Patents by Inventor Tian Bu

Tian Bu has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 7929514
    Abstract: A method, apparatus, and computer-readable storage medium for generating a mobile flow record for a mobile flow of a mobile node are provided. A method includes receiving information associated with signaling traffic of the mobile node, receiving information associated with bearer traffic of the mobile node, and generating the mobile flow record by correlating the information associated with signaling traffic of the mobile node and the information associated with bearer traffic of the mobile node. The mobile flow record includes IP layer information associated with the mobile flow and wireless layer information associated with the mobile flow.
    Type: Grant
    Filed: June 30, 2009
    Date of Patent: April 19, 2011
    Assignee: Alcatel-Lucent USA Inc.
    Inventors: Tian Bu, Girish Chandranmenon, Scott Miller, Samphel Norden
  • Publication number: 20110038269
    Abstract: A method is provided, according to which data are collected on downstream packet losses at a single point in a network. From from the collected data, packet loss rates are estimated on at least two subnetworks downstream of the collection point. The respective subnetworks may differ by one or more links.
    Type: Application
    Filed: August 12, 2009
    Publication date: February 17, 2011
    Inventors: Tian Bu, Jin Cao
  • Publication number: 20110010337
    Abstract: A method and apparatus are provided for incrementally tracking quantiles in the presence of multiple record types. A method for performing incremental quantile tracking includes receiving a first data record of a first record type having a first data value, determining whether a second data record of a second record type is received, determining an initial distribution function, updating the initial distribution function to form a new distribution function based on the first data value and whether a second data record is received, generating an approximation of the new distribution function, determining at least one new quantile estimate associated with at least one new probability of the new distribution function using the approximation of the new distribution function, and storing the at least one new quantile estimate and the at least one new probability associated with the at least one new quantile estimate.
    Type: Application
    Filed: August 24, 2009
    Publication date: January 13, 2011
    Inventors: Tian Bu, Jin Cao, Aiyou Chen, Li Li
  • Publication number: 20110010327
    Abstract: A method and apparatus for incremental tracking of multiples quantiles is provided. A method for performing an incremental quantile update using a data value of a received data record includes determining an initial distribution function, updating the initial distribution function to form a new distribution function based on the received data value, generating an approximation of the new distribution function, and determining new quantile estimates from the approximation of the new distribution function. The initial distribution function includes a plurality of initial quantile estimates and a respective plurality of initial probabilities. The initial distribution function is updated to form the new distribution function based on the received data value. The new distribution function includes a plurality of quantile points identifying the respective initial quantile estimates and a respective plurality of new probabilities associated with the respective initial quantile estimates.
    Type: Application
    Filed: August 24, 2009
    Publication date: January 13, 2011
    Inventors: Tian Bu, Jin Cao, Aiyou Chen, Li Li
  • Publication number: 20100332755
    Abstract: An apparatus and method for improving synchronization between threads in a multi-core processor system are provided. An apparatus includes a memory, a first processor core, and a second processor core. The memory includes a shared ring buffer for storing data units, and stores a plurality of shared variables associated with accessing the shared ring buffer. The first processor core runs a first thread and has a first cache associated therewith. The first cache stores a first set of local variables associated with the first processor core. The first thread controls insertion of data items into the shared ring buffer using at least one of the shared variables and the first set of local variables. The second processor core runs a second thread and has a second cache associated therewith. The second cache stores a second set of local variables associated with the second processor core.
    Type: Application
    Filed: June 26, 2009
    Publication date: December 30, 2010
    Inventors: Tian Bu, Girish Chandranmenon, Pak-Ching Lee
  • Publication number: 20100329145
    Abstract: A method, apparatus, and computer-readable storage medium for generating a mobile flow record for a mobile flow of a mobile node are provided. A method includes receiving information associated with signaling traffic of the mobile node, receiving information associated with bearer traffic of the mobile node, and generating the mobile flow record by correlating the information associated with signaling traffic of the mobile node and the information associated with bearer traffic of the mobile node. The mobile flow record includes IP layer information associated with the mobile flow and wireless layer information associated with the mobile flow.
    Type: Application
    Filed: June 30, 2009
    Publication date: December 30, 2010
    Inventors: Tian Bu, Girish Chandranmenon, Scott Miller, Samphel Norden
  • Publication number: 20100299287
    Abstract: In one embodiment, a statistical model is generated based on observed data, the observed data being associated with a network device, online parameter fitting is performed on parameters of the statistical model, and for each newly observed data value, a forecast value is generated based on the statistical model, the forecast value being a prediction of a next observed data value, a forecasting error is generated based on the forecast value and the newly observed data value, and whether the data of the network stream is abnormal is determined based on a log likelihood ratio test of the forecasting errors and a threshold value.
    Type: Application
    Filed: May 22, 2009
    Publication date: November 25, 2010
    Inventors: Jin Cao, Aiyou Chen, Tian Bu
  • Publication number: 20100292995
    Abstract: A method and apparatus for incremental quantile estimation is provided. A method for performing incremental quantile estimation using an estimated cumulative distribution function includes receiving a record, identifying an entity with which the received record is associated, determining a record type of the received record based at least in part on the entity with which the received record is associated, updating the estimated cumulative distribution function based on the record type of the received record, and storing the estimated cumulative distribution function. The record type of the received record is indicative of whether the received record is an insertion record, an update record, or a deletion record. The estimated cumulative distribution function may be used to respond to quantile query requests in real-time or near-real-time.
    Type: Application
    Filed: May 18, 2009
    Publication date: November 18, 2010
    Inventors: Tian Bu, Jin Cao, Li Li
  • Patent number: 7779143
    Abstract: Methods and apparatuses are provided for detecting traffic patterns in a data network. A sequential hashing scheme can be utilized that has D hash arrays. Each hash array i, wherein 1?i?D, includes Mi independent hash tables each having K buckets, with each of the buckets having an associated traffic total. Each of the keys corresponds with a single bucket of each of the Mi independent hash tables of each hash array i. The keys of the data network are partitioned into D words. As traffic is received for a key, a traffic total of each bucket that corresponds with a key is updated. The hash arrays can then be utilized to identify high traffic buckets of the independent hash tables having a traffic total greater than a threshold value. The high traffic buckets can be used to detect significant traffic patterns of the data network.
    Type: Grant
    Filed: June 28, 2007
    Date of Patent: August 17, 2010
    Assignee: Alcatel-Lucent USA Inc.
    Inventors: Tian Bu, Jin Cao, Aiyou Chen, Pak-Ching Lee
  • Publication number: 20090268623
    Abstract: In one embodiment, a method of monitoring a network. The method includes, at each node of a fixed set, constructing a corresponding vector of M components based on data packets received at the node during a time period, M being an integer greater than 1, the fixed set being formed of some nodes of the network; and, based on the constructed vectors, estimating how many of the received data packets have been received by all of the nodes of the set or estimating how many flows of the received data packets have data packets that have passed through all of the nodes of the set. The constructing includes updating a component of the vector of one of the nodes in response to the one of the nodes receiving a data packet. The updating includes selecting the component for updating by hashing a property of the data packet received by the one of the nodes.
    Type: Application
    Filed: April 28, 2008
    Publication date: October 29, 2009
    Applicant: LUCENT TECHNOLOGIES INC.
    Inventors: Tian Bu, Jin Cao, Aiyou Chen
  • Publication number: 20090190511
    Abstract: A system and method for network based detection of wireless data subscribers using network address translation devices is provided. The method includes identifying a minimum number of devices showing the same internet protocol address. Packet identification sequences may include port numbers or internet protocol identification numbers. The method continues with grouping these applications by their packet identification sequences and applying detection logic where detection logic yields a conclusion that there are multiple host computers when a set of applications appears in a plurality of packet identification sequences. This method is particularly useful when internet protocol addresses are dynamic, as opposed to static. This method overcomes previous embodiments known in the art by being able to account for and work with live traffic, which enables real time detection.
    Type: Application
    Filed: January 30, 2008
    Publication date: July 30, 2009
    Inventors: Li (Erran) Li, Tian Bu, Scott C. Miller, Aiyou Chen
  • Patent number: 7515926
    Abstract: In a wireless network, an architecture for wireless attack resistance (AWARE) detects power-drain denial-of-service (DoS) attacks by generating statistical measures relating the power consumption by a mobile unit and data transmitted to and from the mobile unit during normal operations of the wireless network. The AWARE architecture compares those statistical measures to current measures to detect a DoS attack if the current measure differs from the statistical measure by more than a specified threshold. If a DoS attack is detected, then the AWARE architecture can inhibit communications with the mobile unit to prevent the mobile from consuming too much power. The statistical measure may be an energy efficiency ratio relating the number of bits of data transmitted to or from the mobile unit over a specified time interval to the amount of power consumed by the mobile unit during that time interval.
    Type: Grant
    Filed: March 30, 2005
    Date of Patent: April 7, 2009
    Assignee: Alcatel-Lucent USA Inc.
    Inventors: Tian Bu, Samphel Norden, Thomas Y. Woo
  • Publication number: 20090088147
    Abstract: The present invention relates to a correlation module for correlating IP layer traffic and wireless layer network elements in a network. According to an example embodiment, the correlation module includes an RNC analyzer, a Gn snoop unit, and/or a mapping unit. The RNC analyzer is configured to collect wireless layer network element information from at least one RNC. The Gn snoop unit is configured to collect wireless layer network element information and IP layer traffic information from at least one Gn interface between a serving GPRS support node and a gateway GPRS support node. The mapping unit is configured to map the IP layer traffic and the wireless layer network elements in the network based on the collected IP layer traffic information and the collected wireless layer network element information. A method of correlating IP layer traffic and wireless layer network elements in a network is also disclosed.
    Type: Application
    Filed: September 28, 2007
    Publication date: April 2, 2009
    Inventors: Tian BU, Ruth Schaefer Gayde, Scott C. Miller, Kathleen Ellen Moczulewski, Alex Ibrahim Moukalled, Samphel Norden
  • Publication number: 20090006607
    Abstract: Methods and apparatuses are provided for detecting traffic patterns in a data network. A sequential hashing scheme can be utilized that has D hash arrays. Each hash array i, wherein 1?i?D, includes Mi independent hash tables each having K buckets, with each of the buckets having an associated traffic total. Each of the keys corresponds with a single bucket of each of the Mi independent hash tables of each hash array i. The keys of the data network are partitioned into D words. As traffic is received for a key, a traffic total of each bucket that corresponds with a key is updated. The hash arrays can then be utilized to identify high traffic buckets of the independent hash tables having a traffic total greater than a threshold value. The high traffic buckets can be used to detect significant traffic patterns of the data network.
    Type: Application
    Filed: June 28, 2007
    Publication date: January 1, 2009
    Inventors: Tian Bu, Jin Cao, Aiyou Chen, Pak-Ching Lee
  • Publication number: 20080159299
    Abstract: Novel, Internet-related architectures, methods and devices are proposed that are based on a fundamentally different philosophy: hosts (e.g., source and destination nodes) are given the ability to specify their access control policies to the network they are a part of, and the network enforces these policies. The architecture proposed is mobility friendly to the ever increasing number of mobile hosts and is scalable as well.
    Type: Application
    Filed: December 29, 2006
    Publication date: July 3, 2008
    Inventors: Tian Bu, Li Li, Ramachandran Ramjee
  • Publication number: 20080137608
    Abstract: The transmission of data from base stations to users (and their devices) in a wireless network is made using proportional fairness without sacrificing throughput by taking in to account fairness considerations at the time the devices are associated with a base station.
    Type: Application
    Filed: December 8, 2006
    Publication date: June 12, 2008
    Inventors: Tian Bu, Li Li, Ramachandran Ramjee
  • Publication number: 20070234424
    Abstract: A method and computer product are presented for identifying Internet worm propagation based upon changes in packet arrival rates at a network connection. First, unsolicited (i.e., packets that were not requested by the receiver) traffic is separated from solicited traffic at the network connection. The unsolicited traffic arrival patterns are monitored and analyzed for any changes. Once changes in the unsolicited traffic arrival patterns are detected, the changes are mathematically analyzed to detect growth trends. The presence of growth trends that follow certain key characteristics indicate whether the changes are due to worm propagation.
    Type: Application
    Filed: March 31, 2006
    Publication date: October 4, 2007
    Applicant: Lucent Technologies, Inc.
    Inventors: Tian Bu, Aiyou Chen, Scott Vander Wiel, Thomas Woo
  • Publication number: 20070143769
    Abstract: Wireless state information collected or inferred from a 3G wireless network is used to detect and prevent malicious attacks against the network.
    Type: Application
    Filed: December 19, 2005
    Publication date: June 21, 2007
    Inventors: Tian Bu, Samphel Norden, Thomas Woo
  • Publication number: 20070091937
    Abstract: There is provided a system and method for estimating network tomography. More specifically, there is provided a computer system configured to measure the transmission delay along a path from a source endpoint of a computer network to a plurality of destination endpoints of the computer network, wherein the path includes at least two data links and wherein at least one of the data links is shared by the plurality of destination endpoints for transmissions from the source endpoint, to calculate a characteristic function of the measured transmission delay, and to calculate a performance parameter of one of the data links based on the characteristic function.
    Type: Application
    Filed: October 21, 2005
    Publication date: April 26, 2007
    Inventors: Tian Bu, Jin Cao, Aiyou Chen
  • Publication number: 20070070933
    Abstract: Estimates are provided for the number of links needed in a Internet Protocol-Radio Access Network (IP-RAN) to ensure the IP-RAN is resilient to base station and radio network controller type failures.
    Type: Application
    Filed: September 28, 2005
    Publication date: March 29, 2007
    Inventors: Mun-Choon Chan, Ramachandran Ramjee, Tian Bu