Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

1959results about "Computer security arrangements" patented technology

Artificial intelligence-powered large-scale content generator

An AI-powered content generation system that creates consistent, coherent, and engaging multi-modal content by integrating multiple specialized AI components. The system analyzes user input, identifies key elements, and maintains continuity throughout the generation process. It incorporates a feedback loop to learn and adapt based on user preferences, enabling personalized content experiences. The modular architecture allows for seamless integration of AI components focusing on text, images, audio, and interactive elements. The system ensures consistency across modalities and over extended periods, while managing rights, licenses, and royalties using blockchain technology. This advanced platform revolutionizes content creation, consumption, and management in the digital age.
Owner:QOMPLX INC

Security and Privacy Preserving Agentic Browser

A computer implemented method for governing risk actions by an artificial intelligence (AI) browser, by classifying a proposed action by the AI browser based on a large language model (LLM) as safe or risky based on AI weights or based on policy rules; initiating a step up authentication flow for a risk action; presenting an action summary and required capabilities to the user for approval; and enforcing user configured spend or scope limits on the risk action.
Owner:TRAN BAO

Packaging evidence for long term validation

A method for packaging digital evidence for long term validation comprises forming a package of a digital document (10), an electronic signature (12) for the document (10), together with evidence (16) of the authority of the signature in the document and a time stamp (20) indicating when the document was digitally signed. All of the pieces form parts of the packaged evidence.
Owner:GEN DIGITAL INC

Misconfiguration Detection and Prevention in a Data Fabric

The present disclosure describes systems and methods for detecting and preventing data misconfigurations within a security-focused data fabric platform. The system integrates an advanced script migration engine designed to streamline the translation of security rules and scripts across different scripting languages while ensuring alignment with the fabric's unified schema. The method involves receiving inputs from data sources, mapping these inputs to entities of a target schema, monitoring real-time data changes, and simulating impacts on operational dependencies to detect misconfigurations proactively. Leveraging AI-driven mechanisms, including Large Language Models (LLMs), the system dynamically identifies breaking changes in third-party data streams, issues alerts, and provides suggested fixes. The script migration engine further enhances the platform's functionality by automating cross-platform script translations and enabling faster onboarding of security tools. Together, these innovations ensure scalable, accurate, and resilient integration and management of security data across heterogeneous sources, strengthening operational integrity and minimizing security risks.
Owner:AVALOR TECH LTD

Intelligent Data Fabric Query Engine

The disclosed embodiments provide systems and methods for performing queries via an intelligent query engine. Various embodiments include receiving an input query and parsing the input query into a query representation object; generating an evaluation plan based on the query representation object, wherein the evaluation plan comprises a graph of computation nodes, each computation node specifying a granularity for grouping, associated filters, an aggregation schema, and join dependencies required for node computation, and wherein the evaluation plan is ordered to account for hierarchical dependencies among the computation nodes; translating the evaluation plan into an executable query optimized for a specific target data store, wherein the translation adapts query syntax and join structures to capabilities of a target data store; and executing the translated query on the target data store, resolving dependencies and aggregations according to the evaluation plan to generate query results satisfying the input query.
Owner:AVALOR TECH LTD

Artificial Intelligence (AI) agent evaluation framework

Systems and methods for an Artificial Intelligence (AI) agent evaluation framework include operating, in a test environment, an Artificial Intelligence (AI) agent system that includes an agent core connected to memory, one or more tools, and a planner; providing the AI agent with one or more requests; receiving a response to each of the one or more requests; and evaluating performance of the AI agent based on responses to each of the one or more requests. The one or more requests can be LLM-generated variations of a seed request either for testing the AI agent's ability to respond to queries or to test the ability of the AI agent to ignore malicious requests.
Owner:ZSCALER INC

Large language model federated fine-tuning method and apparatus based on gradient compression

Disclosed in the present invention are a large language model federated fine-tuning method and apparatus based on gradient compression. The method comprises the following steps: constructing, on the basis of a gradient tensor generated during fine tuning of a large language model, a raw data set having a time series relationship, performing inference by means of an autoencoder to obtain a reconstructed gradient data set, and constructing a reconstruction loss function to optimize the autoencoder; and initializing a base model of the large language model as a global model at a server end, the server end updating the global model to a client, using a pre-trained encoder to obtain a compressed gradient at the client, and at the server end, using a pre-trained decoder to decode and aggregate the compressed gradient, and then updating the global model. The present invention can improve the fine-tuning efficiency of the large language model and reduce computing resource requirements while ensuring data privacy protection, and is suitable for application scenarios such as communication optimization improvement and privacy protection enhancement in the process of scientific computing-oriented large model fine-tuning and training.
Owner:ZHEJIANG LAB

Method and apparatus for clustering input data

A method comprising:obtaining a dataset of input samples, one of said input samples comprising a number of input data features,applying said input samples to a machine learning system comprising a first machine learning model, or encoder, configured to output encoded samples, one of said output encoded samples comprising fewer encoded features than the number of input data features,applying said output encoded samples to a second machine learning model, or decoder, of said machine learning system, configured to produce reconstructed input samples from said encoded samples,determining a reconstruction loss based on a difference between the input samples and the reconstructed samples,clustering said encoded samples into a plurality of clusters,determining a clustering error, said clustering error being defined as taking on a lower value the more homogeneous and separated the clusters are,obtaining a total loss based on the reconstruction loss and clustering error, andwhile a stopping condition comprising the total loss being less than a best total loss, is not reached, tuning internal weights of said encoder and said decoder based on said total loss, and reiterating the previous steps.
Owner:NOKIA SOLUTIONS & NETWORKS OY

Core AI Serving Platform Enhancements

A computer system implements a unified framework integrating an adaptive elastic funnel (AEF) with a convergent intelligence fabric (CIF) for flexible and contextualized multi-agent AI and human collaboration at scale. The system provides a universal multi-modal key-value subsystem for sharing partial computations across agents, implements a hybrid greedy / non-greedy placement strategy for dynamic memory management, orchestrates dynamic computational workflows and tensor workflows using hierarchical tensor-fragment scheduling, enables cross-agent orchestration with policy-based privacy preservation, and incorporates quantum-resistant secure memory enclaves. The architecture supports continuous learning without catastrophic forgetting, compositional reasoning across modalities, and secure task execution in distributed environments. This integration enables unprecedented computational efficiency, secure collaboration, and adaptive intelligence in high-dimensional decision-making environments while supporting incremental adoption through modular interfaces.
Owner:QOMPLX INC

Location-based social media search mechanism with dynamically variable search period

A social media platform provides a map-based graphical user interface (GUI) for accessing social media content submitted for public accessibility via the social media platform supported by the map-based GUI. The GUI includes a map providing interactive location-based searching functionality in that selection of a target location by the user in the GUI, such as by tapping or clicking at the target location, triggers a search for social media content having geo-tag data indicating geographic locations within a geographical search area centered on the target location. A search period for which content is returned is dynamically variable based on the duration for which the tap or click is held.
Owner:SNAP INC

Ai-based entity maliciousness analysis using embedding and sampling

Techniques are described herein that are capable of performing AI-based entity maliciousness analysis using embedding and sampling. A representative sample of data associated with an entity is selected by comparing embeddings that represent the data. A potentially anomalous data point is identified in at least a portion of the data based on a proximity of a node, which corresponds to the potentially anomalous data point, in a tree to a root node of the tree. A statistically anomalous data point is identified in representative sample data points, which define the representative sample, as a result of the statistically anomalous data point indicating an unexpected occurrence of an event. An AI model is triggered to determine whether the entity exhibits malicious behavior by providing an AI prompt, including the representative sample and a description of the potentially anomalous data point and the statistically anomalous data point, to the AI model.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

System and method for detecting deep fake audio

A system for analyzing audio includes a memory configured to store known digital audio representation containing known fraudulent audio streams and a processor operably coupled to the memory. The processor receives a portion of an audio stream from an external device and produces a transcript of the portion of the audio stream. The processor then determines a timing score, an emotional score, a background score, and a content score by analyzing the portion of an audio stream and the corresponding transcript and comparing them to the known digital audio representations and transcripts. The processor then determines if the audio stream is malicious by combining the timing score, emotional score, background score, and content score to produce a combined score and comparing the combined score to a threshold. The processor notifies a user that the call may be fraudulent when the combined score is greater than the threshold.
Owner:BANK OF AMERICA CORP

Intelligent prioritization of assessment and remediation of common vulnerabilities and exposures for network nodes

The node exposure score generator and the attack path modeling component are configured to cooperate to analyze the actual detected vulnerabilities that exist for that network node in the network, the importance of network nodes in the network compared to other network nodes in the network, and the key pathways within the network and the vulnerable network nodes in the network that a cyber-attack would use during the cyber-attack in order to provide an intelligent prioritization of remediation actions to remediate the actual detected vulnerabilities for each network node from the network protected by a cyber security appliance.
Owner:DARKTRACE HLDG LTD

ECU safety design method and device, medium and vehicle

The invention provides an ECU safety design method and device, a medium and a vehicle. The method comprises the steps of obtaining a knowledge graph; the knowledge graph comprises a plurality of entities and entity relationships among the plurality of entities; the plurality of entities include vehicle functions of the ECU of the vehicle, security levels of the vehicle functions, and security mechanisms; determining a target security mechanism matched with the function link from the knowledge graph according to the function link of the ECU; the function link is used for realizing the vehicle function of the ECU; the function link is determined according to an original system architecture diagram of the ECU; the knowledge graph comprises a target security mechanism; and adding the target security mechanism in the original system architecture diagram to obtain a target system architecture diagram. According to the embodiment of the invention, the accuracy of ECU safety design can be improved.
Owner:ZHEJIANG ZEEKR INTELLIGENT TECH CO LTD +1

Malicious activity detection based on changes in a security graph

Systems, methods, and techniques are directed to detecting potential anomalous activity based on changes in a security graph. In an example, a security system receives a first snapshot of a graph representative of a tenant account of a network-based system corresponding to a first timestamp. The security system receives a second snapshot of the graph corresponding to a second timestamp. The security system determines a first change in the graph based on the first and second snapshots and a second change related to the first change. The security system detects a potential anomaly based on the first and second changes. Responsive to detecting a potential anomaly, the security system causes a mitigation step to be performed with respect to the tenant account. In a further example, the security system determines relationships between a sequence of changes satisfies a cumulative anomaly criterion.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Data processing method and device based on request interception, equipment and medium

The invention provides a data processing method based on request interception, which comprises the following steps of: intercepting a calling request for marking a service method through a request interception mechanism, preposing a decision point of service logic, and selecting whether the service method is executed or not according to a request context. According to the method and the device, the business rules are stored in the configuration center, external rule configuration is performed, the business rule expressions are pre-stored in the configuration center, dynamic acquisition is performed based on the rule identifiers, decoupling of the business rules and the codes is realized, the business rules can be configured independent of the codes, and flexible business processing can be realized only by modifying the expressions of the corresponding rules in the configuration center. The problems of code expansion and difficult maintenance caused by business rule change in a multi-channel environment are effectively solved, so that the flexibility and maintainability of a business data processing system are improved. The method can be applied to a business processing system in the financial field or the medical field, so that the flexibility of the business processing system in the financial field or the medical field is improved.
Owner:PING AN TECH (SHENZHEN) CO LTD

Surgical data system and control

A device to process data associated with a surgical event of a surgery may include a processor. The processor may be configured to receive multiple data streams during the surgical event. The processor may be configured to select a primary data stream based on a surgical data interface via which the primary data stream is received. The processor may be configured to select a secondary data stream based on a surgical data interface via which the second data stream is received. The processor may be configured to identify the surgical data interfaces. The processor may be configured to generate situational data associated with the primary data stream based on the secondary data stream. The situational data may indicate a medical decision-making factor of the surgical event. The primary data stream and the situational data may be sent during the surgical event.
Owner:CILAG GMBH INTERNATIONAL

Data Loss Prevention in an Enterprise Data Management and Monitoring System

Data loss prevention systems and methods in an enterprise data management and monitoring system may intercept a request to a network service, e.g., a service using an artificial intelligence and / or machine learning model. The systems and methods may represent contents of the request via one or more vector embeddings, which may be compared to vector embeddings corresponding to respective ones of a plurality of sensitive data elements in the enterprise. The data loss prevention system and methods may apply various data sensitivity policies based on determinations of whether sensitive data of the enterprise is included in the request to the network service, e.g., by blocking or redacting the request to prevent exposure of the sensitive data to the network service.
Owner:SUREPATH AI INC

System and method for software service policy exception in computing environments

A system and method for managing a cybersecurity policy exception on a software service in a computing environment is presented. The method includes detecting a software service in a computing environment, the service including a code object and a resource; generating a representation of the software service in a security database, the security database further including a representation of the computing environment; applying a policy on the representation of the software service, the policy including a conditional rule; detecting a policy exception in response to applying the policy resulting in a policy fail of the conditional rule; determining that the software service passes the policy in response to applying the policy exception resulting in a pass; and initiating a remediation action, in response to determining that applying the policy exception results in a policy fail.
Owner:WIZ INC

Cybersecurity vulnerability detection with artificial intelligence models

The present disclosure provides techniques for red teaming with artificial intelligence (AI) models. A processing device generates, via a first AI model, an agent action space based on security data, where the agent action space is indicative of actions to perform to potentially compromise at least one of a computing system, a network, or an application. The processing device performs a reinforcement learning process with an agent based on the agent action space to obtain a log of the reinforcement learning process. The processing device generates, via a second AI model, a report based on the security data and at least a portion of the log, where the report is indicative of a security weakness of the at least one of the computing system, the network, or the application.
Owner:CROWDSTRIKE

Systems, methods, and apparatuses for secure hybrid based communications

Systems, methods, and apparatuses for securing a communication network are provided. Transmitting a first signal including encoding a first timestamp, a first identifier, and a message authentication component. Obtaining a message signal comprising one or more service variables associated and an encrypted unique identifier. Authenticating the encrypted unique identifier based on a comparison of the encrypted unique identifier against a plurality of stored unique identifiers in a lookup table. Generating a second signal comprising an encoding of a subset of the service variables, the encrypted unique identifier, and a second timestamp. Transmitting the second signal to each remote receiver in a subset of the plurality of remote receivers.
Owner:E RADIO USA

Context-aware permission reduction

Systems, methods, apparatuses, and program products are disclosed for context-aware permission reduction. A candidate permission set is determined for an entity. A current permission set of the entity is replaced with the candidate permission set based on a criticality score indicative of a criticality of the entity, a stability score indicative of a likelihood that usage of a current permission set by the entity will change in a predetermined period of time, and a security gain score indicative of an amount of security improvement achievable by replacing the current permission set with the candidate permission set. The stability score for the entity may be determined based on historical usage of the current permission set by the entity.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Combined real-time and batch threat detection

First event data, indicative of a first activity on a computer network and second event data indicative of a second activity on the computer network, is received. A first machine learning anomaly detection model is applied to the first event data, by a real-time analysis engine operated by the threat indicator detection system in real time, to detect first anomaly data. A second machine learning anomaly detection model is applied to the first anomaly data and the second event data, by a batch analysis engine operated by the threat indicator detection system in a batch mode, to detect second anomaly data. A third anomaly is detected using an anomaly detection rule. The threat indictor system processes the first anomaly data, the second anomaly data, and the third anomaly data using a threat indicator model to identify a threat indicator associated with a potential security threat to the computer network.
Owner:CISCO TECHNOLOGY INC

Technology discovery techniques in cloud computing environments utilizing disk cloning

A system and method for technology stack discovery by performing active inspection of a cloud computing environment utilizing disk cloning is described. The method includes: generating an inspectable disk based on an original disk of a reachable resource, wherein the reachable resource is a cloud object deployed in the cloud computing environment, and accessible from a network which is external to the cloud computing environment; detecting a cybersecurity object on the inspectable disk, the cybersecurity object indicating a cybersecurity issue; selecting a network path including a network protocol to access the reachable resource; and actively inspecting the network path to detect the cybersecurity issue.
Owner:WIZ INC

Decentralized identity permissioned privacy enhancing technology

This disclosure provides techniques to utilize decentralized identifiers (DIDs) and verifiable credentials for secure, privacy-preserving transactions. In one aspect, a method is provided that includes: receiving user information; determining a DID based on the information; providing the DID to a user device; verifying the user's identity by validating the DID and associated verifiable credentials; and performing a transaction based on the verified DID. Other aspects are provided, such as generating a public-private key pair for the user, associating the DID with the public key, and / or creating a DID document stored on a distributed ledger accessible to authorized entities. Further aspects include processing transactions through smart contracts on a blockchain network, which may involve converting central bank digital currency to fiat currency while maintaining user privacy, applying transaction limits based on verified identity attributes, and providing zero-knowledge proofs to auditors to verify compliance without accessing underlying transaction details.
Owner:HSBC SOFTWARE DEV (GUANGDONG) LTD

Iterative data processing optimization engine in a data intelligence system

Methods, systems, and computer storage media for providing iterative data processing optimization using an iterative data processing optimization engine in a data intelligence system are described. Iterative data processing refers to handling data where the processing steps are repeated multiple times, across multiple views or modalities, to train machine learning models, filter and score data or generate output. The iterative data processing optimization engine employs expectation step machine learning models that are simple but with fast language models to efficiently and effectively probe and analyze data, while iteratively refining maximization step machine learning models that are optimized and fast to approximate the probing mechanism of the expectation step machine learning models more efficiently, for example, using metadata, external information, and compressed representation. The iterative data processing optimization engine can operate based on an agentic framework using lightweight artificial intelligence (AI) agents to perform model fitting, featurization, and report generation autonomously.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Systems and methods for detailed cloud posture remediation recommendations utilizing custom large language models (LLMs)

Systems and methods for detailed cloud posture remediation recommendations utilizing custom Large Language Models (LLMs). The present systems and methods are configured to perform the steps of scanning a cloud environment for posture control data; generating one or more alerts related to any of risky configurations and risky activities associated with the cloud environment; generating one or more remediation recommendations based on the one or more alerts; and providing the one or more alerts and the one or more remediation recommendations to administrators of the cloud environment.
Owner:ZSCALER INC

Dynamically providing cybersecurity training based on user-specific threat information

Aspects of the disclosure relate to dynamically providing cybersecurity training based on user-specific threat information. A computing platform may receive, from a targeted attack protection (TAP) server, user-specific threat information indicating at least one threat that has been encountered by at least one user. The computing platform may identify one or more users to receive cybersecurity training in a first cybersecurity training topic based on the user-specific threat information indicating the at least one threat that has been encountered by the at least one user. Subsequently, the computing platform may load one or more cybersecurity training modules based on identifying the one or more users to receive the cybersecurity training in the first cybersecurity training topic. Then, the computing platform may provide the one or more cybersecurity training modules to one or more user computing devices.
Owner:PROOFPOINT INC

System for cyber risks evaluation

A method and system for evaluating cyber risk of an entity comprising a risk evaluation module configured to collect risk data on risks of cyber-attacks connected to SaaS, infrastructure, and legal regulations classified by geolocation, industry type, and size of the victim organization, an entity evaluation module for collecting vulnerability data on assets of the entity classified by industry type, geolocation, size and cyber threat vector vulnerabilities and a monetization engine configured to make an assessment of expected financial loss from a specified cyber-attack to an entity classified by geolocation, industry type, and size, based on the risk data.
Owner:LEVY GIL +4