Patents Examined by Sarah Su
  • Patent number: 12705364
    Abstract: Prediction of matches between CPEs and banners greatly improves computer functioning. Many web services have an unknown common platform enumeration (CPE). When the CPE is unknown, a computer system is unable to obtain cybersecurity flaws and software fixes for a software product or web service. A similarity between the CPE and a service banner, though, accurately predicts a match the CPE and the web service. CPEs, for example, may thus be identified for old, obsolete, and uncomment software products and services.
    Type: Grant
    Filed: September 25, 2024
    Date of Patent: August 11, 2026
    Assignee: CrowdStrike, Inc.
    Inventors: Shaefer Drew, Moshe Shimon Perez, Michael Avraham Brautbar, Yotam Lichter
  • Patent number: 12699810
    Abstract: A method for operation of a personal identification information processing apparatus, according to an embodiment of the present invention, comprises the steps of: acquiring personal identification information corresponding to personal information; identifying a de-identification mode corresponding to the personal identification information; in correspondence to the personal identification information, processing an iterative hash chain a determined number of times according to the de-identification mode; configuring a relational database by using information regarding the result of the iterative hash chain and the personal identification information; and providing to a target network by replacing the information regarding the result of the iterative hash chain stored in the relational database with de-identification information of the personal identification information.
    Type: Grant
    Filed: September 26, 2024
    Date of Patent: August 4, 2026
    Assignee: LEADPOINT SYSTEM INC.
    Inventor: Eun Ju Baek
  • Patent number: 12689648
    Abstract: A method and system for mapping vulnerabilities to a private network identifier are provided. The method includes generating a request addressed to a public network identifier of a server, wherein the request includes a first beacon; transmitting the generated request to the server, wherein upon receiving the request by the server, the request causes a registry of a log file of the server, wherein the log includes at least the first beacon; in response to a query, receiving a response from the server, wherein the response includes a second beacon, and a private network identifier of the server; associating the public network identifier with the private network identifier, when the first beacon matches the second beacon; and mapping vulnerabilities identified with the public network identifier to associate the identified vulnerabilities with the associated public network identifier and the private network identifier.
    Type: Grant
    Filed: March 5, 2024
    Date of Patent: July 21, 2026
    Assignee: Cynergy Cybersecurity 2019 Ltd
    Inventors: Liran Segal, Andrey Gvozdenko, Michael Mishalov, Gil Levy, Alexander Peleg
  • Patent number: 12682053
    Abstract: A system and a method for reducing false alerts from network detection and response tools retrieves traffic data associated with a network session between a client device and a server. The traffic data includes a first set of parameters associated with the client device and a second set of parameters associated with the server. The system determines client and server entropy values based upon the retrieved traffic data. The system determines a non-empty packet value based upon the first set of parameters associated with the client device and the second set of parameters associated with the server. The system provides to a machine learning (ML) model, as an input, the client and server entropy values, and the non-empty packet value, and generates an alert based upon an output of the ML model.
    Type: Grant
    Filed: September 17, 2024
    Date of Patent: July 14, 2026
    Assignee: Vehere Interactive Pvt Ltd
    Inventors: Praveen Jaiswal, Debapriyay Mukhopadhyay, Japneet Singh Chahal
  • Patent number: 12676881
    Abstract: An indication is received that a first online platform has undergone/is undergoing a first electronic attack made by one or more actors engaged in online malicious actions with the first online platform. Responsive to the indication of the first electronic attack, one or more vulnerability characteristics of the first online platform are determined, where the vulnerability characteristics are associated with the first electronic attack. A plurality of other online platforms are analyzed to identify a second online platform that shares at least one of the vulnerability characteristics with the first online platform. Based on the determining and/or the analyzing, the second online platform is predicted to be a potential target for a second electronic attack having an attack vector in common with the first electronic attack that corresponds to the shared vulnerability characteristics. An action is performed to mitigate potential damage of the second electronic attack.
    Type: Grant
    Filed: January 26, 2024
    Date of Patent: July 7, 2026
    Assignee: PAYPAL, INC.
    Inventors: Yuri Shafet, Bradley Wardman, Ilya Chernyakov
  • Patent number: 12676878
    Abstract: A system and method for detecting a protection gap in a cybersecurity system is provided. The method includes scanning a computing environment to detect a cybersecurity monitoring system connected to the computing environment; scanning the computing environment to detect a plurality of resources deployed in the computing environment; detecting a resource of the plurality of resources which is of a first resource type; determining that the cybersecurity monitoring system is not configured to monitor the first resource type; and initiating a mitigation action in response to determining that the cybersecurity monitoring system is not configured to monitor the first resource type.
    Type: Grant
    Filed: January 10, 2024
    Date of Patent: July 7, 2026
    Assignees: Avalor Technologies, Ltd., Zscaler, Inc.
    Inventors: Kfir Aharon Tishbi, Raanan Raz
  • Patent number: 12652418
    Abstract: Aspects of a trustworthiness check of a video data stream are described. According to a first aspect, a unique identifier which identifies a media asset to which a portion of a video data stream to be checked on trustworthiness belongs, is included into the trustworthiness check. According to a second aspect, a certificate of a content provider for performing the trustworthiness check is retrieved from a track of editors stored at an external resource. A third aspect provides a method for identifying a portion of a video data stream to be checked on trustworthiness using a digital signature. According to a fourth aspect, a digital signature for checking a portion of a video data stream is retrieved from an external resource.
    Type: Grant
    Filed: August 15, 2025
    Date of Patent: June 9, 2026
    Assignee: Fraunhofer-Gesellschaft zur Foerderung der angewandten Forschung e.V.
    Inventors: Jonathan Pfaff, Tobias Hinz, Karsten Suehring, Heiko Schwarz, Karsten Grueneberg, Robert Skupin, Yago Sánchez De La Fuente, Cornelius Hellge, Thomas Schierl, Detlev Marpe, Thomas Wiegand
  • Patent number: 12652309
    Abstract: A method for providing cyber security measures in a shared network estimates in a probabilistic model, a likelihood of a cybersecurity event occurring in a system. Based on the estimated likelihood selectively applies some but not all of the cyber security measures. Based constraints of system resources available for operations a combination discretionary security measures are selected for execution. During runtime of the system, security risk of an aspect of the system is periodically evaluated causing reconfiguration of the security measures for execution based on the estimated security risk and system resources available for operations. Timed automata corresponding to security threats are assigned a risk score associated with the security threat based on one or more states of the automata. An aggregation of multiple risk scores produces a trust score for the overall system. A number of security measures may be selected and allocated based on the trust score.
    Type: Grant
    Filed: August 3, 2023
    Date of Patent: June 9, 2026
    Assignee: Siemens Corporation
    Inventors: Valerio Formicola, Charif Mahmoudi, Shashank Shekhar
  • Patent number: 12645815
    Abstract: Masking a data rate of transmitted data is disclosed. As data is transmitted from a production site to a secondary site, the data rate is masked. Masking the data rate can include transmitting at a fixed rate, a random rate, or an adaptive rate. Each mode of data transmission masks or obscures the actual data rate and thus prevents others from gaining information about the data or the data owner from the data transfer rate.
    Type: Grant
    Filed: June 21, 2024
    Date of Patent: June 2, 2026
    Assignee: EMC IP Holding Company LLC
    Inventors: Amos Zamir, Jehuda Shemer, Kfir Wolfson
  • Patent number: 12647450
    Abstract: The present disclosure relates to a remote attestation in a network. Embodiments provide a method comprising: attesting a first node in a network, by a node adjacent to the first node in the network; and generating an attestation result of the first node. A plurality of attestation results of the first node generated by a plurality of nodes adjacent to the first node in the network are combined to determine a credibility of the first node. In such embodiments, a fixed verifier for other nodes is eliminated, and a risk of a collapse due to a failure of such fixed verifier may be avoided.
    Type: Grant
    Filed: September 10, 2024
    Date of Patent: June 2, 2026
    Assignee: Nokia Technologies Oy
    Inventors: Anmin Fu, Jingyu Feng
  • Patent number: 12634321
    Abstract: Methods, systems, and devices for large language model (LLM) based security insights and/or recommendations at a data security system are described. A data security system may obtain event information associated with monitored computing assets and/or user accounts for a client or customer of the data security system. The data security system may filter the event information and associated computing asset and/or user account information in accordance with a security policy for the client and may generate a prompt for an LLM based on the filtered event and computing asset and/or user account information. The data security system may provide the prompt to the LLM, and the LLM may provide a natural language response to the prompt that provides a security action recommendation to resolve one or more events and/or insights such as a rationale for the security action recommendation and/or an explanation of threats associated with the event.
    Type: Grant
    Filed: June 24, 2025
    Date of Patent: May 19, 2026
    Inventors: Joel M. Fulton, Jeremy Sherwood, Shuning Wu
  • Patent number: 12634333
    Abstract: A system and a method are disclosed for generating protection actions to protect a target application. The system scans a target application to detect a potential risk associated with one or more chunks of code in the target application and determines configuration information of the one or more chunks of code. The system may input scanning results and the configuration information into machine learning models and receive an output including the one or more protection actions. The system applies the protection actions to the target application. Responsive to completing the one or more protection actions, the system re-scans the target application to determine a result of applying the one or more protection actions on the target application.
    Type: Grant
    Filed: July 15, 2025
    Date of Patent: May 19, 2026
    Assignee: Zimperium, Inc.
    Inventors: Grant Stewart Goodes, Nicolás Chiaraviglio, Jonathan Paterson
  • Patent number: 12627700
    Abstract: Techniques, systems, and computer-readable media for dynamic behavior-based asset classification are described herein. An asset classification system can detect and receive data associated with a host computer, determine, based on the data, a behavior associated with the host computer, assign the host computer a server classification based on the determination that the behavior represents a behavior of focus, and record the assigned server classification associated with the host computer. In various examples, the asset classification system can determine the behavior is a behavior of focus based on one or more of: a number of connections to other computers associated with a shared customer identifier, a number of unique other host computers connecting to the host computer, and/or a number of unique non-local accounts that have logged in to the host computer, and that the host computer has had an inbound connection on a common port.
    Type: Grant
    Filed: December 19, 2023
    Date of Patent: May 12, 2026
    Assignee: CrowdStrike, Inc.
    Inventors: Ryan Inghilterra, Shaefer Drew, Michael Brautbar
  • Patent number: 12627515
    Abstract: A device may maintain, as a member of a two blockchain networks respective first and second blockchains. The first blockchain may include one or more sets of operations, and the second blockchain may include cross-chain authorization information. The device may identify a request to invoke a particular set of operations included in the first blockchain, where the request includes a set of input parameters and an identifier. The device may determine that the identifier satisfies the cross-chain authorization information included in the second blockchain, and may accordingly communicate with the second blockchain network to execute the particular set of operations. Executing the particular set of operations may include generating a set of output parameters. The device may output the set of output parameters in response to the request.
    Type: Grant
    Filed: January 23, 2024
    Date of Patent: May 12, 2026
    Assignee: Verizon Patent and Licensing Inc.
    Inventors: Ahmed A. Khan, Nityanand Sharma, Mohammed Alsadi
  • Patent number: 12627699
    Abstract: A computer-implemented method comprises establishing a database based at least in part on network traffic data received from a network, detecting adversarial behavior within the network traffic data, identifying an adversary associated with the adversarial behavior, determining a plurality of specific indicators of compromise that are associated with the adversary that has been identified, constructing a query based on the plurality of specific indicators of compromise, submitting the query to search for the plurality of specific indicators of compromise within the network traffic data, searching for the plurality of specific indicators of compromise within the network traffic data, and generating, responsive to having located at least one potential indicator of compromise, a search report containing at least one specific indicator of compromise and displaying the search report to a user interface.
    Type: Grant
    Filed: June 6, 2023
    Date of Patent: May 12, 2026
    Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
    Inventor: Dineshkumar Ramnath Barai
  • Patent number: 12627703
    Abstract: Embodiments of this application provide a method for obtaining a security classification result for a location area. A security function network element receives an identifier of a target location area and determines to perform security analytics on the target location area based on the identifier of the target location area. The security function network element may determine a security classification result of the target location area based on first information, where the security classification result indicates a degree to which a potential attack exists in the target location area. The first information is related to behavior information of a terminal device in the target location area, where the behavior information includes traffic data and/or movement track information.
    Type: Grant
    Filed: May 9, 2024
    Date of Patent: May 12, 2026
    Assignee: HUAWEI TECHNOLOGIES CO., LTD.
    Inventors: Ao Lei, Yizhuang Wu, Yang Cui, Taoran Sun
  • Patent number: 12621327
    Abstract: An enterprise network has network assets, with each network asset having a network interface. A network graph has the network assets as nodes and connections between network interfaces of network assets as edges. An activity graph has nodes and edges, with each node representing a logical resource that performs an activity on the enterprise network, and each edge representing a relationship between the logical resources. Subgraphs of the activity graph are aligned to subgraphs of the network graph to create a mapping based on network assets associated with activities. Activity subgraphs that are aligned to the same network subgraph are compared for similarity to detect anomalous activities. The network graph is displayed at different hierarchical levels as a visualization on a display screen, with risk assessments overlayed on corresponding nodes on the visualization.
    Type: Grant
    Filed: February 20, 2024
    Date of Patent: May 5, 2026
    Assignee: Trend Micro Incorporated
    Inventors: Michael Dysart, Partheeban Chandrasekaran
  • Patent number: 12621345
    Abstract: Methods and systems are described herein for protecting client data while training machine learning models. The system may transmit, to client devices, simple models to be trained on a respective client device to generate predictions based on a respective subset of respective client data of the respective client device. The system may receive the trained simple models from the client devices. The system may input, into an ensemble model including the simple models, an unlabeled synthetic dataset. This may cause the ensemble model to aggregate a set of predictions generated by each simple model to generate labels for the unlabeled synthetic dataset. The system may then input, into a new model, the unlabeled synthetic dataset and the labels to train the new model to predict the labels for the unlabeled synthetic dataset.
    Type: Grant
    Filed: September 9, 2024
    Date of Patent: May 5, 2026
    Assignee: Capital One Services, LLC
    Inventors: Jeremy Goodsitt, Michael Davis, Taylor Turner, Kenny Bean, Tyler Farnan
  • Patent number: 12608493
    Abstract: Systems and methods for mutual trust establishment among components of an Information Handling System (IHS) are described. In an illustrative, non-limiting embodiment, an IHS may include: at least one processor; and at least one memory coupled to the processor, wherein the at least one memory comprises program instructions stored thereon that, upon execution by the at least one processor, cause the at least one processor to: obtain a plurality of identifiers for a respective plurality of CPLDs or FPGAs, including an identifier for a first CPLD or FPGA; and provide to a second CPLD or FPGA an expected handshake token for the first CPLD or FPGA, wherein the expected handshake token is based, at least in part, on the identifier for the first CPLD or FPGA, and wherein the second CPLD or FPGA uses the expected handshake token to establish trust for communication with the first CPLD or FPGA.
    Type: Grant
    Filed: October 20, 2023
    Date of Patent: April 21, 2026
    Assignee: Dell Products, L.P.
    Inventors: Eugene David Cho, Milton Olavo Decarvalho Taveira, Travis Gilbert, Mukund P. Khatri
  • Patent number: 12602496
    Abstract: In an example, a hypervisor measuring the state of a protected virtual machine using a Trusted Platform Module (TPM) filter. Using the TPM filter, the system ensures an untrusted operating system attempting to access the TPM is secure, without having to trust the security of the operating system or the operating system's built in hypervisor.
    Type: Grant
    Filed: July 7, 2023
    Date of Patent: April 14, 2026
    Assignee: Hewlett-Packard Development Company, L.P.
    Inventors: Adrian Laurence Shaw, Remy Husson, Adrian John Baldwin, Joshua Serratelli Schiffman, Christopher Ian Dalton