Patents by Inventor Ming-Wei Wu

Ming-Wei Wu has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Publication number: 20260135871
    Abstract: A method for predicting an attacked path on enterprise networks includes: obtaining a plurality of accounts, a plurality of machines and network resource data, where the plurality of machines include at least one attacked target; calculating, according to the network resource data, a plurality of evaluated values of executing access on other machines of each account logging in at least one machine; and presenting an attacked path where a machine at least one account logs in accesses the attacked target directly, or indirectly by connecting to other machines, and the machine the at least one account logs in points to the attacked target directly, or indirectly by connecting to other machines.
    Type: Application
    Filed: January 6, 2026
    Publication date: May 14, 2026
    Inventors: Ming-Chang Chiu, Pei-Kan Tsung, Ming-Wei Wu, Cheng-Lin Yang, Che-Yu Lin, Sian-Yao Huang
  • Patent number: 12542799
    Abstract: A method for predicting an attacked path on enterprise networks includes: obtaining a plurality of accounts, a plurality of machines and network resource data, where the plurality of machines include at least one attacked target; calculating, according to the network resource data, a plurality of evaluated values of executing access on other machines of each account logging in at least one machine; and presenting an attacked path where a machine at least one account logs in accesses the attacked target directly, or indirectly by connecting to other machines, and the machine the at least one account logs in points to the attacked target directly, or indirectly by connecting to other machines.
    Type: Grant
    Filed: June 9, 2023
    Date of Patent: February 3, 2026
    Assignee: CyCraft Singapore Pte., Ltd
    Inventors: Ming-Chang Chiu, Pei-Kan Tsung, Ming-Wei Wu, Cheng-Lin Yang, Che-Yu Lin, Sian-Yao Huang
  • Patent number: 12177233
    Abstract: The present invention provides an information security incident diagnosis system for assisting in detecting whether a target network system has been hacked. First, a plurality of activities records of one or more computing devices in a target network system are collected. Then, a discrete space metric tree is generated according to the plurality of activities records, and a clustering operation is performed on the discrete space metric tree to generate one or more event clusters associated with one or more suspicious event categories. Each event cluster may form a guide tree corresponding to the event cluster through single linkage clustering analysis to indicate a merging order from high to low similarity. The merging order is used for recursively performing a graph generating operation to convert a plurality of activities records corresponding to the one or more event clusters into a hierarchical directed acyclic graph (HDAG).
    Type: Grant
    Filed: July 18, 2022
    Date of Patent: December 24, 2024
    Assignee: CyCarrier Technology Co., Ltd.
    Inventors: Ming-Chang Chiu, Ming-Wei Wu, Pei-Kan Tsung, Che-Yu Lin, Cheng-Lin Yang
  • Patent number: 12086241
    Abstract: The present invention provides an event visualization device configured to generate one or more directed acyclic graphs (DAGs) that can be used as a basis for diagnosing whether a target network system has been hacked according to a plurality of activities records. The plurality of activities records pertain to an event cluster associated with a suspicious event category. The event visualization device performs a graph generating operation on the plurality of activities records in a recursive manner to generate a hierarchical directed acyclic graph (HDAG). The graph generating operation includes: interpreting an activities record into a target DAG, and performing a hierarchical partial order alignment (HPOA) operation on the target DAG and a reference DAG to obtain a merging condition of each node; and merging the target DAG and the reference DAG into the HDAG according to the merging condition.
    Type: Grant
    Filed: July 18, 2022
    Date of Patent: September 10, 2024
    Assignee: CyCarrier Technology Co., Ltd.
    Inventors: Ming-Chang Chiu, Ming-Wei Wu, Pei-Kan Tsung, Che-Yu Lin, Cheng-Lin Yang
  • Patent number: 12081570
    Abstract: The present invention provides a log classification system configured to perform a hierarchical similarity analysis operation according to a plurality of activities records to generate a discrete space metric tree, and perform a clustering operation on the discrete space metric tree to generate one or more event clusters associated with one or more suspicious event categories. The log classification system includes an output device configured to output the one or more event clusters to an information security incident diagnosis system, and allow the information security incident diagnosis system to calculate similar feature information and differential feature information of a plurality of activities records in the one or more event clusters as auxiliary information for diagnosing whether there are intrusions or abnormalities in a target network system.
    Type: Grant
    Filed: July 18, 2022
    Date of Patent: September 3, 2024
    Assignee: CyCarrier Technology Co., Ltd.
    Inventors: Ming-Chang Chiu, Ming-Wei Wu, Pei-Kan Tsung, Che-Yu Lin, Cheng-Lin Yang
  • Publication number: 20240056469
    Abstract: A method for predicting an attacked path on enterprise networks includes: obtaining a plurality of accounts, a plurality of machines and network resource data, where the plurality of machines include at least one attacked target; calculating, according to the network resource data, a plurality of evaluated values of executing access on other machines of each account logging in at least one machine; and presenting an attacked path where a machine at least one account logs in accesses the attacked target directly, or indirectly by connecting to other machines, and the machine the at least one account logs in points to the attacked target directly, or indirectly by connecting to other machines.
    Type: Application
    Filed: June 9, 2023
    Publication date: February 15, 2024
    Inventors: Ming-Chang Chiu, Pei-Kan Tsung, Ming-Wei Wu, Cheng-Lin Yang, Che-Yu Lin, Sian-Yao Huang
  • Publication number: 20230036609
    Abstract: The present invention provides an event visualization device configured to generate one or more directed acyclic graphs (DAGs) that can be used as a basis for diagnosing whether a target network system has been hacked according to a plurality of activities records. The plurality of activities records pertain to an event cluster associated with a suspicious event category. The event visualization device performs a graph generating operation on the plurality of activities records in a recursive manner to generate a hierarchical directed acyclic graph (HDAG). The graph generating operation includes: interpreting an activities record into a target DAG, and performing a hierarchical partial order alignment (HPOA) operation on the target DAG and a reference DAG to obtain a merging condition of each node; and merging the target DAG and the reference DAG into the HDAG according to the merging condition.
    Type: Application
    Filed: July 18, 2022
    Publication date: February 2, 2023
    Inventors: Ming-Chang Chiu, Ming-Wei Wu, Pei-Kan Tsung, Che-Yu Lin, Cheng-Lin Yang
  • Publication number: 20230032070
    Abstract: The present invention provides a log classification system configured to perform a hierarchical similarity analysis operation according to a plurality of activities records to generate a discrete space metric tree, and perform a clustering operation on the discrete space metric tree to generate one or more event clusters associated with one or more suspicious event categories. The log classification system includes an output device configured to output the one or more event clusters to an information security incident diagnosis system, and allow the information security incident diagnosis system to calculate similar feature information and differential feature information of a plurality of activities records in the one or more event clusters as auxiliary information for diagnosing whether there are intrusions or abnormalities in a target network system.
    Type: Application
    Filed: July 18, 2022
    Publication date: February 2, 2023
    Inventors: Ming-Chang Chiu, Ming-Wei Wu, Pei-Kan Tsung, Che-Yu Lin, Cheng-Lin Yang
  • Publication number: 20230022709
    Abstract: The present invention provides an information security incident diagnosis system for assisting in detecting whether a target network system has been hacked. First, a plurality of activities records of one or more computing devices in a target network system are collected. Then, a discrete space metric tree is generated according to the plurality of activities records, and a clustering operation is performed on the discrete space metric tree to generate one or more event clusters associated with one or more suspicious event categories. Each event cluster may form a guide tree corresponding to the event cluster through single linkage clustering analysis to indicate a merging order from high to low similarity. The merging order is used for recursively performing a graph generating operation to convert a plurality of activities records corresponding to the one or more event clusters into a hierarchical directed acyclic graph (HDAG).
    Type: Application
    Filed: July 18, 2022
    Publication date: January 26, 2023
    Inventors: Ming-Chang Chiu, Ming-Wei Wu, Pei-Kan Tsung, Che-Yu Lin, Cheng-Lin Yang
  • Patent number: 10065244
    Abstract: The present invention discloses a method for fabricating a porous spherical iron-based alloy powder, a powder thereof and a sintered body thereof. The method comprises steps: mixing an iron oxide powder and an alloying powder to form a mixed powder; spray-granulating the mixed powder to form a spherical spray-granulated powder; and placing the spherical spray-granulated powder in a reducing environment and heating it to a temperature of lower than 700° C. to obtain a porous spherical iron-based alloy powder having high flowability, high compressibility, superior sinterability and low cost.
    Type: Grant
    Filed: April 18, 2016
    Date of Patent: September 4, 2018
    Assignee: Taiwan Powder Technologies Co., Ltd.
    Inventors: Kuen-Shyang Hwang, Ming-Wei Wu, Yang-Liang Fan
  • Publication number: 20170297114
    Abstract: The present invention discloses a method for fabricating a porous spherical iron-based alloy powder, a powder thereof and a sintered body thereof. The method comprises steps: mixing an iron oxide powder and an alloying powder to form a mixed powder; spray-granulating the mixed powder to form a spherical spray-granulated powder; and placing the spherical spray-granulated powder in a reducing environment and heating it to a temperature of lower than 700° C. to obtain a porous spherical iron-based alloy powder having high flowability, high compressibility, superior sinterability and low cost.
    Type: Application
    Filed: April 18, 2016
    Publication date: October 19, 2017
    Inventors: Kuen-Shyang HWANG, Ming-Wei WU, Yang-Liang FAN
  • Publication number: 20160134652
    Abstract: A method for recognizing disguised malicious document, carried out by a computer system including a central processing unit (CPU), a memory, and a database storing rules for defining executable file and non-executable file, comprising steps of: receiving a static file through a network and an input/out interface; scanning the static file for a file header to determine if it is a non-executable file; analyzing file body of the non-executable file to locate components of an executable file and mark these positions; extracting components of the executable file from the non-executable file; concatenating the extracted components in accordance with a default rule or a heuristic rule to form a new file; and obtaining a new file that is executable, such that the received static file is a non-executable file having an embedded executable file, thus labeling the static file as a disguised malicious document.
    Type: Application
    Filed: January 18, 2016
    Publication date: May 12, 2016
    Inventors: Ming-Chang Chiu, Ming-Wei Wu, Ching-Chung Wang, Che-Kuo Hsu, Pei-Kan Tsung
  • Publication number: 20140150101
    Abstract: A method for recognizing malicious file has steps: receiving a static file through a network or an input/out interface to be stored in the memory; defining suspicious positions where components of a malware are possibly encrypted in the static file; decrypting the suspicious positions to identify a PE header and a shellcode; extracting the PE header and the shellcode terms in segments; and determining whether the PE header and the shellcode terms can be assembled into an executable binary which indicates a recognition of the malicious file.
    Type: Application
    Filed: January 29, 2014
    Publication date: May 29, 2014
    Applicant: Xecure Lab Co., Ltd.
    Inventors: Ming-Chang Chiu, Ming-Wei Wu, Ching-Chung Wang, Che-Kuo Hsu, Pei-Kan Tsung
  • Publication number: 20130179975
    Abstract: A method for extracting the genetic fingerprinting of a malicious document file includes the steps of establishing a database to store a plurality of genetic fingerprinting data of the first malicious document, then retrieving a document file sent via the Internet, and then proceeding with multi-point detection and extraction to the document file, so as to obtain a multi-point section, then comparing and analyzing the multi-point section with the plurality of genetic fingerprinting data of the first malicious document to confirm whether the multi-point section program code of the document file matches a malicious feature, thereby achieves the goal of extracting the content information of the document file and converts it into the genetic fingerprinting data of a new malicious document.
    Type: Application
    Filed: September 12, 2012
    Publication date: July 11, 2013
    Inventors: Ming-Chang Chiu, Ming-Wei Wu, Ching-Chung Wang, Che-Kuo Hsu, Pei-Kan Tsung
  • Publication number: 20110003177
    Abstract: A method for producing a sputtering target containing boron has steps of providing cobalt-chromium (Co·Cr) prealloy powder, mixing Co·Cr prealloy powder and raw material powder containing boron and oxide to form a mixture, preforming the mixture to form a green compact, and sintering the green compact to obtain the sputtering target containing boron. Because Co·Cr prealloy powder is provided, then is mixed with boron, oxide or the like, size and distribution of boride particles can be efficiently controlled. Therefore, Co, Cr, B or the like are uniformly distributed in the sputtering target.
    Type: Application
    Filed: July 6, 2009
    Publication date: January 6, 2011
    Applicant: SOLAR APPLIED MATERIALS TECHNOLOGY CORP.
    Inventors: Ming-Wei Wu, Hao-Chia Liao