Patents Assigned to AO Kaspersky Lab
  • Patent number: 12665915
    Abstract: An exemplary method for security monitoring and incident response using large language models comprises: receiving input data from elements of Security Operations Center (SOC), generating and sending a query based on the received input data to a Large Language Model (LLM), parsing a response received from the LLM, and performing analysis to determine whether a threat has been identified. In one aspect, the method further comprises: when a threat is identified, collecting artifacts of the threat, and analyzing the threat further with involvement of security professionals, when a threat is not identified, determining whether additional data is needed, and when additional data is needed, determining a type of the additional data, when the type of additional data that is determined, collecting additional information from elements of the SOC, and when additional data is not needed, terminating the incident response.
    Type: Grant
    Filed: March 8, 2024
    Date of Patent: June 23, 2026
    Assignee: AO Kaspersky Lab
    Inventor: Victor G. Sergeev
  • Patent number: 12627684
    Abstract: Disclosed system and method for secure transfer of data between networks. An example method comprises: setting a first state of the gateway, wherein in the first state a destination agent of the gateway is granted access to a first memory and denied access to a second network; while the gateway is in the first state, configuring the destination agent, based on one or more parameters stored in the first memory, to transfer data received from a source agent of the gateway to the second network; changing the state of the gateway to a second state, wherein in the second state the destination agent is denied access to the first memory and granted access to the second network; and while the gateway is in the second state, controlling transfer of the data from the source agent of the first network to the destination agent of the second network.
    Type: Grant
    Filed: October 30, 2024
    Date of Patent: May 12, 2026
    Assignee: AO Kaspersky Lab
    Inventors: Dmitry S. Lukiyan, Alexey G. Vereshchagin, Maxim A. Dontsov, Ruslan Y. Morozov, Denis S. Kashitsyn
  • Patent number: 12572124
    Abstract: A method for determination of anomalies in a cyber-physical system (CPS) includes generating one or more diagnostic rules configured to calculate at least one auxiliary CPS variable. One or more values of the at least one auxiliary CPS variable are calculated for a predefined output interval of time based on collected values of a group of primary CPS variables for a predefined input interval of time based on the generated diagnostic rule. An anomaly is determined based on the collected values of the group of primary CPS variables and the one or more calculated values of the at least one auxiliary CPS variable.
    Type: Grant
    Filed: September 7, 2022
    Date of Patent: March 10, 2026
    Assignee: AO Kaspersky Lab
    Inventors: Andrey B. Lavrentyev, Artem M. Vorontsov, Dmitry A. Ivanov, Vyacheslav I. Shkulev, Nikolay N. Demidov, Artyom M. Nechiporuk, Maxim A. Mamaev, Alexander V. Travov
  • Patent number: 12506833
    Abstract: A method of interrupting an incoming call on a mobile device includes: intercepting an incoming telephone call received by a mobile device; determining one or more parameters of the intercepted telephone call; determining if the intercepted telephone call matches one or more telephone calls associated with a list of prohibited phone numbers by comparing the determined parameters of the intercepted call with parameters of the one or more telephone calls associated with the list of prohibited phone numbers; and in response to determining a match between the intercepted telephone call and the one or more telephone calls associated with the list of prohibited phone numbers: blocking reception of the intercepted telephone call; identifying a calling party associated with the intercepted telephone call; sending an authentication request to the identified calling party; and interrupting the intercepted telephone call in response to unsuccessful authentication.
    Type: Grant
    Filed: November 18, 2022
    Date of Patent: December 23, 2025
    Assignee: AO Kaspersky Lab
    Inventors: Sergey A. Kochanov, Alexey P. Komissarov, Victor V. Yablokov
  • Patent number: 12481759
    Abstract: Disclosed herein are systems and methods for anti-virus scanning of objects on a mobile device. In one aspect, an exemplary method comprises: receiving, by a security module, a command from a protection module of a third-party application to perform an anti-virus scan, when a mobile security application is installed or pre-installed, when the mobile security application is not activated, activating the mobile security application, when the mobile security application is not installed or pre-installed on the mobile device, installing and activating the mobile security application, transmitting the object to the mobile security application, performing an anti-virus scan of the object to determine whether the object is malicious, transmitting results of the anti-virus scan to a protection module of a third-party application, selecting at least one response measure based on the result of the anti-virus scan, and applying at least one selected response measure.
    Type: Grant
    Filed: March 27, 2024
    Date of Patent: November 25, 2025
    Assignee: AO Kaspersky Lab
    Inventors: Victor V. Yablokov, Konstantin M. Filatov
  • Patent number: 12477003
    Abstract: Disclosed herein are systems and methods for creating a classifier for detecting phishing sites using Document Object Model (DOM) hashes. In one aspect, an exemplary method comprises: parsing each page of the website, wherein the parsing includes at least generating a DOM tree of the page, for each page, generating at least one string of DOM tree elements according to predetermined patterns, creating a first hash based on the string, creating a second hash for the page, generating a first dataset comprising hashes of safe pages and a second dataset comprising hashes of phishing pages, analyzing the first and second datasets to determine whether there is diversity of data in each dataset, generating a training sample from the datasets when there is diversity of data, and training a classifier of a machine learning model based on the training sample generated from the first and second datasets.
    Type: Grant
    Filed: March 18, 2024
    Date of Patent: November 18, 2025
    Assignee: AO Kaspersky Lab
    Inventor: Vladislav N. Tushkanov
  • Patent number: 12438844
    Abstract: A method for securing a plurality of IoT devices using a gateway includes intercepting, by a gateway, information about interactions between a first IoT device and at least one of: a second IoT device, a computer server, and a computer service. One or more cyber security threats are detected by the gateway based on the intercepted information and based on information stored in at least one of a first database and a second database. The first database is configured to store information about IoT devices and the second database is configured to store information about cyber security threats. One or more cyber security threat mitigation actions are identified by the gateway to address the detected one or more cyber security threats. The identified one or more cyber security threat mitigation actions are performed by the gateway.
    Type: Grant
    Filed: September 23, 2022
    Date of Patent: October 7, 2025
    Assignee: AO Kaspersky Lab
    Inventors: Konstantin M. Filatov, Victor V. Yablokov
  • Patent number: 12425422
    Abstract: Disclosed herein are systems and methods for providing security to an Internet of Things (IoT) device. An exemplary method comprises, obtaining, by an interceptor located on at least one gateway or the device, information about an interaction of the device with at least one of: other devices, service, and server; by an analysis tool located on the gateway: determining at least one category of the device and at least one category of a user of the device by interacting with a security service based on information received about the interaction of the device; receiving data from the security service, and identifying the security component to be installed on the device based on the data received from the security service, the category of the device and the category of a user of the device; and installing on the device, by the interceptor, the security component identified by the analysis tool.
    Type: Grant
    Filed: June 27, 2023
    Date of Patent: September 23, 2025
    Assignee: AO Kaspersky Lab
    Inventors: Victor V. Yablokov, Konstantin M. Filatov
  • Patent number: 12411484
    Abstract: A method for diagnostics and monitoring of anomalies in a cyber-physical system (CPS) includes obtaining information related to anomalies identified in the CPS. The obtained information includes at least one value of one or more CPS variables. One or more classifying features of the identified anomalies in the CPS are generated based on the obtained information. Classification of the identified anomalies in the CPS into two or more anomaly classes is performed based on the generated classifying features. Each of the two or more anomaly classes is associated with one or more anomaly characteristics. Diagnostics of anomalies are performed in each of the two or more anomaly classes by calculating values of the anomaly characteristics associated with each of the two or more anomaly classes. Anomalies of each of the two or more anomaly classes are monitored based on the calculated values of the anomaly characteristics associated with each of the two or more anomaly classes.
    Type: Grant
    Filed: October 26, 2022
    Date of Patent: September 9, 2025
    Assignee: AO Kaspersky Lab
    Inventors: Andrey B. Lavrentyev, Artem M. Vorontsov, Dmitry A. Ivanov, Vyacheslav I. Shkulev, Nikolay N. Demidov, Artyom M. Nechiporuk, Maxim A. Mamaev, Alexander V. Travov
  • Patent number: 12393680
    Abstract: Disclosed herein are systems and methods for detecting an unapproved use of a computing device of a user. In one aspect, an exemplary method comprises, by a security application: detecting a script executing in a browser on the computing device of the user, intercepting messages being exchanged during an interaction of the script with a server, wherein the intercepted messages comprise at least one of messages sent from the script to the server and from the server to the script, analyzing the intercepted messages to determine whether or not attributes of an unapproved use of resources of the computing device of the user are present, detecting the unapproved use of the resources of the computing device of the user when at least one of said attributes is detected.
    Type: Grant
    Filed: March 24, 2021
    Date of Patent: August 19, 2025
    Assignee: AO Kaspersky Lab
    Inventors: Denis I. Parinov, Dmitry V. Vinogradov, Victoria V. Vlasova, Vasily A. Davydov
  • Patent number: 12333009
    Abstract: This application provides a method for detecting anomalies in the behavior of a trusted process. An example method includes detecting a launch of a trusted process in a computer system; selecting a basic behavior model corresponding to the trusted process and a machine learning model corresponding to the trusted process; monitoring execution of the trusted process using the basic behavior model; comparing a total probability of occurrence of all of the plurality of identified events with a predefined threshold; extracting data corresponding to the identified events from a Markov chain, in response to determining that the probability of occurrence of all of the plurality of identified events is below the predefined threshold; analyzing the extracted data using the machine learning model; and generating a decision with respect to presence of anomalous behavior in the trusted process based on the analysis performed by the machine learning model.
    Type: Grant
    Filed: October 6, 2022
    Date of Patent: June 17, 2025
    Assignee: AO Kaspersky Lab
    Inventor: Andrey A. Ivanov
  • Patent number: 12328411
    Abstract: Disclosed herein are systems and methods for recognizing undesirable calls on a remote device. In one aspect, an exemplary method comprises, generating, for each call, a call identifier from a probabilistic hash received from a secure device, the probabilistic hash having been computed by the secure device based on a unique call identifier associated with call data collected for the call; analyzing the generated call identifiers to identify at least one of the generated call identifiers as a suspicious call identifier; requesting data, from the secure device associated with the suspicious call identifiers, where the requested data includes at least information about the call associated with the suspicious call identifier; and analyzing data received in response to the request and recognizing suspicious call identifier and the call associated with the suspicious call identifier as undesirable based on the analysis of the data received in response to the request.
    Type: Grant
    Filed: July 28, 2023
    Date of Patent: June 10, 2025
    Assignee: AO Kaspersky Lab
    Inventors: Daniil A. Yazovsky, Dmitry V. Shvetsov, Vitaly S. Vorobiov
  • Patent number: 12321405
    Abstract: Disclosed herein are systems and methods for providing a trained model to a computing device of a user. In one aspect, an exemplary method comprises, receiving, by a model transmitter, registration information from the computing device of the user comprising a trained model of the user's behavior, wherein the model is constructed using software provided by a service, storing, by the model transmitter, the received registration information in a database of behavior models, and during a repeat visit, by the user, to the service, updating the trained model of the user's behavior and transmitting the updated trained model to the service, wherein the updated trained model differs from a previously sent model of the user's behavior by no more than is allowed for unambiguous identification of the user on the service.
    Type: Grant
    Filed: May 10, 2024
    Date of Patent: June 3, 2025
    Assignee: AO Kaspersky Lab
    Inventors: Andrey A. Efremov, Pavel V. Filonov
  • Patent number: 12292985
    Abstract: Disclosed herein are systems and methods for detecting harmful scripts. In one aspect, an exemplary method comprises, identifying a file containing a script, wherein the identification of the file is performed by analyzing each file of a plurality of files for a presence of a harmful script, generating a summary of the script based on the identified file, calculating static and dynamic parameters of the generated summary of the script, recognizing a script programming language based on the calculated static parameters and dynamic parameters of the generated summary of the script using at least one language recognition rule, processing the identified file based on the data about the recognized script programming language, generating a set of hash codes based on a processed file using rules for generating hash codes, and detecting the harmful script when the generated set of hash codes is similar to known harmful sets of hash codes.
    Type: Grant
    Filed: September 7, 2022
    Date of Patent: May 6, 2025
    Assignee: AO Kaspersky Lab
    Inventors: Andrei I. Kalegin, Vitaly V. Butuzov, Dmitry N. Glavatskikh, Denis I. Parinov, Alexey M. Romanenko
  • Patent number: 12248575
    Abstract: Disclosed herein are systems and methods for monitoring delivery of messages passed between processes from different operating systems. In one aspect, an exemplary method comprises, creating a proxy process in a first Operating System (OS) for a second process, wherein the second process is from a second OS, the first and second OS being installed in respective computing environments, assigning at least one security policy to the created proxy process for monitoring delivery of messages associated with the created proxy process, where the messages are transmitted through a programming interface of the created proxy process corresponding to a programming interface of the second process, generating a security monitor for the first OS based on the created proxy process and security policies of the first OS, and monitoring the delivery of messages between at least a first process in the first OS and the second process based on the security policies.
    Type: Grant
    Filed: June 8, 2022
    Date of Patent: March 11, 2025
    Assignee: AO Kaspersky Lab
    Inventors: Stanislav V. Pinchuk, Andrey Y. Simanovsky, Sergey V. Rogachev
  • Patent number: 12184760
    Abstract: Disclosed herein are systems and methods for granting a user data processor access to a cryptocontainer of user data. In one aspect, an exemplary method comprises, creating a cryptocontainer for user's data, wherein the cryptocontainer receives at least one element of the user's data and encrypts the element; for the user data processor, establishing rights for accessing the element using a first key, and forming at least one access structure, the forming including, placing the first key in the access structure based on the established rights, receiving, from the user data processor, a second key linked to the user data processor which is to be used for accessing the first key, and encrypting the first key with the second key; and when a request for access to the cryptocontainer is received, granting, to the user data processor, access to the cryptocontainer based on the formed at least one access structure.
    Type: Grant
    Filed: June 1, 2021
    Date of Patent: December 31, 2024
    Assignee: AO Kaspersky Lab
    Inventors: Sergey V. Kozlov, Andrey A. Efremov, Dmitry V. Shmoylov, Pavel V. Filonov, Dmitry G. Ivanov
  • Patent number: 12166771
    Abstract: A method for transferring data from a first network to a second network using a gateway includes setting, by a security monitor, a state of the gateway to a first state indicating to a destination agent that access is granted to trusted memory and denied to the second network and untrusted memory. The destination agent is configured, while the gateway is in the first state, based on parameters stored in the trusted memory, to transfer data received from a source agent to the second network. The state of the gateway is changed to a second state indicating to the destination agent that access is denied to the trusted memory and granted to the second network and the untrusted memory. Transfer of the data from the source agent of the first network to the destination agent of the second network is controlled, while the gateway is in the second state.
    Type: Grant
    Filed: May 23, 2022
    Date of Patent: December 10, 2024
    Assignee: AO KASPERSKY LAB
    Inventors: Dmitry S. Lukiyan, Alexey G. Vereshchagin, Maxim A. Dontsov, Ruslan Y. Morozov, Denis S. Kashitsyn
  • Patent number: 12143358
    Abstract: A method for generating a signature of a spam message includes determining one or more classification attributes and one or more clustering attributes contained in successively intercepted first and second electronic messages. The first electronic message is classified using a trained classification model for classifying electronic messages based on the one or more classification attributes. The first electronic message is classified as spam if a degree of similarity of the first electronic message to one or more spam messages is greater than a predetermined value. A determination is made whether the first electronic message and the second electronic message belong to a single cluster based on the determined one or more clustering attributes. A signature of a spam message is generated based on the the identified single cluster of electronic messages.
    Type: Grant
    Filed: December 30, 2021
    Date of Patent: November 12, 2024
    Assignee: AO Kaspersky Lab
    Inventors: Yury G. Slobodyanuk, Dmitry S. Golubev, Alexey S. Marchenko, Alexey E. Utki-Otki
  • Patent number: 12141269
    Abstract: A method for building a security monitor includes identifying one or more objects of a microkernel Operating System (OS) participating in transmission of an Inter Process Communication (IPC) message. The one or more OS objects include one or more processes and/or one or more applications executed by the microkernel OS. One or more security policies associated with the identified microkernel OS objects are selected from a security policy database. A policy verification module is configured based on the selected security policies to generate a decision related to controlling the transmission of the IPC message. A security monitor is generated using the configured policy verification module to control the transmission of the message based on the decision generated by the policy verification module.
    Type: Grant
    Filed: April 1, 2022
    Date of Patent: November 12, 2024
    Assignee: AO Kaspersky Lab
    Inventors: Vladimir S. Burenkov, Alexander A. Bondarenko
  • Patent number: 12113826
    Abstract: A method creating a heuristic rule to identify Business Email Compromise (BEC) attacks includes filtering text of received email messages, using a first classifier, to extract one or more terms indicative of a BEC attack from the text of the received email messages, wherein the first classifier includes a trained recurrent neural network that includes a language model, generating, using the first classifier, one or more n-grams based on the extracted terms, wherein each of the n-grams characterizes a particular extracted term, generating, using a second classifier, a vector representation of the extracted terms based on the generated n-grams, assigning a weight coefficient to each of the extracted terms, wherein a higher weight coefficient indicates higher relevancy to BEC attack of the corresponding extracted term, and generating a heuristic rule associated with the BEC attack by combining the weight coefficients of a combination of the extracted terms.
    Type: Grant
    Filed: November 30, 2023
    Date of Patent: October 8, 2024
    Assignee: AO Kaspersky Lab
    Inventors: Roman A Dedenok, Nikita D. Benkovich, Dmitry S. Golubev, Yury G. Slobodyanuk