Patents by Inventor Ulfar Erlingsson

Ulfar Erlingsson has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 12676874
    Abstract: An illustrative method for querying multiple datasets may include accessing a plurality of datasets including data associated with monitoring one or more compute environments and ingested at varying time intervals, receiving a query request for information that depends on the data included in multiple datasets of the plurality of datasets, querying, based on the query request, the multiple datasets, prioritizing, based on the varying time intervals, information that depends on the data included in the multiple datasets and presenting, based on the prioritizing, a query result representative of the information that depends on the data included in the multiple datasets.
    Type: Grant
    Filed: December 14, 2023
    Date of Patent: July 7, 2026
    Assignee: Fortinet, Inc.
    Inventors: Ulfar Erlingsson, Helgi K. Sigurbjarnarson, Ross T. Bunker, Yijou Chen
  • Patent number: 12659325
    Abstract: An illustrative method includes accessing, by a data platform, workload data associated with one or more workloads deployed within a compute environment and associated with an entity; generating, by the data platform and based on an analysis of the workload data, a rule specific to the entity and associated with an operation of the one or more workloads; and performing, by the data platform, an operation with respect to implementation of the rule within the compute environment.
    Type: Grant
    Filed: November 17, 2022
    Date of Patent: June 16, 2026
    Assignee: Fortinet, Inc.
    Inventors: George B. Spofford, Ulfar Erlingsson, Yijou Chen
  • Patent number: 12615271
    Abstract: A data collection system is disclosed to be communicatively coupled to a data platform configured to perform security monitoring of a compute environment. A sub-kernel component of the data collection system may live capture a state snapshot of a compute resource within the compute environment. The live capture of the state snapshot may be performed by updating a master state snapshot with delta state snapshots so as to avoid detectable disruption to the compute resource during the live capture. Based on the state snapshot, the data collection system may determine event data that represents events occurring with respect to the compute resource and may provide the event data to the data platform for use by the data platform in performing the security monitoring of the compute environment. Corresponding methods, systems, and products for compute environment security monitoring using a live state snapshot of a compute resource are also disclosed.
    Type: Grant
    Filed: May 25, 2023
    Date of Patent: April 28, 2026
    Assignee: Fortinet, Inc.
    Inventors: Ulfar Erlingsson, Yijou Chen
  • Patent number: 12500912
    Abstract: An illustrative method for querying multiple datasets may include generating, based on models each associated with and defining attributes of a different datasets stored in a plurality of data stores, a semantic layer defining relationships between the models and that provides a centralized application programming interface (API) for exposing the datasets by way of a common query language, receiving, by way of the centralized API, a query request for information that depends on data included in multiple datasets included in the plurality of datasets, querying, based on the query request and the relationships between the models defined by the semantic layer, the multiple datasets, and presenting, based on the querying, a query result representative of the information that depends on the data included in the multiple datasets.
    Type: Grant
    Filed: July 31, 2023
    Date of Patent: December 16, 2025
    Assignee: Fortinet, Inc.
    Inventors: Ulfar Erlingsson, Christopher R. Golden, Ross T. Bunker, Helgi K. Sigurbjarnarson, Jean-Philippe E. Martin, Neil B. Vachharajani, Amey Sakhadeo, Yijou Chen
  • Patent number: 12335286
    Abstract: A data collection system is disclosed to be communicatively coupled to a data platform configured to perform security monitoring of a compute environment. A sub-kernel component of the data collection system may collect sub-kernel data accessible from a sub-kernel space below an operating system of a compute resource in the compute environment. The data collection system may manipulate the collected sub-kernel data to prepare the sub-kernel data to be used by the data platform in performing the security monitoring of the compute environment. The data collection system may then communicate the manipulated sub-kernel data to the data platform. Corresponding methods, systems, and products for compute environment security monitoring using data collected from a sub-kernel space are also disclosed.
    Type: Grant
    Filed: May 25, 2023
    Date of Patent: June 17, 2025
    Assignee: Fortinet, Inc.
    Inventors: Ulfar Erlingsson, Yijou Chen
  • Patent number: 12095794
    Abstract: An example method includes accessing, by a data platform via a network, data from one or more cloud environments; identifying, by the data platform and in the data, first data associated with a first entity and a first data type and second data associated with a second entity and a second data type; mapping, by the data platform and based on the first entity and the first data type, the first data to a first data stream of a data streaming platform; mapping, by the data platform and based on the second entity and the second data type, the second data to a second data stream of the data streaming platform, the second data stream different from the first data stream of the data streaming platform; and generating, based on the first data stream, a graph representing activity associated with the first entity in the one or more cloud environments.
    Type: Grant
    Filed: May 31, 2022
    Date of Patent: September 17, 2024
    Assignee: Lacework, Inc.
    Inventors: Gurunatha Karaje, Helgi Sigurbjarnarson, Jean-Philippe E. Martin, Ashwin Jayaprakash, Ulfar Erlingsson, Anastasios Arvanitis, Sai Samrat Karlapudi, Yijou Chen
  • Publication number: 20230075355
    Abstract: An illustrative method for monitoring a cloud environment may include identifying, by at least one computing device and based on a scan of a cloud environment, a vulnerable software component in the cloud environment, determining, by the at least one computing device, an operational status for the vulnerable software component in the cloud environment, and generating, by the at least one computing device and based on the operational status for the vulnerable software component, an alert for the vulnerable software component.
    Type: Application
    Filed: June 10, 2022
    Publication date: March 9, 2023
    Inventors: Andrew Twigg, Matti A. Vanninen, Theodore M. Reed, Ulfar Erlingsson, Christien R. Rioux, Yijou Chen
  • Patent number: 10437573
    Abstract: General-purpose distributed data-parallel computing using a high-level language is disclosed. Data parallel portions of a sequential program that is written by a developer in a high-level language are automatically translated into a distributed execution plan. The distributed execution plan is then executed on large compute clusters. Thus, the developer is allowed to write the program using familiar programming constructs in the high level language. Moreover, developers without experience with distributed compute systems are able to take advantage of such systems.
    Type: Grant
    Filed: July 10, 2017
    Date of Patent: October 8, 2019
    Assignee: MICROSOFT TECHNOLOGY LICENSING, LLC
    Inventors: Yuan Yu, Dennis Fetterly, Michael Isard, Ulfar Erlingsson, Mihai Budiu
  • Publication number: 20170371721
    Abstract: General-purpose distributed data-parallel computing using a high-level language is disclosed. Data parallel portions of a sequential program that is written by a developer in a high-level language are automatically translated into a distributed execution plan. The distributed execution plan is then executed on large compute clusters. Thus, the developer is allowed to write the program using familiar programming constructs in the high level language. Moreover, developers without experience with distributed compute systems are able to take advantage of such systems.
    Type: Application
    Filed: July 10, 2017
    Publication date: December 28, 2017
    Applicant: Microsoft Technology Licensing, LLC
    Inventors: Yuan Yu, Dennis Fetterly, Michael Isard, Ulfar Erlingsson, Mihai Budiu
  • Patent number: 9720743
    Abstract: General-purpose distributed data-parallel computing using a high-level language is disclosed. Data parallel portions of a sequential program that is written by a developer in a high-level language are automatically translated into a distributed execution plan. The distributed execution plan is then executed on large compute clusters. Thus, the developer is allowed to write the program using familiar programming constructs in the high level language. Moreover, developers without experience with distributed compute systems are able to take advantage of such systems.
    Type: Grant
    Filed: July 23, 2015
    Date of Patent: August 1, 2017
    Assignee: Microsoft Technology Licensing, LLC
    Inventors: Yuan Yu, Dennis Fetterly, Michael Isard, Ulfar Erlingsson, Mihai Budiu
  • Patent number: 9516032
    Abstract: Methods, systems and articles of manufacture consistent with features of the present invention allow the generation and use of derived user accounts, or DUA, in a computer system comprising user accounts. In particular, derivation rules define how a DUA is linked to or created based on an existing original user account, or OUA. Derivation transformations may also update the state of a DUA based on its corresponding OUA or give feedback from the state of a DUA to the state of its corresponding OUA.
    Type: Grant
    Filed: September 26, 2014
    Date of Patent: December 6, 2016
    Assignee: GOOGLE INC.
    Inventor: Ulfar Erlingsson
  • Patent number: 9397990
    Abstract: A method of controlling the sharing of data between entities that are in electronic communication with each other may include generating an authentication credential comprising an identifier for the target service and a unique signature, attenuating the authentication credential, and determining whether a client device is authorized to access the target service, and, only if so, providing the authentication credential to the client device. In an embodiment, the method may include receiving an access request from the client device, identifying that the authentication credential includes the unique signature and a third party caveat that is associated with a third party authentication service, in response to the identifying, determining whether the request also comprises a discharge credential for the third party caveat, and if the request includes the discharge credential, providing the client device with the requested service, otherwise denying the request.
    Type: Grant
    Filed: November 8, 2013
    Date of Patent: July 19, 2016
    Assignee: Google Inc.
    Inventors: Ankur Taly, Ulfar Erlingsson, Arnar Birgisson, Joseph Gibbs Politz, Mark Lentczner
  • Patent number: 9246926
    Abstract: Methods and systems are disclosed for providing secure transmissions across a network comprising a transmitting device and a receiving device. At the transmitting device, a stream of watermark bits is generated. Next, a plurality of watermarks is generated, each of the plurality of watermarks comprising an index number and a portion of the stream of watermark bits. The watermarks are inserted, into each header of a plurality of outgoing packets. At the receiving device, the plurality of outgoing packets are received and it is determined if a received packet is valid based on the watermark in the header of the received packet. The stream of watermark bits may be generated using a stream cipher such as RC4, a block cipher such as 3DES in CBC mode, or other equivalent pseudo-random stream generating techniques.
    Type: Grant
    Filed: July 29, 2013
    Date of Patent: January 26, 2016
    Assignee: Google Inc.
    Inventors: Ulfar Erlingsson, Xavier Boyen, Darrell Anderson, Wayne Gray
  • Publication number: 20150324242
    Abstract: General-purpose distributed data-parallel computing using a high-level language is disclosed. Data parallel portions of a sequential program that is written by a developer in a high-level language are automatically translated into a distributed execution plan. The distributed execution plan is then executed on large compute clusters. Thus, the developer is allowed to write the program using familiar programming constructs in the high level language. Moreover, developers without experience with distributed compute systems are able to take advantage of such systems.
    Type: Application
    Filed: July 23, 2015
    Publication date: November 12, 2015
    Inventors: Yuan Yu, Dennis Fetterly, Michael Isard, Ulfar Erlingsson, Mihai Budiu
  • Patent number: 9110706
    Abstract: General-purpose distributed data-parallel computing using a high-level language is disclosed. Data parallel portions of a sequential program that is written by a developer in a high-level language are automatically translated into a distributed execution plan. The distributed execution plan is then executed on large compute clusters. Thus, the developer is allowed to write the program using familiar programming constructs in the high level language. Moreover, developers without experience with distributed compute systems are able to take advantage of such systems.
    Type: Grant
    Filed: February 9, 2009
    Date of Patent: August 18, 2015
    Assignee: Microsoft Technology Licensing, LLC
    Inventors: Yuan Yu, Dennis Fetterly, Michael Isard, Ulfar Erlingsson, Mihai Budiu
  • Publication number: 20150052592
    Abstract: Methods, systems and articles of manufacture consistent with features of the present invention allow the generation and use of derived user accounts, or DUA, in a computer system comprising user accounts. In particular, derivation rules define how a DUA is linked to or created based on an existing original user account, or OUA. Derivation transformations may also update the state of a DUA based on its corresponding OUA or give feedback from the state of a DUA to the state of its corresponding OUA.
    Type: Application
    Filed: September 26, 2014
    Publication date: February 19, 2015
    Applicant: Google Inc.
    Inventor: Ulfar Erlingsson
  • Patent number: 8935675
    Abstract: A method includes receiving a budget cost for monitoring a plurality of tracepoints that occur as a result of operation of a device. The method further includes organizing a plurality of tracepoints into buckets such that each of the buckets corresponds to a range of expected interarrival times, and all tracepoints in a bucket have an expected interarrival time that is within the range for that bucket. The method further includes assigning a trigger to a first plurality of the bucketed tracepoints to yield a plurality of triggered tracepoints, wherein the triggers are proportionally assigned such that a tracepoint having a low expected interarrival time is less likely to be assigned a trigger than an tracepoint having a associated expected interarrival time such that an expected cost of the triggered tracepoints does not exceed the budget cost. Additionally, the method includes monitoring tracepoint occurrence during a first period of operation.
    Type: Grant
    Filed: September 25, 2013
    Date of Patent: January 13, 2015
    Assignee: Google Inc.
    Inventors: Michael Daniel Vrable, Ulfar Erlingsson, Yinqian Zhang
  • Patent number: 8875281
    Abstract: Methods, systems and articles of manufacture consistent with features of the present invention allow the generation and use of derived user accounts, or DUA, in a computer system comprising user accounts. In particular, derivation rules define how a DUA is linked to or created based on an existing original user account, or OUA. Derivation transformations may also update the state of a DUA based on its corresponding OUA or give feedback from the state of a DUA to the state of its corresponding OUA.
    Type: Grant
    Filed: February 3, 2014
    Date of Patent: October 28, 2014
    Assignee: Google Inc
    Inventor: Ulfar Erlingsson
  • Patent number: 8850574
    Abstract: Methods, systems, and apparatus, including computer programs encoded on a computer storage medium, for runtime language-independent sandboxing of software. In one aspect, a system implements an extended Software Fault Isolation (SFI) software sandboxing system configured to provide a user-mode program interface for receiving runtime requests for modifying verifiably safe executable machine code. Requests can include dynamic code creation, dynamic code deletion, and atomic modification of machine code instructions. A runtime modification of a verifiably safe executable memory region is made in response to each received runtime request, and code within the modified memory region has a guarantee of safe execution.
    Type: Grant
    Filed: February 28, 2011
    Date of Patent: September 30, 2014
    Assignee: Google Inc.
    Inventors: Jason Ansel, Cliff L. Biffle, Ulfar Erlingsson, David C. Sehr
  • Publication number: 20140150122
    Abstract: Methods, systems and articles of manufacture consistent with features of the present invention allow the generation and use of derived user accounts, or DUA, in a computer system comprising user accounts. In particular, derivation rules define how a DUA is linked to or created based on an existing original user account, or OUA. Derivation transformations may also update the state of a DUA based on its corresponding OUA or give feedback from the state of a DUA to the state of its corresponding OUA.
    Type: Application
    Filed: February 3, 2014
    Publication date: May 29, 2014
    Applicant: Google Inc.
    Inventor: Ulfar ERLINGSSON