Patents by Inventor Eric Varsanyi
Eric Varsanyi has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Publication number: 20230308458Abstract: Structured Data Discovery and Cryptographic Analysis. In an embodiment, transport sessions are assembled from raw packets captured in network traffic. Data is extracted from two or more encapsulation layers of each transport session. In particular, each encapsulation layer may be classified into a protocol, and data may be extracted from the encapsulation layer based on the protocol. For example, cryptographic metadata may be extracted from a cryptographic encapsulation layer. The extracted data is incorporated into a data model of the network, which comprises tallies of traffic within the network, grouped according to a plurality of dimensions. Analytic model(s) may be applied to the data model to, for example, generate a data web of the network that represents structured data stores and data flows to and/or from the data stores within the network.Type: ApplicationFiled: July 27, 2021Publication date: September 28, 2023Inventors: Eric Varsanyi, Brett Helm
-
Patent number: 9525642Abstract: Ordering partial network traffic. In an embodiment, data packets are received from a network tap and separated into two queues. For each queue, a push-sequence is maintained to represent a sequence number that must be pushed in order to maintain a consecutive order. When both push-sequences are equal to the sequence number of their first packets, if the acknowledgement number of the first packet on one queue is greater than the push-sequence for the other queue and less than or equal to the push-sequence of the one queue, data is pushed off the other queue. Otherwise, a queue having the earlier timestamp is identified as a first queue, the existence of a next acknowledgement number is determined for the second (other) queue, and data is pushed off the first queue according to the existence of the next acknowledgement number. Gap packets may be generated to force progress.Type: GrantFiled: December 4, 2014Date of Patent: December 20, 2016Assignee: DB NETWORKS, INC.Inventor: Eric Varsanyi
-
Patent number: 9185125Abstract: Systems, methods, and computer-readable media for detecting threats on a network. In an embodiment, target network traffic being transmitted between two or more hosts is captured. The target network traffic comprises a plurality of packets, which are assembled into one or more messages. The assembled message(s) may be parsed to generate a semantic model of the target network traffic. The semantic model may comprise representation(s) of operation(s) or event(s) represented by the message(s). Score(s) for the operation(s) or event(s) may be generated using a plurality of scoring algorithms, and potential threats among the operation(s) or event(s) may be identified using the score(s).Type: GrantFiled: January 9, 2014Date of Patent: November 10, 2015Assignee: DB NETWORKS, INC.Inventors: Eric Varsanyi, David Rosenberg, Chuck Paterson, Steve Schnetzler, Timothy Ruddick
-
Publication number: 20150304184Abstract: Systems and methods for generating a semantic description of operations between network agents. In an embodiment, packet-level traffic between two or more network agents is captured. The packet-level traffic is bundled into one or more messages, wherein each message comprises one or more elements. For each of the messages, the elements of the message are matched to one or more attributes, and the message is decoded into message data based on the matched attributes. The message data is then used to generate a semantic description of operations between the network agents.Type: ApplicationFiled: June 30, 2015Publication date: October 22, 2015Inventors: Timothy W. Ruddick, Eric Varsanyi, Charles A. Paterson, David A. Rosenberg
-
Patent number: 9100291Abstract: Systems and methods for generating a semantic description of operations between network agents. In an embodiment, packet-level traffic between two or more network agents is captured. The packet-level traffic is bundled into one or more messages, wherein each message comprises one or more elements. For each of the messages, the elements of the message are matched to one or more attributes, and the message is decoded into message data based on the matched attributes. The message data is then used to generate a semantic description of operations between the network agents.Type: GrantFiled: January 25, 2013Date of Patent: August 4, 2015Assignee: DB Networks, Inc.Inventors: Timothy W. Ruddick, Eric Varsanyi, Charles A. Paterson, David A. Rosenberg
-
Publication number: 20150156130Abstract: Ordering partial network traffic. In an embodiment, data packets are received from a network tap and separated into two queues. For each queue, a push-sequence is maintained to represent a sequence number that must be pushed in order to maintain a consecutive order. When both push-sequences are equal to the sequence number of their first packets, if the acknowledgement number of the first packet on one queue is greater than the push-sequence for the other queue and less than or equal to the push-sequence of the one queue, data is pushed off the other queue. Otherwise, a queue having the earlier timestamp is identified as a first queue, the existence of a next acknowledgement number is determined for the second (other) queue, and data is pushed off the first queue according to the existence of the next acknowledgement number. Gap packets may be generated to force progress.Type: ApplicationFiled: December 4, 2014Publication date: June 4, 2015Inventor: Eric Varsanyi
-
Publication number: 20140201838Abstract: Systems, methods, and computer-readable media for detecting threats on a network. In an embodiment, target network traffic being transmitted between two or more hosts is captured. The target network traffic comprises a plurality of packets, which are assembled into one or more messages. The assembled message(s) may be parsed to generate a semantic model of the target network traffic. The semantic model may comprise representation(s) of operation(s) or event(s) represented by the message(s). Score(s) for the operation(s) or event(s) may be generated using a plurality of scoring algorithms, and potential threats among the operation(s) or event(s) may be identified using the score(s).Type: ApplicationFiled: January 9, 2014Publication date: July 17, 2014Applicant: DB Networks, Inc.Inventors: Eric Varsanyi, David Rosenberg, Chuck Paterson, Steve Schnetzler, Brett Helm, Timothy Ruddick, Steven Hunt
-
Patent number: 7673026Abstract: The response time from a client on a network is measured and a destination address is selected based on the measured response time. The client requests an address from the network. The network may be a local network or a wide area network such as the Internet. The response time of the client is measured to determine the optimum speed at which the client may operate. The measured response time is communicated to the server, where a destination address is selected based on the requested address and the measured response time. The client may then be connected to the destination address.Type: GrantFiled: May 5, 2004Date of Patent: March 2, 2010Assignee: Intel CorporationInventors: Cary A. Jardin, Eric Varsanyi, Phil J. Duclos, Vincent M. Padua, Robert C. Trescott, Jr.
-
Patent number: 7308713Abstract: A link lock system for a network includes a computer, a network interface device, a bus monitor, and a security switch. The network interface device provides the computer with access to the network. The bus monitor monitors a link between the network interface device and the computer. The bus monitor reports detected failures or intrusions. The security switch switches the link from a non-secured mode to a secured mode when a report of the detected failures or intrusions is received from the bus monitor.Type: GrantFiled: November 22, 2000Date of Patent: December 11, 2007Assignee: Intel CorporationInventors: Cary A. Jardin, Eric Varsanyi, Phil J. Duclos, Vincent M. Padua
-
Publication number: 20040255019Abstract: The response time from a client on a network is measured and a destination address is selected based on the measured response time. The client requests an address from the network. The network may be a local network or a wide area network such as the Internet. The response time of the client is measured to determine the optimum speed at which the client may operate. The measured response time is communicated to the server, where a destination address is selected based on the requested address and the measured response time. The client may then be connected to the destination address.Type: ApplicationFiled: May 5, 2004Publication date: December 16, 2004Applicant: Intel Corporation, a Delaware corporationInventors: Cary A. Jardin, Eric Varsanyi, Phil J. Duclos, Vincent M. Padua, Robert C. Trescott
-
Patent number: 6766354Abstract: The response time from a client on a network is measured and a destination address is selected based on the measured response time. The client requests an address from the network. The network may be a local network or a wide area network such as the Internet. The response time of the client is measured to determine the optimum speed at which the client may operate. The measured response time is communicated to the server, where a destination address is selected based on the requested address and the measured response time. The client may then be connected to the destination address.Type: GrantFiled: September 28, 2000Date of Patent: July 20, 2004Assignee: Intel CorporationInventors: Cary A Jardin, Eric Varsanyi, Phil J. Duclos, Vincent M. Padua, Robert C. Trescott, Jr.