Patents by Inventor Alfonso De Jesus Valdes

Alfonso De Jesus Valdes has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 9407509
    Abstract: A method of network surveillance includes receiving network packets handled by a network entity and building at least one long-term and at least one short-term statistical profile from a measure of the network packets that monitors data transfers, errors, or network connections. A comparison of the statistical profiles is used to determine whether the difference between the statistical profiles indicates suspicious network activity.
    Type: Grant
    Filed: September 21, 2009
    Date of Patent: August 2, 2016
    Assignee: SRI International
    Inventors: Phillip Andrew Porras, Alfonso De Jesus Valdes
  • Publication number: 20120210425
    Abstract: A method of network surveillance includes receiving network packets handled by a network entity and building at least one long-term and at least one short-term statistical profile from a measure of the network packets that monitors data transfers, errors, or network connections. A comparison of the statistical profiles is used to determine whether the difference between the statistical profiles indicates suspicious network activity.
    Type: Application
    Filed: April 20, 2012
    Publication date: August 16, 2012
    Applicant: SRI INTERNATIONAL
    Inventors: Phillip Andrew Porras, Alfonso de Jesus Valdes
  • Patent number: 7917393
    Abstract: This invention uses probabilistic correlation techniques to increase sensitivity, reduce false alarms, and improve alert report quality in intrusion detection systems. In one preferred embodiment, an intrusion detection system includes at least two sensors to monitor different aspects of a computer network, such as a sensor that monitors network traffic and a sensor that discovers and monitors available network resources. The sensors are correlated in that the belief state of one sensor is used to update or modify the belief state of another sensor. In another embodiment of this invention, probabilistic correlation techniques are used to organize alerts generated by different sensors in an intrusion detection system.
    Type: Grant
    Filed: August 31, 2001
    Date of Patent: March 29, 2011
    Assignee: SRI International, Inc.
    Inventors: Alfonso De Jesus Valdes, Keith Skinner
  • Publication number: 20100050248
    Abstract: A method of network surveillance includes receiving network packets handled by a network entity and building at least one long-term and at least one short-term statistical profile from a measure of the network packets that monitors data transfers, errors, or network connections. A comparison of the statistical profiles is used to determine whether the difference between the statistical profiles indicates suspicious network activity.
    Type: Application
    Filed: September 21, 2009
    Publication date: February 25, 2010
    Applicant: SRI International
    Inventors: Phillip Andrew Porras, Alfonso De Jesus Valdes
  • Patent number: 7379993
    Abstract: This invention uses Bayesian techniques to prioritize alerts or alert groups generated by intrusion detection systems and other information security devices, such as network analyzers, network monitors, firewalls, antivirus software, authentication services, host and application security services, etc. In a preferred embodiment, alerts are examined for the presence of one or more relevant features, such as the type of an attack, the target of an attack, the outcome of an attack, etc. At least a subset of the features is then provided to a real-time Bayes network, which assigns relevance scores to the received alerts or alert groups. In another embodiment, a network manager (a person) can disagree with the relevance score assigned by the Bayes network, and give an alert or alert group a different relevance score. The Bayes network is then modified so that similar future alerts or alert groups will be assigned a relevance score that more closely matches the score given by the network manager.
    Type: Grant
    Filed: September 13, 2001
    Date of Patent: May 27, 2008
    Assignee: SRI International
    Inventors: Alfonso De Jesus Valdes, Martin Wayne Fong, Phillip Andrew Porras
  • Publication number: 20030093514
    Abstract: This invention uses Bayesian techniques to prioritize alerts or alert groups generated by intrusion detection systems and other information security devices, such as network analyzers, network monitors, firewalls, antivirus software, authentication services, host and application security services, etc. In a preferred embodiment, alerts are examined for the presence of one or more relevant features, such as the type of an attack, the target of an attack, the outcome of an attack, etc. At least a subset of the features is then provided to a real-time Bayes network, which assigns relevance scores to the received alerts or alert groups. In another embodiment, a network manager (a person) can disagree with the relevance score assigned by the Bayes network, and give an alert or alert group a different relevance score. The Bayes network is then modified so that similar future alerts or alert groups will be assigned a relevance score that more closely matches the score given by the network manager.
    Type: Application
    Filed: September 13, 2001
    Publication date: May 15, 2003
    Inventors: Alfonso De Jesus Valdes, Martin Wayne Fong, Phillip Andrew Porras
  • Publication number: 20020059078
    Abstract: This invention uses probabilistic correlation techniques to increase sensitivity, reduce false alarms, and improve alert report quality in intrusion detection systems. In one preferred embodiment, an intrusion detection system includes at least two sensors to monitor different aspects of a computer network, such as a sensor that monitors network traffic and a sensor that discovers and monitors available network resources. The sensors are correlated in that the belief state of one sensor is used to update or modify the belief state of another sensor. In another embodiment of this invention, probabilistic correlation techniques are used to organize alerts generated by different sensors in an intrusion detection system.
    Type: Application
    Filed: August 31, 2001
    Publication date: May 16, 2002
    Inventors: Alfonso De Jesus Valdes, Keith Skinner