Patents by Inventor Ulfar Erlingsson
Ulfar Erlingsson has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Patent number: 12676874Abstract: An illustrative method for querying multiple datasets may include accessing a plurality of datasets including data associated with monitoring one or more compute environments and ingested at varying time intervals, receiving a query request for information that depends on the data included in multiple datasets of the plurality of datasets, querying, based on the query request, the multiple datasets, prioritizing, based on the varying time intervals, information that depends on the data included in the multiple datasets and presenting, based on the prioritizing, a query result representative of the information that depends on the data included in the multiple datasets.Type: GrantFiled: December 14, 2023Date of Patent: July 7, 2026Assignee: Fortinet, Inc.Inventors: Ulfar Erlingsson, Helgi K. Sigurbjarnarson, Ross T. Bunker, Yijou Chen
-
Patent number: 12659325Abstract: An illustrative method includes accessing, by a data platform, workload data associated with one or more workloads deployed within a compute environment and associated with an entity; generating, by the data platform and based on an analysis of the workload data, a rule specific to the entity and associated with an operation of the one or more workloads; and performing, by the data platform, an operation with respect to implementation of the rule within the compute environment.Type: GrantFiled: November 17, 2022Date of Patent: June 16, 2026Assignee: Fortinet, Inc.Inventors: George B. Spofford, Ulfar Erlingsson, Yijou Chen
-
Patent number: 12615271Abstract: A data collection system is disclosed to be communicatively coupled to a data platform configured to perform security monitoring of a compute environment. A sub-kernel component of the data collection system may live capture a state snapshot of a compute resource within the compute environment. The live capture of the state snapshot may be performed by updating a master state snapshot with delta state snapshots so as to avoid detectable disruption to the compute resource during the live capture. Based on the state snapshot, the data collection system may determine event data that represents events occurring with respect to the compute resource and may provide the event data to the data platform for use by the data platform in performing the security monitoring of the compute environment. Corresponding methods, systems, and products for compute environment security monitoring using a live state snapshot of a compute resource are also disclosed.Type: GrantFiled: May 25, 2023Date of Patent: April 28, 2026Assignee: Fortinet, Inc.Inventors: Ulfar Erlingsson, Yijou Chen
-
Patent number: 12500912Abstract: An illustrative method for querying multiple datasets may include generating, based on models each associated with and defining attributes of a different datasets stored in a plurality of data stores, a semantic layer defining relationships between the models and that provides a centralized application programming interface (API) for exposing the datasets by way of a common query language, receiving, by way of the centralized API, a query request for information that depends on data included in multiple datasets included in the plurality of datasets, querying, based on the query request and the relationships between the models defined by the semantic layer, the multiple datasets, and presenting, based on the querying, a query result representative of the information that depends on the data included in the multiple datasets.Type: GrantFiled: July 31, 2023Date of Patent: December 16, 2025Assignee: Fortinet, Inc.Inventors: Ulfar Erlingsson, Christopher R. Golden, Ross T. Bunker, Helgi K. Sigurbjarnarson, Jean-Philippe E. Martin, Neil B. Vachharajani, Amey Sakhadeo, Yijou Chen
-
Patent number: 12335286Abstract: A data collection system is disclosed to be communicatively coupled to a data platform configured to perform security monitoring of a compute environment. A sub-kernel component of the data collection system may collect sub-kernel data accessible from a sub-kernel space below an operating system of a compute resource in the compute environment. The data collection system may manipulate the collected sub-kernel data to prepare the sub-kernel data to be used by the data platform in performing the security monitoring of the compute environment. The data collection system may then communicate the manipulated sub-kernel data to the data platform. Corresponding methods, systems, and products for compute environment security monitoring using data collected from a sub-kernel space are also disclosed.Type: GrantFiled: May 25, 2023Date of Patent: June 17, 2025Assignee: Fortinet, Inc.Inventors: Ulfar Erlingsson, Yijou Chen
-
Patent number: 12095794Abstract: An example method includes accessing, by a data platform via a network, data from one or more cloud environments; identifying, by the data platform and in the data, first data associated with a first entity and a first data type and second data associated with a second entity and a second data type; mapping, by the data platform and based on the first entity and the first data type, the first data to a first data stream of a data streaming platform; mapping, by the data platform and based on the second entity and the second data type, the second data to a second data stream of the data streaming platform, the second data stream different from the first data stream of the data streaming platform; and generating, based on the first data stream, a graph representing activity associated with the first entity in the one or more cloud environments.Type: GrantFiled: May 31, 2022Date of Patent: September 17, 2024Assignee: Lacework, Inc.Inventors: Gurunatha Karaje, Helgi Sigurbjarnarson, Jean-Philippe E. Martin, Ashwin Jayaprakash, Ulfar Erlingsson, Anastasios Arvanitis, Sai Samrat Karlapudi, Yijou Chen
-
Publication number: 20230075355Abstract: An illustrative method for monitoring a cloud environment may include identifying, by at least one computing device and based on a scan of a cloud environment, a vulnerable software component in the cloud environment, determining, by the at least one computing device, an operational status for the vulnerable software component in the cloud environment, and generating, by the at least one computing device and based on the operational status for the vulnerable software component, an alert for the vulnerable software component.Type: ApplicationFiled: June 10, 2022Publication date: March 9, 2023Inventors: Andrew Twigg, Matti A. Vanninen, Theodore M. Reed, Ulfar Erlingsson, Christien R. Rioux, Yijou Chen
-
Patent number: 10437573Abstract: General-purpose distributed data-parallel computing using a high-level language is disclosed. Data parallel portions of a sequential program that is written by a developer in a high-level language are automatically translated into a distributed execution plan. The distributed execution plan is then executed on large compute clusters. Thus, the developer is allowed to write the program using familiar programming constructs in the high level language. Moreover, developers without experience with distributed compute systems are able to take advantage of such systems.Type: GrantFiled: July 10, 2017Date of Patent: October 8, 2019Assignee: MICROSOFT TECHNOLOGY LICENSING, LLCInventors: Yuan Yu, Dennis Fetterly, Michael Isard, Ulfar Erlingsson, Mihai Budiu
-
Publication number: 20170371721Abstract: General-purpose distributed data-parallel computing using a high-level language is disclosed. Data parallel portions of a sequential program that is written by a developer in a high-level language are automatically translated into a distributed execution plan. The distributed execution plan is then executed on large compute clusters. Thus, the developer is allowed to write the program using familiar programming constructs in the high level language. Moreover, developers without experience with distributed compute systems are able to take advantage of such systems.Type: ApplicationFiled: July 10, 2017Publication date: December 28, 2017Applicant: Microsoft Technology Licensing, LLCInventors: Yuan Yu, Dennis Fetterly, Michael Isard, Ulfar Erlingsson, Mihai Budiu
-
Patent number: 9720743Abstract: General-purpose distributed data-parallel computing using a high-level language is disclosed. Data parallel portions of a sequential program that is written by a developer in a high-level language are automatically translated into a distributed execution plan. The distributed execution plan is then executed on large compute clusters. Thus, the developer is allowed to write the program using familiar programming constructs in the high level language. Moreover, developers without experience with distributed compute systems are able to take advantage of such systems.Type: GrantFiled: July 23, 2015Date of Patent: August 1, 2017Assignee: Microsoft Technology Licensing, LLCInventors: Yuan Yu, Dennis Fetterly, Michael Isard, Ulfar Erlingsson, Mihai Budiu
-
Patent number: 9516032Abstract: Methods, systems and articles of manufacture consistent with features of the present invention allow the generation and use of derived user accounts, or DUA, in a computer system comprising user accounts. In particular, derivation rules define how a DUA is linked to or created based on an existing original user account, or OUA. Derivation transformations may also update the state of a DUA based on its corresponding OUA or give feedback from the state of a DUA to the state of its corresponding OUA.Type: GrantFiled: September 26, 2014Date of Patent: December 6, 2016Assignee: GOOGLE INC.Inventor: Ulfar Erlingsson
-
Patent number: 9397990Abstract: A method of controlling the sharing of data between entities that are in electronic communication with each other may include generating an authentication credential comprising an identifier for the target service and a unique signature, attenuating the authentication credential, and determining whether a client device is authorized to access the target service, and, only if so, providing the authentication credential to the client device. In an embodiment, the method may include receiving an access request from the client device, identifying that the authentication credential includes the unique signature and a third party caveat that is associated with a third party authentication service, in response to the identifying, determining whether the request also comprises a discharge credential for the third party caveat, and if the request includes the discharge credential, providing the client device with the requested service, otherwise denying the request.Type: GrantFiled: November 8, 2013Date of Patent: July 19, 2016Assignee: Google Inc.Inventors: Ankur Taly, Ulfar Erlingsson, Arnar Birgisson, Joseph Gibbs Politz, Mark Lentczner
-
Patent number: 9246926Abstract: Methods and systems are disclosed for providing secure transmissions across a network comprising a transmitting device and a receiving device. At the transmitting device, a stream of watermark bits is generated. Next, a plurality of watermarks is generated, each of the plurality of watermarks comprising an index number and a portion of the stream of watermark bits. The watermarks are inserted, into each header of a plurality of outgoing packets. At the receiving device, the plurality of outgoing packets are received and it is determined if a received packet is valid based on the watermark in the header of the received packet. The stream of watermark bits may be generated using a stream cipher such as RC4, a block cipher such as 3DES in CBC mode, or other equivalent pseudo-random stream generating techniques.Type: GrantFiled: July 29, 2013Date of Patent: January 26, 2016Assignee: Google Inc.Inventors: Ulfar Erlingsson, Xavier Boyen, Darrell Anderson, Wayne Gray
-
Publication number: 20150324242Abstract: General-purpose distributed data-parallel computing using a high-level language is disclosed. Data parallel portions of a sequential program that is written by a developer in a high-level language are automatically translated into a distributed execution plan. The distributed execution plan is then executed on large compute clusters. Thus, the developer is allowed to write the program using familiar programming constructs in the high level language. Moreover, developers without experience with distributed compute systems are able to take advantage of such systems.Type: ApplicationFiled: July 23, 2015Publication date: November 12, 2015Inventors: Yuan Yu, Dennis Fetterly, Michael Isard, Ulfar Erlingsson, Mihai Budiu
-
Patent number: 9110706Abstract: General-purpose distributed data-parallel computing using a high-level language is disclosed. Data parallel portions of a sequential program that is written by a developer in a high-level language are automatically translated into a distributed execution plan. The distributed execution plan is then executed on large compute clusters. Thus, the developer is allowed to write the program using familiar programming constructs in the high level language. Moreover, developers without experience with distributed compute systems are able to take advantage of such systems.Type: GrantFiled: February 9, 2009Date of Patent: August 18, 2015Assignee: Microsoft Technology Licensing, LLCInventors: Yuan Yu, Dennis Fetterly, Michael Isard, Ulfar Erlingsson, Mihai Budiu
-
Publication number: 20150052592Abstract: Methods, systems and articles of manufacture consistent with features of the present invention allow the generation and use of derived user accounts, or DUA, in a computer system comprising user accounts. In particular, derivation rules define how a DUA is linked to or created based on an existing original user account, or OUA. Derivation transformations may also update the state of a DUA based on its corresponding OUA or give feedback from the state of a DUA to the state of its corresponding OUA.Type: ApplicationFiled: September 26, 2014Publication date: February 19, 2015Applicant: Google Inc.Inventor: Ulfar Erlingsson
-
Patent number: 8935675Abstract: A method includes receiving a budget cost for monitoring a plurality of tracepoints that occur as a result of operation of a device. The method further includes organizing a plurality of tracepoints into buckets such that each of the buckets corresponds to a range of expected interarrival times, and all tracepoints in a bucket have an expected interarrival time that is within the range for that bucket. The method further includes assigning a trigger to a first plurality of the bucketed tracepoints to yield a plurality of triggered tracepoints, wherein the triggers are proportionally assigned such that a tracepoint having a low expected interarrival time is less likely to be assigned a trigger than an tracepoint having a associated expected interarrival time such that an expected cost of the triggered tracepoints does not exceed the budget cost. Additionally, the method includes monitoring tracepoint occurrence during a first period of operation.Type: GrantFiled: September 25, 2013Date of Patent: January 13, 2015Assignee: Google Inc.Inventors: Michael Daniel Vrable, Ulfar Erlingsson, Yinqian Zhang
-
Patent number: 8875281Abstract: Methods, systems and articles of manufacture consistent with features of the present invention allow the generation and use of derived user accounts, or DUA, in a computer system comprising user accounts. In particular, derivation rules define how a DUA is linked to or created based on an existing original user account, or OUA. Derivation transformations may also update the state of a DUA based on its corresponding OUA or give feedback from the state of a DUA to the state of its corresponding OUA.Type: GrantFiled: February 3, 2014Date of Patent: October 28, 2014Assignee: Google IncInventor: Ulfar Erlingsson
-
Patent number: 8850574Abstract: Methods, systems, and apparatus, including computer programs encoded on a computer storage medium, for runtime language-independent sandboxing of software. In one aspect, a system implements an extended Software Fault Isolation (SFI) software sandboxing system configured to provide a user-mode program interface for receiving runtime requests for modifying verifiably safe executable machine code. Requests can include dynamic code creation, dynamic code deletion, and atomic modification of machine code instructions. A runtime modification of a verifiably safe executable memory region is made in response to each received runtime request, and code within the modified memory region has a guarantee of safe execution.Type: GrantFiled: February 28, 2011Date of Patent: September 30, 2014Assignee: Google Inc.Inventors: Jason Ansel, Cliff L. Biffle, Ulfar Erlingsson, David C. Sehr
-
Publication number: 20140150122Abstract: Methods, systems and articles of manufacture consistent with features of the present invention allow the generation and use of derived user accounts, or DUA, in a computer system comprising user accounts. In particular, derivation rules define how a DUA is linked to or created based on an existing original user account, or OUA. Derivation transformations may also update the state of a DUA based on its corresponding OUA or give feedback from the state of a DUA to the state of its corresponding OUA.Type: ApplicationFiled: February 3, 2014Publication date: May 29, 2014Applicant: Google Inc.Inventor: Ulfar ERLINGSSON