Patents Assigned to ANOMALI INCORPORATED
-
Patent number: 12536177Abstract: An application receives user input of a search query by way of a search interface. The application determines a task based on the search query, and divides the task into a plurality of sub-tasks, at least some of the plurality of sub-tasks divided for parallel processing by different compute components. The application receives publication of partial results from the different compute components as those partial results are completed by their respective compute components. The application inputs the partial results into a reducer to create an aggregate partial result, and generates for display the aggregate partial result within the search interface, where the aggregate partial result is updated in real time as further partial results are published.Type: GrantFiled: January 30, 2025Date of Patent: January 27, 2026Assignee: Anomali IncorporatedInventors: Wei Huang, Yizheng Zhou, Hugh Seretse Njemanze
-
Patent number: 12493688Abstract: Systems and methods are disclosed herein for receiving, based on user interaction with a user interface, a user input of a natural language search query for identifying a cybersecurity threat by way of a search interface, the natural language search query requesting a specialized search of a threat database. An application generates a search vocabulary based on the natural language search query. The application performs a query lookup using the threat database, the query lookup returning a plurality of files that at least partially match the search query. The application prompts a large language model to generate an answer to the natural language search query using the plurality of files that at least partially match the search query, and outputs for display the answer using the user interface.Type: GrantFiled: January 30, 2025Date of Patent: December 9, 2025Assignee: Anomali IncorporatedInventor: Wei Huang
-
Patent number: 12360988Abstract: A query building tool receives user input of a natural language query by way of a search interface and decomposes the natural language query into sections. The tool prompts a large language model to, for each section, search a portion of a grammar of a query language having a corresponding query type for each section and construct a query language prompt corresponding to the section. The tool aggregates each query language prompt into an aggregated query language prompt, executes a search using the aggregated query language prompt, and outputs for display using the search interface search results for the natural language query.Type: GrantFiled: January 30, 2025Date of Patent: July 15, 2025Assignee: Anomali IncorporatedInventors: Mohsen Imani, Yizheng Zhou
-
Patent number: 10659486Abstract: A universal link to extract and classify log data is disclosed. In various embodiments, a set of candidate data values that match a top level pattern that is common to two or more types of data value of interest is identified. The candidate data values are processed through a plurality of successive filtering stages, each stage of which includes determining which, if any, of said candidates match a more specific pattern associated more specifically with a specific data value type. Candidates, if any, which match the more specific pattern are classified as being of a corresponding specific data type and are removed from the set of candidate data values. A structured data record that associates each candidate data value determined to be of a corresponding one of said types of data value of interest with said corresponding one of said types of data value of interest is generated and stored.Type: GrantFiled: April 17, 2019Date of Patent: May 19, 2020Assignee: Anomali IncorporatedInventors: Wei Huang, Yizheng Zhou, Hugh Seretse Njemanze, Zhong Deng
-
Patent number: 10616248Abstract: A security monitoring system operated by a downstream client continually collects event information indicating events that have occurred within the computing environment of the downstream client. The monitoring system, using software provided by a threat analytics system, aggregates the event information into a secure and space efficient data structure. The monitoring system transmits the data structures storing event information to the threat analytics system for further processing. The threat analytics system also receives threat indicators from intelligence feed data sources. The threat analytics system compares the event information received from each security monitoring system against the threat indicators collected from the intelligence feed data sources to identify red flag events. The threat analytics system processes the event information to synthesize all information related to the red flag event and reports the red flag event to the downstream client.Type: GrantFiled: January 23, 2019Date of Patent: April 7, 2020Assignee: Anomali IncorporatedInventors: Wei Huang, Yizheng Zhou, Hugh Njemanze
-
Patent number: 10367829Abstract: A threat analytics system expends significant resources to acquire, structure, and filter the threat indicators provided to the client-side monitoring systems. To protect the threat indicators from misuse, the threat analytics system only provides enough information about the threat indicators to the client-side systems to allow the client-side systems to detect past and ongoing threats. Specifically, the threat analytics system provides obfuscated threat indicators to the client-side monitoring systems. The obfuscated threat indicators enable the client-side systems to detect threats while protecting the threat indicators from misuse or malicious actors.Type: GrantFiled: November 19, 2015Date of Patent: July 30, 2019Assignee: Anomali IncorporatedInventors: Wei Huang, Yizheng Zhou, Hugh Njemanze
-
Patent number: 10313377Abstract: A universal link to extract and classify log data is disclosed. In various embodiments, a set of candidate data values that match a top level pattern that is common to two or more types of data value of interest is identified. The candidate data values are processed through a plurality of successive filtering stages, each stage of which includes determining which, if any, of said candidates match a more specific pattern associated more specifically with a specific data value type. Candidates, if any, which match the more specific pattern are classified as being of a corresponding specific data type and are removed from the set of candidate data values. A structured data record that associates each candidate data value determined to be of a corresponding one of said types of data value of interest with said corresponding one of said types of data value of interest is generated and stored.Type: GrantFiled: October 19, 2016Date of Patent: June 4, 2019Assignee: Anomali IncorporatedInventors: Wei Huang, Yizheng Zhou, Hugh Seretse Njemanze, Zhong Deng
-
Patent number: 10230742Abstract: A security monitoring system operated by a downstream client continually collects event information indicating events that have occurred within the computing environment of the downstream client. The monitoring system, using software provided by a threat analytics system, aggregates the event information into a secure and space efficient data structure. The monitoring system transmits the data structures storing event information to the threat analytics system for further processing. The threat analytics system also receives threat indicators from intelligence feed data sources. The threat analytics system compares the event information received from each security monitoring system against the threat indicators collected from the intelligence feed data sources to identify red flag events. The threat analytics system processes the event information to synthesize all information related to the red flag event and reports the red flag event to the downstream client.Type: GrantFiled: January 26, 2016Date of Patent: March 12, 2019Assignee: ANOMALI INCORPORATEDInventors: Wei Huang, Yizheng Zhou, Hugh Njemanze