Patents by Inventor Peter Thayer
Peter Thayer has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Patent number: 11916934Abstract: Example methods disclosed herein to determine whether a first monitored device is compromised include determining a first entropy value for the first monitored device based on a first number of unique event identifiers included in log entries obtained for the first monitored device, the log entries associated with a first time window. Disclosed example methods also include determining a second entropy value for the first monitored device based on numbers of unique event identifiers included in corresponding groups of log entries obtained for respective ones of a plurality of monitored devices including the first monitored device, the groups of log entries associated with the first time window. Disclosed example methods further include determining whether the first monitored device is compromised based on the first entropy value and the second entropy value, and performing an action in response to a determination that the first monitored device is compromised.Type: GrantFiled: May 16, 2022Date of Patent: February 27, 2024Assignee: MUSARUBRA US LLCInventors: Peter Thayer, Gabriel G. Infante-Lopez, Leandro J. Ferrado, Alejandro Houspanossian
-
Publication number: 20220353280Abstract: Example methods disclosed herein to determine whether a first monitored device is compromised include determining a first entropy value for the first monitored device based on a first number of unique event identifiers included in log entries obtained for the first monitored device, the log entries associated with a first time window. Disclosed example methods also include determining a second entropy value for the first monitored device based on numbers of unique event identifiers included in corresponding groups of log entries obtained for respective ones of a plurality of monitored devices including the first monitored device, the groups of log entries associated with the first time window. Disclosed example methods further include determining whether the first monitored device is compromised based on the first entropy value and the second entropy value, and performing an action in response to a determination that the first monitored device is compromised.Type: ApplicationFiled: May 16, 2022Publication date: November 3, 2022Inventors: Peter Thayer, Gabriel G. Infante-Lopez, Leandro J. Ferrado, Alejandro Houspanossian
-
Patent number: 11336665Abstract: Example methods disclosed herein to determine whether a first monitored device is compromised include determining a first entropy value for the first monitored device based on a first number of unique event identifiers included in log entries obtained for the first monitored device, the log entries associated with a first time window. Disclosed example methods also include determining a second entropy value for the first monitored device based on numbers of unique event identifiers included in corresponding groups of log entries obtained for respective ones of a plurality of monitored devices including the first monitored device, the groups of log entries associated with the first time window. Disclosed example methods further include determining whether the first monitored device is compromised based on the first entropy value and the second entropy value, and performing an action in response to a determination that the first monitored device is compromised.Type: GrantFiled: September 30, 2019Date of Patent: May 17, 2022Assignee: Musarubra US LLCInventors: Peter Thayer, Gabriel G. Infante-Lopez, Leandro J. Ferrado, Alejandro Houspanossian
-
Patent number: 11290489Abstract: A computing system performs adaptive clustering of machines (e.g., computing devices) and/or machine users in an organization for attack surface reduction (ASR) responsively to event feedback including system-based exclusion events and user-based requests for exclusion. The cluster adaptation may be applied to conventional vector-quantization clustering algorithms, for example K-Means, expectation-maximization (EM) clustering, or affinity clustering, to provide adaptable clusters of machines or users. The adaptation enables aggregation or disaggregation of endpoints into clusters to minimize negative business impacts on the organization while maximizing security in view of changes in the organization that occur dynamically such as varying roles for users, new applications and updates being released, and the like.Type: GrantFiled: March 7, 2019Date of Patent: March 29, 2022Assignee: Microsoft Technology Licensing, LLCInventors: Yalan Xing, Joseph Carl Nelson Blackbird, Francis Allan Tan Seng, Prachi Rathee, Peter Thayer
-
Publication number: 20200287938Abstract: A computing system performs adaptive clustering of machines (e.g., computing devices) and/or machine users in an organization for attack surface reduction (ASR) responsively to event feedback including system-based exclusion events and user-based requests for exclusion. The cluster adaptation may be applied to conventional vector-quantization clustering algorithms, for example K-Means, expectation-maximization (EM) clustering, or affinity clustering, to provide adaptable clusters of machines or users. The adaptation enables aggregation or disaggregation of endpoints into clusters to minimize negative business impacts on the organization while maximizing security in view of changes in the organization that occur dynamically such as varying roles for users, new applications and updates being released, and the like.Type: ApplicationFiled: March 7, 2019Publication date: September 10, 2020Inventors: Yalan XING, Joseph Carl Nelson BLACKBIRD, Francis Allan TAN SENG, Prachi RATHEE, Peter THAYER
-
Publication number: 20200106786Abstract: Example methods disclosed herein to determine whether a first monitored device is compromised include determining a first entropy value for the first monitored device based on a first number of unique event identifiers included in log entries obtained for the first monitored device, the log entries associated with a first time window. Disclosed example methods also include determining a second entropy value for the first monitored device based on numbers of unique event identifiers included in corresponding groups of log entries obtained for respective ones of a plurality of monitored devices including the first monitored device, the groups of log entries associated with the first time window. Disclosed example methods further include determining whether the first monitored device is compromised based on the first entropy value and the second entropy value, and performing an action in response to a determination that the first monitored device is compromised.Type: ApplicationFiled: September 30, 2019Publication date: April 2, 2020Inventors: Peter Thayer, Gabriel G. Infante-Lopez, Leandro J. Ferrado, Alejandro Houspanossian
-
Publication number: 20200028871Abstract: Features of the present disclosure solve the above-identified problem by implementing user and entity behavior analytics (UEBA) system to group one or more computer machines into different clusters based on monitored behavior of the one or more computer machines. Specifically, a network device (e.g., administrator computer system) may monitor the activity of the one or more computer machines for a predetermined time period in order to identify the applications that the computer machines utilize. Based on the clustering and the identifying, the network device may automatically apply different access control policies for different clusters of machines and review those access control policies against future behavior periodically. By clustering machines based on usage behavior patterns and automatically recommending a rule set for deployment, the UEBA system may reduce potential points of failure for cybersecurity breaches.Type: ApplicationFiled: April 17, 2018Publication date: January 23, 2020Inventors: Peter THAYER, Deepak Jagannathan MANOHAR, Kambiz KOULADJIE, Joseph Carl Nelson BLACKBIRD, Prachi RATHEE
-
Patent number: 10440037Abstract: Detecting a malware attack includes monitoring an event log of a first device, wherein the event log identifies events indicating that the first device is likely compromised, determining an expected rate of log entries during a time window, identifying that an actual rate of log entries during the time window satisfies a threshold, determining, in response to the identifying, that the first device is a compromised device, and performing an action in response to determining that the first device is a compromised device.Type: GrantFiled: March 31, 2017Date of Patent: October 8, 2019Assignee: McAfee, LLCInventors: Peter Thayer, Gabriel G. Infante-Lopez, Leandro J. Ferrado, Alejandro Houspanossian
-
Publication number: 20180288074Abstract: Detecting a malware attack includes monitoring an event log of a first device, wherein the event log identifies events indicating that the first device is likely compromised, determining an expected rate of log entries during a time window, identifying that an actual rate of log entries during the time window satisfies a threshold, determining, in response to the identifying, that the first device is a compromised device, and performing an action in response to determining that the first device is a compromised device.Type: ApplicationFiled: March 31, 2017Publication date: October 4, 2018Inventors: Peter Thayer, Gabriel G. Infante-Lopez, Leandro J. Ferrado, Alejandro Houspanossian
-
Publication number: 20070086482Abstract: A system and method for managing wireless vehicular communications include a system and method for vehicle protocol conversion. The system and method for vehicle protocol conversion have the ability to receive messages through a vehicle bus connector according to a vehicle bus protocol, analyze the messages to determine whether they should be transmitted, and transmit the messages over a wireless link if they should be transmitted.Type: ApplicationFiled: October 17, 2006Publication date: April 19, 2007Applicant: ELECTRONIC DATA SYSTEMS CORPORATIONInventors: Brian Pruzan, Peter Thayer, Steven Enyart, Paul Phillips, Leonid Shlayen, Timothy Hans
-
Publication number: 20060184613Abstract: This disclosure describes techniques for data transfer between web browsers and a server computer in a web-based environment. In particular, this disclosure describes a data transfer system that includes a set of web-based applications designed to rapidly transfer large amounts of data as a background task, and similarly transfer updated data without requiring a user to request the updated data. In accordance with the invention, a cache of data is stored on the web browser. The web browser and server computer make use of web browser components or add-ins, referred to herein as data conduit modules. The data conduit modules provide the web browsers with the ability to poll the server for updates, as a background task. Additionally, the data conduit modules are capable of retrieving changed data from the server and updating the data in the local cache. Such updates can occur automatically, and independent of user requests.Type: ApplicationFiled: March 31, 2005Publication date: August 17, 2006Applicant: Xata CorporationInventors: David Stienessen, Eric Smisek, Peter Thayer, Jeffrey Ferguson, Margaret Ratcliff, Patrick Exley
-
Publication number: 20060028205Abstract: In a railway line, thermally-induced stresses are a factor for both rail breaks and rail buckling. These stresses are in the longitudinal direction. A nondestructive measuring technique enables the residual stress in a rail to be determined, and hence the thermally-induced stress. An electromagnetic probe is used to measure the stresses in the rail web in the vertical direction, and in the direction parallel to the longitudinal axis. The residual stress in the longitudinal direction can be deduced from the measured stress in the vertical direction; hence the thermally-induced stress can be determined.Type: ApplicationFiled: February 13, 2004Publication date: February 9, 2006Inventors: David Buttle, William Dalzell, Peter Thayer
-
Publication number: 20040176905Abstract: A mobile device for a vehicle is disclosed, which uses scripts provided from a server. The scripts can include indications that indicate the appropriateness of input data. Additionally, the scripts can include conditional actions that only occur when certain input data values are recorded.Type: ApplicationFiled: March 6, 2003Publication date: September 9, 2004Inventors: Douglas Ray Sanqunetti, Jeffrey D. Johnson, Rena Yamamoto, Peter Thayer