Patents by Inventor Bhushan Prasad Khanal
Bhushan Prasad Khanal has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Patent number: 12355816Abstract: Embodiments are directed to monitoring network traffic using network monitoring computers (NMCs). Anomalous events may be classified based on the monitored network traffic and attack models such that the classification determines that targets of the anomalous events may be currently subject to attacks by entities communicating on the networks. A honeypot trap may be provided in the networks based on the classified events such that the honeypot trap mimics characteristics of the targets. The portions of the network traffic associated with the honeypot trap may be monitored. Characteristics of the attacks may be determined based on the monitored portions of network traffic. Reports that include information based on the characteristics of the attacks may be generated.Type: GrantFiled: September 30, 2024Date of Patent: July 8, 2025Assignee: ExtraHop Networks, Inc.Inventors: Xue Jun Wu, Bhushan Prasad Khanal, Swagat Dasgupta, Changhwan Oh, J. Braund
-
Publication number: 20250023914Abstract: Embodiments are directed to monitoring network traffic using network monitoring computers (NMCs). Anomalous events may be classified based on the monitored network traffic and attack models such that the classification determines that targets of the anomalous events may be currently subject to attacks by entities communicating on the networks. A honeypot trap may be provided in the networks based on the classified events such that the honeypot trap mimics characteristics of the targets. The portions of the network traffic associated with the honeypot trap may be monitored. Characteristics of the attacks may be determined based on the monitored portions of network traffic. Reports that include information based on the characteristics of the attacks may be generated.Type: ApplicationFiled: September 30, 2024Publication date: January 16, 2025Inventors: Xue Jun Wu, Bhushan Prasad Khanal, Swagat Dasgupta, Changhwan Oh, J. Braund
-
Patent number: 12107888Abstract: Embodiments are directed to monitoring network traffic using network monitoring computers (NMCs). Anomalous events may be classified based on the monitored network traffic and attack models such that the classification determines that targets of the anomalous events may be currently subject to attacks by entities communicating on the networks. A honeypot trap may be provided in the networks based on the classified events such that the honeypot trap mimics characteristics of the targets. The portions of the network traffic associated with the honeypot trap may be monitored. Characteristics of the attacks may be determined based on the monitored portions of network traffic. Reports that include information based on the characteristics of the attacks may be generated.Type: GrantFiled: November 1, 2021Date of Patent: October 1, 2024Assignee: ExtraHop Networks, Inc.Inventors: Xue Jun Wu, Bhushan Prasad Khanal, Swagat Dasgupta, Changhwan Oh, J. Braund
-
Patent number: 11496378Abstract: Embodiments are directed to monitoring network traffic using a monitoring engine that monitors network traffic in networks to provide metrics. An inference engine may provide activity profiles based on portions of the network traffic where each activity profile includes features associated with the portions of network traffic. The inference engine may determine other activity profiles correlated with the activity profiles based on correlation models such that the determination of the other activity profiles occurs prior to monitoring an occurrence of other portions of the network traffic. The inference engine may modify monitoring actions of the monitoring engine based on the other activity profiles. The inference engine may provide reports based on the portions of the network traffic, the activity profiles, the other portions of the network traffic, or the other activity profiles.Type: GrantFiled: May 12, 2021Date of Patent: November 8, 2022Assignee: ExtraHop Networks, Inc.Inventors: Eric Jacob Ball, Eric Joseph Hammerle, Benjamin Thomas Higgins, Bhushan Prasad Khanal, Michael Kerber Krause Montague, Xue Jun Wu
-
Patent number: 11463299Abstract: Embodiments are directed to monitoring network traffic. A monitoring engine may monitor network traffic associated with a plurality of entities in networks to provide metrics. And provide a device relation model based on the plurality of entities, the network traffic, and the metrics. An inference engine may associate each entity in the plurality of entities with an importance score based on the device relation model and the metrics such that each importance score is associated with a significance of an entity to operations of the networks. An alert engine may generate a plurality of alerts associated with the plurality of entities based on the metrics. And provide one or more alerts from the plurality of alerts to one or more users based on one or more ranked importance scores associated with one or more entities.Type: GrantFiled: April 9, 2021Date of Patent: October 4, 2022Assignee: ExtraHop Networks, Inc.Inventors: Xue Jun Wu, Nicholas Jordan Braun, Joel Benjamin Deaguero, Michael Kerber Krause Montague, Bhushan Prasad Khanal
-
Publication number: 20220070073Abstract: Embodiments are directed to monitoring network traffic using a monitoring engine that monitors network traffic in networks to provide metrics. An inference engine may provide activity profiles based on portions of the network traffic where each activity profile includes features associated with the portions of network traffic. The inference engine may determine other activity profiles correlated with the activity profiles based on correlation models such that the determination of the other activity profiles occurs prior to monitoring an occurrence of other portions of the network traffic. The inference engine may modify monitoring actions of the monitoring engine based on the other activity profiles. The inference engine may provide reports based on the portions of the network traffic, the activity profiles, the other portions of the network traffic, or the other activity profiles.Type: ApplicationFiled: May 12, 2021Publication date: March 3, 2022Inventors: Eric Jacob Ball, Eric Joseph Hammerle, Benjamin Thomas Higgins, Bhushan Prasad Khanal, Michael Kerber Krause Montague, Xue Jun Wu
-
Publication number: 20220060503Abstract: Embodiments are directed to monitoring network traffic using NMCs that may be arranged to provide scores based on threat assessments associated with anomaly classes such that the anomaly classes may be associated with types of anomalous activity. NMCs may employ the anomaly classes, the scores, characteristics of the anomaly classes, or the like, to determine triage models. The NMCs may modify the scores based on the triage models or archival information associated with the anomaly classes. The NMCs may associate the modified scores with the anomaly classes. In response to detecting anomalous activity, the NMCs may provide other scores based on the anomalous activity and provide a report that includes the other scores to a user.Type: ApplicationFiled: November 1, 2021Publication date: February 24, 2022Inventors: Po-Shen Lee, Songqian Chen, Amanda Jewitt, Olga Kazakova, Todd Kemmerling, Bhushan Prasad Khanal, Katherine Megan Porterfield, Jade Alexi Tabony, Karan Rajesh Thakker, Xue Jun Wu
-
Publication number: 20220053022Abstract: Embodiments are directed to monitoring network traffic using network monitoring computers (NMCs). Anomalous events may be classified based on the monitored network traffic and attack models such that the classification determines that targets of the anomalous events may be currently subject to attacks by entities communicating on the networks. A honeypot trap may be provided in the networks based on the classified events such that the honeypot trap mimics characteristics of the targets. The portions of the network traffic associated with the honeypot trap may be monitored. Characteristics of the attacks may be determined based on the monitored portions of network traffic. Reports that include information based on the characteristics of the attacks may be generated.Type: ApplicationFiled: November 1, 2021Publication date: February 17, 2022Inventors: Xue Jun Wu, Bhushan Prasad Khanal, Swagat Dasgupta, Changhwan Oh, J. Braund
-
Publication number: 20220029875Abstract: Embodiments are directed to monitoring network traffic. A monitoring engine may monitor network traffic associated with a plurality of entities in networks to provide metrics. And provide a device relation model based on the plurality of entities, the network traffic, and the metrics. An inference engine may associate each entity in the plurality of entities with an importance score based on the device relation model and the metrics such that each importance score is associated with a significance of an entity to operations of the networks. An alert engine may generate a plurality of alerts associated with the plurality of entities based on the metrics. And provide one or more alerts from the plurality of alerts to one or more users based on one or more ranked importance scores associated with one or more entities.Type: ApplicationFiled: April 9, 2021Publication date: January 27, 2022Inventors: Xue Jun Wu, Nicholas Jordan Braun, Joel Benjamin Deaguero, Michael Kerber Krause Montague, Bhushan Prasad Khanal
-
Patent number: 11165814Abstract: Embodiments are directed to monitoring network traffic using NMCs that may be arranged to provide scores based on threat assessments associated with anomaly classes such that the anomaly classes may be associated with types of anomalous activity. NMCs may employ the anomaly classes, the scores, characteristics of the anomaly classes, or the like, to determine triage models. The NMCs may modify the scores based on the triage models or archival information associated with the anomaly classes. The NMCs may associate the modified scores with the anomaly classes. In response to detecting anomalous activity, the NMCs may provide other scores based on the anomalous activity and provide a report that includes the other scores to a user.Type: GrantFiled: July 29, 2019Date of Patent: November 2, 2021Assignee: ExtraHop Networks, Inc.Inventors: Po-Shen Lee, Songqian Chen, Amanda Jewitt, Olga Kazakova, Todd Kemmerling, Bhushan Prasad Khanal, Katherine Megan Porterfield, Jade Alexi Tabony, Karan Rajesh Thakker, Xue Jun Wu
-
Patent number: 11165823Abstract: Embodiments are directed to monitoring network traffic using network monitoring computers (NMCs). Anomalous events may be classified based on the monitored network traffic and attack models such that the classification determines that targets of the anomalous events may be currently subject to attacks by entities communicating on the networks. A honeypot trap may be provided in the networks based on the classified events such that the honeypot trap mimics characteristics of the targets. The portions of the network traffic associated with the honeypot trap may be monitored. Characteristics of the attacks may be determined based on the monitored portions of network traffic. Reports that include information based on the characteristics of the attacks may be generated.Type: GrantFiled: December 17, 2019Date of Patent: November 2, 2021Assignee: ExtraHop Networks, Inc.Inventors: Xue Jun Wu, Bhushan Prasad Khanal, Swagat Dasgupta, Changhwan Oh, J. Braund
-
Publication number: 20210185087Abstract: Embodiments are directed to monitoring network traffic using network monitoring computers (NMCs). Anomalous events may be classified based on the monitored network traffic and attack models such that the classification determines that targets of the anomalous events may be currently subject to attacks by entities communicating on the networks. A honeypot trap may be provided in the networks based on the classified events such that the honeypot trap mimics characteristics of the targets. The portions of the network traffic associated with the honeypot trap may be monitored. Characteristics of the attacks may be determined based on the monitored portions of network traffic. Reports that include information based on the characteristics of the attacks may be generated.Type: ApplicationFiled: December 17, 2019Publication date: June 17, 2021Inventors: Xue Jun Wu, Bhushan Prasad Khanal, Swagat Dasgupta, Changhwan Oh, J. Braund
-
Patent number: 11012329Abstract: Embodiments are directed to monitoring network traffic using a monitoring engine that monitors network traffic in networks to provide metrics. An inference engine may provide activity profiles based on portions of the network traffic where each activity profile includes features associated with the portions of network traffic. The inference engine may determine other activity profiles correlated with the activity profiles based on correlation models such that the determination of the other activity profiles occurs prior to monitoring an occurrence of other portions of the network traffic. The inference engine may modify monitoring actions of the monitoring engine based on the other activity profiles. The inference engine may provide reports based on the portions of the network traffic, the activity profiles, the other portions of the network traffic, or the other activity profiles.Type: GrantFiled: September 9, 2019Date of Patent: May 18, 2021Assignee: ExtraHop Networks, Inc.Inventors: Eric Jacob Ball, Eric Joseph Hammerle, Benjamin Thomas Higgins, Bhushan Prasad Khanal, Michael Kerber Krause Montague, Xue Jun Wu
-
Patent number: 10979282Abstract: Embodiments are directed to monitoring network traffic. A monitoring engine may monitor network traffic associated with a plurality of entities in networks to provide metrics. And provide a device relation model based on the plurality of entities, the network traffic, and the metrics. An inference engine may associate each entity in the plurality of entities with an importance score based on the device relation model and the metrics such that each importance score is associated with a significance of an entity to operations of the networks. An alert engine may generate a plurality of alerts associated with the plurality of entities based on the metrics. And provide one or more alerts from the plurality of alerts to one or more users based on one or more ranked importance scores associated with one or more entities.Type: GrantFiled: August 16, 2019Date of Patent: April 13, 2021Assignee: ExtraHop Networks, Inc.Inventors: Xue Jun Wu, Nicholas Jordan Braun, Joel Benjamin Deaguero, Michael Kerber Krause Montague, Bhushan Prasad Khanal
-
Publication number: 20210037043Abstract: Embodiments are directed to monitoring network traffic using NMCs that may be arranged to provide scores based on threat assessments associated with anomaly classes such that the anomaly classes may be associated with types of anomalous activity. NMCs may employ the anomaly classes, the scores, characteristics of the anomaly classes, or the like, to determine triage models. The NMCs may modify the scores based on the triage models or archival information associated with the anomaly classes. The NMCs may associate the modified scores with the anomaly classes. In response to detecting anomalous activity, the NMCs may provide other scores based on the anomalous activity and provide a report that includes the other scores to a user.Type: ApplicationFiled: July 29, 2019Publication date: February 4, 2021Inventors: Po-Shen Lee, Songqian Chen, Amanda Jewitt, Olga Kazakova, Todd Kemmerling, Bhushan Prasad Khanal, Katherine Megan Porterfield, Jade Alexi Tabony, Karan Rajesh Thakker, Xue Jun Wu
-
Patent number: 10728126Abstract: Embodiments are directed to monitoring network traffic using network computers. A monitoring engine may monitor network traffic associated with a plurality of entities in a network to provide metrics. A device relation model may be provided based on the plurality of entities, the network traffic, and the metrics. Interest information for a user may be provided based on one or more properties associated with the user. An inference engine may associate each entity in the plurality of entities with an interest score based on the interest information, the device relation model, and the metrics. An alert engine may generate a plurality of alerts associated with the plurality of entities based on the metrics. Some of the alerts may be provided to the user based on ranked interest scores associated with the entities.Type: GrantFiled: July 30, 2018Date of Patent: July 28, 2020Assignee: ExtraHop Networks, Inc.Inventors: Xue Jun Wu, Nicholas Jordan Braun, Joel Benjamin Deaguero, Michael Kerber Krause Montague, Bhushan Prasad Khanal
-
Patent number: 10594709Abstract: Embodiments are directed to monitoring network traffic using network computers. Monitoring triggers associated with one or more conditions and one or more actions may be provided. A monitoring engine may monitor information that is associated with network traffic associated with networks based on an inspection detail level. The monitoring engine may compare the monitored information to the conditions associated with the monitoring triggers. The monitoring engine may activate one or more monitoring triggers based on a result of the comparison. The monitoring engine may modify the inspection detail level based on the actions associated with the activated monitoring triggers to increase the amount of the information monitored by the monitoring engine. An analysis engine may provide analysis of the network traffic based on the monitored information.Type: GrantFiled: April 15, 2019Date of Patent: March 17, 2020Assignee: ExtraHop Networks, Inc.Inventors: Xue Jun Wu, Nicholas Jordan Braun, Joel Benjamin Deaguero, Michael Kerber Krause Montague, Bhushan Prasad Khanal
-
Publication number: 20200052985Abstract: Embodiments are directed to monitoring network traffic using a monitoring engine that monitors network traffic in networks to provide metrics. An inference engine may provide activity profiles based on portions of the network traffic where each activity profile includes features associated with the portions of network traffic. The inference engine may determine other activity profiles correlated with the activity profiles based on correlation models such that the determination of the other activity profiles occurs prior to monitoring an occurrence of other portions of the network traffic. The inference engine may modify monitoring actions of the monitoring engine based on the other activity profiles. The inference engine may provide reports based on the portions of the network traffic, the activity profiles, the other portions of the network traffic, or the other activity profiles.Type: ApplicationFiled: September 9, 2019Publication date: February 13, 2020Inventors: Eric Jacob Ball, Eric Joseph Hammerle, Benjamin Thomas Higgins, Bhushan Prasad Khanal, Michael Kerber Krause Montague, Xue Jun Wu
-
Publication number: 20190372828Abstract: Embodiments are directed to monitoring network traffic. A monitoring engine may monitor network traffic associated with a plurality of entities in networks to provide metrics. And provide a device relation model based on the plurality of entities, the network traffic, and the metrics. An inference engine may associate each entity in the plurality of entities with an importance score based on the device relation model and the metrics such that each importance score is associated with a significance of an entity to operations of the networks. An alert engine may generate a plurality of alerts associated with the plurality of entities based on the metrics. And provide one or more alerts from the plurality of alerts to one or more users based on one or more ranked importance scores associated with one or more entities.Type: ApplicationFiled: August 16, 2019Publication date: December 5, 2019Inventors: Xue Jun Wu, Nicholas Jordan Braun, Joel Benjamin Deaguero, Michael Kerber Krause Montague, Bhushan Prasad Khanal
-
Patent number: 10411978Abstract: Embodiments are directed to monitoring network traffic using a monitoring engine that monitors network traffic in networks to provide metrics. An inference engine may provide activity profiles based on portions of the network traffic where each activity profile includes features associated with the portions of network traffic. The inference engine may determine other activity profiles correlated with the activity profiles based on correlation models such that the determination of the other activity profiles occurs prior to monitoring an occurrence of other portions of the network traffic. The inference engine may modify monitoring actions of the monitoring engine based on the other activity profiles. The inference engine may provide reports based on the portions of the network traffic, the activity profiles, the other portions of the network traffic, or the other activity profiles.Type: GrantFiled: August 9, 2018Date of Patent: September 10, 2019Assignee: ExtraHop Networks, Inc.Inventors: Eric Jacob Ball, Eric Joseph Hammerle, Benjamin Thomas Higgins, Bhushan Prasad Khanal, Michael Kerber Krause Montague, Xue Jun Wu