Patents by Inventor Eric Steinbrecher

Eric Steinbrecher has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 9106689
    Abstract: An intrusion detection method, system and computer-readable media are disclosed. The system can include a processor programmed to perform computer network intrusion detection. The intrusion detection can include an identification module and a detection module. The identification module can be adapted to perform semi-supervised machine learning to identify key components of a network attack and develop MDL models representing those attack components. The detection module can cluster the MDL models and use the clustered MDL models to classify network activity and detect polymorphic or zero-day attacks.
    Type: Grant
    Filed: May 6, 2011
    Date of Patent: August 11, 2015
    Assignee: Lockheed Martin Corporation
    Inventors: Eric Steinbrecher, Jeremy Impson, Bruce Barnett, Scott Charles Evans, Bernhard Scholz, Weizhong Yan, Thomas Markham, Stephen J. Dill
  • Patent number: 8312542
    Abstract: A network intrusion detection system and method that includes a grammar inference engine. A grammar-based Minimum Description Length (MDL) compression algorithm is used to determine an attack based on closeness of fit to one or more compression models. The network intrusion detection system and method can determine zero day attacks.
    Type: Grant
    Filed: October 29, 2008
    Date of Patent: November 13, 2012
    Assignee: Lockheed Martin Corporation
    Inventors: Edward E. Eiland, Scott C. Evans, Jeremy D. Impson, Thomas S. Markham, Eric Steinbrecher
  • Publication number: 20120284793
    Abstract: An intrusion detection method, system and computer-readable media are disclosed. The system can include a processor programmed to perform computer network intrusion detection. The intrusion detection can include an identification module and a detection module. The identification module can be adapted to perform semi-supervised machine learning to identify key components of a network attack and develop MDL models representing those attack components. The detection module can cluster the MDL models and use the clustered MDL models to classify network activity and detect polymorphic or zero-day attacks.
    Type: Application
    Filed: May 6, 2011
    Publication date: November 8, 2012
    Applicant: Lockheed Martin Corporation
    Inventors: Eric Steinbrecher, Jeremy Impson, Bruce Barnett, Scott Charles Evans, Bernhard Scholz, Weizhong Yang, Thomas Markham, Stephen J. Dill
  • Patent number: 8245302
    Abstract: A network activity visualization system can include an MDL grammar database adapted to store a plurality of MDL grammars, and a pattern matching module adapted to match a received network activity data set against the MDL grammars by calculating a distance of the network activity data set from each MDL grammar. The system can also include an intelligent icon module adapted to receive the MDL grammars and distances of a network data set from each respective MDL grammar, and adapted to generate intelligent icons based on the MDL grammars and distances. The system can further include a display system adapted to display the intelligent icons so as to provide a visual indication of network security.
    Type: Grant
    Filed: September 15, 2010
    Date of Patent: August 14, 2012
    Assignee: Lockheed Martin Corporation
    Inventors: Scott C. Evans, T. Stephen Markham, Richard Bejtlich, Bruce G. Barnett, Bernhard J. Scholz, Robert J. Mitchell, Jr., Weizhong Yan, Jeremy Impson, Eric Steinbrecher
  • Patent number: 8245301
    Abstract: A network activity visualization system can include a minimum description length (MDL) based network intrusion detection system having an MDL grammar database adapted to store a plurality of MDL grammars, and a pattern matching module adapted to match a received network activity data set against the MDL grammars by calculating a distance of the network activity data set from each MDL grammar. The system can also include an intelligent icon module coupled to the MDL-based intrusion detection system and adapted to receive the MDL grammars and distances of a network data set from each respective MDL grammar, and adapted to generate intelligent icons based on the MDL grammars and distances. The system can further include a display system adapted to display the intelligent icons so as to provide a visual indication of network security.
    Type: Grant
    Filed: September 15, 2009
    Date of Patent: August 14, 2012
    Assignee: Lockheed Martin Corporation
    Inventors: Scott Charles Evans, Thomas Markham, Richard Bejtlich, Jeremy Impson, Eric Steinbrecher
  • Publication number: 20110066409
    Abstract: A network activity visualization system can include an MDL grammar database adapted to store a plurality of MDL grammars, and a pattern matching module adapted to match a received network activity data set against the MDL grammars by calculating a distance of the network activity data set from each MDL grammar. The system can also include an intelligent icon module adapted to receive the MDL grammars and distances of a network data set from each respective MDL grammar, and adapted to generate intelligent icons based on the MDL grammars and distances. The system can further include a display system adapted to display the intelligent icons so as to provide a visual indication of network security.
    Type: Application
    Filed: September 15, 2010
    Publication date: March 17, 2011
    Applicant: Lockheed Martin Corporation
    Inventors: Scott C. Evans, T. Stephen Markham, Richard Bejtlich, Bruce G. Barnett, Bernhard J. Scholz, Robert J. Mitchell, JR., Weizhong Yan, Jeremy Impson, Eric Steinbrecher
  • Publication number: 20110067106
    Abstract: A network activity visualization system can include a minimum description length (MDL) based network intrusion detection system having an MDL grammar database adapted to store a plurality of MDL grammars, and a pattern matching module adapted to match a received network activity data set against the MDL grammars by calculating a distance of the network activity data set from each MDL grammar. The system can also include an intelligent icon module coupled to the MDL-based intrusion detection system and adapted to receive the MDL grammars and distances of a network data set from each respective MDL grammar, and adapted to generate intelligent icons based on the MDL grammars and distances. The system can further include a display system adapted to display the intelligent icons so as to provide a visual indication of network security.
    Type: Application
    Filed: September 15, 2009
    Publication date: March 17, 2011
    Inventors: Scott Charles Evans, Thomas Markham, Richard Bejtlich, Jeremy Impson, Eric Steinbrecher
  • Publication number: 20100107254
    Abstract: A network intrusion detection system and method that includes a grammar inference engine. A grammar-based Minimum Description Length (MDL) compression algorithm is used to determine an attack based on closeness of fit to one or more compression models. The network intrusion detection system and method can determine zero day attacks.
    Type: Application
    Filed: October 29, 2008
    Publication date: April 29, 2010
    Inventors: Edward E. Eiland, Scott C. Evans, Jeremy D. Impson, Thomas S. Markham, Eric Steinbrecher