Patents by Inventor Antonio Nucci

Antonio Nucci has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 7945668
    Abstract: A method for performing a network operation is disclosed. The method includes obtaining an association matrix representing association parameters between first entities and second entities of the network, generating a reduced matrix of the association matrix by aggregating the first entities into a reduced number of representative entities, partitioning a set containing the representative entities and the second entities into intermediate co-clusters based on a reduced-matrix based cohesiveness criterion, generating an expanded intermediate co-cluster from an intermediate co-cluster, partitioning the expanded intermediate co-cluster into final co-clusters based on an association-matrix based cohesiveness criterion, generating a profile of network activities based on the final co-clusters, and performing the network operation based on the profile of the network activities.
    Type: Grant
    Filed: August 21, 2009
    Date of Patent: May 17, 2011
    Assignee: Narus, Inc.
    Inventors: Antonio Nucci, Ram Keralapura
  • Patent number: 7944822
    Abstract: Embodiments of the invention provide a framework for traffic classification that bridges the gap between the packet content inspection and the flow-based behavioral analysis techniques. In particular, IP packets and/or IP flows are used as an input, network nodes are associated to specific network applications by leveraging information gathered from the web, and packet-level and/or flow-level signatures are extracted in an off-line fashion using clustering and signature extraction algorithms. The signatures learned are systematically exported to a traffic classifier that uses the newly available signatures to classify applications on-the-fly.
    Type: Grant
    Filed: July 10, 2009
    Date of Patent: May 17, 2011
    Assignee: Narus, Inc.
    Inventors: Antonio Nucci, Ram Keralapura, Joshua Robinson
  • Patent number: 7945658
    Abstract: The present invention comprises a multi-tier system. Major goals of the system are to 1) clearly visualize BGP dynamics and alert/report important deviation of BGP dynamics to avoid overwhelming the operators with too much information and 2) analyze the root cause of the problems by using a multi-tier approach, with a light-computational analysis and high-level classification for a real-time problem identification followed by a more rigorous off-line analysis for a further and more detailed trouble shooting. An example embodiment is provided that comprises four modules. The first module comprises a distributed family of collectors in charge of collecting real-time network information. The second module filters out non-relevant prefixes and extracts and profiles key features of the network information.
    Type: Grant
    Filed: December 5, 2005
    Date of Patent: May 17, 2011
    Assignee: Narus, Inc.
    Inventors: Antonio Nucci, Soon-Tee Teoh, Chen-Nee Chuah
  • Patent number: 7930424
    Abstract: The present invention relates to a method of detecting invalid border gateway protocol (BGP) route in a network, wherein network traffic is routed based at least on BGP announcements from one or more BGP routers, the method comprising obtaining a plurality of routing information objects from the BGP announcements during an observation window, each routing information object comprising at least one selected from a group consisting of an prefix-origin autonomous system (AS) association and a directed AS-link, identifying a transient routing information object having at least one selected from a group consisting of a up time less than a first pre-determined threshold or a lifespan less than a second pre-determined threshold, defining a valid routing information object set by eliminating the transient routing information object from the plurality of routing information objects, and detecting a BGP route from the BGP announcements as invalid based on the valid routing information object set.
    Type: Grant
    Filed: May 9, 2007
    Date of Patent: April 19, 2011
    Assignee: Narus, Inc.
    Inventors: Antonio Nucci, Supranamaya Ranjan, Lixin Gao, Jian Qiu
  • Patent number: 7823202
    Abstract: The invention relates to a method for generating a prefix hijacking alert in a network, wherein a plurality of network traffic flows are routed based at least on a plurality of prefix announcements from one or more Border Gateway Protocol (BGP) router, the method comprises identifying an anomalous prefix from the plurality of prefix announcements, identifying a network traffic anomaly from the plurality of network traffic flows, and correlating the anomalous prefix and the network traffic anomaly to generate the prefix hijacking alert.
    Type: Grant
    Filed: March 21, 2007
    Date of Patent: October 26, 2010
    Assignee: Narus, Inc.
    Inventors: Antonio Nucci, Supranamaya Ranjan, Lixin Gao, Jian Qiu
  • Patent number: 7768927
    Abstract: The present invention comprises methods for increasing the rank of the routing matrix of an IP network by systematically altering link weights in the IP network. A full rank routing matrix may be used with further methods in accordance with the present invention to estimate the mean traffic of the IP network based upon the full rank routing matrix and measured link utilization values. The mean traffic and the covariance of the traffic may be iteratively estimated until the estimates coverage. Example methods in accordance with the present invention for estimating mean traffic and covariance of traffic are described for both stationary and non-stationary link utilization data.
    Type: Grant
    Filed: October 30, 2007
    Date of Patent: August 3, 2010
    Assignee: Sprint Communications Company L.P.
    Inventors: Antonio Nucci, Nina Taft
  • Patent number: 7756043
    Abstract: The present invention provides methods for identifying high traffic origin-destination node pairs in a packet based network and for estimating the mean traffic between the high traffic origin-destination node pairs. High traffic origin-destination node pairs may be identified in accordance with the present invention by modeling the variance of traffic in a static routing environment and identifying the origin-destination node pairs with a high variance as high traffic origin-destination node pairs. For estimating purposes, traffic between low traffic origin-destination node pairs may be assumed to be a predetermined value, such as zero, to reduce the number of variables to estimate. Routing changes necessary to create a full rank routing matrix may be identified and applied to the network, and link utilization information collected under each routing scenario may be used to estimate the mean traffic between the high traffic origin-destination node pairs.
    Type: Grant
    Filed: June 9, 2004
    Date of Patent: July 13, 2010
    Assignee: Sprint Communications Company L.P.
    Inventors: Antonio Nucci, Augustin Soule
  • Patent number: 7729269
    Abstract: The present invention provides methods for identifying high traffic origin-destination node pairs in a packet based network and for estimating the mean traffic between the high traffic origin-destination node pairs. High traffic origin-destination node pairs may be identified in accordance with the present invention by modeling the variance of traffic in a static routing environment and identifying the origin-destination node pairs with a high variance as high traffic origin-destination node pairs. For estimating purposes, traffic between low traffic origin-destination node pairs may be assumed to be a predetermined value, such as zero, to reduce the number of variables to estimate. Routing changes necessary to create a full rank routing matrix may be identified and applied to the network, and link utilization information collected under each routing scenario may be used to estimate the mean traffic between the high traffic origin-destination node pairs.
    Type: Grant
    Filed: June 9, 2004
    Date of Patent: June 1, 2010
    Assignee: Sprint Communications Company L.P.
    Inventors: Antonio Nucci, Augustin Soule
  • Patent number: 7712134
    Abstract: A method and an apparatus is provided that is efficient in detecting network virus and worms while using only the layer-4 information that is easily extracted from core routers and also be scalable when layer-7 information is available. Entropy analysis is used to identify anomalous activity at the flow level. Thereafter, only the contents of suspicious flows are analyzed with fingerprinting extraction. By doing so, the present invention brings together the characteristics of being deployable for real-time high data to rate links and the efficiency and reliability of content fingerprinting techniques.
    Type: Grant
    Filed: January 6, 2006
    Date of Patent: May 4, 2010
    Assignee: Narus, Inc.
    Inventors: Antonio Nucci, Supranamaya Ranjan
  • Patent number: 7684320
    Abstract: A method is provided to classify network traffic flows in real-time using spectral analysis techniques to extract regularities inside the network traffic flows. In one embodiment of the invention, subspace decomposition on power spectral density feature vectors and minimum coding length criterion are utilized for training traffic flows of different classifications. Experimental results are shown to demonstrate the effectiveness and robustness of the invention.
    Type: Grant
    Filed: December 22, 2006
    Date of Patent: March 23, 2010
    Assignee: Narus, Inc.
    Inventor: Antonio Nucci
  • Patent number: 7649853
    Abstract: A method is provided for identifying an event of network activity associated with a network where the network includes a plurality of interfaces and the method includes providing a first data structure comprising a node, partitioning the plurality of interfaces into a plurality of groups, associating the plurality of groups with the node, providing a vector corresponding to a group of the plurality of groups for representing a summary of the network activity, and identifying an event of network activity according to the vector. Experimental results are shown to demonstrate the effectiveness and robustness of the invention.
    Type: Grant
    Filed: January 22, 2007
    Date of Patent: January 19, 2010
    Assignee: Narus, Inc.
    Inventors: Antonio Nucci, Yihua Wu
  • Patent number: 7644150
    Abstract: The present invention relates to a method of managing a network. The method steps includes extracting a signature from a first traffic flow of a plurality of traffic flows on the network based on layer-3/layer-4 information of the first traffic flow, storing the signature and an identification of a layer-7 application associated with the signature in a signature repository, identifying a second traffic flow of the plurality of traffic flows being associated with the layer-7 application by correlating the second traffic flow to the signature, and managing the network based on layer-7 application identification of the plurality of traffic flows.
    Type: Grant
    Filed: August 22, 2007
    Date of Patent: January 5, 2010
    Assignee: Narus, Inc.
    Inventors: Antonio Nucci, Ram Keralapura
  • Patent number: 7644180
    Abstract: The present invention comprises methods for increasing the rank of the routing matrix of an IP network by systematically altering link weights in the IP network. A full rank routing matrix may be used with further methods in accordance with the present invention to estimate the mean traffic of the IP network based upon the full rank routing matrix and measured link utilization values. The mean traffic and the covariance of the traffic may be iteratively estimated until the estimates coverage. Example methods in accordance with the present invention for estimating mean traffic and covariance of traffic are described for both stationary and non-stationary link utilization data.
    Type: Grant
    Filed: October 30, 2007
    Date of Patent: January 5, 2010
    Assignee: Sprint Communications Company L.P.
    Inventors: Antonio Nucci, Nina Taft
  • Patent number: 7584507
    Abstract: The present invention efficiently detects various DDoS attacks for large scale Internet with the temporal correlation of traffic flows on the two directions of a single link, the spatial correlation of DDoS attack traffic at different locations and powerful machine learning algorithms. With these techniques, the present invention effectively detects and identifies attack sources without modifying existing IP forwarding mechanisms and without a global upgrade to Internet backbone routers. More importantly, the present invention can detect synchronized DDoS attacks even if the volume of attack traffic is extremely small at the location that is close to the attack source.
    Type: Grant
    Filed: July 29, 2005
    Date of Patent: September 1, 2009
    Assignee: Narus, Inc.
    Inventor: Antonio Nucci
  • Patent number: 7558290
    Abstract: An important component of network monitoring is to collect traffic data which is a bottleneck due to large data size. We introduce a new table compression method called “Group Compression” to address this problem. This method uses a small training set to learn the relationship among columns and group them; the result is a “compression plan”. Based on this plan, each group is compressed separately. This method can reduce the compressed size to 60%-70% of the IP flow logs compressed by GZIP.
    Type: Grant
    Filed: December 16, 2005
    Date of Patent: July 7, 2009
    Assignee: Narus, Inc.
    Inventors: Antonio Nucci, Su Chen
  • Patent number: 7453824
    Abstract: A method and system for identifying optimal mapping of logical links to the physical topology of a network is provided. Upon obtaining one or more mapping options for mapping multiple logical links between two or more pairs of network nodes onto physical paths that are as at least relatively disjoint and a priority order of the network node pairs, the mapping options are correlated with the priority order of the network nodes to identify optimal mapping of logical links to the physical topology of a network.
    Type: Grant
    Filed: July 10, 2003
    Date of Patent: November 18, 2008
    Assignee: Sprint Communications Company L.P.
    Inventors: Antonio Nucci, Nina A. Taft, Christophe Diot, Frederic Giroire
  • Patent number: 7441429
    Abstract: With the widespread adoption of SIP-based VoIP, understanding the characteristics of SIP traffic behavior is critical to problem diagnosis and security protection of VoIP services. A general methodology is provided for profiling SIP-based VoIP traffic behavior at several levels: SIP server host, server entity (e.g., registrar and call proxy) and individual user levels. Using SIP traffic traces captured in a production VoIP network, the characteristics of SIP-based VoIP traffic behavior in an operational environment is illustrated and the effectiveness of the general profiling methodology is demonstrated. In particular, the profiling methodology identifies anomalies due to performance problems and/or implementation flaws through a case study. The efficacy of the methodology in detecting potential VoIP attacks is also demonstrated through a test bed experimentation.
    Type: Grant
    Filed: September 28, 2006
    Date of Patent: October 28, 2008
    Assignee: Narus, inc.
    Inventors: Antonio Nucci, Supranamaya Ranjan, Zhi-Li Zhang
  • Patent number: 7395351
    Abstract: The present invention includes a method and system for determining link weights that when utilized will optimize the performance of a network in the event of a link failure without the need to alter the link weights. The method includes determining two sets of links, one that includes links with a significant amount of loading and one that includes links with a modest amount of loading. A set of permissible solutions is generated utilizing one randomly chosen link from each set. After omitting recent best permissible solutions, the remaining permissible solutions are evaluated by analyzing for the complete network topology and for the topologies corresponding to all single-link failure states and the best permissible solution is found. If the best permissible solution is better than the current optimal solution, then the best permissible solution is made the optimal solution. These steps are repeated until a predetermined number of iterations have been evaluated without a change in the optimal solution.
    Type: Grant
    Filed: January 28, 2003
    Date of Patent: July 1, 2008
    Assignee: Sprint Spectrum L.P.
    Inventors: Antonio Nucci, Bianca Schroeder, Supratik Bhattacharyya, Nina Taft, Christophe Diot
  • Patent number: 7394760
    Abstract: A system and method for identifying optimal mapping of logical links to the physical topology of a network is provided. Upon obtaining one or more mapping options for mapping multiple logical links between one or more pairs of network nodes onto physical paths that are at least relatively disjoint and obtaining a maximum time delay allowed between the each pair of network nodes, the mapping options are correlated with the maximum time delay to identify optimal mapping of logical links to the physical topology of a network.
    Type: Grant
    Filed: July 9, 2003
    Date of Patent: July 1, 2008
    Assignee: Sprint Communications Company L.P.
    Inventors: Antonio Nucci, Nina A. Taft, Christophe Diot, Frederic Giroire
  • Patent number: 7363386
    Abstract: The present invention comprises methods for increasing the rank of the routing matrix of an IP network by systematically altering link weights in the IP network. A full rank routing matrix may be used with further methods in accordance with the present invention to estimate the mean traffic of the IP network based upon the full rank routing matrix and measured link utilization values. The mean traffic and the covariance of the traffic may be iteratively estimated until the estimates coverage. Example methods in accordance with the present invention for estimating mean traffic and covariance of traffic are described for both stationary and non-stationary link utilization data.
    Type: Grant
    Filed: November 6, 2003
    Date of Patent: April 22, 2008
    Assignee: Sprint Communications Company L.P.
    Inventors: Antonio Nucci, Nina Taft