Patents Assigned to NetScout Systems, Inc.
-
Patent number: 12712902Abstract: The present disclosure describes a method for detecting and mitigating network attacks. The method includes collecting network data packets transmitted by a plurality of computing devices across a communications network; presenting a user interface on a user device, the user interface comprising a threshold calculation button and one or more fields each corresponding to a threshold for a different network characteristic of the communications network; receiving a selection of the threshold calculation button from the user device; determining a threshold for each of the one or more fields based on the collected network data packets; responsive to receiving the selection of the threshold calculation button, automatically populating each of the one or more fields with the threshold determined for the field; and detecting an attack on the communications network using a first threshold that was automatically populated into a first field of the one or more fields.Type: GrantFiled: September 26, 2024Date of Patent: August 18, 2026Assignee: NetScout Systems, Inc.Inventors: William Northway, Michael Ratanatharathorn, Michael Van Der Laar, Kyle Oswald
-
Publication number: 20260238366Abstract: A system can obtain candidate geolocations of a mobile device participating in a communications session with a computing device over a communications network. The system can calculate a predicted reference signal received power (RSRP) for each candidate geolocation based on signal propagation characteristics, calculate a penalty for each candidate geolocation as a function of the predicted RSRP, and identify a first candidate geolocation associated with a lowest penalty. The system can generate a left arc length and a right arc length from the first candidate geolocation based on candidate geolocations corresponding with penalties greater than or equal to the lowest penalty plus a variation threshold. The system can calculate an accuracy as a function of the left arc length and the right arc length, and store, responsive to determining the accuracy exceeds a threshold, an association between the first candidate geolocation and the mobile device.Type: ApplicationFiled: February 6, 2026Publication date: August 13, 2026Applicant: NetScout Systems, Inc.Inventors: Imran Hafeez, Le Yang, Oguz Dogan, Michael Wright, Yahya Idrissi
-
Publication number: 20260238678Abstract: A system can include one or more memory devices that can store instructions thereon. The instructions can, when executed by one or more processors, cause the one or more processors to monitor network traffic across a network provided by a first autonomous system, detect an attack on an Internet Protocol (IP) address of the network, prompt a network device for one or more flow records that list (i) the IP address of the network as a destination IP address, and (ii) the first autonomous system as a destination autonomous system, generate a first node that comprises at least one of (i) the IP address of the network within the graph or (ii) an identification of the first autonomous system within the graph, and detect that at least one flow record of the one or more flow records lists the first autonomous system as a next hop autonomous system.Type: ApplicationFiled: February 12, 2025Publication date: August 13, 2026Applicant: NetScout Systems, Inc.Inventors: Steinthor Bjarnason, Marcin Nawrocki
-
Publication number: 20260230321Abstract: A system may include one or more memory devices storing instructions thereon that, when executed by one or more processors, cause the one or more processors to obtain network connection information associated with communication across a network, store the network connection information in a first data cache, detect an initiation of a Secure Sockets Layer (SSL) function, identify an initiation of data transmission function that results in (i) a transmission of the encrypted data packet to a network stack or (ii) receipt of the encrypted data packet from the network stack, detect a termination of the data transmission function, store a network socket handle in a second data cache, detect a termination of the SSL function, wherein detection of the termination of the SSL function triggers, and associate one or more segments of the network connection information with a payload based on a context of the SSL function.Type: ApplicationFiled: January 31, 2025Publication date: August 6, 2026Applicant: NetScout Systems, Inc.Inventor: Douglas Jenney
-
Patent number: 12676837Abstract: Decrypting synthetic transactions with beacon packets is provided. A probe receives, from a client device, a start beacon packet that identifies a test of a service provided by one or more servers. The probe establishes, responsive to receipt of the start beacon packet, a log for the test. The probe stores, in the log established responsive to the start beacon packet, data packets transmitted between the client device and the one or more servers subsequent to the start beacon packet and encrypted with a key using a security protocol. The probe receives, from the client device, key information used to decrypt the data packets of the test encrypted with the key using the security protocol. The probe provides at least one of the data packets for evaluation or decryption using the key information to determine a performance of the service.Type: GrantFiled: August 26, 2024Date of Patent: July 7, 2026Assignee: NetScout Systems, Inc.Inventors: Bruce Kosbab, Bob Vogt, Paul Alexander Barrett, Anil K. Singhal, Ashwani Singhal, Narendra Byrapuram, Colm Toomey, Connor Monk
-
Publication number: 20260164261Abstract: A method for detecting PCI confusion during cellular network handovers includes identifying a geographic location of a handover failure of a user device from a first cell to a second cell, determining a strength of a signal to be received by the user device from the second cell, identifying, based on the strength of the signal to be received by the user device from the second cell, a hidden neighbor cell of the first cell, determining a strength of a signal to be received by the user device from the hidden neighbor cell, classifying, based on the determined signal strength of the hidden neighbor cell, a cause of the confusion during cellular network handovers, modifying, based on the classified cause of confusion, one or more parameters of the second cell or the hidden neighbor cell to prevent confusion during future cellular network handovers.Type: ApplicationFiled: December 10, 2024Publication date: June 11, 2026Applicant: NetScout Systems, Inc.Inventor: Bill Guo
-
Patent number: 12652213Abstract: A system and method for analyzing error codes includes detecting a failure condition on a network, identifying a subset of subscribers impacted by the failure condition, determining for each subscriber in the subset of subscribers a first set of error codes associated with the failure condition, creating a Bayesian network comprising one or more error codes from the first set of error codes of each the subset of subscribers, computing a Conditional Probability Distribution (CPD) for each of the one or more error codes of the Bayesian network, and determining a second set of error codes based on the CPD, the second set of error codes indicative of a cause of the failure condition.Type: GrantFiled: September 29, 2023Date of Patent: June 9, 2026Assignee: NetScout Systems, Inc.Inventors: Quenie Sun, Erdem Uysal, Steve Loker, Greg Mayo
-
Publication number: 20260142884Abstract: Systems and methods for network element clustering include identifying a plurality of network elements, each network element configured to send and receive a plurality of data packets across a communications network, assigning each network element of the plurality of network elements to a cluster of a first plurality of clusters according to a location of each network element, determining a distance between each network element assigned to a cluster and a centroid of the cluster, executing an optimization algorithm using the distances to reassign the plurality of network elements to clusters of a second plurality of clusters that reduces a cost value of the optimization algorithm, generating a matrix indicating an assignment of each network element of the plurality of network elements to a cluster of the second plurality of clusters, and routing one or more data packets received from the plurality of network elements according to the generated matrix.Type: ApplicationFiled: January 27, 2025Publication date: May 21, 2026Applicant: NetScout Systems, Inc.Inventors: Xiaolong Niu, Xiaojun Zeng, Huelpuesch Steffen
-
Patent number: 12634318Abstract: Systems and methods for network traffic monitoring are provided. A system may obtain a data packet of a data packet exchange between the server and a network device, extract a time to live (TTL) value and an internet protocol (IP) address of the network device from the data packet, compare the TTL value with a TTL value range or signature determined based on TTL values observed from data packets transmitted across a communications network, determine that the TTL value violates an authentication policy based on the TTL value being outside of the TTL value range or signature, and apply a tag to the IP address of the network device in a database stored memory.Type: GrantFiled: September 10, 2024Date of Patent: May 19, 2026Assignee: NetScout Systems, Inc.Inventors: Steinthor Bjarnason, Roman Lara, Scott Lekel-Johnson, Max Resing
-
Patent number: 12621342Abstract: A system includes instructions that cause processors to store a directed acyclic graph including nodes comprising selector nodes, mitigator nodes, and actor nodes, each of the nodes linked to another node, receive a data packet, inspect, using a selector node, a header of the data packet to determine a protection group, tag the data packet with an identification of the protection group based on the inspection, apply, using a mitigator node, criteria of a protection group policy corresponding to the protection group to the data packet based on the identification of the protection group tagged to the data packet, tag the data packet with a mitigation flag corresponding to a mitigation measure selected based on the application of the criteria of the protection group policy to the data packet, and apply, using an actor node, the mitigation measure corresponding to the mitigation tag to the data packet.Type: GrantFiled: June 12, 2024Date of Patent: May 5, 2026Assignee: NetScout Systems, Inc.Inventors: Steinthor Bjarnason, Brian St. Pierre
-
Publication number: 20260122154Abstract: The present disclosure describes a system including one or more processors to store a plurality of inspection tools in memory; detect a plurality of data packet exchanges between pairs of network devices communicating across a communications network; store metadata generated from the plurality of data packet exchanges in respective records corresponding to the different data packet exchanges; receive a data packet transmitted from a first network device to a second network device across a communications network; extract session information from a header of the data packet; responsive to determining the extracted session information matches stored session information for a communication session, tag the data packet with an indication of an active session; and process the data packet based on the tag of the data packet indicating the active session.Type: ApplicationFiled: June 4, 2025Publication date: April 30, 2026Applicant: NetScout Systems, Inc.Inventors: Steinthor Bjarnason, Brian St. Pierre, Samantha DelaOssa
-
Publication number: 20260122106Abstract: A system may include one or more memory devices storing instructions thereon that, when executed by one or more processors, cause the one or more processors to detect a transmission of a first data packet between a computing device and a server, determine a first amount of time elapsed between the transmission of the first data packet and a transmission of a second data packet, store the first amount of time in a data structure in a database, detect a transmission of a third data packet between the computing device and the server, determine a second amount of time elapsed between the transmission of the second data packet and the transmission of the third data packet, and determine that the computing device is utilizing a proxy device to communicate with the server.Type: ApplicationFiled: October 31, 2024Publication date: April 30, 2026Applicant: NetScout Systems, Inc.Inventors: Steinthor Bjarnason, Chris Conrad
-
Patent number: 12615538Abstract: A method for detecting cell positioning anomalies is disclosed. Control plane signaling data packets are collected associated with multiple cells of a communications network. Distance and azimuth values for individual communication sessions are calculated for each cell. A machine learning model is executed using various communication parameters as input to generate a classification for each cell. A list identifying which cells are experiencing anomalies is generated.Type: GrantFiled: March 22, 2023Date of Patent: April 28, 2026Assignee: NetScout Systems, Inc.Inventors: Imran Hafeez, Wing F. Lo, Jonathan Zingman
-
Publication number: 20260106878Abstract: Systems and methods for source-based misuse detection are provided. A system may store a managed objects in memory. Each of the managed objects corresponding to one or more computing devices configured to communicate over a communications network and having a configuration including one or more thresholds corresponding to network parameters for detecting an attack on the communications network. The system may monitor network traffic. The system may detect a first network parameter exceeds a threshold of a first misuse type. The system may identify a source internet protocol (IP) address associated with the first network parameter exceeding the threshold. The system may generate a tag for each source IP address indicating misuse of the communications network by the source IP address.Type: ApplicationFiled: October 16, 2024Publication date: April 16, 2026Applicant: NetScout Systems, Inc.Inventors: William Northway, Rob Skrobola, Ryan O’Reilly, Danielle Fritz, Grant Levene, Jamie Winquist
-
Publication number: 20260075072Abstract: Systems and methods for network traffic monitoring are provided. A system may obtain a data packet of a data packet exchange between the server and a network device, extract a time to live (TTL) value and an internet protocol (IP) address of the network device from the data packet, compare the TTL value with a TTL value range or signature determined based on TTL values observed from data packets transmitted across a communications network, determine that the TTL value violates an authentication policy based on the TTL value being outside of the TTL value range or signature, and apply a tag to the IP address of the network device in a database stored memory.Type: ApplicationFiled: September 10, 2024Publication date: March 12, 2026Applicant: NetScout Systems, Inc.Inventors: Steinthor Bjarnason, Roman Lara, Scott lekel-Johnson, Max Resing
-
Publication number: 20260075086Abstract: A system may detect a plurality of data packet exchanges, the plurality of data packet exchanges representing establishments of communication sessions between a server and a plurality of network devices; extract, from first information associated with the plurality of data packet exchanges, a plurality of time to live (TTL) values that correspond to the plurality of data packet exchanges; and store, responsive to extraction of the plurality of TTL values, second information that represents the plurality of TTL values in a data structure, the data structure configured to store the second information according to a Classless Inter-Domain Routing (CIDR) block that indicates a list of internet protocol (IP) addresses associated with the communications network; and responsive to a determination that a network characteristic of the monitored network traffic satisfies a condition, change operation from an observation mode to an idle mode.Type: ApplicationFiled: September 10, 2024Publication date: March 12, 2026Applicant: NetScout Systems, Inc.Inventors: Steinthor Bjarnason, Roman Lara, Scott Iekel-Johnson, Max Resing
-
Patent number: 12568397Abstract: A method is disclosed. A first data packet is received. Data is extracted from the first data packet. A first synthetic data packet is generated from data of the first data packet. A second data packet is received. Data is extracted from the second data packet. A key performance indicator is generated from data of the first and second synthetic data packets.Type: GrantFiled: February 22, 2023Date of Patent: March 3, 2026Assignee: NetScout Systems, Inc.Inventors: Sandeep Prasad, Abhishek Saraswati, John Curtin, Yu Wang, Rajeev Nadkarni, Bruce Kelley, Tauras Liubinskas
-
Patent number: 12566562Abstract: A method is disclosed. In the method, a set of data blocks can be stored. A continuous stream of data can be received. First data from the continuous stream of data can be stored in a first subset of data blocks. Second data from the continuous stream of data can be stored in a second subset of data blocks. Responsive to determining each of the set of data blocks is filled with data, data in a third subset of data blocks can be overwritten with data from the continuous stream of data.Type: GrantFiled: March 13, 2024Date of Patent: March 3, 2026Assignee: NetScout Systems, Inc.Inventors: Sapana Jogwadikar, Ruchira Naik, Sayali Jadhav, Mahesh Rajmane
-
Patent number: RE50817Abstract: A system for selective user plane (UP) monitoring includes a service gateway (SGW) having a plurality of units. The system further includes a network packet broker (NPB) configured to receive packets including UP data from tunnels created to enable transmission of the UP packets from UE to the plurality of SGW units. The NPB is also configured to receive packets including control plane (CP) data from channels enabling transmission of the CP packets from a base transceiver station to the SGW. The system also includes a plurality of probes operatively coupled to the NPB. The probes are configured to generate first metrics associated with the received CP packets and to selectively generate second metrics associated with the received UP packets based on one or more identifiers. The NPB is configured to forward UP packets being processed by a particular SGW unit to a particular probe of the plurality of probes.Type: GrantFiled: September 1, 2022Date of Patent: March 10, 2026Assignee: NetScout Systems, Inc.Inventors: Anil K. Singhal, Bruce A. Kelley, Jr., Rajeev Nadkarni, Narendra Byrapuram
-
Patent number: RE51007Abstract: A method for optimizing a radio access network includes receiving at least one area of the radio access network to be analyzed from a user and receiving a desired outcome from a user. A plurality of network monitoring parameters related to a user requested analysis is identified. The identified plurality of network monitoring parameters is correlated. A root cause analysis is performed using an automated classification model based on the correlated plurality of network monitoring parameters. A recommendation related to the desired outcome is generated based on the performed root cause analysis.Type: GrantFiled: September 19, 2022Date of Patent: August 18, 2026Assignee: NetScout Systems, Inc.Inventors: Robert William Froehlich, Ralf Kreher