Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

14968results about "Platform integrity maintainance" patented technology

Context-aware privileged access control system for dynamic risk-based authorization

A context-dependent, privileged access control system for dynamic, risk-based authorization, consisting of: a context acquisition subsystem configured to ingest and normalize multimodal contextual data streams from a variety of sources, including endpoint telemetry, geolocation sensors, user authentication metadata, device status metrics, and network traffic descriptors; a behavior profiling processing unit communicatively coupled to the context detection subsystem, the engine configured to maintain per-user behavior baselines using unsupervised learning models and to compute behavioral deviation vectors in real time for each privileged access request; a dynamic risk assessment module operatively connected to the behavioral profile processing unit, the module configured to calculate a multidimensional risk score for each session by applying a weighted aggregate function to behavioral deviation vectors, device risk posture, threat intelligence indicators, and environmental context volatility; a policy decision engine configured to apply programmable access control policies to the calculated risk score using a context-sensitive policy scoring language, wherein the engine is further configured to dynamically determine whether to authorize, deny, elevate, or revoke privileged access according to the current trust thresholds and permission boundaries; A permission enforcement controller unit communicatively connected to one or more endpoints, cloud services, and virtual infrastructure resources. The framework is configured to implement policy decisions by generating ephemeral access tokens, providing just-in-time (JIT) permissions, and initiating permission revocation workflows upon contextual anomalies. a secure hardware appliance consisting of a plurality of tamper-evident modules configured to host the behavioral profile processing unit, the risk assessment module, and the policy decision control unit in a trusted execution environment isolated from general computing resources.
Owner:KOTAPATI RAVI KUMAR FRISCO

Systems and Methods for Protecting Machine Learning (ML) Units, Artificial Intelligence (AI) Units, Large Language Model (LLM) Units, Deep Learning (DL) Units, and Reinforcement Learning (RL) Units

Systems and methods for protecting and fortifying machine learning engines, artificial intelligence (AI) engines, large language models, deep learning engines, reinforcement learning engines, and AI-based agentic units. An Offline Protection Unit analyzes characteristics of a Protected Engine, and performs offline fortification of the Protected Engine against attacks; by changing operational properties or operational parameters of the Protected Engine to reduce its vulnerability to attacks. An Online Protection Unit performs analysis of at least one of: (i) inputs that are intended to be inputs of the Protected Engine, (ii) outputs that are generated by the Protected Engine; and based on the analysis, dynamically performs online fortification of the Protected Engine against attacks; by dynamically changing operational properties or operational parameters of the Protected Engine to reduce its vulnerability to attacks.
Owner:DEEPKEEP LTD

Secure Systems of Guardrails for Securing the Use of Large Language Models (LLMS)

The present disclosure includes computer-implemented methods of guardrails for securely using large language models (LLMs). The method comprises monitoring user data flow using an application programming interface (API) and receiving an administrative policy from an administration communication interface. The method involves dynamically applying a plurality of LLM input inspectors to LLM input data. The application of the plurality of LLM input inspectors is based on the administration policy. The dynamic application of the plurality of LLM input inspectors is in sequence for latency optimization. The plurality of LLM input inspectors serve as LLM input guardrails for a plurality of secure deployed large language models (LLMs). The plurality of LLM input inspectors are configured by the administrative policy and validate the LLM input data to validated LLM input data based on the administration policy. Additionally, the method comprises dynamically applying a plurality of LLM output inspectors to LLM output data.
Owner:WITNESSAI INC

System and method for ai safety red-teaming with policy fuzzing and adversarial prompting

The present invention discloses a system and method for performing artificial intelligence (AI) safety red-teaming with integrated policy fuzzing and adversarial prompting to systematically identify, characterize, and mitigate unsafe or non-compliant behaviors in AI models. The disclosed invention automates the process of generating, executing, and analyzing adversarial test cases through coordinated functional units comprising a policy fuzzing unit, an adversarial prompting unit, an execution sandbox, a telemetry processing unit, a scoring and triage processor, and a cryptographic provenance processor. The system applies grammar-driven and reinforcement-based fuzzing techniques to vary policy descriptors, model configuration parameters, and instruction hierarchies, while a learned adversarial prompt generator synthesizes contextually coherent adversarial prompts optimized for maximum policy violation likelihood. The generated prompts and policy vectors are executed in an isolated, instrumented sandbox that records input-output interactions, timing characteristics, and intermediate representations.
Owner:MOGALI SUNEEL KUMAR +3

Activity monitoring of a cloud compute environment based on container orchestration data

Activity monitoring of a cloud compute environment based on container orchestration data may be performed by a data platform. For example, the data platform may obtain audit log data generated by a container orchestrator within a cloud compute environment, generate a data model based on the audit log data, and use the data model to monitor the activity for a security issue. The data model may be indicative of activity occurring with respect to one or more containerized applications executing within the cloud compute environment and the monitored activity may be activity with respect to the one or more containerized applications. Corresponding methods, systems, and products are also disclosed.
Owner:FORTINET INC

Attack path risk mitigation by a data platform

An illustrative method includes scanning a compute environment associated with an entity and identifying one or more attack paths from a network to one or more datasets associated with the entity. The one or more attack paths each include a series of risk artifacts within the compute environment that can be exploited by an attacker to access the one or more datasets. The method further includes generating one or more attack path risk scores associated with the one or more attack paths and indicative of one or more levels of risk that the one or more attack paths could be exploited to access the one or more datasets. A risk mitigation operation associated with the one or more attack paths is performed based on the one or more attack path risk scores.
Owner:FORTINET INC

Autonomous agent observation and control

Systems, methods, and devices that relate to monitoring and managing autonomous agents are disclosed. In one example aspect, the method includes receiving activity data from autonomous agents in an operational environment, deploying static and dynamic observing agents to monitor expected behavior and deviations, detecting a deviation by an autonomous agent, determining the cause through analysis, performing a mitigative action based on the cause, and executing a preventative action to block similar future deviations. The method may also involve configuring observing agents with different observation modalities, periodically modifying observation parameters unpredictably, facilitating direct communication between observing agents, resolving conflicts in observations, and updating observation policies. Mitigative actions can include disabling credentials, rerouting communications, and logging actions. Preventative measures may involve updating behavioral policies and adjusting agent parameters to disincentivize problematic behaviors.
Owner:CITIBANK N A

Cybersecurity threat detection and mitigation classification system

In some implementations, a cybersecurity threat detection and mitigation system is provided. The system refines an artificial intelligence (AI) model with a corpus of historical data that represents security events that occurred, queries that were submitted by security analysts in response to the security events, and actions that were performed for mitigating the security events. Telemetry data that corresponds to behavior and performance of a computer network is collected and provided to the AI model. Based on the telemetry data, the AI model predicts a potential security threat to the computer network and performs an assessment of risk to the computer network. When the assessment of risk to the computer network indicates that the potential security threat is an actual security threat, a security alert that corresponds to the actual security threat is triggered. Other embodiments are described and claimed.
Owner:ARCTIC WOLF NETWORKS INC

Cloud compliance monitoring for a cloud compute environment managed by a container orchestrator

Cloud compliance monitoring for a cloud compute environment managed by a container orchestrator may be performed by a data platform. For example, the data platform may obtain cluster configuration data from a control plane of a cluster that is managed by a container orchestrator within a cloud compute environment, obtain node configuration data from one or more compute nodes associated with a data plane of the cluster that is managed by the container orchestrator, and generate a compliance statement based on the cluster configuration data and node configuration data. The compliance statement may indicate a configuration posture of the cloud compute environment according to a compliance benchmark. Corresponding methods, systems, and products are also disclosed.
Owner:FORTINET INC

Failure chain quantitative analysis and risk assessment method and system based on multi-level security model

The invention discloses a failure chain quantitative analysis and risk assessment method and system based on a multi-level security model, and aims to solve the defects that accident cause analysis of a complex social technology system is inaccurate, and a risk assessment result is lack of effective verification. According to the method, a multi-level causal model is systematically constructed, a multi-dimensional failure chain (MDFC) is extracted, multi-dimensional risk quantification is performed on the MDFC, a directed weighted failure propagation network is constructed based on the multi-dimensional risk quantification, and structural features of the directed weighted failure propagation network are analyzed to identify key risk factors. The core innovation of the method is that reverse accident reason tracing and forward risk propagation path analysis based on the weighted network are fused, mutual verification and iterative optimization are realized by comparing analysis results of the two paths, so that the understanding of an accident evolution mechanism is deepened, and the reliability of evaluation is improved. The system vulnerability can be revealed more comprehensively, powerful support is provided for formulating accurate risk control measures, and the overall safety level of a complex system is improved.
Owner:CHINA UNIV OF PETROLEUM (EAST CHINA)

Compute resource risk mitigation by a data platform

An illustrative method includes identifying, based on a scan of a compute environment associated with an entity, a plurality of attack paths from one or more networks to one or more datasets associated with the entity and determining a set of one or more attack paths included in the plurality of attack paths that include a particular risk artifact. Based on one or more characteristics of the set of one or more attack paths, a risk score specific to the particular risk artifact may be determined and a risk mitigation operation associated with the particular risk artifact may be performed.
Owner:FORTINET INC

Smart recognition and consumer-centric activity recognition based system for battery management in mobile device

PendingUS20260006557A1Power managementPlatform integrity maintainanceActivity classificationElectrical battery
The present invention relates to an intelligent, context-aware battery management system embedded within a mobile device that dynamically allocates power resources based on real-time user behavior, system state, and environmental context. It incorporates a smart recognition engine that analyzes sensor-derived telemetry data to compute behavioral deviation scores, enabling the system to anticipate abnormal or emergency-prone conditions. A continuous activity classification module contextualizes user motion and geolocation to inform power policy decisions. Upon detecting significant behavioral anomalies or critically low battery conditions, an emergency mode subsystem is triggered, restricting device operations to essential functionalities while preserving energy for critical communication and navigation tasks. The system also establishes a secure, lightweight emergency communication tunnel for relaying essential metadata, including GPS and behavioral indicators, to predefined response servers.
Owner:ALMALKI SULTAN AHMED +3

Power generation side industrial control system network security target building method based on virtual-real combination

The invention discloses a virtual-real combination-based power generation side industrial control system network security target construction method. The method comprises the following steps of: constructing a virtual-real combination target environment consisting of a physical equipment layer and a virtual model layer; the heterogeneous industrial control protocol between the physical equipment layer and the virtual model layer is analyzed, protocol semantic information is extracted, and a bidirectional dynamic mapping rule of a physical equipment state and a virtual model state is generated based on the protocol semantic information; based on a state change event of the physical equipment layer, according to a bidirectional dynamic mapping rule, synchronizing changed equipment state data to the virtual model layer in real time, and simulating protocol behavior logic corresponding to the equipment state data in the virtual model layer according to a security test requirement; and based on the attack instruction or the abnormal state signal generated by the virtual model layer, according to the protocol specification format of the target physical equipment, converting the instruction or the signal into an executable control command, and driving the physical equipment layer to execute an operation corresponding to the control command.
Owner:HUANENG POWER INT INC +1

Intelligent risk identification and self-adaptive repair method, system and equipment for software supply chain and medium

The invention discloses an intelligent risk identification and self-adaptive repair method, system and device for a software supply chain and a medium, belongs to the field of network security and automatic software engineering, and aims to solve the technical problem of how to accurately and comprehensively identify software code supply chain risks including code snippets. A reliable and efficient automatic closed-loop repair scheme is provided, and the technical defects that in the prior art, the software code supply chain recognition range is limited, the repair process is rigid and the reliability is low are overcome. Analyzing the declarative dependency; meanwhile, semantic traceability based on artificial intelligence is carried out on the code snippets, and a global software material list is generated; and performing intelligent mapping on the software components in the global software bill of materials and the vulnerability database to identify risks.
Owner:SHANDONG ZHENBAI INFORMATION TECHNOLOGY CO LTD

Artificial intelligence security vulnerability detection platform based on deep learning

The invention discloses a deep learning artificial intelligence security vulnerability detection platform, and relates to the technical field of intelligent detection, and the platform comprises an information processing module which collects heterogeneous data in real time, carries out the labeling, format unification and modal aggregation processing of the data, and generates a sample set; the feature learning module is used for performing feature unwrapping on the sample set by using a variational auto-encoder, extracting modal data features and potential space representation learning, and outputting a potential space vector; the response generation module is used for generating a vulnerability response strategy through a modal consistency verification and response template matching mechanism based on the vulnerability risk level vector in combination with a response generation engine; and the repair feedback module is used for executing automatic vulnerability repair operation in combination with federal reinforcement learning and Bayesian optimization, performing feedback optimization according to an execution result, and outputting the vulnerability repair operation and a feedback result. According to the method, the response strategy is combined with intelligent matching of the real-time risk level, so that the accuracy and adaptability of vulnerability repair are improved.
Owner:HEFEI TANOVO INFORMATION SECURITY TECH CO LTD

Jailbreak detection for language models in conversational ai systems and applications

In various examples, systems and methods are disclosed relating to language model jailbreak detection using length-perplexity metrics. A system can identify a prompt for a language model—such as an LLM, VLM, etc.—and generate a perplexity score for the prompt. The system can determine, based at least on the perplexity score and a length of the prompt, that the prompt is indicative of a jailbreak attempt for the large language model. The system can restrict the prompt from input to the large language model—or block an output generated based on the prompt from being shared—responsive to determining that the prompt is indicative of the jailbreak attempt.
Owner:NVIDIA CORP

Capturing and using application-level data to monitor a compute environment

An illustrative method includes receiving, by a data platform configured to monitor the compute environment, runtime workload data collected by an agent deployed to the compute environment, wherein the runtime workload data comprises user space data collected from a user space of the compute environment and kernel space data collected from a kernel space of the compute environment. The method further includes performing, by the data platform, a monitoring operation based on the user space data and the kernel space data of the runtime workload data.
Owner:FORTINET INC

Systems and methods for automated continual vulnerability remediation and validation

Systems and methods for continual, automated vulnerability mediation and validation for application development systems are disclosed herein. In some aspects, the system may receive a user input for creating a rebuild code set corresponding to a code sample. The system may store the rebuild code set and the code sample in a container. The system may receive a modification request to generate a modified code sample. The system may execute the rebuild code set on the modified code sample. The system may validate the container based on the modified code sample.
Owner:CAPITAL ONE SERVICES LLC

Techniques for optimizing bootstrapping execution of a fully homomorphic encryption

A method and system of the device may include obtaining hardware constraints of an FHE accelerator configured to execute the FHE program. In addition, the device may include selecting an optimal bootstrapping configuration that corresponds to the hardware constraints. The device may include identifying repetitive data patterns in the auxiliary data to be used in the bootstrapping process. Moreover, the device may include reducing the auxiliary data by applying at least one auxiliary data optimization technique based on the repetitive data patterns. Also, the device may include modifying the FHE program to include an instruction to load at least a portion of the reduced auxiliary data into an internal memory of the FHE accelerator, where the at least a portion of the reduced auxiliary data is loaded to the internal memory once prior to the execution of the plurality of bootstrapping processes.
Owner:CHAIN REACTION LTD

Backtracking analysis model construction method based on attack chain

The invention relates to the technical field of data processing, in particular to a backtracking analysis model construction method based on an attack chain, which comprises the following steps that: a kernel layer security agent acquires process, file and network behavior characteristics in a hardware isolation environment, and generates an event tuple; the tensor network pipeline performs three-dimensional decoupling mapping on the tuple into a behavior fingerprint vector, an orthogonalization noise feature and an asymmetric adjacent tensor, and compresses the behavior fingerprint vector, the orthogonalization noise feature and the asymmetric adjacent tensor into a space-time topology tensor block; the reinforcement learning controller constructs a directed acyclic graph based on the tensor blocks, calculates connectivity loss and outputs an event risk score; the dynamic routing engine constructs a decision tree model according to the risk mark, the burst frequency and the correlation entropy, and implements three-level shunting and a multiple simulation system to generate an anti-interference index; and when the deviation between the physical trajectory and the digital model exceeds the tolerance, the closed-loop feedback weight coefficient updates the loss function parameter and adjusts the channel resource weight. And the problem of threat discovery delay caused by attack chain breakage under massive events is solved.
Owner:HUANENG INFORMATION TECH CO LTD

Cross-platform education data privacy protection analysis system

The invention provides a cross-platform education data privacy protection analysis system, and relates to the technical field of data privacy protection. The cross-platform education data privacy protection analysis system comprises a multi-modal data acquisition unit, a dynamic privacy analysis engine, a federal learning processing core module, a block chain enhanced access control system, a privacy watermark traceability module and a compliance autonomy unit. Dynamic coupling of scene sensitivity and data protection intensity is realized through a dynamic privacy risk scoring equation and an adaptive differential privacy noise equation; the problems of privacy disclosure, compliance verification and traceability and responsibility investigation in cross-platform education data sharing are solved by combining federal learning, block chain evidence storage and privacy watermarking technologies. According to the method, the privacy risk assessment precision is remarkably improved, the model precision loss is reduced, full-life-cycle data security management and control are supported, and the method is suitable for multiple scenes such as K12 education and college educational administration.
Owner:JIUJIANG DIGITAL IND DEV CO LTD

Instance heartbeat

A method for monitoring a plurality agents operating within a plurality compute instances of a tenancy of a cloud environment is disclosed. The method includes receiving a plurality of messages from each of the plurality of agents operating within the plurality of compute instances. The method further includes updating a table that identifies the plurality of agents and the corresponding plurality of compute instances; and reading a list of compute instances, wherein each compute instance on the list is enabled to have an agent installed therewithin. The method further includes comparing the plurality of compute instances within the table against the list of compute instances. The method further includes determining, based on the comparing, that a compute instance within the list of compute instances is missing in the plurality of compute instances of the table; and transmitting a request to reinstall or install an agent within the compute instance.
Owner:ORACLE INT CORP

Detecting anomalous behavior of nodes in a hierarchical cloud deployment

Detecting anomalous behavior of nodes in a hierarchical cloud deployment, including: gathering data describing a cloud deployment as a hierarchy of a plurality of nodes; presenting a graph depicting behavior at a particular hierarchical level of at least a subset of the plurality of nodes; and determining whether behavior associated with a particular node deviates from normal behavior based on a hierarchical portion of plurality of nodes including the particular node.
Owner:FORTINET INC

Managed design and generation of artificial intelligence agents

Systems and methods are described for building artificial intelligence (“AI”) agents. A server can provide a user interface (UI) that includes options to select and connect various agent objects. The agent objects can include prompt objects, dataset objects, model objects, and one or more code objects. A subset of the agent objects can be identified as available for selection based on evaluation of at least one management policy associated with an administrative user. A manifest file is generated based on the connected agent objects, and the manifest is validated against dependency rules to ensure that the stages of the agent meet prerequisites for the stages. Then, the server performs a simulated execution of an agent that corresponds to the validated manifest file, including an identification of at least one execution metric associated with the simulated execution.
Owner:AIRIA LLC

Data analysis pipeline engine in a data intelligence system

Methods, systems, and computer storage media for providing a data analysis pipeline using a data analysis pipeline engine in a data intelligence system are described. A data analysis pipeline refers to a structured sequence of data processing steps that support transforming raw data into meaningful insights or actionable outcomes. The data analysis pipeline engine is an unsupervised learning pipeline based on clustering, topic modeling, and Large Language Models (LLMs). For example, the data analysis pipeline can use advanced machine learning techniques to automatically categorize emails into semantically similar clusters, enabling the data intelligence system to quickly identify and prioritize potentially high-risk emails for further investigation. The data analysis pipeline employs AI agents for context-aware graph induction relevance assessment. The AI agents employ induction and deduction loops to build and refine a data feature hypergraph (e.g., vulnerability hypergraph) that encompasses identified relevant data providing a holistic view of a contextual landscape.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Reducing resource consumption spikes in an anomaly detection framework

Reducing resource consumption spikes in an anomaly detection framework, including: gathering information describing historical job execution associated with a plurality of customers; assigning, based on the information describing historical job execution, each of the plurality of customers to a particular grouping of a plurality of groupings, wherein each of the plurality of groupings corresponds to a particular time offset within a time interval; and scheduling, for each grouping of the plurality of groupings, at a time offset of a corresponding grouping, execution of one or more jobs associated with one or more customers of the corresponding grouping.
Owner:FORTINET INC

Handling of certificates by intermediate actors

Handling of certificates by intermediate actors, including: receiving, by a proxy and from a client, a client certificate and a first private key; generating, by the proxy and based on the client certificate and the first private key, an intermediate certificate; generating, by the proxy and in response to a request from the client to connect to a destination, an alternate certificate for the destination; and providing, to the client, a certificate chain comprising the alternate certificate, the intermediate certificate, and the client certificate.
Owner:FORTINET INC

System and method for generating a security graph in a cloud computing environment

A cybersecurity system provides the ability to detect security risks in a cross-platform cloud solution. A unified data schema is used to abstract resources, principals and others across multiple platforms. A security graph is generated to present a unified view of cloud environments, which are then easily queried using the structure of the data schema. The solution allows a compact representation of cloud environments, which is scalable and multi-layered. Various enrichments may be added to the security graph, which are generated for example based on policies, and inspection of workloads in the cloud environment. The security graph allows for representation of production environments, staging environments, as well as code for deploying workloads in the cloud environment. Thus the solution is also able to present a complete picture of a user's entire cloud environment.
Owner:WIZ INC

Data query method and system for converting natural language into database query language

The invention provides a data query method and system for converting a natural language into a database query language, and the method comprises the steps: analyzing the natural language input of a user through a multi-modal understanding agent on the basis of constructing a dynamic knowledge graph based on metadata, combining a historical session with a business term table, eliminating ambiguity, and generating a standardized Query, a retrieval routing agent selects a query strategy according to Query complexity, simple query directly matches a cache template, complex query traverses a knowledge graph, and related tables, fields and service constraints are returned; then, an expert committee agent generates an SQL (Structured Query Language) by adopting multi-stage collaboration, executes plan pre-evaluation, and selects a version with the highest comprehensive score; the test agent simulates and executes the SQL in the isolation environment, and verifies the grammar legality and the field permission; and finally, executing the detected SQL, and processing a result. According to the method, the accuracy of converting the natural language into the SQL (NL2SQL) in a complex database scene can be effectively improved.
Owner:HI-THINK YONDERVISION (BEIJING) TECH CO LTD

Detecting package execution for threat assessments

Detecting package execution for threat assessments, including: receiving, from an agent on a host of a cloud deployment, data describing one or more active packages installed on the host, wherein each of the one or more active packages are identified by the agent from a plurality of packages in response to detecting a corresponding file open event; and generating a threat assessment for the host describing which of the one or more active packages have any known vulnerabilities.
Owner:FORTINET INC