Patents by Inventor Guofei Gu

Guofei Gu has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 10270803
    Abstract: In one embodiment, the present invention is a method and apparatus for detecting malware infection. One embodiment of a method for detecting a malware infection at a local host in a network, includes monitoring communications between the local host and one or more entities external to the network, generating a dialog warning if the communications include a transaction indicative of a malware infection, declaring a malware infection if, within a predefined period of time, the dialog warnings includes at least one dialog warning indicating a transaction initiated at the local host and at least one dialog warning indicating an additional transaction indicative of a malware infection, and outputting an infection profile for the local host.
    Type: Grant
    Filed: January 21, 2015
    Date of Patent: April 23, 2019
    Assignee: SRI International
    Inventors: Guofei Gu, Phillip A. Porras, Martin W. Fong
  • Publication number: 20160359870
    Abstract: In one embodiment, the present invention is a method and apparatus for detecting malware infection. One embodiment of a method for detecting a malware infection at a local host in a network, includes monitoring communications between the local host and one or more entities external to the network, generating a dialog warning if the communications include a transaction indicative of a malware infection, declaring a malware infection if, within a predefined period of time, the dialog warnings includes at least one dialog warning indicating a transaction initiated at the local host and at least one dialog warning indicating an additional transaction indicative of a malware infection, and outputting an infection profile for the local host.
    Type: Application
    Filed: January 21, 2015
    Publication date: December 8, 2016
    Inventors: Guofei Gu, Phillip A. Porras, Martin W. Fong
  • Patent number: 9088598
    Abstract: A method for detecting malicious servers. The method includes analyzing network traffic data to generate a main similarity measure and a secondary similarity measure for each server pair found in the network traffic data, extracting a main subset and a secondary subset of servers based on the main similarity measure and the secondary similarity measure, identifying a server that belongs to the main subset and the secondary subset, and determining a suspicious score of the server based on at least a first similarity density measure of the main subset, a second similarity density measure of the secondary subset, and a commonality measure of the main subset and the secondary subset.
    Type: Grant
    Filed: November 14, 2013
    Date of Patent: July 21, 2015
    Assignee: Narus, Inc.
    Inventors: Jialong Zhang, Sabyasachi Saha, Guofei Gu, Sung-Ju Lee, Bruno Nardelli
  • Patent number: 8955122
    Abstract: In one embodiment, the present invention is a method and apparatus for detecting malware infection. One embodiment of a method for detecting a malware infection at a local host in a network, includes monitoring communications between the local host and one or more entities external to the network, generating a dialog warning if the communications include a transaction indicative of a malware infection, declaring a malware infection if, within a predefined period of time, the dialog warnings includes at least one dialog warning indicating a transaction initiated at the local host and at least one dialog warning indicating an additional transaction indicative of a malware infection, and outputting an infection profile for the local host.
    Type: Grant
    Filed: April 4, 2008
    Date of Patent: February 10, 2015
    Assignee: SRI International
    Inventors: Guofei Gu, Phillip Andrew Porras, Martin Fong
  • Patent number: 7594275
    Abstract: A public licensing infrastructure (PLI) for a digital rights management (DRM) system is described. In an implementation, a method includes generating a formal license for content. The formal license includes a decryption key for decrypting the content and access rules for accessing the content. A plurality of license authorities is configured to provide a plurality of partial licenses. The plurality of partial licenses is combinable to form the formal license. Each license authority provides a respective partial license.
    Type: Grant
    Filed: October 14, 2003
    Date of Patent: September 22, 2009
    Assignee: Microsoft Corporation
    Inventors: Bin Zhu, Guofei Gu, Shipeng Li
  • Publication number: 20090172815
    Abstract: In one embodiment, the present invention is a method and apparatus for detecting malware infection. One embodiment of a method for detecting a malware infection at a local host in a network, includes monitoring communications between the local host and one or more entities external to the network, generating a dialog warning if the communications include a transaction indicative of a malware infection, declaring a malware infection if, within a predefined period of time, the dialog warnings includes at least one dialog warning indicating a transaction initiated at the local host and at least one dialog warning indicating an additional transaction indicative of a malware infection, and outputting an infection profile for the local host.
    Type: Application
    Filed: April 4, 2008
    Publication date: July 2, 2009
    Inventors: Guofei Gu, Phillip Andrew Porras, Martin Fong
  • Publication number: 20050080746
    Abstract: A public licensing infrastructure (PLI) for a digital rights management (DRM) system is described. In an implementation, a method includes generating a formal license for content. The formal license includes a decryption key for decrypting the content and access rules for accessing the content. A plurality of license authorities is configured to provide a plurality of partial licenses. The plurality of partial licenses is combinable to form the formal license. Each license authority provides a respective partial license.
    Type: Application
    Filed: October 14, 2003
    Publication date: April 14, 2005
    Inventors: Bin Zhu, Guofei Gu, Shipeng Li