Patents by Inventor Kaan Onarlioglu

Kaan Onarlioglu has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 9516039
    Abstract: Methods, apparatus and articles of manufacture for behavioral detection of suspicious host activities in an enterprise are provided herein. A method includes processing log data derived from one or more data sources associated with an enterprise network over a given period of time, wherein the enterprise network comprises multiple host devices; extracting one or more features from said log data on a per host device basis, wherein said extracting comprises: determining a pattern of behavior associated with the multiple host devices based on said processing; and identifying said features representative of host device behavior based on the determined pattern of behavior; clustering the multiple host devices into one or more groups based on said one or more features; and identifying a behavioral anomaly associated with one of the multiple host devices by comparing said host device to the one or more groups across the multiple host devices.
    Type: Grant
    Filed: December 23, 2013
    Date of Patent: December 6, 2016
    Assignee: EMC IP Holding Company LLC
    Inventors: Ting-Fang Yen, Alina Oprea, Kaan Onarlioglu, Todd Leetham, William Robertson, Ari Juels, Engin Kirda
  • Patent number: 9503468
    Abstract: Methods, apparatus and articles of manufacture for detecting suspicious web traffic are provided herein. A method includes generating a database comprising information corresponding to each of multiple connections between one or more destinations external to an enterprise network and one or more hosts within the enterprise network, wherein said multiple connections occur over a given period of time; processing multiple additional connections between one or more destinations external to the enterprise network and one or more hosts within the enterprise network with one or more filtering operations to produce one or more filtered connections, wherein said multiple additional connections occur subsequent to said given period of time; and analyzing said filtered connections against the database to identify a connection to a destination external to the enterprise network that is not included in the information in the database.
    Type: Grant
    Filed: April 28, 2015
    Date of Patent: November 22, 2016
    Assignee: EMC IP Holding Company LLC
    Inventors: Ting-Fang Yen, Alina Oprea, Kaan Onarlioglu
  • Patent number: 9430501
    Abstract: Time correction records are created for correcting timestamps of network logs to identify timing of network events in a predetermined time reference frame, the network logs being created by logging devices generating the timestamps in device time reference frames. For each logging device, one or more network events are generated or identified at respective event times in the predetermined time reference frame, each network event having a corresponding event-related network log from the logging device and a respective timestamp in a device time reference frame. For each network event, a respective difference value is calculated as a difference between the event time and a respective timestamp from a network log. For each logging device, a selection function is applied to the difference values to calculate a correction value, and the correction value is stored along with an identifier of the logging device in a time correction record.
    Type: Grant
    Filed: December 31, 2012
    Date of Patent: August 30, 2016
    Assignee: EMC Corporation
    Inventors: Ting-Fang Yen, Ari Juels, Kaan Onarlioglu, Alina Oprea
  • Patent number: 9378361
    Abstract: A threat detection system for detecting threat activity in a protected computer system includes anomaly sensors of distinct types including user-activity sensors, host-activity sensors and application-activity sensors. Each sensor builds a history of pertinent activity over a training period, and during a subsequent detection period the sensor compares current activity to the history to detect new activity. The new activity is identified in respective sensor output. A set of correlators of distinct types are used that correspond to different stages of threat activity according to modeled threat behavior. Each correlator receives output of one or more different-type sensors and applies logical and/or temporal testing to detect activity patterns of the different stages. The results of the logical and/or temporal testing are used to generate alert outputs for a human or machine user.
    Type: Grant
    Filed: December 31, 2012
    Date of Patent: June 28, 2016
    Assignee: EMC Corporation
    Inventors: Ting-Fang Yen, Ari Juels, Aditya Kuppa, Kaan Onarlioglu, Alina Oprea
  • Patent number: 9124585
    Abstract: Mapping network addresses in logs of network activity to corresponding host computers includes generating lists of known-dynamic addresses, static addresses and other-dynamic addresses from network addresses appearing in the logs. The static addresses and other-dynamic addresses are assigned to host computers having respective first host identifiers, and the known-dynamic addresses are associated with corresponding host computers having respective second host computer identifiers contained in dynamic address assignment activity. For the static and other-dynamic addresses, the first host identifiers are obtained, and first address-to-host bindings are created for address-based lookups of first host identifiers using respective addresses.
    Type: Grant
    Filed: December 31, 2012
    Date of Patent: September 1, 2015
    Assignee: EMC Corporation
    Inventors: Ting-Fang Yen, Kaan Onarlioglu
  • Patent number: 9049221
    Abstract: Methods, apparatus and articles of manufacture for detecting suspicious web traffic are provided herein. A method includes generating a database comprising information corresponding to each of multiple connections between one or more destinations external to an enterprise network and one or more hosts within the enterprise network, wherein said multiple connections occur over a given period of time; processing multiple additional connections between one or more destinations external to the enterprise network and one or more hosts within the enterprise network with one or more filtering operations to produce one or more filtered connections, wherein said multiple additional connections occur subsequent to said given period of time; and analyzing said filtered connections against the database to identify a connection to a destination external to the enterprise network that is not included in the information in the database.
    Type: Grant
    Filed: December 23, 2013
    Date of Patent: June 2, 2015
    Assignee: EMC Corporation
    Inventors: Ting-Fang Yen, Alina Oprea, Kaan Onarlioglu