Patents by Inventor Takeaki Nishioka

Takeaki Nishioka has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Publication number: 20240129218
    Abstract: A conversion device (10) analyzes an input packet and acquires header information included in the packet. Furthermore, the conversion device (10) classifies packets into one of a plurality of groups on the basis of the acquired header information and set grouping conditions. Subsequently, the conversion device (10) generates packets for analysis on the basis of the processing corresponding to the classified groups.
    Type: Application
    Filed: February 16, 2021
    Publication date: April 18, 2024
    Inventors: Takeaki NISHIOKA, Chiharu MORIOKA, Shohei KAMAMURA, Yuhei HAYASHI, Yuki MIYOSHI
  • Publication number: 20240129221
    Abstract: A conversion device analyzes information of an input packet using hardware and determines whether to perform predetermined previous stage processing using the hardware. Furthermore, when it is determined to perform the previous stage processing, the conversion device uses the hardware to provide metadata including identification information indicating a group of packets to the packets on the basis of the fixed-length header information of the packets. In addition, the conversion device uses software to generate analysis packets corresponding to the group of packets using the provided metadata.
    Type: Application
    Filed: February 16, 2021
    Publication date: April 18, 2024
    Inventors: Yuki MIYOSHI, Yuhei HAYASHI, Chiharu MORIOKA, Takeaki NISHIOKA, Shohei KAMAMURA
  • Publication number: 20240121193
    Abstract: An extraction unit extracts predetermined information from an outer header and an inner header of a tunneled packet passing through a network device in which congestion has occurred. An evaluation unit evaluates an order in which fine grain flows in a tunnel subdivided with reference to the extracted predetermined information are subject to TE, based on attribute information of the fine grain flows.
    Type: Application
    Filed: February 2, 2021
    Publication date: April 11, 2024
    Inventors: Yuhei HAYASHI, Shohei KAMAMURA, Satoshi NAKATSUKASA, Yuki TAKEI, Chiharu MORIOKA, Takeaki NISHIOKA, Yuki MIYOSHI
  • Publication number: 20240121190
    Abstract: A design apparatus optimizes, with a first granularity (for example, a real number solution), a traffic volume allocated to each of links between adjacent nodes included in a network. In addition, the design apparatus calculates an approximation solution obtained by approximating, with a second granularity (for example, an integer solution), the traffic volume having been optimized with the first granularity. Furthermore, the design apparatus maps logical paths to each of routes constituted by the links in accordance with the approximated traffic volume.
    Type: Application
    Filed: February 12, 2021
    Publication date: April 11, 2024
    Inventors: Shohei KAMAMURA, Yuhei HAYASHI, Yuki MIYOSHI, Takeaki NISHIOKA, Chiharu MORIOKA, Satoshi NAKATSUKASA, Yuki TAKEI
  • Patent number: 11902310
    Abstract: A feature calculation unit calculates a feature of header information of a packet. A classification unit classifies the packet as a normal packet or an abnormal packet by using the calculated feature. An adding unit adds a label indicating a tool name of a known attack tool to header information of a packet attacked using the attack tool. A learning unit learns the addition of the label by using the label and the feature calculated for the packet to which the label has been added as teacher data.
    Type: Grant
    Filed: February 4, 2020
    Date of Patent: February 13, 2024
    Assignee: Nippon Telegraph and Telephone Corporation
    Inventors: Yuhei Hayashi, Ichiro Kudo, Hiroshi Osawa, Takeaki Nishioka
  • Patent number: 11863416
    Abstract: A detection device includes: a statistic unit that acquires statistical value data on 5-tuple flows in a certain time period; a degree centrality calculation unit that calculates a degree centrality of a node including an indegree, which is a total sum of a weight of each edge flowing into the node, and an outdegree, which is a total sum of a weight of each edge flowing out of the node, based on the statistical value data on the 5-tuple flows in the certain time period; and a degree centrality impartation unit that imparts the degree centrality, as a feature, to the statistical value data on the 5-tuple flows in the certain time period.
    Type: Grant
    Filed: February 27, 2020
    Date of Patent: January 2, 2024
    Assignee: Nippon Telegraph and Telephone Corporation
    Inventors: Yuhei Hayashi, Hiroshi Osawa, Takeaki Nishioka, Hiroki Inoue
  • Patent number: 11824767
    Abstract: A continuity checking apparatus generates a continuity checking packet to which a predetermined flag and user attributes are assigned and transmits the generated continuity checking packet to an edge router connected to a service that is an entrance of a service chain. Each service transmits an arrival message with respect to the continuity checking packet to the continuity checking apparatus upon reception of the continuity checking packet to which the predetermined flag is assigned. In addition, each service transfers the continuity checking packet to a next service device of the service chain on the basis of the user attributes assigned to the received continuity checking packet. The continuity checking apparatus identifies a path representing service devices through which the continuity checking packet passes on the basis of the arrival message transmitted from each service, and determines whether the identified path is the same as a path of the service chain that is a continuity checking target.
    Type: Grant
    Filed: January 23, 2020
    Date of Patent: November 21, 2023
    Assignee: Nippon Telegraph and Telephone Corporation
    Inventors: Yuki Miyoshi, Ichiro Kudo, Hiroshi Osawa, Hiroshi Suzuki, Takeaki Nishioka, Yuhei Hayashi
  • Patent number: 11729103
    Abstract: The controller (10) acquires information about the band of the flow within the tunnel and the band of each flow after policing or shaping, calculates the ratio of the traffic volume after policing or shaping to the traffic volume before policing or shaping by using the acquired information about the band, and estimates the traffic volume of the flow to be monitored within the tunnel by using the calculated ratio and the band of each flow after policing or shaping.
    Type: Grant
    Filed: August 16, 2019
    Date of Patent: August 15, 2023
    Assignee: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
    Inventors: Hiroshi Suzuki, Yuhei Hayashi, Yuki Miyoshi, Takeaki Nishioka, Hiroshi Osawa, Ichiro Kudo
  • Publication number: 20230254234
    Abstract: A detection device (10) includes: a statistic unit (131) that acquires statistical value data on 5-tuple flows in a certain time period; a degree centrality calculation unit (132) that calculates a degree centrality of a node including an indegree, which is a total sum of a weight of each edge flowing into the node, and an outdegree, which is a total sum of a weight of each edge flowing out of the node, based on the statistical value data on the 5-tuple flows in the certain time period; and a degree centrality impartation unit (133) that imparts the degree centrality, as a feature, to the statistical value data on the 5-tuple flows in the certain time period.
    Type: Application
    Filed: February 27, 2020
    Publication date: August 10, 2023
    Inventors: Yuhei HAYASHI, Hiroshi OSAWA, Takeaki NISHIOKA, Hiroki INOUE
  • Publication number: 20230038630
    Abstract: A conversion device (10) includes a separation unit (11) that separates an inputted encapsulated packet into flow information and sampled headers including outer headers and inner headers, a decapsulation unit (12) that separates the outer headers from the sampled headers, and a conversion unit (13) that obtains statistics about the inner headers on the basis of the sampled headers separated from the outer headers, generates an xFlow packet including at least statistical information indicating the statistics about the inner headers, and outputs the generated xFlow packet to an external device.
    Type: Application
    Filed: January 24, 2020
    Publication date: February 9, 2023
    Inventors: Yuki MIYOSHI, Hiroshi OSAWA, Yuhei HAYASHI, Chiharu MORIOKA, Hiroki INOUE, Takeaki NISHIOKA
  • Patent number: 11570206
    Abstract: A handling apparatus (14a) handles a server attack taking place on a network (1Na) or handles a server attack as requested by a security system provided on another network. In accordance with a determination that it is not possible to handle the server attack by the handling apparatus (14a), the control determination apparatus (12a) makes a request to another security system (1Sb) capable of handling the server attack to handle the server attack. A centralized control apparatus (11) determines whether the server attack taking place on the network (1Na) can be handled on another network.
    Type: Grant
    Filed: February 4, 2019
    Date of Patent: January 31, 2023
    Assignee: Nippon Telegraph and Telephone Corporation
    Inventors: Hiroshi Suzuki, Yuhei Hayashi, Takeaki Nishioka, Katsuhiko Sakai, Ichiro Kudo
  • Patent number: 11570067
    Abstract: A collection device (10) collects traffic from a core network (10N) connected to a plurality of operator networks (20N). Further, an analysis device has a plurality of functions of analyzing traffic. Further, a setting device sets a scenario that designates at least one of the plurality of functions. Further, a pre-processing device converts the traffic collected by the collection device (10) to traffic of a format suitable for the function designated by the scenario. Further, a distribution device distributes the traffic converted by the pre-processing device to a designated function.
    Type: Grant
    Filed: August 13, 2019
    Date of Patent: January 31, 2023
    Assignee: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
    Inventors: Ichiro Kudo, Hiroyuki Onishi, Hiroshi Osawa, Hiroshi Suzuki, Takeaki Nishioka, Yuki Miyoshi, Yuhei Hayashi
  • Publication number: 20220407794
    Abstract: When receiving packets of a flow from a network device (1), a transmission control device (10) determines, according to processing abilities of flow collectors (20), rates in transmitting information concerning the flow to the collectors 20. The transmission control device (10) selects, based on header information of the received packets, the flow collector (20) to be a transmission destination of the information concerning the flow of the packets. The transmission control device (10) transmits the information concerning the flow at the rate determined for each of the flow collectors (20).
    Type: Application
    Filed: October 30, 2019
    Publication date: December 22, 2022
    Inventors: Hiroshi OSAWA, Yuhei HAYASHI, Chiharu MORIOKA, Hiroki INOUE, Takeaki NISHIOKA, Yuki MIYOSHI
  • Publication number: 20220400079
    Abstract: The sorting unit (10) has a sorting function unit (13) that acquires a frame and a sorting key, embeds the sorting key in a header of the frame, and sorts the frame into a processing thread based on the value of the sorting key in the header.
    Type: Application
    Filed: November 13, 2019
    Publication date: December 15, 2022
    Inventors: Yuhei HAYASHI, Hiroshi OSAWA, Chiharu MORIOKA, Hiroki INOUE, Takeaki NISHIOKA, Yuki MIYOSHI
  • Publication number: 20220182361
    Abstract: A registration device (10) includes an extracting unit (131) that extracts inner header information and outer header information of an encapsulated packet, a filter unit (132) that calculates a hash value of the inner header information and the outer header information as an address of a hash table in which arrival information indicating whether a first packet of a series of flow has arrived is registered for each address and causes, based on the hash table, inner header information and outer header information of the first packet of the series of flow to pass, and a registering unit (133) that registers the inner header information and the outer header information of the first packet, which the filter unit (132) has caused to pass, in a database in association with each other.
    Type: Application
    Filed: March 26, 2020
    Publication date: June 9, 2022
    Inventors: Yuhei HAYASHI, Hiroshi SUZUKI, Ichiro KUDO, Hiroshi OSAWA, Yuki MIYOSHI, Takeaki NISHIOKA
  • Publication number: 20220131722
    Abstract: when packets are received via any one of the plurality of inflow VRFs provided for respective route patterns, a chaining edge router (10) redirects the packets to a chain VRF corresponding to the inflow VRF. The chaining edge router (10) transfers the packets redirected to the chain VRF to respective functions via a communication path constructed using a VLAN in advance according to a route pattern corresponding to the chain VRF.
    Type: Application
    Filed: January 22, 2020
    Publication date: April 28, 2022
    Inventors: Takeaki NISHIOKA, Hiroshi OSAWA, Satomi Inoue
  • Publication number: 20220131789
    Abstract: A continuity checking apparatus generates a continuity checking packet to which a predetermined flag and user attributes are assigned and transmits the generated continuity checking packet to an edge router connected to a service that is an entrance of a service chain. Each service transmits an arrival message with respect to the continuity checking packet to the continuity checking apparatus upon reception of the continuity checking packet to which the predetermined flag is assigned. In addition, each service transfers the continuity checking packet to a next service device of the service chain on the basis of the user attributes assigned to the received continuity checking packet. The continuity checking apparatus identifies a path representing service devices through which the continuity checking packet passes on the basis of the arrival message transmitted from each service, and determines whether the identified path is the same as a path of the service chain that is a continuity checking target.
    Type: Application
    Filed: January 23, 2020
    Publication date: April 28, 2022
    Inventors: Yuki MIYOSHI, Ichiro KUDO, Hiroshi OSAWA, Hiroshi SUZUKI, Takeaki NISHIOKA, Yuhei HAYASHI
  • Publication number: 20210385241
    Abstract: A feature calculation unit (15b) calculates a feature of header information of a packet. A classification unit (15c) classifies the packet as a normal packet or an abnormal packet by using the calculated feature. An adding unit (15d) adds a label indicating a tool name of a known attack tool to header information of a packet attacked using the attack tool. A learning unit (15e) learns the addition of the label by using the label and the feature calculated for the packet to which the label has been added as teacher data.
    Type: Application
    Filed: February 4, 2020
    Publication date: December 9, 2021
    Inventors: Yuhei HAYASHI, Ichiro KUDO, Hiroshi OSAWA, Takeaki NISHIOKA
  • Publication number: 20210328932
    Abstract: The controller (10) acquires information about the band of the flow within the tunnel and the band of each flow after policing or shaping, calculates the ratio of the traffic volume after policing or shaping to the traffic volume before policing or shaping by using the acquired information about the band, and estimates the traffic volume of the flow to be monitored within the tunnel by using the calculated ratio and the band of each flow after policing or shaping.
    Type: Application
    Filed: August 16, 2019
    Publication date: October 21, 2021
    Applicant: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
    Inventors: Hiroshi SUZUKI, Yuhei HAYASHI, Yuki MIYOSHI, Takeaki NISHIOKA, Hiroshi OSAWA, Ichiro KUDO
  • Publication number: 20210306357
    Abstract: A copy unit (11c) copies packets received from a network. A compression unit (11d) compresses the payload of each of the copied packets and transfers each of the compressed packets to a security apparatus (20a). A storage unit stores filter information identifying the attack packet detected by the security apparatus, and a discarding unit (11a) uses the filter information to discard the attack packet. The storage unit stores an assignment rule designating a processing method for each predetermined flow of the network traffic, and an assignment unit (11b) uses the assignment rule to assign each of the packets received from the network to a copy unit (11c) or to another security apparatus (20b), for each of the predetermined flows.
    Type: Application
    Filed: July 17, 2019
    Publication date: September 30, 2021
    Inventors: Hiroyuki Onishi, Takeaki Nishioka, Yuhei Hayashi