U.S. patents available from 1976 to present.
U.S. patent applications available from 2005 to present.

Icon_funbox Bizarre Patents

Patent No. 5871518

Smoking Cessation Lighter and Method

A lighter for tobacco products suppresses the urge to smoke by operant conditioning.

Newsletter  PatentStorm News

Make the Most of Our Site

See this month's Top Inventors and Most Cited Patents.

Stay on top of the latest innovations by subscribing to an RSS feed.

Registered users: Manage your profile.

 

Class 726/23 - Intrusion detection


Subclass of Class 726 - Information security
Definition: Subject matter comprising means to sense the presence
No. of patents: 679
Last issue date: 02/14/2012


1                      
NumberTitleIssue Date
8117657Detection and mitigation of rapidly propagating threats from P2P, IRC and gaming
A network switch detects at least two simultaneous connections on a single network port. The simultaneous connections use different protocols despite using the same port. The network switch mirrors network traffic associated with the simultaneous connections to a se...
02/14/2012
8117658Access point, mobile station, and method for detecting attacks thereon
A mobile station (STA) communicates with a WLAN device over a communication system includes a storage system, at least one processor, a detection module, an address determination module, a transmission module, and a response module. The STA detects a MAC management ...
02/14/2012
8112803IPv6 malicious code blocking system and method
An agent on a network is preconfigured to automatically respond to neighborhood discovery by sending an advertisement having a spoof IPv6 address. A spoof IPv6 address includes a spoof NIC value that is a value that identifies a network interface card not being used...
02/07/2012
8112804Malignant BOT confrontation method and its system
A method for dealing with attacks of malicious BOTs in a network security system includes detecting and analyzing a domain name receiving excessive DNS queries to judge the infection of a malicious BOT, registering the corresponding domain name as normal or abnormal...
02/07/2012
8112805Methods and systems that selectively resurrect blocked communications between devices
Data communications between devices are selectively blocked and resurrected based on error notifications. Data communications from one or more source devices to one or more intended destination devices are selectively blocked based on content of the data communicati...
02/07/2012
8108931Method and apparatus for identifying invariants to detect software tampering
Various embodiments of a method and an apparatus for identifying invariants to detect software tampering is disclosed. In one embodiment, a method of identifying invariants associated with a software package comprises applying a machine learning technique to a plura...
01/31/2012
8108929Method and system for detecting intrusive anomalous use of a software system using multiple detection algorithms
A target software system is instrumented to generate behavior data representing a current observation or observation aggregate. A method then determines whether the current observation or observation aggregate warrants a second level examination; preferably, this de...
01/31/2012
8108930Secure self-organizing and self-provisioning anomalous event detection systems
An approach for providing managed security services is disclosed. A database, within a server or a pre-existing anomalous event detection system, stores a rule set specifying a security policy for a network associated with a customer. An anomalous detection event mo...
01/31/2012
8099783Security method for data protection
An integrated circuit (IC) security apparatus with complementary security traces and a method for producing such an apparatus is disclosed. The security apparatus comprises a pattern generator, and a plurality of security traces. The arrangement of security trace pa...
01/17/2012
8099784Behavioral detection based on uninstaller modification or removal
To evade heuristic detection, malware is often designed to trick users into installing the malware by being packaged in a standard installer known to the user's computer for typically installing legitimate software. To prevent removal of the malware, the malware mod...
01/17/2012
8095981Worm detection by trending fan out
The invention detects stealth worm propagation by comparing the repeat elements in sets of destinations of a source in multiple time windows to a fitted distribution of same, stored as a benchmark plot. Measurements are performed over N time windows, wherein a repre...
01/10/2012
RE43103System and method for protecting a computer system from malicious software
In a computer system, a first electronic data processor is communicatively coupled to a first memory space and a second memory space. A second electronic data processor is communicatively coupled the second memory space and to a network interface device. The second ...
01/10/2012
8091131Method and apparatus for communicating intrusion-related information between internet service providers
Disclosed is a system and method for the sharing of intrusion-related information. The sharing of intrusion-related information occurs via a peering relationship between a first Internet Service Provider (ISP) and a second ISP. A first node associated with a first I...
01/03/2012
8091132Behavior-based traffic differentiation (BTD) for defending against distributed denial of service (DDoS) attacks
Embodiments are directed toward a method for Behavior-based Traffic Differentiation (BTD) that initially receives incoming packets and performs traffic classification to determine the protocol of the incoming packets. In addition, BTD performs bandwidth division/all...
01/03/2012
8091133Apparatus and method for detecting malicious process
Provided are an apparatus and method for detecting a malicious process. The apparatus includes: a process monitoring unit for monitoring a process generated in a computing environment; a target process setting unit for previously setting a test target process among ...
01/03/2012
8091130Geographical intrusion response prioritization mapping system
Systems and methods for geographically mapping an intrusion into a network having one or more network points include receiving intrusion information identifying a intrusion into a point of the network, correlating the intrusion information with location information ...
01/03/2012
8082586Snoop echo response extractor
A mechanism is provided for identifying a snooping device in a network environment. A snoop echo response extractor generates an echo request packet with a bogus MAC address that will only be received by a snooping device. The snoop echo response extractor also uses...
12/20/2011
8079083Method and system for recording network traffic and predicting potential security events
Recording network traffic is disclosed. Data associated with a network flow are monitored. If it is determined that the data associated with the network flow satisfy a first criterion based at least in part on a prediction value that reflects a likelihood that the n...
12/13/2011
8074277System and methodology for intrusion detection and prevention
System and methodology for intrusion detection and prevention is described. In one embodiment, for example, a method is described for detecting and preventing network intrusion, the method comprises steps of: defining intrusion descriptions specifying exploits that ...
12/06/2011
8074279Detecting rogue access points in a computer network
Detecting an unauthorized wireless access point in a network uses a detector. A rogue access point detector receives an incoming data packet which is scanned for a time expiration value. The time expiration value may be a Time To Live (TTL) value as used in Internet...
12/06/2011
8074278Apparatus and methods for intrusion protection in safety instrumented process control systems
Apparatus and methods for intrusion protection in safety instrumented process control systems are disclosed. An example method of protecting a safety instrumented system includes receiving legitimate information from a component of a process control system wherein t...
12/06/2011
8074280Detection of undesired computer files in archives
Systems and methods for an anti-virus detection module that can detect known undesired computer files in archives that may be encrypted, compressed and/or password-protected are provided. According to one embodiment, a method is provided for detection of malicious o...
12/06/2011
8069484System and method for determining data entropy to identify malware
Systems and methods for performing malware detection for determining suspicious data based on data entropy are provided. The method includes acquiring a block of data, calculating an entropy value for the block of data, comparing the entropy value to a threshold val...
11/29/2011
8069483Device for and method of wireless intrusion detection
A device for and method of detecting intrusion into a wireless network that includes a configuration file, a rules files, a main processor, a set packet processor, an initialize preprocessor, a parse rules file, an interface thread unit, a process packet unit, a dec...
11/29/2011
8065734Code module operating system (OS) interactions intercepting system and method
A method includes creating an intercept function for a tracked Dynamic Link Library (DLL) function of a Dynamic Link Library (DLL) being loaded into a suspicious module. Further, the import address table entry for the tracked DLL function is replaced with the respec...
11/22/2011
8065735Method of securing a calculation of an exponentiation or a multiplication by a scalar in an electronic device
A cryptographic operation includes calculating a multiplication of an element of an additively denoted group by a scalar. After two registers R0+R1, are initialized, iterations are carried out over the components Ki of the scalar K. ...
11/22/2011
8065733Method for evolving detectors to detect malign behavior in an artificial immune system
A system, apparatus, and method are directed to evolving detectors in an Artificial Immune System for use in detecting unauthorized computing activities. In one embodiment, a population of detectors is generated with a matching value and expectation value of zero. T...
11/22/2011
8056131Apparatus, methods and articles of manufacture for intercepting, examining and controlling code, data and files and their transfer
Apparatus, methods and articles of manufacture are disclosed for intercepting, examining and controlling proscribed or predetermined code, data and files and their transfers. A preprocessing component, code decomposition component, valuation component and comparison...
11/08/2011
8056132Client-side technique for detecting software robots
Software robots (“bots”) may be detected in a client computer using a client-side bot detector. The client-side bot detector may be configured to receive bot event profiles indicating IP (Internet Protocol) addresses involved in malicious online activities perpe...
11/08/2011
8051482Nullification of malicious code by data file transformation
To nullify any malicious code potentially contained within a data file, a transformation engine randomly selects a transformation from a number of available file transformations each arranged to alter the bit pattern of a file to which it is applied while still enab...
11/01/2011
8046832Spam detector with challenges
A system and method facilitating detection of unsolicited e-mail message(s) with challenges is provided. The invention includes an e-mail component and a challenge component. The system can receive e-mail message(s) and associated probabilities that the e-mail messa...
10/25/2011
8046833Intrusion event correlation with network discovery information
A policy component includes policy configuration information. The policy configuration information contains one or more rules. Each rule and group of rules can be associated with a set of response actions. As the nodes on the monitored networks change or intrusive a...
10/25/2011
8046374Automatic training of a database intrusion detection system
A database intrusion detection system (DIDS) automatically trains itself to account for changes to the database. The DIDS monitors upstream queries sent to the database and downstream data provided in response to the queries. The DIDS classifies an upstream query as...
10/25/2011
8042183Method and apparatus for detecting computer-related attacks
Disclosed is a method and apparatus for detecting prefix hijacking attacks. A source node is separated from a destination network at a first time via an original path. The destination network is associated with a prefix. At a second time, a packet is transmitted fro...
10/18/2011
8042182Method and system for network intrusion detection, related network and computer program product
A system for providing intrusion detection in a network wherein data flows are exchanged using associated network ports and application layer protocols. The system includes a monitoring module configured for monitoring data flows in the network, a protocol identific...
10/18/2011
8037532Application protection from malicious network traffic
A program, method and system for embedding a programmable packet filter into an application to protect the application against malicious network packets are disclosed. Traditional packet filtering techniques to protect against malicious packets designed to exploit d...
10/11/2011
8037533Detecting method for network intrusion
A detecting method for network intrusion includes: selecting a plurality of features contained within plural statistical data by a data-transforming module; normalizing a plurality of feature values of the selected features into the same scale to obtain a plurality ...
10/11/2011
8037531Dynamic network security system and control method thereof
A dynamic network security system and a control method thereof in a router where an Intrusion Detection System (IDS) and a Voice over Internet Protocol Application Level Gateway (VoIP ALG) are integrated, system including: a VoIP ALG module for acquiring VoIP IP/por...
10/11/2011
8037530Method and apparatus for providing adaptive self-synchronized dynamic address translation as an intrusion detection sensor
A translator is provided for translating predetermined portions of packet header information including an address of a data packet according to a cipher algorithm keyed by a cipher key derived by a key exchanger. A mapping device is also provided for mapping the add...
10/11/2011
8032936Systems and methods for detecting a security breach in a computer system
The present invention provides systems and methods for applying hard-real-time capabilities in software to software security. For example, the systems and methods of the present invention allow a programmer to attach a periodic integrity check to an application so t...
10/04/2011
1                      
 
Sign InRegister
Username  
Password   
forgot password?