Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

93 results about "Internet safety" patented technology

Internet safety or online safety or cyber safety is trying to be safe on the internet and is the knowledge of maximizing the user's personal safety and security risks to private information and property associated with using the internet, and the self-protection from computer crime. One key element of internet safety is the ability to maintain privacy. Internet privacy involves the right or mandate of personal privacy concerning the storing, repurposing, provision to third parties, and displaying of information pertaining to oneself via the Internet. Internet privacy is a subset of data privacy. Privacy concerns have been articulated from the beginnings of large-scale computer sharing.

Cyber security protection of electronic communications including detecting topic shifts

PendingUS20260019438A1Securing communicationOutbound communicationElectronic communication
Systems and methods for protecting electronic communications are described. A cyber security appliance may be configured to calculate a topic shift score for a communication by comparing a first lexical profile derived from the communication to a historical lexical profile established for an associated user. This analysis may be performed without using a large language model. The system may also parse communications to extract sensitive data and content from attachments, performing behavioral modeling on the extracted data. Based on the analysis, an autonomous response module may take a variety of mitigation actions. Furthermore, a security mailbox assistant module may perform a secondary, in-depth analysis on user-submitted communications and generate a deterministic report. For outbound communications, a data loss prevention architecture may divert messages for in-line analysis and may include a fail-safe timeout mechanism to ensure service continuity.
Owner:DARKTRACE HLDG LTD

Lookalike Domain Phishing Detection

The present disclosure enhances domain lookalike detection by integrating a phishing risk assessment score into a multi-layered evaluation framework. The method systematically generates lookalike domains through genetic algorithms. Registered domains undergo advanced phishing analysis, incorporating domain and URL checks, technical infrastructure assessments, content inspections, and reputation-based intelligence to calculate a dynamic phishing score. A comprehensive risk score is then determined by merging phishing likelihood with business attributes, graphical / contextual similarity metrics, and domain registration patterns. Domains are categorized into predefined risk levels including phishing, registered, preventative, company-owned, or watchlist, with specific action recommendations provided for each category. The system generates prioritized alerts for high-risk domains, offering customers actionable intelligence to mitigate threats. By combining phishing-specific indicators with contextual evaluations, this solution improves detection accuracy, reduces false positives, and enables organizations to respond effectively to domain-based threats in real time, addressing evolving cybersecurity challenges.
Owner:ZSCALER INC

Automated ai model-based pipeline for detection explainability

The present disclosure provides techniques for AI model-based detection explainability. A processing device obtains computer-readable text and an indication of a false positive detection of malicious behavior with respect to the computer-readable text by a cybersecurity system, The processing device obtains, via an artificial intelligence (AI) model trained to generate language, a reason for the false positive detection of the malicious behavior. The processing device provides an indication of the reason for the false positive detection to a destination device.
Owner:CROWDSTRIKE

Application-level cybersecurity using multiple stages of classifiers

Various embodiments include systems and methods to implement a security platform providing application-level cyberattack detection using multiple stages of classifiers. The security platform may use requests received by a web service to determine training data to train one or more machine learning models. The training data may be determined by instrumenting an application, such as a web service, with a first stage classifier to determine security events indicative of cyberattacks. The security platform may train machine learning models using aggregations of security events over various periods of time. The machine learning models may serve as second stage classifiers for the security platform.
Owner:RAPID7 INC

Internet-Exposed Device Discovery

A cloud-based, external attack surface management (or EASM) service identifies computers, servers, smartphones, and other devices that are exposed to the public Internet. Any device that can connect to the public Internet may be vulnerable to cybersecurity attacks. The EASM service identifies a device exposed to the public Internet by comparing connection notifications to an address scan of the entire Internet. The connection notifications are sent by cybersecurity sensory agents installed at client devices. When a connection notification and the address scan of the entire Internet references a matching IP address and / or a matching port within a timeframe, the corresponding device is identified as being exposed to the public Internet.
Owner:CROWDSTRIKE

Cybersecurity threat network traffic generation with large language models

A security feed normalizer aggregates and normalizes threat intelligence data across security feeds and extracts threat descriptors of cybersecurity threats from the aggregated / normalized data. A first large language model (LLM) determines whether each threat descriptor is informative, i.e., comprises sufficient information for reproducing / generating network traffic of the corresponding cybersecurity threat. For informative threat descriptors, a second LLM generates network traffic for the corresponding cybersecurity threats. The generated network traffic is used for subsequent remediation of corresponding threats.
Owner:PALO ALTO NETWORKS INC

CPE Prediction Using Banner Similarity

Prediction of matches between CPEs and banners greatly improves computer functioning. Many web services have an unknown common platform enumeration (CPE). When the CPE is unknown, a computer system is unable to obtain cybersecurity flaws and software fixes for a software product or web service. A similarity between the CPE and a service banner, though, accurately predicts a match the CPE and the web service. CPEs, for example, may thus be identified for old, obsolete, and uncomment software products and services.
Owner:CROWDSTRIKE

CPE prediction using banner-prompted AI / ML modeling

Prediction of CPEs using banners greatly improves computer functioning. Many web services have an unknown common platform enumeration (CPE). When the CPE is unknown, a computer system is unable to obtain cybersecurity flaws and software fixes for a software product or web service. A CPE, though, is predicted by banner-prompting an AI / ML model using a web service banner. Once the CPE is predicted, vulnerabilities may be identified.
Owner:CROWDSTRIKE

DI intercommunication for cybersecurity protection and OS piracy protection

A method actuating a device to perform hardware interfacing for hardware and / or OS IDs (referring to identification numbers and / or serial numbers) embedded or installed thereon, setting at least one of the IDs as DI (device identification) information, and selectively allowing the DI information to be transmitted out, for providing cybersecurity protection to the device itself and / or to an external control system / Internet system to be accessed, for establishing unique DI intercommunication with the external control system / Internet system, for replacing the conventional antivirus software, for providing OS piracy protection to an OS maker, for functioning as a unique private key in encrypting / decrypting outgoing commands and / or feedback signals, wherein the device may be any communication device, computer, control system, server, Internet system, smartphone, smartwatch, Autonomous Thing (AuT), Internet of Autonomous Thing (IoAT), Internet of Medical Thing (IoMT), AI device / machine, robot, android, autonomous car or unmanned aerial vehicle, drone or unmanned aircraft system.
Owner:DI CYBERSECURITY CORP

Systems and methods for analyzing cybersecurity threat severity using machine learning

A method for cybersecurity threat actor severity scoring, the method comprising: receiving public data that includes publicly available information obtained via monitoring of a data connection between one or more networks; parsing first data related to a cybersecurity event from the public data; associating the first data with a first threat actor; obtaining second data that includes information regarding one or more previous cybersecurity events associated with the first threat actor; determining a first threat actor score based on the first data and the second data; receiving a second threat actor score for a second threat actor; causing a graphical user interface to display a graphical depiction of a ranking of the first threat actor and the second threat actor based on the first threat actor score and the second threat actor score.
Owner:CAPITAL ONE SERVICES LLC

Cybersecurity tools for managing anomalous security data items

This disclosure provides a filtering mechanism to manage anomalous security data items. An anomalous security data item is provided to an analysis engine (such as a Large Language Model (LLM) or another form of generative language model) for interpretation. By curating a selection of one or more relevant non-anomalous security data items to provide with the anomalous data item, the filtering mechanism enables the analysis engine to perform with increased accuracy, without requiring the analyst engine to process large numbers of data items to ascertain their relevance to the anomalous security data item.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Web security auditing method and device based on browser runtime

The invention discloses a Web security auditing method and device based on browser operation, and relates to the technical field of network security. Comprising the following steps: forcibly activating a credible type mechanism in a browser environment of a to-be-audited page, and constructing a hybrid monitoring environment with the assistance of API instrumentation; javaScript code data of a page are obtained, and a path control function is injected into a control flow branch of the JavaScript code data through abstract syntax tree analysis; executing the converted code in a monitoring environment, guiding to traverse different logic branches by utilizing a path control function, and capturing a call stack containing a vulnerability trigger point and a code snippet when triggering monitoring is executed; and based on call stack information, extracting precise code slices, combining with cue words, inputting the cue words into a large language model to perform safety semantic reasoning, and generating an audit report according to a structured result output by the model. High-coverage and low-false-alarm automatic detection of deep DOM XSS vulnerabilities is realized, and the problems that a path is difficult to reach and intelligent analysis is insufficient in a traditional security audit technology are solved.
Owner:BEIJING CHAITIN TECH CO LTD

Internet-based technical consultation risk assessment method and system

This invention discloses a method and system for assessing technical consulting risks based on the internet, relating to the field of data protection technology. It involves defining an enterprise data pool and establishing connections between the enterprise data pool and both the enterprise itself and the technical consulting platform. The enterprise sends consulting data to the technical consulting platform, which then provides suggested data based on the data. The consulting data and corresponding suggested data are stored in the enterprise data pool. A tracking set is set for the enterprise data pool to statistically analyze access information, including the processing results of accessed data (removal / destruction and normal access), resulting in a risk assessment index for the technical consulting. This invention ensures the security of enterprise-related data storage and also helps identify the cybersecurity risks faced by the enterprise during technical consulting.
Owner:SICHUAN XINRONG HUICHUANG TECHNOLOGY CO LTD

Cybersecurity for resource sharing among internet of things devices

Examples described herein provide a method for mitigating known-unknown threats for an internet of things (IoT) device. The method includes receiving data from the IoT device and analyzing the data to determine whether the data indicates a potential cyber threat to the IoT device. The method further includes determining whether the potential cyber threat is a known-known cyber threat or a known-unknown cyber threat. Responsive to determining that the potential cyber threat is the known-unknown cyber threat, the method includes identifying a mitigation action associated with the known-unknown cyber threat to overcome the known-unknown cyber threat. The method further includes updating a resource sharing security matrix to include the known-unknown cyber threat and the mitigation action associated with the known-unknown cyber threat.
Owner:GM GLOBAL TECHNOLOGY OPERATIONS LLC

Di intercommunication for cybersecurity and os piracy protections

A method actuates a device to perform hardware interfacing (S1314 and S1323) for retrieving hardware and / or OS DI (device identification) information embedded or installed thereon, so as to provide cybersecurity protection (S1326) to the device itself (S1320) and / or to an external control system (S1311) or Internet system to be accessed (S309), for establishing unique DI intercommunication (S1315 and S1324) with the external control system (S1311), for replacing the conventional antivirus software, for providing OS piracy protection (S1109) to an OS maker, for functioning as a unique private key (S1317) in encrypting / decrypting outgoing commands (S1328) and / or feedback signals (S1319).
Owner:LEE HOWARD HONG DOUGH

Self-adjusting cybersecurity analysis with network mapping

ActiveUS12719932B2Network onEngineering
A system and method for self-adjusting cybersecurity analysis with network mapping, wherein a reconnaissance engine gathers data about a client's computer network from the client, from devices and systems on the client's network, and from the Internet regarding various aspects of cybersecurity. Each of these aspects is evaluated independently, weighted, and cross-referenced to generate a cybersecurity score by aggregating individual vulnerability and risk factors together to provide a comprehensive characterization of cybersecurity risk using a transparent and traceable methodology. The scoring system itself can be used as a state machine with the cybersecurity score acting as a feedback mechanism, in which a cybersecurity score can be set at a level appropriate for a given organization, and data from clients or groups of clients with more extensive reporting can be used to supplement data for clients or groups of clients with less extensive reporting to enhance cybersecurity analysis and scoring.
Owner:QOMPLX INC

Cyber security protection of electronic communications including detecting topic shifts

PCT designated stageWO2026019729A1Machine learningNeural architecturesOutbound communicationElectronic communication
Systems and methods for protecting electronic communications are described. A cyber security appliance may be configured to calculate a topic shift score for a communication by comparing a first lexical profile derived from the communication to a historical lexical profile established for an associated user. This analysis may be performed without using a large language model. The system may also parse communications to extract sensitive data and content from attachments, performing behavioral modeling on the extracted data. Based on the analysis, an autonomous response module may take a variety of mitigation actions. Furthermore, a security mailbox assistant module may perform a secondary, in-depth analysis on user-submitted communications and generate a deterministic report. For outbound communications, a data loss prevention architecture may divert messages for in-line analysis and may include a fail-safe timeout mechanism to ensure service continuity.
Owner:DARKTRACE INC

Internet data center information security management method and system

The invention relates to the technical field of data management, and discloses an Internet data center information security management method and system, and the method comprises data in-storage management, data storage management and data out-storage management. The system corresponds to the method. According to the information security management method and system for the Internet data center, closed-loop management of data receiving-data storage and data distribution of the data center is realized through data in-storage management, data storage management and data out-storage management, and in the data storage, the stored data is modulated and encrypted, so that the security of the data center is improved. Therefore, the data stored in the data center is stored in an encrypted form, so that the corresponding dangerous source cannot directly obtain the corresponding data even if network security vulnerabilities occur, and the security of data storage is ensured.
Owner:GUANGZHOU FUTURE TECH CO LTD

Cybersecurity threat network traffic generation with large language models

A security feed normalizer aggregates and normalizes threat intelligence data across security feeds and extracts threat descriptors of cybersecurity threats from the aggregated / normalized data. A first large language model (LLM) determines whether each threat descriptor is informative, i.e., comprises sufficient information for reproducing / generating network traffic of the corresponding cybersecurity threat. For informative threat descriptors, a second LLM generates network traffic for the corresponding cybersecurity threats. The generated network traffic is used for subsequent remediation of corresponding threats.
Owner:PALO ALTO NETWORKS INC

Technology consultation risk assessment method and system based on Internet

The invention discloses a technology consultation risk assessment method and system based on the Internet, and relates to the technical field of data protection, an enterprise data pool is determined, and the connection relation between the enterprise data pool and an enterprise terminal and the connection relation between the enterprise data pool and a technology consultation platform are established; consultation data is sent to a technology consultation platform through an enterprise terminal, the technology consultation platform gives suggestion data according to the consultation data, and the consultation data and the corresponding suggestion data are stored in an enterprise data pool; a tracking set is set corresponding to the enterprise data pool, the access information of the enterprise data pool is counted, the access information comprises the processed result of the access data, the result comprises removal and destruction and normal access, and the risk assessment index of the technical consultation is obtained. According to the system and the method, the storage security of related data of the enterprise can be ensured, and meanwhile, the network security risk faced by the enterprise in the technology consultation process can be known.
Owner:SICHUAN XINRONG HUICHUANG TECHNOLOGY CO LTD

Device and method for performing task for cybersecurity based on dark web

Provided are a device and method for performing a task for cybersecurity on the basis of a dark web. The method performed by a device includes acquiring raw dark web data from a database, acquiring first dark web data by preprocessing the raw dark web data, pretraining a bidirectional encoder representations from transformers (BERT)-based language model using the first dark web data, fine-tuning the pretrained BERT-based language model using second dark web data, and performing a task for cybersecurity using the fine-tuned BERT-based language model.
Owner:S2W INC +1

Privacy risk assessment method based on causal dependency graph cyclic decomposition

The invention discloses an Internet of Things privacy risk assessment method based on causal dependency graph cyclic decomposition. The method belongs to the technical field of network security and data privacy protection. The method comprises the following steps: (1) constructing a causal dependency graph, and setting intervention nodes; (2) decomposing a causal loop through an edge removal strategy to generate a plurality of effective directed acyclic subgraphs; (3) executing causal effect inference in each sub-graph, and quantifying state change after attribute leakage; (4) calculating causal susceptibility and downstream causal influence of the identity attribute based on an inference result; (5) aggregating all sub-graph results to generate a standardized privacy risk score; and (6) grading according to the score and outputting an identity theft path and a protection suggestion. According to the invention, the problem of cause and effect identification failure caused by a loop structure is effectively solved; clear semantics of an identity theft path are reserved by decomposing the sub-graphs; a dynamic causal index is introduced, and accurate quantification of the cascading privacy risk in the Internet of Things environment is realized.
Owner:TAIZHOU RES INST ZHEJIANG UNIV OF TECH

System and method for self-adjusting cybersecurity analysis and score generation

A reconnaissance engine gathers data about a client's computer network from the client, from devices and systems on the client's network, and from the Internet regarding various aspects of cybersecurity. Each of these aspects is evaluated independently, weighted, and cross-referenced to generate a cybersecurity score by aggregating individual vulnerability and risk factors together to provide a comprehensive characterization of cybersecurity risk using a transparent and traceable methodology. The scoring system itself can be used as a state machine with the cybersecurity score acting as a feedback mechanism, in which a cybersecurity score can be set at a level appropriate for a given organization, and data from clients or groups of clients with more extensive reporting can be used to supplement data for clients or groups of clients with less extensive reporting to enhance cybersecurity analysis and scoring.
Owner:QOMPLX INC

Method and internet of things (IOT) system for safely replacing a gas pipeline network component based on a supervision network

A method and an Internet of Things (IoT) system for safely replacing a gas pipeline network component are provided. The method includes: acquiring a component feature of a gas numerical control component based on a data center; determining a replacement necessity degree of the gas numerical control component based on the component feature; determining a replacement parameter based on the replacement necessity degree; generating a replacement task instruction and a gas shutoff parameter based on the replacement parameter; in response to receiving a shutoff parameter confirmation instruction, generating a gas shutoff instruction and transmitting the gas shutoff instruction to a gas supply control device; generating gas shutoff reminder information; and in response to receiving a replacement completion message, determining a replaced component and updating a data partition corresponding to the replaced component.
Owner:CHENGDU QINCHUAN IOT TECH CO LTD

Apparatus and method for intelligent processing of cyber security risk data

An apparatus and method for intelligent processing of cyber security risk assessment data are provided. The apparatus includes a processor and a memory communicatively coupled to the at least a processor. The memory contains instructions configuring the at least a processor to receive a cyber profile associated with a digital environment. The processor is also configured to generate a cyber profile summary of the cyber profile data and generate a user interface data structure including the cyber profile summary and the cyber profile. A graphical user interface (GUI) is communicatively connected to the processor and the GUI is configured to receive the user interface data structure including the cyber profile summary and the cyber profile and display the cyber profile summary on a first portion of the GUI.
Owner:SECOND SIGHT DATA DISCOVERY INC

Privacy information security protection method and system for power transaction platform

The application relates to the technical field of network security, in particular to a private information security protection method and system for a power transaction platform. The method first determines the attack possibility of the power transaction platform suffering from a DDOS attack; in combination with the attack possibility, the historical transaction of a transaction combination and the periodic characteristics of transaction power, determines a protection attention factor of the transaction combination; according to the encryption condition of the transaction combination when the transaction content is encrypted, determines the transaction privacy degree of the transaction combination; in combination with the protection attention factor and the transaction privacy degree, determines the request threshold demand index of the transaction combination; according to the request threshold demand index, adjusts the preset rated QPS threshold value to obtain the adaptive QPS threshold value of the transaction combination; and according to the adaptive QPS threshold value of each transaction combination, carries out the security protection measure on the transaction request of the power transaction platform. The application improves the security protection efficiency of the private information of the power transaction platform.
Owner:TIANJIN ANJIE PUBLIC FACILITIES SERVICE CO LTD

Real-time data security monitoring system based on online data modeling

This invention discloses a real-time data security monitoring system based on online data modeling, specifically relating to the field of network security technology. The system includes a data acquisition module for collecting real-time network stream data and extracting feature sequences of behavioral patterns; a feature space module for constructing a feature space and generating feature drift mapping sequences and abnormal behavior recognition sensitivity change trend sequences; a shift analysis module for identifying feature variation trends caused by low-intensity probing attack samples; a decay detection module for identifying the degradation characteristics of the real-time security monitoring classifier's ability to recognize real attack events; a risk assessment module for evaluating the risk level of induced drift in the real-time security monitoring classifier based on feature variation trends and recognition ability degradation characteristics; and a reconstruction trigger module for determining the risk level of the real-time data security monitoring system based on the risk level and triggering a security reconstruction mechanism for the real-time security monitoring classifier, thereby improving the stability of the security monitoring system in recognizing persistent induced attack behaviors.
Owner:XIAMEN NEUSOFT HANHE INFORMATION TECH CO LTD

Ensemble machine learning model for email cybersecurity system

A method for training an ensemble machine learning model. The method includes applying a first language model to a training data set, having emails stored in a non-transitory computer readable storage medium, to split email addresses in the emails into gibberish email addresses and non-gibberish email addresses. The gibberish email addresses include a first text string that the first language model classifies as gibberish. The non-gibberish email addresses include a second text string that the first language model classifies as non-gibberish. The method also includes training a second language model on the gibberish email addresses. The second language model is trained to determine whether the gibberish email addresses are valid or invalid. The method also includes training a third language model on the non-gibberish email addresses. The third language model is trained to determine whether the non-gibberish email addresses are valid or invalid.
Owner:INTUIT INC

Suffix proxied web application collaboration

In some embodiments, a collaboration feature overlays a web application by receiving a network communication that was redirected from the web application by a suffix proxy. The collaboration feature supplements or replaces activity of the web application by maintaining per-user-account activity states, deriving a shared collaboration state from the activity states, and supplying the shared collaboration state to multiple user accounts. The collaboration feature is installed without modifying the web application. The collaboration feature provides user accounts with a collaboration capability, such as shared document editing, chat rooms, shared calendars, or shared private workspaces. Some collaboration features overlay multiple web applications, even from different vendors, and some collaboration features support posting collaboratively created content to a website even when some contributors to the content are not registered users of the website. Some collaboration features impose stricter or different cybersecurity than an underlying website.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC