Patents by Inventor Dirk Harz
Dirk Harz has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Patent number: 11689548Abstract: A method for identification of malicious domains is provided. The method extracts a set of domain information from one or more input streams. The set of domain information includes a set of domains and a set of domain characteristics describing each domain. The method clusters the set of domains to generate a set of campaign clusters of related domains. The clusters are based on the set of domain characteristics. The method modifies the set of campaign clusters with a set of threat intelligence ratings to generate a set of enriched campaign clusters. A portion of the set of threat intelligence ratings correspond to one or more domains within the set of campaign clusters. The method determines a cluster designation for each campaign cluster of the set of enriched campaign clusters and distributes the cluster designations for each campaign cluster to one or more threat intelligence resource.Type: GrantFiled: July 11, 2019Date of Patent: June 27, 2023Assignee: International Business Machines CorporationInventors: Mark Usher, Johannes Noll, Uwe Küllmar, Dirk Harz, Marc Noske
-
Patent number: 11568416Abstract: A method for identification of malicious internet content and campaigns is provided. The method extracts a cryptocurrency indicator within a compromised data set and inserts the cryptocurrency indicator into a threat intelligence database. The method identifies a set of cryptocurrency transactions associated with the cryptocurrency indicator. From the cryptocurrency indicator and the set of cryptocurrency transactions, the method generates a transaction graph with a set of features representing the set of cryptocurrency transactions. The method modifies the threat intelligence database with at least a portion of the transaction graph.Type: GrantFiled: June 24, 2019Date of Patent: January 31, 2023Assignee: International Business Machines CorporationInventors: Markus Ludwig, Marc Noske, Dirk Harz, Johannes Noll, Martin Steigemann
-
Patent number: 10897483Abstract: A method for automated determination of IP address information of malicious attacks. An intrusion detection system may receive an index tree for storing IP addresses in one or more nodes of the index tree in a predefined sorting order. The instruction detection system may receive a data structure including a first set of one or more IP addresses from a honeypot system. The intrusion detection may receive unstructured data indicative of a second set of one or more IP addresses from a predefined data source. The intrusion detection system may process the unstructured data to determine the second set of one or more IP addresses. The intrusion detection system may insert each IP address of the first and second sets of one or more IP addresses into one or more nodes of the index tree.Type: GrantFiled: August 10, 2018Date of Patent: January 19, 2021Assignee: International Business Machines CorporationInventors: Dirk Harz, Matthias Seul, Jens Thamm, Gideon Zenz
-
Publication number: 20210014252Abstract: A method for identification of malicious domains is provided. The method extracts a set of domain information from one or more input streams. The set of domain information includes a set of domains and a set of domain characteristics describing each domain. The method clusters the set of domains to generate a set of campaign clusters of related domains. The clusters are based on the set of domain characteristics. The method modifies the set of campaign clusters with a set of threat intelligence ratings to generate a set of enriched campaign clusters. A portion of the set of threat intelligence ratings correspond to one or more domains within the set of campaign clusters. The method determines a cluster designation for each campaign cluster of the set of enriched campaign clusters and distributes the cluster designations for each campaign cluster to one or more threat intelligence resource.Type: ApplicationFiled: July 11, 2019Publication date: January 14, 2021Inventors: Mark Usher, Johannes Noll, Uwe Küllmar, Dirk Harz, Marc Noske
-
Publication number: 20200402061Abstract: A method for identification of malicious internet content and campaigns is provided. The method extracts a cryptocurrency indicator within a compromised data set and inserts the cryptocurrency indicator into a threat intelligence database. The method identifies a set of cryptocurrency transactions associated with the cryptocurrency indicator. From the cryptocurrency indicator and the set of cryptocurrency transactions, the method generates a transaction graph with a set of features representing the set of cryptocurrency transactions. The method modifies the threat intelligence database with at least a portion of the transaction graph.Type: ApplicationFiled: June 24, 2019Publication date: December 24, 2020Inventors: Markus Ludwig, Marc Noske, Dirk Harz, Johannes Noll, Martin Steigemann
-
Patent number: 10810176Abstract: According to one exemplary embodiment, a method for detecting unsolicited bulk emails (UBE) is provided. The method may include receiving an email. The method may also include identifying a uniform resource locator (URL) contained in the received email. The method may then include dividing the identified URL into a plurality of component parts. The method may further include generating a tree structure based on the plurality of component parts. The method may also include generating an input string based on the generated tree structure. The method may then include calculating a hash value based on the generated input string. The method may further include determining if the calculated hash value matches a UBE hash value within a plurality of UBE hash values. The method may also include identifying the received email as a UBE based on determining that the calculated hash value matches the UBE hash value.Type: GrantFiled: April 28, 2015Date of Patent: October 20, 2020Assignee: International Business Machines CorporationInventors: Astrid Granacher, Dirk Harz, Juergen Kader, Johannes Noll, Mark Usher
-
Patent number: 10764353Abstract: A mechanism is provided for automatic genre determination of web content. For each type of web content genre, a set of relevant feature types are extracted from collected training material, where genre features and non-genre features are represented by tokens and an integer counts represents a frequency of appearance of the token in both a first type of training material and a second type of training material. In a classification process, fixed length tokens are extracted for relevant features types from different text and structural elements of web content. For each relevant feature type, a corresponding feature probability is calculated. The feature probabilities are combined to an overall genre probability that the web content belongs to a specific trained web content genre. A genre classification result is then output comprising at least one specific trained web content genre to which the web content belongs together with a corresponding genre probability.Type: GrantFiled: October 18, 2018Date of Patent: September 1, 2020Assignee: International Business Machines CorporationInventors: Dirk Harz, Ralf Iffert, Mark Keinhoerster, Mark Usher
-
Patent number: 10706032Abstract: According to one exemplary embodiment, a method for detecting unsolicited bulk emails (UBE) is provided. The method may include receiving an email. The method may also include identifying a uniform resource locator (URL) contained in the received email. The method may then include dividing the identified URL into a plurality of component parts. The method may further include generating a tree structure based on the plurality of component parts. The method may also include generating an input string based on the generated tree structure. The method may then include calculating a hash value based on the generated input string. The method may further include determining if the calculated hash value matches a UBE hash value within a plurality of UBE hash values. The method may also include identifying the received email as a UBE based on determining that the calculated hash value matches the UBE hash value.Type: GrantFiled: June 3, 2015Date of Patent: July 7, 2020Assignee: International Business Machines CorporationInventors: Astrid Granacher, Dirk Harz, Juergen Kader, Johannes Noll, Mark Usher
-
Patent number: 10686807Abstract: A method for classification of suspicious activities is provided. In the method, a first intrusion detection system comprising a normal operation mode and which is connected to a second intrusion detection system by a first communications connection is implemented. In response to detecting a malfunction of the first communications connection, the first intrusion detection system is switched from the normal operation mode to a limited operation mode for receiving first data from one or more honeypot systems and second data from the second intrusion detection system. A prediction model for representing malicious attacks is generated by execution of a predefined classification algorithm with respect to the received data, wherein the predefined classification algorithm further determine a model evaluation metric with respect to the prediction model. The prediction model is deployed to detect the malicious attacks if the model evaluation metric meets a predefined validation condition.Type: GrantFiled: June 12, 2018Date of Patent: June 16, 2020Assignee: International Business Machines CorporationInventors: Gideon Zenz, Volker Vogeley, Dirk Harz, Mark Usher, Astrid Granacher
-
Publication number: 20200053122Abstract: A method for automated determination of IP address information of malicious attacks. An intrusion detection system may receive an index tree for storing IP addresses in one or more nodes of the index tree in a predefined sorting order. The instruction detection system may receive a data structure including a first set of one or more IP addresses from a honeypot system. The intrusion detection may receive unstructured data indicative of a second set of one or more IP addresses from a predefined data source. The intrusion detection system may process the unstructured data to determine the second set of one or more IP addresses. The intrusion detection system may insert each IP address of the first and second sets of one or more IP addresses into one or more nodes of the index tree.Type: ApplicationFiled: August 10, 2018Publication date: February 13, 2020Inventors: Dirk Harz, Matthias Seul, Jens Thamm, Gideon Zenz
-
Publication number: 20190379677Abstract: A method for classification of suspicious activities is provided. In the method, a first intrusion detection system comprising a normal operation mode and which is connected to a second intrusion detection system by a first communications connection is implemented. In response to detecting a malfunction of the first communications connection, the first intrusion detection system is switched from the normal operation mode to a limited operation mode for receiving first data from one or more honeypot systems and second data from the second intrusion detection system. A prediction model for representing malicious attacks is generated by execution of a predefined classification algorithm with respect to the received data, wherein the predefined classification algorithm further determine a model evaluation metric with respect to the prediction model. The prediction model is deployed to detect the malicious attacks if the model evaluation metric meets a predefined validation condition.Type: ApplicationFiled: June 12, 2018Publication date: December 12, 2019Inventors: Gideon Zenz, Volker Vogeley, Dirk Harz, Mark Usher, Astrid Granacher
-
Publication number: 20190052694Abstract: A mechanism is provided for automatic genre determination of web content. For each type of web content genre, a set of relevant feature types are extracted from collected training material, where genre features and non-genre features are represented by tokens and an integer counts represents a frequency of appearance of the token in both a first type of training material and a second type of training material. In a classification process, fixed length tokens are extracted for relevant features types from different text and structural elements of web content. For each relevant feature type, a corresponding feature probability is calculated. The feature probabilities are combined to an overall genre probability that the web content belongs to a specific trained web content genre. A genre classification result is then output comprising at least one specific trained web content genre to which the web content belongs together with a corresponding genre probability.Type: ApplicationFiled: October 18, 2018Publication date: February 14, 2019Inventors: Dirk Harz, Ralf Iffert, Mark Keinhoerster, Mark Usher
-
Patent number: 10110658Abstract: A mechanism is provided for automatic genre determination of web content. For each type of web content genre, a set of relevant feature types are extracted from collected training material, where genre features and non-genre features are represented by tokens and an integer counts represents a frequency of appearance of the token in both a first type of training material and a second type of training material. In a classification process, fixed length tokens are extracted for relevant features types from different text and structural elements of web content. For each relevant feature type, a corresponding feature probability is calculated. The feature probabilities are combined to an overall genre probability that the web content belongs to a specific trained web content genre. A genre classification result is then output comprising at least one specific trained web content genre to which the web content belongs together with a corresponding genre probability.Type: GrantFiled: June 3, 2015Date of Patent: October 23, 2018Assignee: International Business Machines CorporationInventors: Dirk Harz, Ralf Iffert, Mark Keinhoerster, Mark Usher
-
Patent number: 9565236Abstract: A mechanism is provided for automatic genre determination of web content. For each type of web content genre, a set of relevant feature types are extracted from collected training material, where genre features and non-genre features are represented by tokens and an integer counts represents a frequency of appearance of the token in both a first type of training material and a second type of training material. In a classification process, fixed length tokens are extracted for relevant features types from different text and structural elements of web content. For each relevant feature type, a corresponding feature probability is calculated. The feature probabilities are combined to an overall genre probability that the web content belongs to a specific trained web content genre. A genre classification result is then output comprising at least one specific trained web content genre to which the web content belongs together with a corresponding genre probability.Type: GrantFiled: December 4, 2013Date of Patent: February 7, 2017Assignee: International Business Machines CorporationInventors: Dirk Harz, Ralf Iffert, Mark Keinhoerster, Mark Usher
-
Publication number: 20160321254Abstract: According to one exemplary embodiment, a method for detecting unsolicited bulk emails (UBE) is provided. The method may include receiving an email. The method may also include identifying a uniform resource locator (URL) contained in the received email. The method may then include dividing the identified URL into a plurality of component parts. The method may further include generating a tree structure based on the plurality of component parts. The method may also include generating an input string based on the generated tree structure. The method may then include calculating a hash value based on the generated input string. The method may further include determining if the calculated hash value matches a UBE hash value within a plurality of UBE hash values. The method may also include identifying the received email as a UBE based on determining that the calculated hash value matches the UBE hash value.Type: ApplicationFiled: April 28, 2015Publication date: November 3, 2016Inventors: Astrid Granacher, Dirk Harz, Juergen Kader, Johannes Noll, Mark Usher
-
Publication number: 20160321255Abstract: According to one exemplary embodiment, a method for detecting unsolicited bulk emails (UBE) is provided. The method may include receiving an email. The method may also include identifying a uniform resource locator (URL) contained in the received email. The method may then include dividing the identified URL into a plurality of component parts. The method may further include generating a tree structure based on the plurality of component parts. The method may also include generating an input string based on the generated tree structure. The method may then include calculating a hash value based on the generated input string. The method may further include determining if the calculated hash value matches a UBE hash value within a plurality of UBE hash values. The method may also include identifying the received email as a UBE based on determining that the calculated hash value matches the UBE hash value.Type: ApplicationFiled: June 3, 2015Publication date: November 3, 2016Inventors: Astrid Granacher, Dirk Harz, Juergen Kader, Johannes Noll, Mark Usher
-
Publication number: 20150264107Abstract: A mechanism is provided for automatic genre determination of web content. For each type of web content genre, a set of relevant feature types are extracted from collected training material, where genre features and non-genre features are represented by tokens and an integer counts represents a frequency of appearance of the token in both a first type of training material and a second type of training material. In a classification process, fixed length tokens are extracted for relevant features types from different text and structural elements of web content. For each relevant feature type, a corresponding feature probability is calculated. The feature probabilities are combined to an overall genre probability that the web content belongs to a specific trained web content genre. A genre classification result is then output comprising at least one specific trained web content genre to which the web content belongs together with a corresponding genre probability.Type: ApplicationFiled: June 3, 2015Publication date: September 17, 2015Inventors: Dirk Harz, Ralf Iffert, Mark Keinhoerster, Mark Usher
-
Publication number: 20140201113Abstract: A mechanism is provided for automatic genre determination of web content. For each type of web content genre, a set of relevant feature types are extracted from collected training material, where genre features and non-genre features are represented by tokens and an integer counts represents a frequency of appearance of the token in both a first type of training material and a second type of training material. In a classification process, fixed length tokens are extracted for relevant features types from different text and structural elements of web content. For each relevant feature type, a corresponding feature probability is calculated. The feature probabilities are combined to an overall genre probability that the web content belongs to a specific trained web content genre. A genre classification result is then output comprising at least one specific trained web content genre to which the web content belongs together with a corresponding genre probability.Type: ApplicationFiled: December 4, 2013Publication date: July 17, 2014Applicant: International Business Machines CorporationInventors: Dirk Harz, Ralf Iffert, Mark Keinhoerster, Mark Usher