Patents by Inventor Yingbo Song
Yingbo Song has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Patent number: 10819726Abstract: Systems, methods, and media for detecting network anomalies are provided. In some embodiments, a training dataset of communication protocol messages having argument strings is received. The content and structure associated with each of the argument strings is determined and a probabilistic model is trained using the determined content and structure of each of the argument strings. A communication protocol message having an argument string that is transmitted from a first processor to a second processor across a computer network is received. The received communication protocol message is compared to the probabilistic model and then it is determined whether the communication protocol message is anomalous.Type: GrantFiled: July 26, 2018Date of Patent: October 27, 2020Assignee: The Trustees of Columbia University in the City of New YorkInventors: Yingbo Song, Angelos D. Keromytis, Salvatore J. Stolfo
-
Publication number: 20190182279Abstract: Systems, methods, and media for detecting network anomalies are provided. In some embodiments, a training dataset of communication protocol messages having argument strings is received. The content and structure associated with each of the argument strings is determined and a probabilistic model is trained using the determined content and structure of each of the argument strings. A communication protocol message having an argument string that is transmitted from a first processor to a second processor across a computer network is received. The received communication protocol message is compared to the probabilistic model and then it is determined whether the communication protocol message is anomalous.Type: ApplicationFiled: July 26, 2018Publication date: June 13, 2019Inventors: Yingbo Song, Angelos D. Keromytis, Salvatore J. Stolfo
-
Patent number: 10063576Abstract: Systems, methods, and media for detecting network anomalies are provided. In some embodiments, a training dataset of communication protocol messages having argument strings is received. The content and structure associated with each of the argument strings is determined and a probabilistic model is trained using the determined content and structure of each of the argument strings. A communication protocol message having an argument string that is transmitted from a first processor to a second processor across a computer network is received. The received communication protocol message is compared to the probabilistic model and then it is determined whether the communication protocol message is anomalous.Type: GrantFiled: December 29, 2015Date of Patent: August 28, 2018Assignee: The Trustees of Columbia University in the City of New YorkInventors: Yingbo Song, Angelos D. Keromytis, Salvatore J. Stolfo
-
Patent number: 9870455Abstract: The interaction of a plurality of users with a computer system is monitored and measurements are made of different features of this interaction such as process creation, registry key changes, and file system actions. These measurements are then analyzed to identify those features that are more discriminatory. The set of features is then used to develop for each user a model of his/her interaction with the computer system that can then be used to authenticate that user when interacting with the computer system at a later time. Advantageously, these steps are performed automatically and may be performed periodically or even continuously to verify that each user of the computer system is indeed the individual he/she purports to be. Illustratively, the feature extraction is performed using Fisher's criteria; and the user model is developed using a Gaussian mixture model. A method for updating the user model is also disclosed.Type: GrantFiled: February 8, 2016Date of Patent: January 16, 2018Assignee: Allure Security Technology Inc.Inventors: Yingbo Song, Salvatore J. Stolfo
-
Publication number: 20160366169Abstract: Systems, methods, and media for detecting network anomalies are provided. In some embodiments, a training dataset of communication protocol messages having argument strings is received. The content and structure associated with each of the argument strings is determined and a probabilistic model is trained using the determined content and structure of each of the argument strings. A communication protocol message having an argument string that is transmitted from a first processor to a second processor across a computer network is received. The received communication protocol message is compared to the probabilistic model and then it is determined whether the communication protocol message is anomalous.Type: ApplicationFiled: December 29, 2015Publication date: December 15, 2016Inventors: Yingbo Song, Angelos D. Keromytis, Salvatore J. Stolfo
-
Publication number: 20160171197Abstract: The interaction of a plurality of users with a computer system is monitored and measurements are made of different features of this interaction such as process creation, registry key changes, and file system actions. These measurements are then analyzed to identify those features that are more discriminatory. The set of features is then used to develop for each user a model of his/her interaction with the computer system that can then be used to authenticate that user when interacting with the computer system at a later time. Advantageously, these steps are performed automatically and may be performed periodically or even continuously to verify that each user of the computer system is indeed the individual he/she purports to be. Illustratively, the feature extraction is performed using Fisher's criteria; and the user model is developed using a Gaussian mixture model. A method for updating the user model is also disclosed.Type: ApplicationFiled: February 8, 2016Publication date: June 16, 2016Applicant: ALLURE SECURITY TECHNOLOGY INC.Inventors: Yingbo Song, Salvatore J. Stolfo
-
Patent number: 9275345Abstract: The interaction of a plurality of users with a computer system is monitored and measurements are made of different features of this interaction such as process creation, registry key changes, and file system actions. These measurements are then analyzed to identify those features that are more discriminatory. The set of features is then used to develop for each user a model of his/her interaction with the computer system that can then be used to authenticate that user when interacting with the computer system at a later time. Advantageously, these steps are performed automatically and may be performed periodically or even continuously to verify that each user of the computer system is indeed the individual he/she purports to be. Illustratively, the feature extraction is performed using Fisher's criteria; and the user model is developed using a Gaussian mixture model. A method for updating the user model is also disclosed.Type: GrantFiled: February 5, 2014Date of Patent: March 1, 2016Assignee: Allure Security Technology, Inc.Inventors: Yingbo Song, Salvatore J. Stolfo
-
Patent number: 9253201Abstract: Systems, methods, and media for detecting network anomalies are provided. In some embodiments, a training dataset of communication protocol messages having argument strings is received. The content and structure associated with each of the argument strings is determined and a probabilistic model is trained using the determined content and structure of each of the argument strings. A communication protocol message having an argument string that is transmitted from a first processor to a second processor across a computer network is received. The received communication protocol message is compared to the probabilistic model and then it is determined whether the communication protocol message is anomalous.Type: GrantFiled: September 3, 2014Date of Patent: February 2, 2016Assignee: The Trustees of Columbia University in the City of New YorkInventors: Yingbo Song, Angelos D. Keromytis, Salvatore J. Stolfo
-
Publication number: 20140373150Abstract: Systems, methods, and media for detecting network anomalies are provided. In some embodiments, a training dataset of communication protocol messages having argument strings is received. The content and structure associated with each of the argument strings is determined and a probabilistic model is trained using the determined content and structure of each of the argument strings. A communication protocol message having an argument string that is transmitted from a first processor to a second processor across a computer network is received. The received communication protocol message is compared to the probabilistic model and then it is determined whether the communication protocol message is anomalous.Type: ApplicationFiled: September 3, 2014Publication date: December 18, 2014Inventors: Yingbo Song, Angelos D. Keromytis, Salvatore J. Stolfo
-
Patent number: 8844033Abstract: Systems, methods, and media for detecting network anomalies are provided. In some embodiments, a training dataset of communication protocol messages having argument strings is received. The content and structure associated with each of the argument strings is determined and a probabilistic model is trained using the determined content and structure of each of the argument strings. A communication protocol message having an argument string that is transmitted from a first processor to a second processor across a computer network is received. The received communication protocol message is compared to the probabilistic model and then it is determined whether the communication protocol message is anomalous.Type: GrantFiled: May 27, 2009Date of Patent: September 23, 2014Assignee: The Trustees of Columbia University in the City of New YorkInventors: Yingbo Song, Angelos D. Keromytis, Salvatore J. Stolfo
-
Publication number: 20110167493Abstract: Systems, methods, and media for detecting network anomalies are provided. In some embodiments, a training dataset of communication protocol messages having argument strings is received. The content and structure associated with each of the argument strings is determined and a probabilistic model is trained using the determined content and structure of each of the argument strings. A communication protocol message having an argument string that is transmitted from a first processor to a second processor across a computer network is received. The received communication protocol message is compared to the probabilistic model and then it is determined whether the communication protocol message is anomalous.Type: ApplicationFiled: May 27, 2009Publication date: July 7, 2011Inventors: Yingbo Song, Angelos D. Keromytis, Salvatore J. Stolfo