Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

123 results about "Internet safety" patented technology

Internet safety or online safety or cyber safety is trying to be safe on the internet and is the knowledge of maximizing the user's personal safety and security risks to private information and property associated with using the internet, and the self-protection from computer crime. One key element of internet safety is the ability to maintain privacy. Internet privacy involves the right or mandate of personal privacy concerning the storing, repurposing, provision to third parties, and displaying of information pertaining to oneself via the Internet. Internet privacy is a subset of data privacy. Privacy concerns have been articulated from the beginnings of large-scale computer sharing.

Cyber security protection of electronic communications including detecting topic shifts

PendingUS20260019438A1Securing communicationOutbound communicationElectronic communication
Systems and methods for protecting electronic communications are described. A cyber security appliance may be configured to calculate a topic shift score for a communication by comparing a first lexical profile derived from the communication to a historical lexical profile established for an associated user. This analysis may be performed without using a large language model. The system may also parse communications to extract sensitive data and content from attachments, performing behavioral modeling on the extracted data. Based on the analysis, an autonomous response module may take a variety of mitigation actions. Furthermore, a security mailbox assistant module may perform a secondary, in-depth analysis on user-submitted communications and generate a deterministic report. For outbound communications, a data loss prevention architecture may divert messages for in-line analysis and may include a fail-safe timeout mechanism to ensure service continuity.
Owner:DARKTRACE HLDG LTD

Lookalike Domain Phishing Detection

The present disclosure enhances domain lookalike detection by integrating a phishing risk assessment score into a multi-layered evaluation framework. The method systematically generates lookalike domains through genetic algorithms. Registered domains undergo advanced phishing analysis, incorporating domain and URL checks, technical infrastructure assessments, content inspections, and reputation-based intelligence to calculate a dynamic phishing score. A comprehensive risk score is then determined by merging phishing likelihood with business attributes, graphical / contextual similarity metrics, and domain registration patterns. Domains are categorized into predefined risk levels including phishing, registered, preventative, company-owned, or watchlist, with specific action recommendations provided for each category. The system generates prioritized alerts for high-risk domains, offering customers actionable intelligence to mitigate threats. By combining phishing-specific indicators with contextual evaluations, this solution improves detection accuracy, reduces false positives, and enables organizations to respond effectively to domain-based threats in real time, addressing evolving cybersecurity challenges.
Owner:ZSCALER INC

Automated ai model-based pipeline for detection explainability

The present disclosure provides techniques for AI model-based detection explainability. A processing device obtains computer-readable text and an indication of a false positive detection of malicious behavior with respect to the computer-readable text by a cybersecurity system, The processing device obtains, via an artificial intelligence (AI) model trained to generate language, a reason for the false positive detection of the malicious behavior. The processing device provides an indication of the reason for the false positive detection to a destination device.
Owner:CROWDSTRIKE

Application-level cybersecurity using multiple stages of classifiers

Various embodiments include systems and methods to implement a security platform providing application-level cyberattack detection using multiple stages of classifiers. The security platform may use requests received by a web service to determine training data to train one or more machine learning models. The training data may be determined by instrumenting an application, such as a web service, with a first stage classifier to determine security events indicative of cyberattacks. The security platform may train machine learning models using aggregations of security events over various periods of time. The machine learning models may serve as second stage classifiers for the security platform.
Owner:RAPID7 INC

Cyber security system for email message protection

Implemented within a cyber security appliance, a non-transitory storage medium configured to store software that, when executed, conducts data loss prevention evaluation of an email message to protect against exfiltration of sensitive data from an enterprise. The software includes an email protection module and high availability (HA) fail-open control logic. The email protection module includes email threat detection logic to analyze content associated with an outbound or lateral email message for potential data loss characteristics. The HA fail-open control logic is configured to (i) detect operational failure of the email protection module or intake disruption of email messages via an Application Programming Interface (API) providing access to the email protection module and (ii) redirect the email messages to HA cloud infrastructure pertaining to the enterprise for temporary storage and subsequent release of the redirected email messages upon detecting the operational failure or the intake disruption.
Owner:DARKTRACE HLDG LTD

Internet-Exposed Device Discovery

A cloud-based, external attack surface management (or EASM) service identifies computers, servers, smartphones, and other devices that are exposed to the public Internet. Any device that can connect to the public Internet may be vulnerable to cybersecurity attacks. The EASM service identifies a device exposed to the public Internet by comparing connection notifications to an address scan of the entire Internet. The connection notifications are sent by cybersecurity sensory agents installed at client devices. When a connection notification and the address scan of the entire Internet references a matching IP address and / or a matching port within a timeframe, the corresponding device is identified as being exposed to the public Internet.
Owner:CROWDSTRIKE

Cybersecurity detection

A cybersecurity service protects endpoint devices from cybersecurity attacks. The cybersecurity service deploys cybersecurity attack feature vectors to agents in the field. The cybersecurity attack feature vectors are created in the cloud to efficiently describe observed groups of cybersecurity attacks. One method to assemble these is to generate clustering centroids for the observed groups. Each agent monitors its host according to the cybersecurity attack feature vectors. Each agent monitors its host's event behaviors and locally extracts an event behavior feature vector. The agent compares the cybersecurity attack feature vectors to the event behavior feature vector and, if similarity is determined, then the agent determines that the host's event behaviors are evidence of a cybersecurity attack. The agent may implement threat procedures, such as suspending / terminating the event behaviors and generating alerts. The agent remains a small, lightweight cybersecurity detector that does not need constant Internet access.
Owner:CROWDSTRIKE

Asynchronous Blocking of Exfiltration Events via Browser Extensions

A cybersecurity data loss prevention service stops users from stealing, or exfiltrating, sensitive data. An endpoint cybersecurity agent coordinates the installation of a browser extension. The browser extension adds content scripts to a web browser that monitor for exfiltration events. The exfiltration events represent a user's browser inputs (such as cut-n-paste or drag-n-drop) that can be used to exfiltrate usernames, passwords, credit card numbers, company secrets, and any other sensitive data. When the browser extension detects any exfiltration event, the browser extension intercepts and synchronously blocks the exfiltration event from the web browser. Moreover, the browser extension sends a duplicate copy of the exfiltration event to the cybersecurity agent for evaluation. If the cybersecurity agent determines that the user's browser inputs should have been allowed, then the browser extension is instructed to trigger the duplicate copy. The web browser thus asynchronously processes the user's browser inputs, albeit slightly delayed.
Owner:CROWDSTRIKE

Cybersecurity threat network traffic generation with large language models

A security feed normalizer aggregates and normalizes threat intelligence data across security feeds and extracts threat descriptors of cybersecurity threats from the aggregated / normalized data. A first large language model (LLM) determines whether each threat descriptor is informative, i.e., comprises sufficient information for reproducing / generating network traffic of the corresponding cybersecurity threat. For informative threat descriptors, a second LLM generates network traffic for the corresponding cybersecurity threats. The generated network traffic is used for subsequent remediation of corresponding threats.
Owner:PALO ALTO NETWORKS INC

Systems and methods for dynamic valuation of protection products

Systems, methods, and computer-readable storage media for protecting data. One system includes a processing circuit configured to receive, identify, or collect cybersecurity data. The processing circuit can further be configured to generate metadata from the cybersecurity data based on characterizing the at least one cyber incident or claim. The processing circuit can further be configured to generate or update a protection parameter of one or more protection products of a protector based on the metadata. The processing circuits can further be configured to determine at least two cyber incidents correspond to a catastrophic incident based on the metadata. The processing circuits can further be configured to generate and provide a claim data package including the metadata and the catastrophic incident.
Owner:AS0001 INC

Multi-vendor web security control integration and management platform

A computer-implemented method of providing web security control integration in a system that utilizes at least one vendor proxy service for securely accessing the Internet. The method comprises receiving an instruction to update a web control policy or exception, generating a web control and exception update request, using a vendor agnostic API, wherein the web control and exception update request includes policy objects and content data, delivering the web control and exception data to a policy sync worker associated with a particular vendor proxy service, converting the web control and exception update request, via the policy sync worker into a format suited to the particular vendor proxy service, and delivering the converted web control and exception update request to the particular vendor proxy service associated with the policy sync worker to update the web control policy at the particular vendor proxy service.
Owner:MORGAN STANLEY SERVICES GROUP INC

CPE Prediction Using Banner Similarity

Prediction of matches between CPEs and banners greatly improves computer functioning. Many web services have an unknown common platform enumeration (CPE). When the CPE is unknown, a computer system is unable to obtain cybersecurity flaws and software fixes for a software product or web service. A similarity between the CPE and a service banner, though, accurately predicts a match the CPE and the web service. CPEs, for example, may thus be identified for old, obsolete, and uncomment software products and services.
Owner:CROWDSTRIKE

Automated service worker installation for client-initiated user identification and DLP scanning

A cybersecurity appliance orchestrates registration and installation of a service worker by a web browser. The service worker intercepts and modifies requests sent by the web browser for a SaaS application with tenant / user information and / or DLP scanning results. The cybersecurity appliance orchestrates the service worker registration and installation by modifying responses to requests sent by the web browser. Once installed, the service worker determines the logged in user for the session and modifies outbound requests to attach the user information (e.g., account name / email address) thereto. The service worker can also or alternatively monitor for input of data into web pages, designate the data for data loss prevention (DLP) scanning, and modify outbound requests to attach the DLP scanning result. The cybersecurity appliance receives the user information and / or DLP scanning results with requests sent by the web browser since the user information and / or results were attached to the requests client-side.
Owner:PALO ALTO NETWORKS INC

CPE prediction using banner-prompted AI / ML modeling

Prediction of CPEs using banners greatly improves computer functioning. Many web services have an unknown common platform enumeration (CPE). When the CPE is unknown, a computer system is unable to obtain cybersecurity flaws and software fixes for a software product or web service. A CPE, though, is predicted by banner-prompting an AI / ML model using a web service banner. Once the CPE is predicted, vulnerabilities may be identified.
Owner:CROWDSTRIKE

DI intercommunication for cybersecurity protection and OS piracy protection

A method actuating a device to perform hardware interfacing for hardware and / or OS IDs (referring to identification numbers and / or serial numbers) embedded or installed thereon, setting at least one of the IDs as DI (device identification) information, and selectively allowing the DI information to be transmitted out, for providing cybersecurity protection to the device itself and / or to an external control system / Internet system to be accessed, for establishing unique DI intercommunication with the external control system / Internet system, for replacing the conventional antivirus software, for providing OS piracy protection to an OS maker, for functioning as a unique private key in encrypting / decrypting outgoing commands and / or feedback signals, wherein the device may be any communication device, computer, control system, server, Internet system, smartphone, smartwatch, Autonomous Thing (AuT), Internet of Autonomous Thing (IoAT), Internet of Medical Thing (IoMT), AI device / machine, robot, android, autonomous car or unmanned aerial vehicle, drone or unmanned aircraft system.
Owner:DI CYBERSECURITY CORP

Systems and methods for analyzing cybersecurity threat severity using machine learning

A method for cybersecurity threat actor severity scoring, the method comprising: receiving public data that includes publicly available information obtained via monitoring of a data connection between one or more networks; parsing first data related to a cybersecurity event from the public data; associating the first data with a first threat actor; obtaining second data that includes information regarding one or more previous cybersecurity events associated with the first threat actor; determining a first threat actor score based on the first data and the second data; receiving a second threat actor score for a second threat actor; causing a graphical user interface to display a graphical depiction of a ranking of the first threat actor and the second threat actor based on the first threat actor score and the second threat actor score.
Owner:CAPITAL ONE SERVICES LLC

Cybersecurity tools for managing anomalous security data items

This disclosure provides a filtering mechanism to manage anomalous security data items. An anomalous security data item is provided to an analysis engine (such as a Large Language Model (LLM) or another form of generative language model) for interpretation. By curating a selection of one or more relevant non-anomalous security data items to provide with the anomalous data item, the filtering mechanism enables the analysis engine to perform with increased accuracy, without requiring the analyst engine to process large numbers of data items to ascertain their relevance to the anomalous security data item.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Suffix proxied web application collaboration

In some embodiments, a collaboration feature overlays a web application by receiving a network communication that was redirected from the web application by a suffix proxy. The collaboration feature supplements or replaces activity of the web application by maintaining per-user-account activity states, deriving a shared collaboration state from the activity states, and supplying the shared collaboration state to multiple user accounts. The collaboration feature is installed without modifying the web application. The collaboration feature provides user accounts with a collaboration capability, such as shared document editing, chat rooms, shared calendars, or shared private workspaces. Some collaboration features overlay multiple web applications, even from different vendors, and some collaboration features support posting collaboratively created content to a website even when some contributors to the content are not registered users of the website. Some collaboration features impose stricter or different cybersecurity than an underlying website.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Internet security monitoring method based on big data

The invention discloses an Internet security monitoring method based on big data, and the method comprises the steps: obtaining network topology data in real time through the deployment of a three-dimensional visualization engine, generating a three-dimensional network structure model, and mapping network nodes and a connection relation into a spatial dimension. According to the method, a multi-dimensional data fusion algorithm is adopted, security indexes are associated with network topology, and a comprehensive security situation view is generated. Meanwhile, historical attack data are trained by using a machine learning algorithm, and potential attack paths and risk nodes are predicted in combination with real-time data. When an abnormal behavior is detected, a path tracking module is triggered to obtain a moving track of an attacker in a network, and key path nodes are highlighted in a three-dimensional model. Through the mode, the visual presentation and real-time monitoring of the network security situation are realized, and the efficiency and the accuracy of network security management are improved.
Owner:GUANGZHOU KAIYAS TECHNOLOGY CO LTD

Web security auditing method and device based on browser runtime

The invention discloses a Web security auditing method and device based on browser operation, and relates to the technical field of network security. Comprising the following steps: forcibly activating a credible type mechanism in a browser environment of a to-be-audited page, and constructing a hybrid monitoring environment with the assistance of API instrumentation; javaScript code data of a page are obtained, and a path control function is injected into a control flow branch of the JavaScript code data through abstract syntax tree analysis; executing the converted code in a monitoring environment, guiding to traverse different logic branches by utilizing a path control function, and capturing a call stack containing a vulnerability trigger point and a code snippet when triggering monitoring is executed; and based on call stack information, extracting precise code slices, combining with cue words, inputting the cue words into a large language model to perform safety semantic reasoning, and generating an audit report according to a structured result output by the model. High-coverage and low-false-alarm automatic detection of deep DOM XSS vulnerabilities is realized, and the problems that a path is difficult to reach and intelligent analysis is insufficient in a traditional security audit technology are solved.
Owner:BEIJING CHAITIN TECH CO LTD

Internet-based technical consultation risk assessment method and system

This invention discloses a method and system for assessing technical consulting risks based on the internet, relating to the field of data protection technology. It involves defining an enterprise data pool and establishing connections between the enterprise data pool and both the enterprise itself and the technical consulting platform. The enterprise sends consulting data to the technical consulting platform, which then provides suggested data based on the data. The consulting data and corresponding suggested data are stored in the enterprise data pool. A tracking set is set for the enterprise data pool to statistically analyze access information, including the processing results of accessed data (removal / destruction and normal access), resulting in a risk assessment index for the technical consulting. This invention ensures the security of enterprise-related data storage and also helps identify the cybersecurity risks faced by the enterprise during technical consulting.
Owner:SICHUAN XINRONG HUICHUANG TECHNOLOGY CO LTD

Cybersecurity for resource sharing among internet of things devices

Examples described herein provide a method for mitigating known-unknown threats for an internet of things (IoT) device. The method includes receiving data from the IoT device and analyzing the data to determine whether the data indicates a potential cyber threat to the IoT device. The method further includes determining whether the potential cyber threat is a known-known cyber threat or a known-unknown cyber threat. Responsive to determining that the potential cyber threat is the known-unknown cyber threat, the method includes identifying a mitigation action associated with the known-unknown cyber threat to overcome the known-unknown cyber threat. The method further includes updating a resource sharing security matrix to include the known-unknown cyber threat and the mitigation action associated with the known-unknown cyber threat.
Owner:GM GLOBAL TECHNOLOGY OPERATIONS LLC

Di intercommunication for cybersecurity and os piracy protections

A method actuates a device to perform hardware interfacing (S1314 and S1323) for retrieving hardware and / or OS DI (device identification) information embedded or installed thereon, so as to provide cybersecurity protection (S1326) to the device itself (S1320) and / or to an external control system (S1311) or Internet system to be accessed (S309), for establishing unique DI intercommunication (S1315 and S1324) with the external control system (S1311), for replacing the conventional antivirus software, for providing OS piracy protection (S1109) to an OS maker, for functioning as a unique private key (S1317) in encrypting / decrypting outgoing commands (S1328) and / or feedback signals (S1319).
Owner:LEE HOWARD HONG DOUGH

Self-adjusting cybersecurity analysis with network mapping

ActiveUS12719932B2Network onEngineering
A system and method for self-adjusting cybersecurity analysis with network mapping, wherein a reconnaissance engine gathers data about a client's computer network from the client, from devices and systems on the client's network, and from the Internet regarding various aspects of cybersecurity. Each of these aspects is evaluated independently, weighted, and cross-referenced to generate a cybersecurity score by aggregating individual vulnerability and risk factors together to provide a comprehensive characterization of cybersecurity risk using a transparent and traceable methodology. The scoring system itself can be used as a state machine with the cybersecurity score acting as a feedback mechanism, in which a cybersecurity score can be set at a level appropriate for a given organization, and data from clients or groups of clients with more extensive reporting can be used to supplement data for clients or groups of clients with less extensive reporting to enhance cybersecurity analysis and scoring.
Owner:QOMPLX INC

Cyber security protection of electronic communications including detecting topic shifts

PCT designated stageWO2026019729A1Machine learningNeural architecturesOutbound communicationElectronic communication
Systems and methods for protecting electronic communications are described. A cyber security appliance may be configured to calculate a topic shift score for a communication by comparing a first lexical profile derived from the communication to a historical lexical profile established for an associated user. This analysis may be performed without using a large language model. The system may also parse communications to extract sensitive data and content from attachments, performing behavioral modeling on the extracted data. Based on the analysis, an autonomous response module may take a variety of mitigation actions. Furthermore, a security mailbox assistant module may perform a secondary, in-depth analysis on user-submitted communications and generate a deterministic report. For outbound communications, a data loss prevention architecture may divert messages for in-line analysis and may include a fail-safe timeout mechanism to ensure service continuity.
Owner:DARKTRACE INC

Internet data center information security management method and system

The invention relates to the technical field of data management, and discloses an Internet data center information security management method and system, and the method comprises data in-storage management, data storage management and data out-storage management. The system corresponds to the method. According to the information security management method and system for the Internet data center, closed-loop management of data receiving-data storage and data distribution of the data center is realized through data in-storage management, data storage management and data out-storage management, and in the data storage, the stored data is modulated and encrypted, so that the security of the data center is improved. Therefore, the data stored in the data center is stored in an encrypted form, so that the corresponding dangerous source cannot directly obtain the corresponding data even if network security vulnerabilities occur, and the security of data storage is ensured.
Owner:GUANGZHOU FUTURE TECH CO LTD

An analytical method for determining the responsible party of Internet web pages

The present invention provides an analysis method for determining the responsible party of an Internet webpage, which relates to the field of network security technology. The method includes: processing webpage information to obtain processed data; treating each data point in the processed data as a particle and determining the initial position and velocity corresponding to each particle; determining a fitness function based on the initial velocity and position corresponding to each particle; updating the velocity and position of each particle based on the fitness function, and obtaining a final solution through multiple iterations; identifying a parameter set of the responsible party based on the final solution, and determining the responsible party of the webpage when a preset number of iterations is reached; and obtaining a responsible party information source based on the responsible party of the webpage. The present invention effectively improves the accuracy and efficiency of identifying the responsible party of a webpage through efficient data processing, while also enhancing the traceability of information.
Owner:SHANDONG TIANHE CYBERSPACE SECURITY TECH RES INST CO LTD +1

Generating trend data for a cybersecurity risk score

Systems and methods for assessing cybersecurity risk of a computer network include the use of a risk model application that is configured to determine an initial cyber risk score value based upon an underwriting process. A cyber risk data stream is sent from the client's computer network to the system processor to periodically calculate an updated cyber risk score based upon actual data. The system processor is adapted to use the data stream to generate client information that is accessible by the client via a web-based client portal. In embodiments, the cyber risk data stream can be actively monitored to identify a threat of a cybersecurity breach.
Owner:AMERICAN INTERNATIONAL GROUP INC

Cybersecurity threat network traffic generation with large language models

A security feed normalizer aggregates and normalizes threat intelligence data across security feeds and extracts threat descriptors of cybersecurity threats from the aggregated / normalized data. A first large language model (LLM) determines whether each threat descriptor is informative, i.e., comprises sufficient information for reproducing / generating network traffic of the corresponding cybersecurity threat. For informative threat descriptors, a second LLM generates network traffic for the corresponding cybersecurity threats. The generated network traffic is used for subsequent remediation of corresponding threats.
Owner:PALO ALTO NETWORKS INC