Patents by Inventor Steinthor Bjarnason
Steinthor Bjarnason has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Patent number: 12634318Abstract: Systems and methods for network traffic monitoring are provided. A system may obtain a data packet of a data packet exchange between the server and a network device, extract a time to live (TTL) value and an internet protocol (IP) address of the network device from the data packet, compare the TTL value with a TTL value range or signature determined based on TTL values observed from data packets transmitted across a communications network, determine that the TTL value violates an authentication policy based on the TTL value being outside of the TTL value range or signature, and apply a tag to the IP address of the network device in a database stored memory.Type: GrantFiled: September 10, 2024Date of Patent: May 19, 2026Assignee: NetScout Systems, Inc.Inventors: Steinthor Bjarnason, Roman Lara, Scott Lekel-Johnson, Max Resing
-
Patent number: 12621342Abstract: A system includes instructions that cause processors to store a directed acyclic graph including nodes comprising selector nodes, mitigator nodes, and actor nodes, each of the nodes linked to another node, receive a data packet, inspect, using a selector node, a header of the data packet to determine a protection group, tag the data packet with an identification of the protection group based on the inspection, apply, using a mitigator node, criteria of a protection group policy corresponding to the protection group to the data packet based on the identification of the protection group tagged to the data packet, tag the data packet with a mitigation flag corresponding to a mitigation measure selected based on the application of the criteria of the protection group policy to the data packet, and apply, using an actor node, the mitigation measure corresponding to the mitigation tag to the data packet.Type: GrantFiled: June 12, 2024Date of Patent: May 5, 2026Assignee: NetScout Systems, Inc.Inventors: Steinthor Bjarnason, Brian St. Pierre
-
Publication number: 20260122154Abstract: The present disclosure describes a system including one or more processors to store a plurality of inspection tools in memory; detect a plurality of data packet exchanges between pairs of network devices communicating across a communications network; store metadata generated from the plurality of data packet exchanges in respective records corresponding to the different data packet exchanges; receive a data packet transmitted from a first network device to a second network device across a communications network; extract session information from a header of the data packet; responsive to determining the extracted session information matches stored session information for a communication session, tag the data packet with an indication of an active session; and process the data packet based on the tag of the data packet indicating the active session.Type: ApplicationFiled: June 4, 2025Publication date: April 30, 2026Applicant: NetScout Systems, Inc.Inventors: Steinthor Bjarnason, Brian St. Pierre, Samantha DelaOssa
-
Publication number: 20260122106Abstract: A system may include one or more memory devices storing instructions thereon that, when executed by one or more processors, cause the one or more processors to detect a transmission of a first data packet between a computing device and a server, determine a first amount of time elapsed between the transmission of the first data packet and a transmission of a second data packet, store the first amount of time in a data structure in a database, detect a transmission of a third data packet between the computing device and the server, determine a second amount of time elapsed between the transmission of the second data packet and the transmission of the third data packet, and determine that the computing device is utilizing a proxy device to communicate with the server.Type: ApplicationFiled: October 31, 2024Publication date: April 30, 2026Applicant: NetScout Systems, Inc.Inventors: Steinthor Bjarnason, Chris Conrad
-
Publication number: 20260075072Abstract: Systems and methods for network traffic monitoring are provided. A system may obtain a data packet of a data packet exchange between the server and a network device, extract a time to live (TTL) value and an internet protocol (IP) address of the network device from the data packet, compare the TTL value with a TTL value range or signature determined based on TTL values observed from data packets transmitted across a communications network, determine that the TTL value violates an authentication policy based on the TTL value being outside of the TTL value range or signature, and apply a tag to the IP address of the network device in a database stored memory.Type: ApplicationFiled: September 10, 2024Publication date: March 12, 2026Applicant: NetScout Systems, Inc.Inventors: Steinthor Bjarnason, Roman Lara, Scott lekel-Johnson, Max Resing
-
Publication number: 20260075086Abstract: A system may detect a plurality of data packet exchanges, the plurality of data packet exchanges representing establishments of communication sessions between a server and a plurality of network devices; extract, from first information associated with the plurality of data packet exchanges, a plurality of time to live (TTL) values that correspond to the plurality of data packet exchanges; and store, responsive to extraction of the plurality of TTL values, second information that represents the plurality of TTL values in a data structure, the data structure configured to store the second information according to a Classless Inter-Domain Routing (CIDR) block that indicates a list of internet protocol (IP) addresses associated with the communications network; and responsive to a determination that a network characteristic of the monitored network traffic satisfies a condition, change operation from an observation mode to an idle mode.Type: ApplicationFiled: September 10, 2024Publication date: March 12, 2026Applicant: NetScout Systems, Inc.Inventors: Steinthor Bjarnason, Roman Lara, Scott Iekel-Johnson, Max Resing
-
Patent number: 12563091Abstract: A computer method and system for determining patterns in network traffic packets having structured subfields for generating filter candidate regular expressions for DDoS attack mitigation. Stored packets are analyzed to extract a query name for each stored packet. Each query name is segregated into subfields. A Results-table is generated utilizing the segregated subfields of the query names. A Field-length table is generated that contains the length of the Field Values (Field-length) for each Field Name and an associated counter indicating how many instances the Field-length for a Field Name is present in the extracted query names. The Field-length table is analyzed to determine patterns of equal length in the “Results” table. Utilizing the Patterns table, unique combinations of the Field Values are generated as a filter candidate regular expression for DDoS attack mitigation purposes.Type: GrantFiled: April 10, 2024Date of Patent: February 24, 2026Assignee: Arbor Networks, Inc.Inventor: Steinthor Bjarnason
-
Patent number: 12549529Abstract: Systems and methods for transparent service response analysis is provided. A system may obtain a network data packet from a network service provider. The system may determine the network data packet includes a response code indicating a status of the request. The system may extract the response code from the network data packet. The system may modify an IP header of the network data packet based on the response code. The system may encapsulate the network data packet based on the response code. The system may send the network data packet with the modified IP header. The system may send the encapsulated network data packet.Type: GrantFiled: September 13, 2023Date of Patent: February 10, 2026Assignee: NetScout Systems, Inc.Inventor: Steinthor Bjarnason
-
Patent number: 12526216Abstract: A method for network anomaly detection and policy-based network state restoration includes collecting a first set of metrics associated with a network at a first time indicating a first state of the network and storing the first set of metrics in association with the first state in a memory at the first time. A second set of metrics associated with the network is collected at a second time indicating a second state of the network. An indication of an anomaly on the network is determined based on a comparison of the second set of metrics with the first set of metrics. A network policy is applied to revert the network from the second state to the first state by restoring configuration parameters and operational settings of the network to match the stored first set of metrics exactly as recorded at the first time in response to determining the indication of the anomaly. The network may be monitored in response to applying the network policy and action may be taken based on the monitoring.Type: GrantFiled: May 31, 2024Date of Patent: January 13, 2026Assignee: NetScout Systems, Inc.Inventors: Steinthor Bjarnason, Roland Dobbins
-
Patent number: 12513187Abstract: A network monitoring device is connected to a communications network and monitors traffic transmitted to and from a server. The system stores a device fingerprint of devices identified as involved in attacks across the communications network, generates attack patterns for attacks across the communications network based on data packets transmitted or received by the devices during an attack based on the data packets corresponding to the device fingerprint, monitors data packet exchanges between the server and network devices, determines a set of transmission parameters for each of the data packet exchanges, compares the set of transmission parameters for the plurality of data packet exchanges to the attack patterns, and, responsive to determining a match between a first set of transmission parameters and an attack pattern, applies a tag to a network device communicating with the server via the data packet exchange indicating the network device is involved in an attack.Type: GrantFiled: May 22, 2024Date of Patent: December 30, 2025Assignee: NetScout Systems, Inc.Inventors: Steinthor Bjarnason, Brian St. Pierre, Filippo Vitale
-
Patent number: 12513194Abstract: Systems and methods for service response analysis via out-of-band signaling is provided. A system may obtain, via a first network channel, a network data packet from a network service provider. The system may determine the network data packet comprises a response code indicating a status of the request. The system may extract the response code from the network data packet. The system may generate an out-of-band response message comprising the response code. The system may send, to an external device via a second network channel, the out-of-band response message comprising the response code.Type: GrantFiled: September 13, 2023Date of Patent: December 30, 2025Assignee: NetScout Systems, Inc.Inventor: Steinthor Bjarnason
-
Publication number: 20250385936Abstract: A system includes instructions that cause processors to store a directed acyclic graph including nodes comprising selector nodes, mitigator nodes, and actor nodes, each of the nodes linked to another node, receive a data packet, inspect, using a selector node, a header of the data packet to determine a protection group, tag the data packet with an identification of the protection group based on the inspection, apply, using a mitigator node, criteria of a protection group policy corresponding to the protection group to the data packet based on the identification of the protection group tagged to the data packet, tag the data packet with a mitigation flag corresponding to a mitigation measure selected based on the application of the criteria of the protection group policy to the data packet, and apply, using an actor node, the mitigation measure corresponding to the mitigation tag to the data packet.Type: ApplicationFiled: June 12, 2024Publication date: December 18, 2025Applicant: NetScout Systems, Inc.Inventors: Steinthor Bjarnason, Brian St. Pierre
-
Publication number: 20250365310Abstract: A network monitoring device is connected to a communications network and monitors traffic transmitted to and from a server. The system stores a device fingerprint of devices identified as involved in attacks across the communications network, generates attack patterns for attacks across the communications network based on data packets transmitted or received by the devices during an attack based on the data packets corresponding to the device fingerprint, monitors data packet exchanges between the server and network devices, determines a set of transmission parameters for each of the data packet exchanges, compares the set of transmission parameters for the plurality of data packet exchanges to the attack patterns, and, responsive to determining a match between a first set of transmission parameters and an attack pattern, applies a tag to a network device communicating with the server via the data packet exchange indicating the network device is involved in an attack.Type: ApplicationFiled: May 22, 2024Publication date: November 27, 2025Applicant: NetScout Systems, Inc.Inventors: Steinthor Bjarnason, Brian St. Pierre, Filippo Vitale
-
Patent number: 12452278Abstract: Systems and methods for network traffic monitoring are provided. A system may monitor a first plurality of encrypted data packet exchanges between a server and a plurality of network devices, determine one or more metric baselines corresponding to a plurality of metric types for communication between the server and the plurality of network devices, monitor a second plurality of encrypted data packet exchanges between the server and a second plurality of network devices, identify a set of encrypted data packet exchanges from the second plurality of encrypted data packet exchanges each having a duration exceeding a first threshold, determine an exchange metric for each of the plurality of metric types, identify one or more encrypted data packet exchanges having at least one exchange metric exceeding a metric baseline, and apply a tag to one or more network devices of the second plurality of network devices.Type: GrantFiled: April 3, 2024Date of Patent: October 21, 2025Assignee: NetScout Systems, Inc.Inventors: Steinthor Bjarnason, Brian St. Pierre
-
Patent number: 12452300Abstract: A system is disclosed. The system can include a network monitoring device connected to a communications network. The network monitoring device to store a probabilistic data structure indicating one or more domain names; receive a response data packet from the DNS server, the response data packet comprising a first domain name transmitted in a query to the DNS server and an affirmative response code; update the probabilistic data structure with the first domain name identified from the response data packet; responsive to detecting an attack on the network, retrieve a query message, the query message containing a second domain name; query the updated probabilistic data structure with the second domain name; and restrict transmission of the query message or communication by the computing device with the DNS server.Type: GrantFiled: September 11, 2023Date of Patent: October 21, 2025Assignee: NetScout Systems, Inc.Inventors: Brian St. Pierre, Steinthor Bjarnason
-
Publication number: 20250317454Abstract: Systems and methods for network traffic monitoring are provided. A system may monitor a first plurality of encrypted data packet exchanges between a server and a plurality of network devices, determine one or more metric baselines corresponding to a plurality of metric types for communication between the server and the plurality of network devices, monitor a second plurality of encrypted data packet exchanges between the server and a second plurality of network devices, identify a set of encrypted data packet exchanges from the second plurality of encrypted data packet exchanges each having a duration exceeding a first threshold, determine an exchange metric for each of the plurality of metric types, identify one or more encrypted data packet exchanges having at least one exchange metric exceeding a metric baseline, and apply a tag to one or more network devices of the second plurality of network devices.Type: ApplicationFiled: April 3, 2024Publication date: October 9, 2025Applicant: NetScout Systems, Inc.Inventors: Steinthor Bjarnason, Brian St. Pierre
-
Publication number: 20250240321Abstract: A network monitoring device can include one or more memory devices that can store executable instructions thereon that, when executed by one or more processors, cause the one or more processors to monitor network traffic transmitted across a communications network, detect at least one first data packet corresponding to a request to establish a communication session, ingest first information associated with the at least one first data packet into a probabilistic data structure, identify at least one second data packet corresponding to a response, determine that the response does not correspond to either (i) the request or (ii) a plurality of requests, and drop the at least one second data packet from the communications network.Type: ApplicationFiled: April 10, 2025Publication date: July 24, 2025Applicant: NetScout Systems, Inc.Inventors: Brian St. Pierre, Steinthor Bjarnason
-
Patent number: 12341810Abstract: A computer implemented method system for obscuring the status of a network service provided by a network device. Received in a network monitoring device is network packet request message intended for a network device. The network monitoring device analyzes the received network packets request to determine whether the received network packet request is a DDoS network probe packet request. If the received packet request was determined to be a DDoS network probe packet requests, a response is generated and sent from the network monitoring device to the device that sent the DDoS network probe packet request indicating a faux degradation of service level for the intended network device.Type: GrantFiled: November 22, 2022Date of Patent: June 24, 2025Assignee: ARBOR NETWORKS, INC.Inventors: Steinthor Bjarnason, Sean O'Hara
-
Publication number: 20250088531Abstract: A system is disclosed. The system can include a network monitoring device connected to a communications network. The network monitoring device to store a probabilistic data structure indicating one or more domain names; receive a response data packet from the DNS server, the response data packet comprising a first domain name transmitted in a query to the DNS server and an affirmative response code; update the probabilistic data structure with the first domain name identified from the response data packet; responsive to detecting an attack on the network, retrieve a query message, the query message containing a second domain name; query the updated probabilistic data structure with the second domain name; and restrict transmission of the query message or communication by the computing device with the DNS server.Type: ApplicationFiled: September 11, 2023Publication date: March 13, 2025Applicant: NetScout Systems, Inc.Inventors: Brian St. Pierre, Steinthor Bjarnason
-
Patent number: RE50354Abstract: A method of detecting patterns in network traffic is provided. The method includes receiving packets of network traffic, performing a frequency analysis per field of the packets as a function of frequency of the occurrence of the same data in the corresponding field, and selecting top values which are values associated with each field of the set of fields that satisfy a criterion as having occurred most frequently in the packets as a function of a result of the frequency analysis.Type: GrantFiled: August 24, 2023Date of Patent: March 25, 2025Assignee: Arbor Networks, Inc.Inventors: Steinthor Bjarnason, Andrew Ralph Beard, David Turnbull