Patents by Inventor Martin Kopp

Martin Kopp has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Publication number: 20220239630
    Abstract: A method includes, at a server in a network, detecting for a user device network incidents relating to one or more security threats in the network using a plurality of threat detectors over a predetermined time period, each of the network incidents including one or more behavior indicators; assigning the network incidents into one or more groups, wherein each group corresponds to a type of security threat; generating a graph for a particular group of the user device, wherein the graph includes a plurality of nodes each representing a behavior indicator in the particular group, and wherein generating the graph includes assigning an edge to connect two nodes of the plurality of nodes if the two nodes correspond to behavior indicators that belong to a same network incident; and displaying the graph on a graphical user interface for a user.
    Type: Application
    Filed: April 18, 2022
    Publication date: July 28, 2022
    Inventors: Martin Kopp, Lukas Machlica
  • Patent number: 11336617
    Abstract: A method includes, at a server in a network, detecting for a user device network incidents relating to one or more security threats in the network using a plurality of threat detectors over a predetermined time period, each of the network incidents including one or more behavior indicators; assigning the network incidents into one or more groups, wherein each group corresponds to a type of security threat; generating a graph for a particular group of the user device, wherein the graph includes a plurality of nodes each representing a behavior indicator in the particular group, and wherein generating the graph includes assigning an edge to connect two nodes of the plurality of nodes if the two nodes correspond to behavior indicators that belong to a same network incident; and displaying the graph on a graphical user interface for a user.
    Type: Grant
    Filed: March 21, 2019
    Date of Patent: May 17, 2022
    Assignee: CISCO TECHNOLOGY, INC.
    Inventors: Martin Kopp, Lukas Machlica
  • Patent number: 11245675
    Abstract: In one embodiment, a traffic analysis service obtains telemetry data regarding encrypted traffic associated with a particular device in the network, wherein the telemetry data comprises Transport Layer Security (TLS) features of the traffic. The service determines, based on the TLS features from the obtained telemetry data, a set of one or more TLS fingerprints for the traffic associated with the particular device. The service calculates a measure of similarity between the set of one or more TLS fingerprints for the traffic associated with the particular device and a set of one or more TLS fingerprints of traffic associated with a second device. The service determines, based on the measure of similarity, that the particular device and the second device were operated by the same user.
    Type: Grant
    Filed: November 18, 2019
    Date of Patent: February 8, 2022
    Assignee: Cisco Technology, Inc.
    Inventors: Jan Kohout, Martin Kopp, Jan Brabec, Lukas Bajer
  • Patent number: 11169061
    Abstract: A method and system for processing particles contained in a liquid biological sample is presented. The method uses a rotatable vessel for processing particles contained in a liquid biological sample. The rotatable vessel has a longitudinal axis about which the vessel is rotatable, an upper portion having a top opening for receiving the liquid containing the particles, a lower portion for holding the liquid while the rotatable vessel is resting, the lower portion having a bottom, and an intermediate portion located between the upper portion and the lower portion, the intermediate portion having a lateral collection chamber for holding the liquid while the rotatable vessel is rotating. The method employs dedicated acceleration and deceleration profiles for sedimentation and re-suspension of the particles of interest.
    Type: Grant
    Filed: August 16, 2019
    Date of Patent: November 9, 2021
    Assignee: Roche Diagnostics Operations, Inc.
    Inventors: Claudio Cherubini, Martin Kopp, Nenad Milicevic, Daniel Mueller, Emad Sarofim, Goran Savatic
  • Publication number: 20210306350
    Abstract: In one embodiment, a device obtains input features for a neural network-based model. The device pre-defines a set of neurons of the model to represent known behaviors associated with the input features. The device constrains weights for a plurality of outputs of the model. The device trains the neural network-based model using the constrained weights for the plurality of outputs of the model and by excluding the pre-defined set of neurons from updates during the training.
    Type: Application
    Filed: March 26, 2020
    Publication date: September 30, 2021
    Inventors: Petr Somol, Martin Kopp, Jan Kohout, Jan Brabec, Marc René Jacques Marie Dupont, Cenek Skarda, Lukas Bajer, Danila Khikhlukha
  • Patent number: 11019095
    Abstract: In one embodiment, a device in a network obtains log data regarding replication of files stored on an endpoint client to a file replication service. The device tracks, based on the obtained logs, encryption changes to the files that convert the files from unencrypted files to encrypted files. The device determines that the tracked encryption changes to the files are indicative of a ransomware infection on the endpoint client. The device initiates a mitigation action regarding the ransomware infection.
    Type: Grant
    Filed: January 30, 2019
    Date of Patent: May 25, 2021
    Assignee: Cisco Technology, Inc.
    Inventors: Martin Grill, Lukas Bajer, Martin Kopp, Jan Kohout
  • Publication number: 20210152526
    Abstract: In one embodiment, a traffic analysis service obtains telemetry data regarding encrypted traffic associated with a particular device in the network, wherein the telemetry data comprises Transport Layer Security (TLS) features of the traffic. The service determines, based on the TLS features from the obtained telemetry data, a set of one or more TLS fingerprints for the traffic associated with the particular device. The service calculates a measure of similarity between the set of one or more TLS fingerprints for the traffic associated with the particular device and a set of one or more TLS fingerprints of traffic associated with a second device. The service determines, based on the measure of similarity, that the particular device and the second device were operated by the same user.
    Type: Application
    Filed: November 18, 2019
    Publication date: May 20, 2021
    Inventors: Jan Kohout, Martin Kopp, Jan Brabec, Lukas Bajer
  • Patent number: 10965704
    Abstract: In one embodiment, a device in a network receives traffic information regarding one or more secure sessions in the network. The device associates the one or more secure sessions with corresponding certificate validation check traffic indicated by the received traffic information. The device makes a self-signed certificate determination for an endpoint domain of a particular secure session based on whether the particular secure session is associated with certificate validation check traffic. The device causes the self-signed certificate determination for the endpoint domain to be used as input to a malware detector.
    Type: Grant
    Filed: June 20, 2019
    Date of Patent: March 30, 2021
    Assignee: Cisco Technology, Inc.
    Inventors: Martin Kopp, Martin Grill, Jan Kohout
  • Publication number: 20210006589
    Abstract: In one embodiment, a device in a network detects an encrypted traffic flow associated with a client in the network. The device captures contextual traffic data regarding the encrypted traffic flow from one or more unencrypted packets associated with the client. The device performs a classification of the encrypted traffic flow by using the contextual traffic data as input to a machine learning-based classifier. The device generates an alert based on the classification of the encrypted traffic flow.
    Type: Application
    Filed: September 23, 2020
    Publication date: January 7, 2021
    Inventors: Jan Kohout, Blake Harrell Anderson, Martin Grill, David McGrew, Martin Kopp, Tomas Pevny
  • Patent number: 10805338
    Abstract: In one embodiment, a device in a network detects an encrypted traffic flow associated with a client in the network. The device captures contextual traffic data regarding the encrypted traffic flow from one or more unencrypted packets associated with the client. The device performs a classification of the encrypted traffic flow by using the contextual traffic data as input to a machine learning-based classifier. The device generates an alert based on the classification of the encrypted traffic flow.
    Type: Grant
    Filed: October 6, 2016
    Date of Patent: October 13, 2020
    Assignee: Cisco Technology, Inc.
    Inventors: Jan Kohout, Blake Harrell Anderson, Martin Grill, David McGrew, Martin Kopp, Tomas Pevny
  • Patent number: 10805377
    Abstract: A computing device having connectivity to a network stores one or more existing device models, where each of the one or more existing device models is a representation of a different client device used by a first authenticated user to access the network. The computing device obtains a device sample, which comprises network traffic data that is captured during a period of time and which is generated by a particular client device associated with the authenticated user of the network. The computing device determines, based on one or more relational criteria, whether the device sample should be assigned to one of the one or more existing device models or to an additional device model that has not yet been created. The computing device then determines relative identity of the particular client device based on whether the device sample is assigned to one of the one or more device models or to an additional device model that has not yet been created.
    Type: Grant
    Filed: May 18, 2017
    Date of Patent: October 13, 2020
    Assignee: CISCO TECHNOLOGY, INC.
    Inventors: Martin Grill, Jan Kohout, Martin Kopp
  • Publication number: 20200304462
    Abstract: A method includes, at a server in a network, detecting for a user device network incidents relating to one or more security threats in the network using a plurality of threat detectors over a predetermined time period, each of the network incidents including one or more behavior indicators; assigning the network incidents into one or more groups, wherein each group corresponds to a type of security threat; generating a graph for a particular group of the user device, wherein the graph includes a plurality of nodes each representing a behavior indicator in the particular group, and wherein generating the graph includes assigning an edge to connect two nodes of the plurality of nodes if the two nodes correspond to behavior indicators that belong to a same network incident; and displaying the graph on a graphical user interface for a user.
    Type: Application
    Filed: March 21, 2019
    Publication date: September 24, 2020
    Inventors: Martin Kopp, Lukas Machlica
  • Patent number: 10749770
    Abstract: In one embodiment, a traffic analysis service obtains telemetry data regarding network traffic associated with a device in a network. The traffic analysis service forms a histogram of frequencies of the traffic features from the telemetry data for the device. The traffic features are indicative of endpoints with which the device communicated. The traffic analysis service associates a device type with the device, by comparing the histogram of the traffic features from the telemetry data to histograms of traffic features associated with other devices. The traffic analysis service initiates, based on the device type associated with the device, an adjustment to treatment of the traffic associated with the device by the network.
    Type: Grant
    Filed: October 10, 2018
    Date of Patent: August 18, 2020
    Assignee: Cisco Technology, Inc.
    Inventors: Jan Kohout, Martin Grill, Martin Kopp, Lukas Bajer
  • Publication number: 20200244672
    Abstract: In one embodiment, a device in a network obtains log data regarding replication of files stored on an endpoint client to a file replication service. The device tracks, based on the obtained logs, encryption changes to the files that convert the files from unencrypted files to encrypted files. The device determines that the tracked encryption changes to the files are indicative of a ransomware infection on the endpoint client. The device initiates a mitigation action regarding the ransomware infection.
    Type: Application
    Filed: January 30, 2019
    Publication date: July 30, 2020
    Inventors: Martin Grill, Lukas Bajer, Martin Kopp, Jan Kohout
  • Patent number: 10708284
    Abstract: In one embodiment, a device in a network maintains a plurality of machine learning-based detectors for an intrusion detection system. Each detector is associated with a different portion of a feature space of traffic characteristics assessed by the intrusion detection system. The device provides data regarding the plurality of detectors to a user interface. The device receives an adjustment instruction from the user interface based on the data provided to the user interface regarding the plurality of detectors. The device adjusts the portions of the feature space associated with the plurality of detectors based on the adjustment instruction received from the user interface.
    Type: Grant
    Filed: July 7, 2017
    Date of Patent: July 7, 2020
    Assignee: Cisco Technology, Inc.
    Inventors: Martin Kopp, Petr Somol, Tomas Pevny, David McGrew
  • Publication number: 20200120004
    Abstract: In one embodiment, a traffic analysis service obtains telemetry data regarding network traffic associated with a device in a network. The traffic analysis service forms a histogram of frequencies of the traffic features from the telemetry data for the device. The traffic features are indicative of endpoints with which the device communicated. The traffic analysis service associates a device type with the device, by comparing the histogram of the traffic features from the telemetry data to histograms of traffic features associated with other devices. The traffic analysis service initiates, based on the device type associated with the device, an adjustment to treatment of the traffic associated with the device by the network.
    Type: Application
    Filed: October 10, 2018
    Publication date: April 16, 2020
    Inventors: Jan Kohout, Martin Grill, Martin Kopp, Lukas Bajer
  • Patent number: 10601847
    Abstract: A user behavior activity detection method is provided in which network traffic relating to user behavior activities in a network is monitored. Data is stored representing network traffic within a plurality of time periods, each of the time periods serving as a transaction. Subsets of the network traffic in the transactions are identified as traffic suspected of relating to certain user behavior activities. The subsets of the network traffic in the transactions are assigned into one or more groups. A determination is made of one or more detection rules for each of the one or more groups based on identifying, for each of the groups, a number of user behavior activities common to each of the subsets of the network traffic. The one or more detection rules are used to monitor future network traffic in the network to detect occurrence of the certain user behavior activities.
    Type: Grant
    Filed: June 22, 2017
    Date of Patent: March 24, 2020
    Assignee: Cisco Technology, Inc.
    Inventors: Martin Kopp, Lukas Machlica
  • Publication number: 20200033240
    Abstract: A method and system for processing particles contained in a liquid biological sample is presented. The method uses a rotatable vessel for processing particles contained in a liquid biological sample. The rotatable vessel has a longitudinal axis about which the vessel is rotatable, an upper portion having a top opening for receiving the liquid comprising the particles, a lower portion for holding the liquid while the rotatable vessel is resting, the lower portion having a bottom, and an intermediate portion located between the upper portion and the lower portion, the intermediate portion having a lateral collection chamber for holding the liquid while the rotatable vessel is rotating. The method employs dedicated acceleration and deceleration profiles for sedimentation and re-suspension of the particles of interest.
    Type: Application
    Filed: August 16, 2019
    Publication date: January 30, 2020
    Applicant: Roche Diagnostics Operations, Inc.
    Inventors: Claudio Cherubini, Martin Kopp, Nenad Milicevic, Daniel Mueller, Emad Sarofim, Goran Savatic
  • Patent number: 10491614
    Abstract: Detecting illegitimate typosquatting with Internet Protocol (IP) information includes, at a computing device having connectivity to a network, obtaining a list of domains and filtering the list to generate a list of monitored domain strings. IP information is passively determined for domains associated with each of the monitored domain strings. A domain requested in network traffic for the network is identified as a candidate typosquatting domain and the candidate typosquatting domain is determined to be an illegitimate typosquatting domain based at least on the IP information. An action is initiated related to the illegitimate typosquatting domain.
    Type: Grant
    Filed: August 25, 2016
    Date of Patent: November 26, 2019
    Assignee: Cisco Technology, Inc.
    Inventors: Martin Grill, Jan Kohout, Martin Kopp, Tomas Pevny
  • Patent number: 10456777
    Abstract: A pressure transmission liquid for a cellular analyzer, a system for transferring a liquid cellular sample for analysis by a cellular analyzer, and a method for transferring a liquid cellar sample for analysis are disclosed. The pressure transmission liquid includes an aqueous solution which is isotonic and substantially non-conductive characteristics. The cellular analyzer includes a pipetting module having a pipetting tip, a device for positioning the pipetting module, a sensor for detecting a liquid level of a liquid cellular sample to be analyzed, a pressure transmission liquid, and a pressure transmission liquid conduit connected to the pipetting tip and the pressure transmission liquid reservoir.
    Type: Grant
    Filed: April 15, 2016
    Date of Patent: October 29, 2019
    Assignee: ROCHE DIAGNOSTICS OPERATIONS, INC.
    Inventors: Martin Kopp, Emad Sarofim