Patents by Inventor Aveek Kumar Das

Aveek Kumar Das has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 12652224
    Abstract: Device type discovery for a private network can be performed based on network address translated (NAT?d) network traffic generated from the network. A security solution analyzes data of network traffic from network devices using a binary classifier to determine whether the network traffic is from a NAT device. A network traffic dataset for a first time interval is preprocessed to generate a feature vector for the binary classifier, the output of which indicates whether the traffic is NAT?d. For NAT?d traffic, the security solution analyzes subsets of the network traffic dataset of smaller intervals within the first time interval. The security solution determines feature values from each network traffic data subset and generates feature vectors which are input to a multiclass classifier to obtain a device classification for each network traffic data subset.
    Type: Grant
    Filed: March 27, 2023
    Date of Patent: June 9, 2026
    Assignee: Palo Alto Networks, Inc.
    Inventors: Deepti Shirish Naik, Yilin Zhao, Ke Tian, Aveek Kumar Das, Sultanbek Omurzakov
  • Patent number: 12561344
    Abstract: Systems, methods, and related technologies for classification are described. Network traffic from a network may be accessed. One or more values associated with one or more properties associated with an entity may be determined. The one or more values may be determined from the network traffic. A first classification attribute is determined based on the one or more values associated with one or more properties associated with the entity. A second classification attribute is determined, by a processing device, based on the first classification attribute and the one or more values associated with one or more properties associated with the entity. The second classification attribute is stored.
    Type: Grant
    Filed: September 24, 2020
    Date of Patent: February 24, 2026
    Assignee: Forescout Technologies, Inc.
    Inventors: Arun Raghuramu, Aveek Kumar Das, Yang Zhang
  • Patent number: 12470588
    Abstract: A software bill of materials (SBOM) and vulnerability management system (“system”) disclosed herein extracts software component-related identifiers for Internet of Things (IoT) devices using deep packet inspection. The system filters the identifiers by removing identifiers that match a blacklist of identifiers known to not correspond to software components. The system then populates SBOM fields using a database storing the filtered identifiers with a schema that is uniform across SBOM file formats and queries a vulnerability database with software components indicated in the filtered identifiers to identify vulnerabilities for each IoT device for security risk assessment.
    Type: Grant
    Filed: July 21, 2023
    Date of Patent: November 11, 2025
    Assignee: Palo Alto Networks, Inc.
    Inventors: Aveek Kumar Das, Dylan Stewart Spagnuolo, Sultanbek Omurzakov, Gong Cheng, Mei Wang, Jianlin Zeng, Xu Zou
  • Patent number: 12395514
    Abstract: Systems, methods, and related technologies for determining a risk associated with a network portion are described. The determination of risk associated with a network portion may include accessing network traffic from a network and determining an entity type associated with at least one entity communicatively coupled to the network. A network portion associated with the at least one entity can be determined. A risk associated with the at least one entity can be determined. A risk associated with the network portion associated with the at least one entity can be determined based on the risk associated with the at least one entity. The risk associated with the network portion can then be stored.
    Type: Grant
    Filed: March 14, 2022
    Date of Patent: August 19, 2025
    Assignee: Forescout Technologies, Inc.
    Inventors: Arun Raghuramu, Aveek Kumar Das, Yang Zhang
  • Publication number: 20250030719
    Abstract: A software bill of materials (SBOM) and vulnerability management system (“system”) disclosed herein extracts software component-related identifiers for Internet of Things (IoT) devices using deep packet inspection. The system filters the identifiers by removing identifiers that match a blacklist of identifiers known to not correspond to software components. The system then populates SBOM fields using a database storing the filtered identifiers with a schema that is uniform across SBOM file formats and queries a vulnerability database with software components indicated in the filtered identifiers to identify vulnerabilities for each IoT device for security risk assessment.
    Type: Application
    Filed: July 21, 2023
    Publication date: January 23, 2025
    Inventors: Aveek Kumar Das, Dylan Stewart Spagnuolo, Sultanbek Omurzakov, Gong Cheng, Mei Wang, Jianlin Zeng, Xu Zou
  • Publication number: 20250030709
    Abstract: Techniques for detecting anomalous network behavior in operational technology (OT) protocols are disclosed. A system, process, and/or computer program product for detecting anomalous network behavior in OT protocols include monitoring network traffic to perform automated OT malware detection analysis of OT related network traffic, extracting one or more features from the OT related network traffic, inputting the one or more extracted features into a model for malware detection analysis, and performing an action based on a result of the model.
    Type: Application
    Filed: July 20, 2023
    Publication date: January 23, 2025
    Inventors: Ke Tian, Aveek Kumar Das, Derick Liang, Rahul Rajewar, Gong Cheng, Mei Wang
  • Publication number: 20240333613
    Abstract: Device type discovery for a private network can be performed based on network address translated (NAT?d) network traffic generated from the network. A security solution analyzes data of network traffic from network devices using a binary classifier to determine whether the network traffic is from a NAT device. A network traffic dataset for a first time interval is preprocessed to generate a feature vector for the binary classifier, the output of which indicates whether the traffic is NAT?d. For NAT?d traffic, the security solution analyzes subsets of the network traffic dataset of smaller intervals within the first time interval. The security solution determines feature values from each network traffic data subset and generates feature vectors which are input to a multiclass classifier to obtain a device classification for each network traffic data subset.
    Type: Application
    Filed: March 27, 2023
    Publication date: October 3, 2024
    Inventors: Deepti Shirish Naik, Yilin Zhao, Ke Tian, Aveek Kumar Das, Sultanbek Omurzakov
  • Publication number: 20240187426
    Abstract: Systems, methods, and related technologies for clustering are described. The method includes determining one or more clusters of entities coupled to a network, the one or more clusters of entities determined based on entity behavior and determining an anomaly associated with an entity coupled to the network based on the one or more clusters of entities.
    Type: Application
    Filed: February 9, 2024
    Publication date: June 6, 2024
    Inventors: Arun Raghuramu, Aveek Kumar Das, Yang Zhang
  • Patent number: 11902304
    Abstract: Systems, methods, and related technologies for clustering are described. The method includes determining one or more access policies associated with each of one or more clusters of entities, wherein a cluster comprises one or more entities with similar behavior. The method further includes determining one or more anomalies based on the one or more clusters, wherein the one or more access policies control communications between entities of the one or more clusters based on the one or more anomalies. The method further includes storing data associated with at least one of the one or more clusters and the one or more anomalies.
    Type: Grant
    Filed: December 8, 2022
    Date of Patent: February 13, 2024
    Assignee: Forescout Technologies, Inc.
    Inventors: Arun Raghuramu, Aveek Kumar Das, Yang Zhang
  • Publication number: 20230275818
    Abstract: Systems, methods, and related technologies for increasing data availability. The determining of one or more recommendations to improve classification may include accessing network traffic from a network and selecting an entity. One or more values associated with one or more properties associated with the entity may be determined. The one or more values may be accessed from the network traffic. The entity may be classified and in response to the classification meeting a condition, one or more properties that are unavailable in the network traffic may be determined. A data source associated with the one or more properties for which a value is not present in the network traffic may be determined and the data source associated with the one or more properties that are unavailable in the network traffic may be stored.
    Type: Application
    Filed: May 2, 2023
    Publication date: August 31, 2023
    Inventors: Arun Raghuramu, Aveek Kumar Das, Yang Zhang
  • Patent number: 11683248
    Abstract: Systems, methods, and related technologies for increasing data availability. The determining of one or more recommendations to improve classification may include accessing network traffic from a network and selecting an entity. One or more values associated with one or more properties associated with the entity may be determined. The one or more values may be accessed from the network traffic. The entity may be classified and in response to the classification meeting a condition, one or more properties that are unavailable in the network traffic may be determined. A data source associated with the one or more properties for which a value is not present in the network traffic may be determined and the data source associated with the one or more properties that are unavailable in the network traffic may be stored.
    Type: Grant
    Filed: December 20, 2019
    Date of Patent: June 20, 2023
    Assignee: FORESCOUT TECHNOLOGIES, INC.
    Inventors: Arun Raghuramu, Aveek Kumar Das, Yang Zhang
  • Publication number: 20230118017
    Abstract: Systems, methods, and related technologies for clustering are described. The method includes determining one or more access policies associated with each of one or more clusters of entities, wherein a cluster comprises one or more entities with similar behavior. The method further includes determining one or more anomalies based on the one or more clusters, wherein the one or more access policies control communications between entities of the one or more clusters based on the one or more anomalies. The method further includes storing data associated with at least one of the one or more clusters and the one or more anomalies.
    Type: Application
    Filed: December 8, 2022
    Publication date: April 20, 2023
    Inventors: Arun Raghuramu, Aveek Kumar Das, Yang Zhang
  • Patent number: 11601445
    Abstract: Systems, methods, and related technologies for clustering are described. Network traffic is accessed from a network and the network may be associated with a plurality of entities. Behavior associated with each entity of the plurality of entities may be determined. The behavior may be determined based one or more communications associated with each entity. A processing device may be used to determine one or more clusters of entities based on entities having similar behavior. A cluster may comprise one or more entities with similar behavior. One or more anomalies may be determined based on the one or more clusters and storing data associated with at least one of the one or more clusters and the one or more anomalies may be stored.
    Type: Grant
    Filed: March 31, 2020
    Date of Patent: March 7, 2023
    Assignee: FORESCOUT TECHNOLOGIES, INC.
    Inventors: Arun Raghuramu, Aveek Kumar Das, Yang Zhang
  • Publication number: 20220201032
    Abstract: Systems, methods, and related technologies for determining a risk associated with a network portion are described. The determination of risk associated with a network portion may include accessing network traffic from a network and determining an entity type associated with at least one entity communicatively coupled to the network. A network portion associated with the at least one entity can be determined. A risk associated with the at least one entity can be determined. A risk associated with the network portion associated with the at least one entity can be determined based on the risk associated with the at least one entity. The risk associated with the network portion can then be stored.
    Type: Application
    Filed: March 14, 2022
    Publication date: June 23, 2022
    Inventors: Arun Raghuramu, Aveek Kumar Das, Yang Zhang
  • Patent number: 11310258
    Abstract: Systems, methods, and related technologies for determining a risk associated with a network portion are described. The determination of risk associated with a network portion may include accessing network traffic from a network and determining an entity type associated with at least one entity communicatively coupled to the network. A network portion associated with the at least one entity can be determined. A risk associated with the at least one entity can be determined. A risk associated with the network portion associated with the at least one entity can be determined based on the risk associated with the at least one entity. The risk associated with the network portion can then be stored.
    Type: Grant
    Filed: September 25, 2019
    Date of Patent: April 19, 2022
    Assignee: FORESCOUT TECHNOLOGIES, INC.
    Inventors: Arun Raghuramu, Aveek Kumar Das, Yang Zhang
  • Publication number: 20220092087
    Abstract: Systems, methods, and related technologies for classification are described. Network traffic from a network may be accessed. One or more values associated with one or more properties associated with an entity may be determined. The one or more values may be determined from the network traffic. A first classification attribute is determined based on the one or more values associated with one or more properties associated with the entity. A second classification attribute is determined, by a processing device, based on the first classification attribute and the one or more values associated with one or more properties associated with the entity. The second classification attribute is stored.
    Type: Application
    Filed: September 24, 2020
    Publication date: March 24, 2022
    Inventors: Arun Raghuramu, Aveek Kumar Das, Yang Zhang
  • Publication number: 20210306354
    Abstract: Systems, methods, and related technologies for clustering are described. Network traffic is accessed from a network and the network may be associated with a plurality of entities. Behavior associated with each entity of the plurality of entities may be determined. The behavior may be determined based one or more communications associated with each entity. A processing device may be used to determine one or more clusters of entities based on entities having similar behavior. A cluster may comprise one or more entities with similar behavior. One or more anomalies may be determined based on the one or more clusters and storing data associated with at least one of the one or more clusters and the one or more anomalies may be stored.
    Type: Application
    Filed: March 31, 2020
    Publication date: September 30, 2021
    Inventors: Arun Raghuramu, Aveek Kumar Das, Yang Zhang
  • Publication number: 20210194785
    Abstract: Systems, methods, and related technologies for increasing data availability. The determining of one or more recommendations to improve classification may include accessing network traffic from a network and selecting an entity. One or more values associated with one or more properties associated with the entity may be determined. The one or more values may be accessed from the network traffic. The entity may be classified and in response to the classification meeting a condition, one or more properties that are unavailable in the network traffic may be determined. A data source associated with the one or more properties for which a value is not present in the network traffic may be determined and the data source associated with the one or more properties that are unavailable in the network traffic may be stored.
    Type: Application
    Filed: December 20, 2019
    Publication date: June 24, 2021
    Inventors: Arun Raghuramu, Aveek Kumar Das, Yang Zhang
  • Publication number: 20200322369
    Abstract: Systems, methods, and related technologies for determining a risk associated with a network portion are described. The determination of risk associated with a network portion may include accessing network traffic from a network and determining an entity type associated with at least one entity communicatively coupled to the network. A network portion associated with the at least one entity can be determined. A risk associated with the at least one entity can be determined. A risk associated with the network portion associated with the at least one entity can be determined based on the risk associated with the at least one entity. The risk associated with the network portion can then be stored.
    Type: Application
    Filed: September 25, 2019
    Publication date: October 8, 2020
    Inventors: Arun Raghuramu, Aveek Kumar Das, Yang Zhang
  • Patent number: 8108119
    Abstract: The present invention provides a collision avoidance apparatus and method employing stereo vision applications for adaptive vehicular control. The stereo vision applications are comprised of a road detection function and a vehicle detection and tracking function. The road detection function makes use of three-dimensional point data, computed from stereo image data, to locate the road surface ahead of a host vehicle. Information gathered by the road detection function is used to guide the vehicle detection and tracking function, which provides lead motion data to a vehicular control system of the collision avoidance apparatus. Similar to the road detection function, stereo image data is used by the vehicle detection and tracking function to determine the depth of image scene features, thereby providing a robust means for identifying potential lead vehicles in a headway direction of the host vehicle.
    Type: Grant
    Filed: April 23, 2007
    Date of Patent: January 31, 2012
    Assignee: SRI International
    Inventors: John Benjamin Southall, Mayank Bansal, Aastha Jain, Manish Kumar, Theodore Armand Camus, Aveek Kumar Das, John Richard Fields, Gary Alan Greene, Jayakrishnan Eledath