Patents by Inventor Peter Thayer

Peter Thayer has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 11916934
    Abstract: Example methods disclosed herein to determine whether a first monitored device is compromised include determining a first entropy value for the first monitored device based on a first number of unique event identifiers included in log entries obtained for the first monitored device, the log entries associated with a first time window. Disclosed example methods also include determining a second entropy value for the first monitored device based on numbers of unique event identifiers included in corresponding groups of log entries obtained for respective ones of a plurality of monitored devices including the first monitored device, the groups of log entries associated with the first time window. Disclosed example methods further include determining whether the first monitored device is compromised based on the first entropy value and the second entropy value, and performing an action in response to a determination that the first monitored device is compromised.
    Type: Grant
    Filed: May 16, 2022
    Date of Patent: February 27, 2024
    Assignee: MUSARUBRA US LLC
    Inventors: Peter Thayer, Gabriel G. Infante-Lopez, Leandro J. Ferrado, Alejandro Houspanossian
  • Publication number: 20220353280
    Abstract: Example methods disclosed herein to determine whether a first monitored device is compromised include determining a first entropy value for the first monitored device based on a first number of unique event identifiers included in log entries obtained for the first monitored device, the log entries associated with a first time window. Disclosed example methods also include determining a second entropy value for the first monitored device based on numbers of unique event identifiers included in corresponding groups of log entries obtained for respective ones of a plurality of monitored devices including the first monitored device, the groups of log entries associated with the first time window. Disclosed example methods further include determining whether the first monitored device is compromised based on the first entropy value and the second entropy value, and performing an action in response to a determination that the first monitored device is compromised.
    Type: Application
    Filed: May 16, 2022
    Publication date: November 3, 2022
    Inventors: Peter Thayer, Gabriel G. Infante-Lopez, Leandro J. Ferrado, Alejandro Houspanossian
  • Patent number: 11336665
    Abstract: Example methods disclosed herein to determine whether a first monitored device is compromised include determining a first entropy value for the first monitored device based on a first number of unique event identifiers included in log entries obtained for the first monitored device, the log entries associated with a first time window. Disclosed example methods also include determining a second entropy value for the first monitored device based on numbers of unique event identifiers included in corresponding groups of log entries obtained for respective ones of a plurality of monitored devices including the first monitored device, the groups of log entries associated with the first time window. Disclosed example methods further include determining whether the first monitored device is compromised based on the first entropy value and the second entropy value, and performing an action in response to a determination that the first monitored device is compromised.
    Type: Grant
    Filed: September 30, 2019
    Date of Patent: May 17, 2022
    Assignee: Musarubra US LLC
    Inventors: Peter Thayer, Gabriel G. Infante-Lopez, Leandro J. Ferrado, Alejandro Houspanossian
  • Patent number: 11290489
    Abstract: A computing system performs adaptive clustering of machines (e.g., computing devices) and/or machine users in an organization for attack surface reduction (ASR) responsively to event feedback including system-based exclusion events and user-based requests for exclusion. The cluster adaptation may be applied to conventional vector-quantization clustering algorithms, for example K-Means, expectation-maximization (EM) clustering, or affinity clustering, to provide adaptable clusters of machines or users. The adaptation enables aggregation or disaggregation of endpoints into clusters to minimize negative business impacts on the organization while maximizing security in view of changes in the organization that occur dynamically such as varying roles for users, new applications and updates being released, and the like.
    Type: Grant
    Filed: March 7, 2019
    Date of Patent: March 29, 2022
    Assignee: Microsoft Technology Licensing, LLC
    Inventors: Yalan Xing, Joseph Carl Nelson Blackbird, Francis Allan Tan Seng, Prachi Rathee, Peter Thayer
  • Publication number: 20200287938
    Abstract: A computing system performs adaptive clustering of machines (e.g., computing devices) and/or machine users in an organization for attack surface reduction (ASR) responsively to event feedback including system-based exclusion events and user-based requests for exclusion. The cluster adaptation may be applied to conventional vector-quantization clustering algorithms, for example K-Means, expectation-maximization (EM) clustering, or affinity clustering, to provide adaptable clusters of machines or users. The adaptation enables aggregation or disaggregation of endpoints into clusters to minimize negative business impacts on the organization while maximizing security in view of changes in the organization that occur dynamically such as varying roles for users, new applications and updates being released, and the like.
    Type: Application
    Filed: March 7, 2019
    Publication date: September 10, 2020
    Inventors: Yalan XING, Joseph Carl Nelson BLACKBIRD, Francis Allan TAN SENG, Prachi RATHEE, Peter THAYER
  • Publication number: 20200106786
    Abstract: Example methods disclosed herein to determine whether a first monitored device is compromised include determining a first entropy value for the first monitored device based on a first number of unique event identifiers included in log entries obtained for the first monitored device, the log entries associated with a first time window. Disclosed example methods also include determining a second entropy value for the first monitored device based on numbers of unique event identifiers included in corresponding groups of log entries obtained for respective ones of a plurality of monitored devices including the first monitored device, the groups of log entries associated with the first time window. Disclosed example methods further include determining whether the first monitored device is compromised based on the first entropy value and the second entropy value, and performing an action in response to a determination that the first monitored device is compromised.
    Type: Application
    Filed: September 30, 2019
    Publication date: April 2, 2020
    Inventors: Peter Thayer, Gabriel G. Infante-Lopez, Leandro J. Ferrado, Alejandro Houspanossian
  • Publication number: 20200028871
    Abstract: Features of the present disclosure solve the above-identified problem by implementing user and entity behavior analytics (UEBA) system to group one or more computer machines into different clusters based on monitored behavior of the one or more computer machines. Specifically, a network device (e.g., administrator computer system) may monitor the activity of the one or more computer machines for a predetermined time period in order to identify the applications that the computer machines utilize. Based on the clustering and the identifying, the network device may automatically apply different access control policies for different clusters of machines and review those access control policies against future behavior periodically. By clustering machines based on usage behavior patterns and automatically recommending a rule set for deployment, the UEBA system may reduce potential points of failure for cybersecurity breaches.
    Type: Application
    Filed: April 17, 2018
    Publication date: January 23, 2020
    Inventors: Peter THAYER, Deepak Jagannathan MANOHAR, Kambiz KOULADJIE, Joseph Carl Nelson BLACKBIRD, Prachi RATHEE
  • Patent number: 10440037
    Abstract: Detecting a malware attack includes monitoring an event log of a first device, wherein the event log identifies events indicating that the first device is likely compromised, determining an expected rate of log entries during a time window, identifying that an actual rate of log entries during the time window satisfies a threshold, determining, in response to the identifying, that the first device is a compromised device, and performing an action in response to determining that the first device is a compromised device.
    Type: Grant
    Filed: March 31, 2017
    Date of Patent: October 8, 2019
    Assignee: McAfee, LLC
    Inventors: Peter Thayer, Gabriel G. Infante-Lopez, Leandro J. Ferrado, Alejandro Houspanossian
  • Publication number: 20180288074
    Abstract: Detecting a malware attack includes monitoring an event log of a first device, wherein the event log identifies events indicating that the first device is likely compromised, determining an expected rate of log entries during a time window, identifying that an actual rate of log entries during the time window satisfies a threshold, determining, in response to the identifying, that the first device is a compromised device, and performing an action in response to determining that the first device is a compromised device.
    Type: Application
    Filed: March 31, 2017
    Publication date: October 4, 2018
    Inventors: Peter Thayer, Gabriel G. Infante-Lopez, Leandro J. Ferrado, Alejandro Houspanossian
  • Publication number: 20070086482
    Abstract: A system and method for managing wireless vehicular communications include a system and method for vehicle protocol conversion. The system and method for vehicle protocol conversion have the ability to receive messages through a vehicle bus connector according to a vehicle bus protocol, analyze the messages to determine whether they should be transmitted, and transmit the messages over a wireless link if they should be transmitted.
    Type: Application
    Filed: October 17, 2006
    Publication date: April 19, 2007
    Applicant: ELECTRONIC DATA SYSTEMS CORPORATION
    Inventors: Brian Pruzan, Peter Thayer, Steven Enyart, Paul Phillips, Leonid Shlayen, Timothy Hans
  • Publication number: 20060184613
    Abstract: This disclosure describes techniques for data transfer between web browsers and a server computer in a web-based environment. In particular, this disclosure describes a data transfer system that includes a set of web-based applications designed to rapidly transfer large amounts of data as a background task, and similarly transfer updated data without requiring a user to request the updated data. In accordance with the invention, a cache of data is stored on the web browser. The web browser and server computer make use of web browser components or add-ins, referred to herein as data conduit modules. The data conduit modules provide the web browsers with the ability to poll the server for updates, as a background task. Additionally, the data conduit modules are capable of retrieving changed data from the server and updating the data in the local cache. Such updates can occur automatically, and independent of user requests.
    Type: Application
    Filed: March 31, 2005
    Publication date: August 17, 2006
    Applicant: Xata Corporation
    Inventors: David Stienessen, Eric Smisek, Peter Thayer, Jeffrey Ferguson, Margaret Ratcliff, Patrick Exley
  • Publication number: 20060028205
    Abstract: In a railway line, thermally-induced stresses are a factor for both rail breaks and rail buckling. These stresses are in the longitudinal direction. A nondestructive measuring technique enables the residual stress in a rail to be determined, and hence the thermally-induced stress. An electromagnetic probe is used to measure the stresses in the rail web in the vertical direction, and in the direction parallel to the longitudinal axis. The residual stress in the longitudinal direction can be deduced from the measured stress in the vertical direction; hence the thermally-induced stress can be determined.
    Type: Application
    Filed: February 13, 2004
    Publication date: February 9, 2006
    Inventors: David Buttle, William Dalzell, Peter Thayer
  • Publication number: 20040176905
    Abstract: A mobile device for a vehicle is disclosed, which uses scripts provided from a server. The scripts can include indications that indicate the appropriateness of input data. Additionally, the scripts can include conditional actions that only occur when certain input data values are recorded.
    Type: Application
    Filed: March 6, 2003
    Publication date: September 9, 2004
    Inventors: Douglas Ray Sanqunetti, Jeffrey D. Johnson, Rena Yamamoto, Peter Thayer