providing the needed telemetry details to the controller, the controller now can directly trigger the application associated with …
Using A Cloud-Based Enterprise Network Security System To Provide Decentralized But Unified General Data Protection Regulation (Gdpr) Consent Management, Thomas Vegas, Anirban Karmakar, Giacomo Trifilo
Using A Cloud-Based Enterprise Network Security System To Provide Decentralized But Unified General Data Protection Regulation (Gdpr) Consent Management, Thomas Vegas, Anirban Karmakar, Giacomo Trifilo
Defensive Publications Series
Techniques presented herein provide a decentralized, yet unified, General Data‑Protection Regulation (GDPR) consent management platform functionality that may utilize Domain Name System level (DNS-level) interposing capabilities of a cloud-based enterprise network security system to collect detailed user privacy preferences, which can be stored locally via a user's browser. Thus, websites may not manage consent, but rather may simply process user requests with inline added consent parameters.
Dot Projector Based On Phase Diffuser, John D. Perreault
Dot Projector Based On Phase Diffuser, John D. Perreault
Defensive Publications Series
This disclosure describes low-weight, low-cost, high-efficiency techniques to project coherent infrared dots onto a subject to sense the depth contour of the subject while capturing a photograph. The techniques generate dot patterns of high number and density. A phase diffuser placed in the path of an infrared laser beam causes the wavefront of the laser beam to develop random undulations. The speckle pattern formed at the plane of the subject due to the randomized wavefront serves as a matrix of infrared dots.
Recovery And Upgrade Of A Device Using An Auxiliary Device, Sudha Broslawsky, Jes Klinke, Shelley Chen, Howard Lee, Julius Werner
Recovery And Upgrade Of A Device Using An Auxiliary Device, Sudha Broslawsky, Jes Klinke, Shelley Chen, Howard Lee, Julius Werner
Defensive Publications Series
A laptop or other device that breaks down or freezes, e.g., due to malicious software or malfunction, can be made operational again if it returns to a known healthy state. However, the present state of such a device prevents it from autonomously recovering, upgrading to a stable software version, establishing an internet connection to recover or upgrade, or from reliably identifying itself from the contents of its RAM. Per the techniques of this disclosure, an auxiliary device, e.g., a mobile device, reads the read-only memory of the device-under-repair to determine its make, model, and other parameters. A recent, stable operating …
Airship-Based Security And Monitoring With Machine Learning, Yan Mayster, Brian Shucker
Airship-Based Security And Monitoring With Machine Learning, Yan Mayster, Brian Shucker
Defensive Publications Series
Large open spaces, e.g., beaches, cattle-grazing grounds, etc., often need to be monitored for security or other reasons. In many cases, monitoring from the air provides the widest and most effective coverage. However, due to the cost of air-based monitoring, such aerial monitoring is often not possible, putting individuals or assets at risk or causing loss of revenue. This disclosure describes techniques to deploy small aircraft, e.g., kites, blimps, low-powered drones, etc. to monitor a given area. A video feed from the aircraft is analyzed using a trained machine-learning model to automatically detect situations that meet safety or compliance criteria, …
Protecting Against Malicious Logins On Virtual Machines Using Blockchain, Sarthak Sharma, Lovepreet Singh, Yegappan Lakshmanan
Protecting Against Malicious Logins On Virtual Machines Using Blockchain, Sarthak Sharma, Lovepreet Singh, Yegappan Lakshmanan
Defensive Publications Series
Presented herein are techniques that involve utilizing a blockchain-based methodology that provides a defense against rollback attacks on a virtual machine and is scalable for other application areas. In one example, a solution is provided to avoid rollback attacks during restoration of a virtual machine under the assumption of a malicious host and hypervisor. Techniques presented herein also address problems associated with an untrusted host under certain assumptions.
Tool-Free 3d Printed Threaded Union Method With Removable Tightening Accessory, Hp Inc
Tool-Free 3d Printed Threaded Union Method With Removable Tightening Accessory, Hp Inc
Defensive Publications Series
The process of connecting parts to form a single body is needed when the components have different
materials or when it has been impossible to manufacture the final part in a sole and continuous body. This
process is common in the 3D printing world as the size of the parts that can be printed is limited to the
machine capabilities, and nowadays these are very limited compared to the traditional manufacturing
methods. In powder‐based 3D printing technologies, splitting parts into several components might also
be a convenient strategy to improve the unfused powder removal process or to improve the nesting …
Overhead Collision Alerts And Overhead-Obstacle Aware Navigation Planning Using Onboard Sensors And Vehicle-To-Vehicle Communication, Yan Mayster, Brian Shucker
Overhead Collision Alerts And Overhead-Obstacle Aware Navigation Planning Using Onboard Sensors And Vehicle-To-Vehicle Communication, Yan Mayster, Brian Shucker
Defensive Publications Series
A common type of single-vehicle accident involves a vehicle entering a passageway with insufficient clearance. Variable vehicle dimensions, e.g., oversized trucks, automobiles with roof-mounted bicycles, etc. pose a special challenge since the dimensions of the vehicle are non-standard for just the duration of the trip. Little is done today to alert drivers of impending overhead collisions. Vehicles today utilize no more than clearance lights to signal their oversize dimensions to other vehicles. Navigation tools that account for low-ceiling passageways do not account for non-standard dimensions. This disclosure describes the use of cameras and LiDAR sensors to determine both the dimensions …
Distributed Multi-Bucket Sampling, Richard Steven Farnsworth
Distributed Multi-Bucket Sampling, Richard Steven Farnsworth
Defensive Publications Series
In many contexts, e.g., training of machine learning models, there is a requirement to sample a large dataset that includes data points that are classified as either positive or negative. Per techniques of this disclosure, distributed sampling is performed such that the dataset is read just once and a minimum number of each type of data point is captured without changing the ratio between positive and negative data points. This disclosure describes techniques to sample a large dataset using a mapreduce strategy. During mapping, a data point is one-to-one mapped to a partial result that includes counts of positive and …
Optimized Simultaneous Authentication Of Equals (Sae) Identity Pre-Shared Key (Ipsk), Abhishek Dhammawat, Shreshta Besagarahalli Manu, Namsoo Kim, Mansi Jain
Optimized Simultaneous Authentication Of Equals (Sae) Identity Pre-Shared Key (Ipsk), Abhishek Dhammawat, Shreshta Besagarahalli Manu, Namsoo Kim, Mansi Jain
Defensive Publications Series
Presented here are techniques for the residential deployment of common Wi-Fi® services with an optimized Simultaneous Authentication of Equals (SAE) Identity Pre-Shared Key (iPSK) flow. The techniques presented herein avoid the use of an Authentication, Authorization, and Accounting (AAA) server for clients whose entries are absent through the upfront use of bloom filter information provided by an AAA server. The techniques presented herein can also be used for Wi-Fi Protected Access II (WPA2) iPSK optimization or SAE (Wi-Fi® Protected Access 3 (WPA3) personal), which has more latency sensitive call flow due to SAE auth commit timeouts consideration.
Virtual Reality (Vr) Screenshot, Anonymous Anonymous
Virtual Reality (Vr) Screenshot, Anonymous Anonymous
Defensive Publications Series
The present disclosure describes a method for capturing virtual reality (VR) screenshots of a three-dimensional (3D) scene for a virtual environment. The method is implemented partially on a VR application that is installed on a computing device and partially on a camera rig. The camera rig, housing one or more cameras, is connected to the computing device via a network. The one or more cameras are directed at different angles or at a specific angle to capture the 3D scene from the different angles or the specific angle, respectively. Also, the camera rig is configured to function as a stationary …
A Head Mounted Capture System, Anonymous Anonymous
A Head Mounted Capture System, Anonymous Anonymous
Defensive Publications Series
The present disclosure provides a physical interface (i.e. a serial link cable) for coupling a head mounted capture (HMC) system to a host receiver. The HMC system includes a multi camera aggregator, a plurality of pulse density modulation (PDM) microphones and a hardware (HW) serializer. The multi camera aggregator further includes a plurality of camera sensors. Each of the plurality of camera sensors provides capture data (i.e. images or videos captured by each of the plurality of camera sensors) as an input to the HW serializer via a camera serial interface (CSI). The plurality of PDM microphones provides audio time-division …
On-Demand Content Generation And Insertion During Content Consumption, Victor Carbune, Alex Damian
On-Demand Content Generation And Insertion During Content Consumption, Victor Carbune, Alex Damian
Defensive Publications Series
Consumers of media content such as audio or video often like some parts of the content more compared to other parts. Currently, a user must accept the choices of the content creators regarding the number of different parts of the content that match the user’s preference. This disclosure describes techniques for on-demand generation and/or insertion of media content at the time of media consumption. To this end, users are provided options that can be invoked to generate additional content similar to the content the user is currently consuming.
Authentication Of Application Flows In Software Defined Network Deployments Using A Transaction Model, Niranjan M. M, Nagaraj Kenchaiah
Authentication Of Application Flows In Software Defined Network Deployments Using A Transaction Model, Niranjan M. M, Nagaraj Kenchaiah
Defensive Publications Series
As Software Defined Networking (SDN) enables third party applications to be integrated into the architecture, a malicious application could have as much of a detrimental effect on the network as a compromised controller. In order to avoid the deployment of malicious/compromised applications, controllers and applications should establish a trusted connection and authenticate the identity of applications and their flows before exchanging control messages. Application flows may be considered network configurations sent by applications that are managed by controllers, which install network configurations into switches. Without authentication, applications may inject malicious configurations into network devices at will, which could reduce network …
Node And Service Discovery In Wireless Local Area Network Controller Cluster Architectures Using Hyperledger, Niranjan M. M, Nagaraj Kenchaiah, Vijay Kothamasu, Ramachandra Murthy
Node And Service Discovery In Wireless Local Area Network Controller Cluster Architectures Using Hyperledger, Niranjan M. M, Nagaraj Kenchaiah, Vijay Kothamasu, Ramachandra Murthy
Defensive Publications Series
In the wireless cluster deployments, node discovery is a challenge. Further, it can be more challenging to discover the services running in such deployments. There are existing methods which use "client side discovery" and "server side discovery" that need a centralized "Service Registry" to maintain all available service instances. Presented herein are techniques that provide for the utilization of a private blockchain and HyperLedger in order to discover nodes and their services in wireless cluster deployments. Techniques of this proposal may provide for de‑centralizing node and service discovery in wireless cluster deployments without compromising authentication and security aspects. In one …
Trustworthiness Among Controllers And Switches In Multi-Provider Software Defined Network Deployments Using A Trusted Platform Module (Tpm) And Secure Ledger, Niranjan M. M, Nagaraj Kenchaiah
Trustworthiness Among Controllers And Switches In Multi-Provider Software Defined Network Deployments Using A Trusted Platform Module (Tpm) And Secure Ledger, Niranjan M. M, Nagaraj Kenchaiah
Defensive Publications Series
The OpenFlow® protocol especially OpenFlow® Discovery Protocol (OFDP) utilizes clear text Link Layer Discovery Protocol (LLDP) message exchanges to discover network topology. Such exchanges lack security and may lead to network attacks such as LLDP flooding, link fabrication, etc. Currently, the OpenFlow® protocol both in the case of discovery (OFDP) as well during subsequent communication between a controller and a switch (even with Transport Layer Security (TLS)) does not offer a way to understand whether or not a discovered controller or switch is a trustworthy device. Presented herein are techniques that provide Trusted Platform Module (TPM) and blockchain-based trust establishment …
Secure And Efficient Method To Distribute Configurations In Wireless Cluster Deployments Using Hyper Ledger, Niranjan M. M, Nagaraj Kenchaiah
Secure And Efficient Method To Distribute Configurations In Wireless Cluster Deployments Using Hyper Ledger, Niranjan M. M, Nagaraj Kenchaiah
Defensive Publications Series
An enterprise wireless clustering deployment is comprises of cluster of Wireless Local Area Network (LAN) Controllers (WLCs), intended to provide collaborative services such as load balancing of Access Points (APs), distributed mDNS gateway, etc. Since these cluster deployments are typically very large, configuring individual WLCs is difficult. Presented herein are techniques to incorporate WLC cluster deployments with an authenticated distributed ledger to securely store the configuration and subsequent changes (e.g., only maintain changes from the previous one, using dictionary method: key-value pair to identify the difference). This avoids the use of control Datagram Transport Layer Security (DTLS) connection between AP …
Dynamic And Customer Tailored Consumable Life Projection Messaging, Hp Inc
Dynamic And Customer Tailored Consumable Life Projection Messaging, Hp Inc
Defensive Publications Series
A technique calculates, based on a customer's own typical printing profile, the
approximate number of remaining pages that can be printed using the current remaining
level of individual consumables in the printer, informs the customer when replenishment
is needed, and enables the customer to reorder consumables more cost-effectively.
Customized Printed Handouts For Sales Prospects, Hp Inc
Customized Printed Handouts For Sales Prospects, Hp Inc
Defensive Publications Series
A system captures an image of a prospective customer, records it with related
image in a CRM database, generates content of value to the customer, and prints a
handout for the customer that includes the valued content.
Offline Cable Detection Method, Hp Inc
Offline Cable Detection Method, Hp Inc
Defensive Publications Series
A printer's cable detect information can be read through an external interface,
even when the printer itself is not powered on.
Communication Bus For Embedded Sensor Systems, Hp Inc
Communication Bus For Embedded Sensor Systems, Hp Inc
Defensive Publications Series
A communications bus using features of both I2C and SPI topologies enables
communications between a master and multiple slaves at high data rates over a span of
several feet.
Hardware Security-Based Data Content Protection, Hp Inc
Hardware Security-Based Data Content Protection, Hp Inc
Defensive Publications Series
The method described here, uses a hardware‐based handshaking and
hardware bound policies executed in computing devices, to geo‐fence
contents being viewed in computers.
Pcle Gen4 And Pcle Gen3/Sata Devices Switching Scheme, Hp Inc
Pcle Gen4 And Pcle Gen3/Sata Devices Switching Scheme, Hp Inc
Defensive Publications Series
Disclosed is a way to support PCIe NVMe Gen4 SSD Devices in addition to maintaining support for
PCIe NVMe Gen3 SSD’s and SATA and Hybrid drives like H10. Chipsets are being architected to
support PCIe Gen4 interface in the CPU for higher bandwidth devices such as graphics and high
speed SSDs. However, the I/O controller in the chipset maintains support for PCIe Gen3/SATA and
stops short of supporting PCIe Gen4 devices.