Patents by Inventor Haifeng Chen

Haifeng Chen has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 10915625
    Abstract: A computer-implemented method for implementing alert interpretation in enterprise security systems is presented. The computer-implemented method includes employing a plurality of sensors to monitor streaming data from a plurality of computing devices, generating alerts based on the monitored streaming data, employing an alert interpretation module to interpret the alerts in real-time, matching problematic entities to the streaming data, retrieving following events, and generating an aftermath graph on a visualization component.
    Type: Grant
    Filed: October 16, 2018
    Date of Patent: February 9, 2021
    Inventors: LuAn Tang, Zhengzhang Chen, Zhichun Li, Zhenyu Wu, Jumpei Kamimura, Haifeng Chen
  • Patent number: 10915626
    Abstract: A computer-implemented method for implementing alert interpretation in enterprise security systems is presented. The computer-implemented method includes employing a plurality of sensors to monitor streaming data from a plurality of computing devices, generating alerts based on the monitored streaming data, and employing an alert interpretation module to interpret the alerts in real-time, the alert interpretation module including a process-star graph constructor for retrieving relationships from the streaming data to construct process-star graph models and an alert cause detector for analyzing the alerts based on the process-star graph models to determine an entity that causes an alert.
    Type: Grant
    Filed: October 16, 2018
    Date of Patent: February 9, 2021
    Inventors: LuAn Tang, Zhengzhang Chen, Zhichun Li, Zhenyu Wu, Jumpei Kamimura, Haifeng Chen
  • Patent number: 10909115
    Abstract: Systems and methods for system event searching based on heterogeneous logs are provided. A system can include a processor device operatively coupled to a memory device wherein the processor device is configured to mine a variety of log patterns from various of heterogeneous logs to obtain known-event log patterns and unknown-event log patterns, as well as to build a weighted vector representation of the log patterns. The processor device is also configured to evaluate a similarity between the vector representation of the unknown-event and known-event log patterns, identify a known event that is most similar to an unknown event to troubleshoot system faults based on past actions for similar events to improve an operation of a computer system.
    Type: Grant
    Filed: November 28, 2018
    Date of Patent: February 2, 2021
    Inventors: Bo Zong, Jianwu Xu, Haifeng Chen
  • Patent number: 10911488
    Abstract: Methods and systems for mitigating a spoofing-based attack include calculating a travel distance between a source Internet Protocol (IP) address and a target IP address from a received packet based on time-to-live information from the received packet. An expected travel distance between the source IP address and the target IP address is estimated based on a sparse set of known source/target distances. It is determined that the received packet has a spoofed source IP address based on a comparison between the calculated travel distance and the expected travel distance. A security action is performed responsive to the determination that the received packet has a spoofed source IP address.
    Type: Grant
    Filed: August 13, 2018
    Date of Patent: February 2, 2021
    Inventors: Cristian Lumezanu, Nipun Arora, Haifeng Chen, Bo Zong, Daeki Cho, Mingda Li
  • Publication number: 20210027019
    Abstract: A system for cross-modal data retrieval is provided that includes a neural network having a time series encoder and text encoder which are jointly trained using an unsupervised training method which is based on a loss function. The loss function jointly evaluates a similarity of feature vectors of training sets of two different modalities of time series and free-form text comments and a compatibility of the time series and the free-form text comments with a word-overlap-based spectral clustering method configured to compute pseudo labels for the unsupervised training method. The computer processing system further includes a database for storing the training sets with feature vectors extracted from encodings of the training sets. The encodings are obtained by encoding a training set of the time series using the time series encoder and encoding a training set of the free-form text comments using the text encoder.
    Type: Application
    Filed: July 1, 2020
    Publication date: January 28, 2021
    Inventors: Yuncong Chen, Hao Yuan, Dongjin Song, Cristian Lumezanu, Haifeng Chen, Takehiko Mizoguchi
  • Publication number: 20210027157
    Abstract: A system for cross-modal data retrieval is provided. The system includes a database for storing training sets of two different modalities of time series and free-form text comments as pairs of mixed modality data. The computer processing system further includes a neural network having a time series encoder and text encoder which are jointly trained using a canonical correlation analysis that finds transformations of feature vectors from among the pairs of mixed modality data such that correlated mixed modality data is emphasized in the two different modalities and uncorrelated mixed modality data is minimized. The feature vectors are obtained by encoding a training set of the time series using the time series encoder and encoding a training set of the free-form text comments using the text encoder.
    Type: Application
    Filed: July 1, 2020
    Publication date: January 28, 2021
    Inventors: Yuncong Chen, Hao Yuan, Dongjin Song, Cristian Lumezanu, Haifeng Chen, Takehiko Mizoguchi
  • Publication number: 20210012061
    Abstract: A system for cross-modal data retrieval is provided which includes a neural network having a time series encoder and text encoder jointly trained based on a triplet loss relating to two different modalities of (i) time series and (ii) free-form text comments. A database stores training sets with feature vectors extracted from encodings of the training sets. The encodings are obtained by encoding the time series using the time series encoder and encoding the text comments using the text encoder. A processor retrieves the feature vectors corresponding to at least one of the modalities from the database for insertion into a feature space together with a feature vector corresponding to a testing input relating to at least one of a testing time series and a testing free-form text comment, determines a set of nearest neighbors from among the feature vectors based on distance criteria, and outputs testing results.
    Type: Application
    Filed: July 1, 2020
    Publication date: January 14, 2021
    Inventors: Yuncong Chen, Dongjin Song, Cristian Lumezanu, Haifeng Chen, Takehiko Mizoguchi
  • Patent number: 10889797
    Abstract: Methods of purifying a virus from a virus-infected cell lysate using three-phase partitioning (TPP) are disclosed. The methods comprise a first round of TPP, including mixing a cell lysate comprising a virus with ammonium sulfate and t-butanol, and separating the mixture, thereby forming a first aqueous phase, a first organic phase, and a first interphase. The first aqueous phase can comprise the virus, which can be subjected to a second round of TPP, resulting in a second aqueous phase, a second organic phase, and a second interphase. The second interphase can comprise highly purified virus. The methods can comprise subjecting a first aqueous phase to further purification by column chromatography or density gradient centrifugation. Purification of AAV, including AAV2, AAV5 and AAV6, from lysates of infected insect cell cultures is demonstrated. TPP-purified AAV particles infect at least as well as those prepared by standard methods.
    Type: Grant
    Filed: November 28, 2018
    Date of Patent: January 12, 2021
    Assignee: Virovek Incorporation
    Inventor: Haifeng Chen
  • Patent number: 10887344
    Abstract: Endpoint security systems and methods include a distance estimation module configured to calculate a travel distance between a source Internet Protocol (IP) address and an IP address for a target network endpoint system from a received packet received by the target network endpoint system based on time-to-live (TTL) information from the received packet. A machine learning model is configured to estimate an expected travel distance between the source IP address and the target network endpoint system IP address based on a sparse set of known source/target distances. A spoof detection module is configured to determine that the received packet has a spoofed source IP address based on a comparison between the calculated travel distance and the expected travel distance. A security module is configured to perform a security action at the target network endpoint system responsive to the determination that the received packet has a spoofed source IP address.
    Type: Grant
    Filed: August 13, 2018
    Date of Patent: January 5, 2021
    Assignee: NEC Corporation
    Inventors: Cristian Lumezanu, Nipun Arora, Haifeng Chen, Bo Zong, Daeki Cho, Mingda Li
  • Patent number: 10885185
    Abstract: A computer-implemented method for implementing alert interpretation in enterprise security systems is presented. The computer-implemented method includes employing a plurality of sensors to monitor streaming data from a plurality of computing devices, generating alerts based on the monitored streaming data, automatically analyzing the alerts, in real-time, by using a graph-based alert interpretation engine employing process-star graph models, retrieving a cause of the alerts, an aftermath of the alerts, and baselines for the alert interpretation, and integrating the cause of the alerts, the aftermath of the alerts, and the baselines to output an alert interpretation graph to a user interface of a user device.
    Type: Grant
    Filed: October 16, 2018
    Date of Patent: January 5, 2021
    Inventors: LuAn Tang, Zhengzhang Chen, Zhichun Li, Zhenyu Wu, Jumpei Kamimura, Haifeng Chen
  • Patent number: 10883345
    Abstract: A method and system are provided for processing computer log messages for log visualization and log retrieval. The method includes collecting log messages from one or more computer system components, performing a log tokenization process on the log messages to generate tokens, transforming the tokens into log vectors associated with a metric space, performing dimensionality reduction on the metric space to project the metric space into a lower dimensional sub-space, storing similarity distances between respective pairs of the log vectors, and in response to receiving a query associated with a query log message for reducing operational inefficiencies of the one or more computer system components, employing the similarity distances to retrieve one or more similar log messages corresponding to the query log message for reducing the operational inefficiencies of the one or more computer system components.
    Type: Grant
    Filed: July 13, 2018
    Date of Patent: January 5, 2021
    Inventors: Jianwu Xu, Tanay Kumar Saha, Haifeng Chen, Hui Zhang
  • Publication number: 20200407696
    Abstract: The present disclosure relates to a heterologous recombinant baculovirus (rBV) expression system for the production of foreign heterologous proteins in insect cells. This system comprises a recombinant baculovirus backbone within a genome with a deletion in the cathepsin gene into which foreign gene cassettes can be integrated, and an insect cell that can be infected by the ?v-cath-rBV, and in which the foreign proteins and/or viral vectors or particles are expressed.
    Type: Application
    Filed: June 25, 2020
    Publication date: December 31, 2020
    Inventor: Haifeng Chen
  • Publication number: 20200380295
    Abstract: Methods and systems for predicting failure in a cyber-physical system include determining a prediction index based on a comparison of input time series, from respective sensors in a cyber-physical system, to failure precursors. A failure precursor is detected in the input time series, responsive to a comparison of the prediction index to a threshold. A subset of the sensors associated with the failure precursor is determined, based on a gradient of the prediction index. A corrective action is performed responsive to the determined subset of sensors.
    Type: Application
    Filed: March 12, 2020
    Publication date: December 3, 2020
    Inventors: Masanao Natsumeda, Wei Cheng, Haifeng Chen, Yuncong Chen
  • Publication number: 20200364563
    Abstract: Systems and methods for updating a classification model of a neural network are provided. The methods include selecting, as a set of landmarks, a limited number of data from a set of historical data used to train a classification model. Additionally, the methods generate new training data from recently collected data. Further, the methods update the classification model with the new training data and the set of landmarks to obtain an updated classification model having a loss function configured to capture similarities in the new training data and remember similarities in the historical data represented by the set of landmarks within a predefined tolerance.
    Type: Application
    Filed: May 5, 2020
    Publication date: November 19, 2020
    Inventors: Cristian Lumezanu, Haifeng Chen, Dongjin Song, Wei Cheng, Takehiko Mizoguchi, Xiaoyuan Liang, Yuncong Chen
  • Publication number: 20200366690
    Abstract: Methods and systems for detecting anomalous behavior in a network include identifying topological state information in a dynamic network using a first neural network. Attribute state information in the dynamic network is identified, based on a partial labeling of nodes in the dynamic network, using a second neural network. The topological state information and the attribute state information are concatenated. Labels for unlabeled nodes in the dynamic network are predicted using a multi-factor attention, based on the concatenated state information. A security action is performed responsive to a determination that at least one node in the dynamic network is anomalous.
    Type: Application
    Filed: May 12, 2020
    Publication date: November 19, 2020
    Inventors: Wei Cheng, Haifeng Chen, Wenchao Yu, Dongkuan Xu
  • Publication number: 20200354347
    Abstract: Disclosed are a compound with anthrone and N-containing heterocycle and an application thereof in an OLED. The compound contains anthrone and N-containing heterocycle structure which are both strong electron-withdrawing groups. The compound has a deep HOMO energy level and high electron mobility and is suitable for use as hole blocking materials or electron transport materials; the compound can also be used as a host material for electron-type light-emitting layers; in addition, the compound of the present invention has strong group rigidity, not easily causes crystallization and aggregation between molecules, and has good film-forming property. After the compound of the present invention is applied to an OLED device as an organic electroluminescent functional layer material, the current efficiency, power efficiency and external quantum efficiency of the device are greatly improved; moreover, the compound can improve the service life of the device.
    Type: Application
    Filed: September 25, 2018
    Publication date: November 12, 2020
    Applicant: VALIANT CO., LTD.
    Inventors: Haifeng CHEN, Chong LI, Zhaochao ZHANG, Xiaoqing ZHANG, Dandan TANG
  • Publication number: 20200321475
    Abstract: A manufacturing method for LTPS TFT substrate is disclosed. Through performing two etchings on the gate metal layer, ion heavy doping and ion light doping of the polysilicon active layer are performed in a self-aligned manner such that the LDD structure of the polysilicon active layer is symmetrically distributed on two sides of the gate electrode, which is beneficial to improve device characteristics, is more stable and reliable than the conventional technology, and can reduce the number of process masks, save mask cost, operation cost, material cost and the time cost. The thinning process of the gate insulation layer can reduce the thickness of the gate insulation layer corresponding to the heavily doped region of the polysilicon active layer, so that the ion implantation efficiency can be effectively improved.
    Type: Application
    Filed: September 22, 2018
    Publication date: October 8, 2020
    Inventors: Xin Zhang, Juncheng Xiao, Haifeng Chen, Haijun Tian, Yanqing Guan, Chao Tian
  • Patent number: 10795753
    Abstract: Methods and systems for system failure diagnosis and correction include extracting syntactic patterns from a plurality of logs with heterogeneous formats. The syntactic patterns are clustered according to categories of system failure. A single semantically unique pattern is extracted for each category of system failure. The semantically unique patterns are matched to recent log information to detect a corresponding system failure. A corrective action us performed responsive to the detected system failure.
    Type: Grant
    Filed: December 3, 2018
    Date of Patent: October 6, 2020
    Assignee: NEC Corporation
    Inventors: Jianwu Xu, Hui Zhang, Haifeng Chen, Tanay Kumar Saha, Pranay Anchuri
  • Publication number: 20200285807
    Abstract: A method detects anomalies in a system having sensors for collecting multivariate sensor data including discrete event sequences. The method determines, using a NMT model, pairwise relationships among the sensors based on the data. The method forms sequences of characters into sentences on a per sensor basis, by treating each discrete variable in the sequences as a character in natural language. The method translates, using the NMT, the sentences of source sensors to sentences of target sensors to obtain a translation score that quantifies a pairwise relationship strength therebetween. The method aggregates the pairwise relationships into a multivariate relationship graph having nodes representing sensors and edges denoted by the translation score for a sensor pair connected thereto to represent the pairwise relationship strength therebetween. The method performs a corrective action to correct an anomaly responsive to a detection of the anomaly relating to the sensor pair.
    Type: Application
    Filed: February 11, 2020
    Publication date: September 10, 2020
    Inventors: Jianwu Xu, Haifeng Chen, Bin Nie
  • Publication number: 20200265227
    Abstract: Systems and methods for anomaly detection are provided. The method includes structuring a multi-channel spatial-temporal sequence as a four-dimensional array. The method also includes decomposing the four-dimensional array to form a low-rank component representing a background signal and a residual component representing anomalies for each time point of the multi-channel spatial-temporal sequence. The method further includes determining a sequence of anomaly maps by stacking the residual components at all time points together.
    Type: Application
    Filed: February 13, 2020
    Publication date: August 20, 2020
    Inventors: Yuncong Chen, Dongjin Song, Haifeng Chen