Patents by Inventor Baris Coskun

Baris Coskun has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 12210622
    Abstract: Systems and methods for performing anomalous activity monitoring for a service provider network are disclosed. In response to receiving an activity log, a machine learning-based activity monitor may parse the activity log into segments, generate event objects from a segment of the activity log, encode the event objects, and then reconstruct the event objects based on decoding the encoded event objects. The encoding and decoding may be performed based on a model that was trained using training data with no known malicious activity. The event objects may comprise at least two or more event defining characteristics and an event count. By comparing the reconstructed event objects to corresponding initial versions of the event objects, the machine learning-activity monitor may determine an anomaly score and may provide an indication of events determined to be anomalous based on the score.
    Type: Grant
    Filed: December 13, 2022
    Date of Patent: January 28, 2025
    Assignee: Amazon Technologies, Inc.
    Inventors: Zhilu Zhang, Qian Cui, Baris Coskun, Wei Ding
  • Patent number: 12204645
    Abstract: Disclosed are systems and methods to compare two or more machine learning models to determine the comparative performance of those models. Markers may be assigned to data items and data item marker scores generated for those data items, independent of the machine learning models. Each of the machine learning models to be compared may then process the data items and generate respective model scores for those data items. A sub-set of the data items may then be generated for each machine learning model based on the model scores assigned to the data items by the respective model. A model marker score may then be computed for each machine learning model based on the marker scores assigned to each of the data items of the sub-set of data items determined for each model. Finally, the model marker scores may be compared to determine which machine learning model has the highest performance.
    Type: Grant
    Filed: November 16, 2021
    Date of Patent: January 21, 2025
    Assignee: Amazon Technologies, Inc.
    Inventors: MohamadAli Torkamani, Bhavna Soman, Jeffrey Earl Bickford, Baris Coskun
  • Patent number: 12028362
    Abstract: Techniques for enabling the identification of anomalous events associated with an object storage service of a cloud provider network using a variational autoencoder model including a pre-trained embedding for selected features of events are described. A variational autoencoder, for example, encodes data into a latent space and reconstructs approximations of the data from an encoding in the latent space. In this context, for example, anomalous events of interest might represent unauthorized or abusive behavior associated with storage resources provided by an object storage service (or in association with other types of computing resources provided by other services of a cloud provider network). Legitimate (or benign) access patterns to an object storage service can be modeled by utilizing observed data plane events stored by an account activity monitoring service. Once trained, the model can be used to identify anomalous events.
    Type: Grant
    Filed: December 8, 2020
    Date of Patent: July 2, 2024
    Assignee: Amazon Technologies, Inc.
    Inventors: Qian Cui, Wei Ding, Oleg Yurievich Polyakov, Baris Coskun
  • Patent number: 11743282
    Abstract: Devices, systems, and methods are provided for cloud-based entity reputation scoring. A method may include determining, based on domain name service (DNS) data associated with entities of the cloud-based environment, a k-partite graph with nodes and edges, a node including a first elastic computing instance. The method may include generating features associated with the first elastic computing instance. The method may include determining, based on the features, a minimum value, a maximum value, and an average value, and generating a feature vector comprising the minimum value, the maximum value, and the average value. The method may include determining, based on the feature vector, a reputation score associated with the first elastic computing instance. The method may include communicating based on the reputation score.
    Type: Grant
    Filed: September 24, 2020
    Date of Patent: August 29, 2023
    Assignee: Amazon Technologies, Inc.
    Inventors: MohamadAli Torkamani, Baris Coskun, Jeffrey Earl Bickford, Shane Anil Pereira
  • Patent number: 11593639
    Abstract: Techniques for monitoring a computing environment for anomalous activity are presented. An example method includes receiving a request to invoke an action within the computing environment. An anomaly score is generated for the received request by applying a probabilistic model to properties of the request. The anomaly score generally indicates a likelihood that the properties of the request correspond to historical activity within the computing environment for a user associated with the request. The probabilistic model generally comprises a model having been trained using historical activity within the computing environment for a plurality of users, the historical activity including information identifying an action performed in the computing environment and contextual information about a historical request.
    Type: Grant
    Filed: September 3, 2019
    Date of Patent: February 28, 2023
    Assignee: Amazon Technologies, Inc.
    Inventors: Pranav Garg, Baris Coskun
  • Patent number: 11537902
    Abstract: Systems, devices, and methods are provided for detecting anomalous events from categorical data using autoencoders. A system may receive a data set associated with actions requested within the computing environment, wherein the data set includes first categorical data indicative of anomalous activity in the computing environment. The system may train an autoencoder to reconstruct approximations of requests associated with the computing environment based on the received data set, wherein training the autoencoder includes using a beta divergence and a maximum mean discrepancy divergence. The trained system may receive a request to invoke an action within the computing environment, may generate a reconstruction of the request to invoke the action using the trained autoencoder, may determine a normalcy score based on a probability that the reconstruction of the request exists in the training data set, and, based on the calculated normalcy score, may determine whether requests indicate anomalous data.
    Type: Grant
    Filed: June 25, 2020
    Date of Patent: December 27, 2022
    Assignee: Amazon Technologies, Inc.
    Inventors: Sergul Aydore, Baris Coskun, Luca Melis
  • Patent number: 11374952
    Abstract: Techniques for monitoring a computing environment for anomalous activity are presented. An example method includes receiving a request to invoke an action within a computing environment, with the request including a plurality of request attributes and a plurality of contextual attributes. A normalcy score is generated for the received request by encoding the received request into a code in latent space of an autoencoder, reconstructing the request from the code, and generating a probability distribution indicating a likelihood that the reconstructed request attributes exist in a data set of non-anomalous activity. Based on the calculated normalcy score, one or more actions are taken to process the request such that execution of non-anomalous requests is allowed, and execution of potentially anomalous requests may be blocked pending confirmation.
    Type: Grant
    Filed: September 27, 2019
    Date of Patent: June 28, 2022
    Assignee: Amazon Technologies, Inc.
    Inventors: Baris Coskun, Wei Ding, Luca Melis
  • Publication number: 20210344632
    Abstract: A method of generating a signature for a group of electronic messages that each include a plurality of characters comprises extracting a plurality of blocks of characters from each of the electronic messages, mathematically processing each of the blocks of characters from each electronic message, and generating a signature for the group of electronic messages based at least in part on the mathematically processed blocks of characters. In some embodiments a counting Bloom filter may be used to generate the signature. The signatures generated by these methods may be used to identify spam.
    Type: Application
    Filed: July 15, 2021
    Publication date: November 4, 2021
    Applicant: AT&T Intellectual Property I, L.P.
    Inventors: Paul Giura, Baris Coskun
  • Patent number: 11095586
    Abstract: A method of generating a signature for a group of electronic messages that each include a plurality of characters comprises extracting a plurality of blocks of characters from each of the electronic messages, mathematically processing each of the blocks of characters from each electronic message, and generating a signature for the group of electronic messages based at least in part on the mathematically processed blocks of characters. In some embodiments a counting Bloom filter may be used to generate the signature. The signatures generated by these methods may be used to identify spam.
    Type: Grant
    Filed: May 17, 2019
    Date of Patent: August 17, 2021
    Assignee: AT&T Intellectual Property I, L.P.
    Inventors: Paul Giura, Baris Coskun
  • Patent number: 10708288
    Abstract: Disclosed are systems and methods for improving interactions with and between computers in content searching, generating, hosting and/or providing systems supported by or configured with personal computing devices, servers and/or platforms. The systems interact to identify and retrieve data within or across platforms, which can be used to improve the quality of data used in processing interactions between or among processors in such systems. The disclosed systems and methods provide a novel clustering framework applied on datasets of network interactions to automatically identify IP clusters carrying out a specific task(s) based on an IP blacklist. The disclosed systems and methods can analyze network activity of devices associated with the IP addresses, and/or the IP addresses themselves, and perform an automatic, on-the-spot analysis that results in a determination whether the activity is permitted on or over a network.
    Type: Grant
    Filed: January 22, 2019
    Date of Patent: July 7, 2020
    Assignee: OATH INC.
    Inventor: Baris Coskun
  • Patent number: 10659492
    Abstract: Mitigation of bot networks in wireless networks and/or on mobile devices is provided. A botnet detection component is provided that inspects data traffic and data flows on the wireless network to identify mobile devices that are suspected of behaving as bots. A traffic profile of the suspected bot behavior can be generated and forwarded to the mobile devices that are suspected of behaving as bots. The mobile device can correlate data traffic on the device to the traffic profile in order to identify applications responsible for the suspected bot behavior, and remove the identified applications.
    Type: Grant
    Filed: November 12, 2015
    Date of Patent: May 19, 2020
    Assignee: AT&T INTELLECTUAL PROPERTY I, L.P.
    Inventors: Arati Baliga, Baris Coskun
  • Patent number: 10636048
    Abstract: Communication accounts may contain information such as account holder names, contact lists, and communication logs. Such information may be processed for generating features that may be used as corpus for a machine learning algorithm for developing classifiers of names. Specifically, names and contact names of the accounts may be arranged in to a document according to the manner in which account holders communicate with the contacts. The document may be used for generating word embedding of the names. Names prelabeled with ethnicity together with their word embedding may be used as training data for developing ethnicity classifiers based on machine learning algorithms.
    Type: Grant
    Filed: January 27, 2017
    Date of Patent: April 28, 2020
    Assignee: Oath Inc.
    Inventors: Junting Ye, Yifan Hu, Baris Coskun, Meizhu Liu, Steven Skiena
  • Patent number: 10419992
    Abstract: Methods and apparatus to migrate a mobile device from a first virtual private mobile network to a second virtual private mobile network are disclosed. An example apparatus includes a processor and a memory including instructions that cause the processor to perform operations including determining, based on a set of latency routing rules, that a communication transmitted via the first virtual private mobile network is a latency sensitive communication. In response to determining the communication is a latency sensitive communication, the mobile device that originated the latency sensitive communication is identified. The mobile device is communicating via the first virtual private mobile network. Example operations also include migrating the mobile device from the first virtual private mobile network to the second virtual private mobile network wherein the second virtual private mobile network is configured to reduce the latency of the latency sensitive communication.
    Type: Grant
    Filed: August 8, 2016
    Date of Patent: September 17, 2019
    Assignee: AT&T Intellectual Property I, L.P.
    Inventors: Jacobus Van der Merwe, Xu Chen, Baris Coskun, Gustavo de los Reyes, Seungjoon Lee, Suhas Mathur, Arati Baliga, Gang Xu
  • Publication number: 20190281000
    Abstract: A method of generating a signature for a group of electronic messages that each include a plurality of characters comprises extracting a plurality of blocks of characters from each of the electronic messages, mathematically processing each of the blocks of characters from each electronic message, and generating a signature for the group of electronic messages based at least in part on the mathematically processed blocks of characters. In some embodiments a counting Bloom filter may be used to generate the signature. The signatures generated by these methods may be used to identify spam.
    Type: Application
    Filed: May 17, 2019
    Publication date: September 12, 2019
    Applicant: AT&T Intellectual Property I, L.P.
    Inventors: Paul Giura, Baris Coskun
  • Patent number: 10333877
    Abstract: A method of generating a signature for a group of electronic messages that each include a plurality of characters comprises extracting a plurality of blocks of characters from each of the electronic messages, mathematically processing each of the blocks of characters from each electronic message, and generating a signature for the group of electronic messages based at least in part on the mathematically processed blocks of characters. In some embodiments a counting Bloom filter may be used to generate the signature. The signatures generated by these methods may be used to identify spam.
    Type: Grant
    Filed: April 29, 2014
    Date of Patent: June 25, 2019
    Assignee: AT&T INTELLECTUAL PROPERTY I, L.P.
    Inventors: Paul Giura, Baris Coskun
  • Publication number: 20190158526
    Abstract: Disclosed are systems and methods for improving interactions with and between computers in content searching, generating, hosting and/or providing systems supported by or configured with personal computing devices, servers and/or platforms. The systems interact to identify and retrieve data within or across platforms, which can be used to improve the quality of data used in processing interactions between or among processors in such systems. The disclosed systems and methods provide a novel clustering framework applied on datasets of network interactions to automatically identify IP clusters carrying out a specific task(s) based on an IP blacklist. The disclosed systems and methods can analyze network activity of devices associated with the IP addresses, and/or the IP addresses themselves, and perform an automatic, on-the-spot analysis that results in a determination whether the activity is permitted on or over a network.
    Type: Application
    Filed: January 22, 2019
    Publication date: May 23, 2019
    Inventor: Baris COSKUN
  • Patent number: 10193900
    Abstract: Methods, apparatus, systems and articles of manufacture are disclosed to identify candidate boundaries of Internet protocol addresses associated with a malicious Internet protocol address. An example method includes collecting, with a processor, netflow data associated with the Internet protocol addresses within a netblock having a lower boundary Internet protocol address and an upper boundary Internet protocol address, generating, with the processor, a first window of Internet protocol addresses numerically lower than the malicious Internet protocol address, generating, with the processor, a second window of Internet protocol addresses numerically higher than the malicious Internet protocol address, for respective Internet protocol addresses in the first and second windows, calculating, with the processor, occurrence counts associated with behavior features, and identifying candidate boundaries within the netblock based on divergence values caused by the behavior features.
    Type: Grant
    Filed: July 7, 2015
    Date of Patent: January 29, 2019
    Assignee: AT&T INTELLECTUAL PROPERTY I., L.P.
    Inventors: Baris Coskun, Suhrid Balakrishnan, Suhas Mathur
  • Patent number: 10193915
    Abstract: Disclosed are systems and methods for improving interactions with and between computers in content searching, generating, hosting and/or providing systems supported by or configured with personal computing devices, servers and/or platforms. The systems interact to identify and retrieve data within or across platforms, which can be used to improve the quality of data used in processing interactions between or among processors in such systems. The disclosed systems and methods provide a novel clustering framework applied on datasets of network interactions to automatically identify IP clusters carrying out a specific task(s) based on an IP blacklist. The disclosed systems and methods can analyze network activity of devices associated with the IP addresses, and/or the IP addresses themselves, and perform an automatic, on-the-spot analysis that results in a determination whether the activity is permitted on or over a network.
    Type: Grant
    Filed: September 30, 2016
    Date of Patent: January 29, 2019
    Assignee: OATH INC.
    Inventor: Baris Coskun
  • Patent number: 10069799
    Abstract: Methods and apparatus to configure virtual private mobile networks are disclosed. Example methods include provisioning a virtual private mobile network within a wireless network, and, after provisioning the virtual private mobile network, determining whether a first communication from a user equipment matches a security event profile. When the first communication matches the profile, the example methods include transmitting, from the wireless network via a first base transceiver station, an instruction to cause the user equipment to be communicatively coupled to the virtual private mobile network. The example methods further include instructing the user equipment to transmit a second communication through a second base transceiver station that is physically separate from the first base transceiver station and through the virtual private mobile network. In the example methods, the virtual private mobile network is isolated in a wireless spectrum from other portions of the network.
    Type: Grant
    Filed: June 27, 2016
    Date of Patent: September 4, 2018
    Assignee: AT&T Intellectual Property I, L.P.
    Inventors: Arati Baliga, Xu Chen, Baris Coskun, Gustavo de los Reyes, Seungjoon Lee, Suhas Mathur, Jacobus Van der Merwe, Gang Xu
  • Patent number: 10044678
    Abstract: Methods and apparatus to configure virtual private mobile networks with virtual private networks are disclosed. A disclosed example method includes logically provisioning, for a client, the virtual private mobile network to process wireless network communications associated with the client that correspond to a specified address space of the client, provisioning at least a portion of a server within a cloud computing data center to host resources for the client, and configuring at least a portion of an edge router of the cloud computing data center to transmit the wireless network communications between the portion of the server and the virtual private mobile network.
    Type: Grant
    Filed: August 31, 2011
    Date of Patent: August 7, 2018
    Assignee: AT&T INTELLECTUAL PROPERTY I, L.P.
    Inventors: Jacobus Van der Merwe, Arati Baliga, Xu Chen, Baris Coskun, Gustavo de los Reyes, Seungjoon Lee, Suhas Mathur, Gang Xu