SYSTEM FOR DETECTING WHETHER CLIENT STATE MATCHES PREDETERMINED STATE
    31.
    发明申请
    SYSTEM FOR DETECTING WHETHER CLIENT STATE MATCHES PREDETERMINED STATE 有权
    用于检测客户状态匹配预测状态的系统

    公开(公告)号:US20130173787A1

    公开(公告)日:2013-07-04

    申请号:US13707705

    申请日:2012-12-07

    IPC分类号: H04L12/26

    摘要: A server connectable to a client able to manage successively transitioned-to states. The server has a set storage unit for storing a set including a predetermined state; a server-side communication unit for communicating with the client using a privacy-preserving set-intersection protocol for detecting whether an element in a mutual set is a common element between mutual sets while preserving privacy; and a determining unit for determining whether the state of the client is included in the set stored by the set storage unit on the basis of ciphertext received in accordance with the privacy-preserving set-intersection protocol. Also provided is an information processing method which is able to manage successively transitioned-to-states.

    摘要翻译: 可连接到能够管理连续转换状态的客户端的服务器。 服务器具有用于存储包括预定状态的集合的集合存储单元; 服务器侧通信单元,用于使用隐私保护设置交集协议与客户端通信,用于检测相互集合中的元素是否是相互集合之间的公共元素,同时保持隐私; 以及确定单元,用于基于根据隐私保护设置交集协议接收的密文来确定客户端的状态是否包括在由设置的存储单元存储的集合中。 还提供了一种信息处理方法,其能够连续地管理状态。

    NODE LEVEL CONTAINER MUTATION DETECTION
    33.
    发明公开

    公开(公告)号:US20240095075A1

    公开(公告)日:2024-03-21

    申请号:US17933865

    申请日:2022-09-21

    IPC分类号: G06F9/50 G06F21/55

    CPC分类号: G06F9/5027 G06F21/554

    摘要: A computer-implemented method for determining container information associated with detected container mutation events is disclosed. The computer-implemented method includes: determining that a system call event to a host operating system includes a call to join a namespace and execute a parent process inside the namespace; determining that the namespace is associated with an existing container; responsive to determining that the namespace is associated with an existing container, determining that the system call event further includes a call to execute a child process inside the namespace; and responsive to determining that the system call event further includes a call to execute a child process inside the namespace: designating the child process as a mutation event to the existing container, and determining container information associated with the mutation event to the existing container. A corresponding computer system and computer program product are also disclosed.

    Role design advisor
    34.
    发明授权

    公开(公告)号:US11809534B2

    公开(公告)日:2023-11-07

    申请号:US17237734

    申请日:2021-04-22

    摘要: A system for controlling access to cluster resources is provided. The system includes one or more processors; and memory operatively coupled to the one or more processors, wherein the one or more processors and the memory form a cluster of computer resources that includes an admission controller configured to receive requests and determine if the request is authorized, a request history database that stores the request information received by the admission controller from a plurality of users, a role design advisor that is configured to adjust permissions for the plurality of users based on a pattern of usage identified from the request history database, and an alert system that communicates an alert to an administrator that a request outside the pattern of requests for the user has been received by the admission controller, wherein the admission controller, request history database, and role design advisor control access to the cluster resources.

    Guided character string alteration
    35.
    发明授权

    公开(公告)号:US11599772B2

    公开(公告)日:2023-03-07

    申请号:US16439021

    申请日:2019-06-12

    IPC分类号: G06N3/04 H04L9/40 G06N3/08

    摘要: Guided character string alteration can be performed by obtaining an original character string and a plurality of altered character strings, traversing the original character string with a first Long Short Term Memory (LSTM) network to generate, for each character of the original character string, a hidden state of a partial original character string up to that character, and applying, during the traversing, an alteration learning process to each hidden state of a partial original character string to produce an alteration function for relating partial original character strings to partial altered character strings.

    CORRESPONDENCE OF EXTERNAL OPERATIONS TO CONTAINERS AND MUTATION EVENTS

    公开(公告)号:US20230054683A1

    公开(公告)日:2023-02-23

    申请号:US17980080

    申请日:2022-11-03

    摘要: A method is provided for determining command-to-process correspondence. The method includes identifying, by the hardware processor, initial processes resulting from executions of container immutability change events for each of multiple initially mutable containers in a cluster, based on an execution time, a process identifier and a process group identifier for each of the container immutability change events. The method also includes designating, by the hardware processor, a particular external command, from among external container commands stored in a database, as having a correspondence to an initial process, responsive to the initial process matching at least one respective process resulting from executing the particular external command.

    Combo-squatting domain linkage
    37.
    发明授权

    公开(公告)号:US11178175B2

    公开(公告)日:2021-11-16

    申请号:US16542561

    申请日:2019-08-16

    IPC分类号: H04L29/06

    摘要: A computer-implemented method for linking combo-squatting domains is provided. The method includes grouping domain names into nameserver groups based on a nameserver for each of the domains. Each of the domain names contain valued words. The method also includes splitting words in each domain name and generating a wordlist for each of the nameserver groups. The method further includes finding feature words among the nameserver groups, and extracting malicious domain names which contain the feature words in each of the nameserver groups. The method further includes outputting, for each of the nameserver groups, the malicious domain names and corresponding registrant identifying data based on the feature words.

    Privacy annotation from differential analysis of snapshots

    公开(公告)号:US10936747B2

    公开(公告)日:2021-03-02

    申请号:US16664303

    申请日:2019-10-25

    摘要: A system prevents divulgation of sensitive data in two snapshots, taken at different times, of one or more systems. The system identifies a set of files from among file pairs. Each file pair is formed from a respective file that includes a difference with respect to each of the two snapshots. The system performs a pattern reducing process that removes, from the set, any file having, as the at least one difference, a predetermined non-sensitive difference between respective executions of a pre-determined system operation. The system performs a commonality reducing process that removes, from the set, any file having, as the at least one difference, a common difference between different system users. The system annotates data in remaining files in the set as potentially being sensitive data. The predetermined non-sensitive difference is determined using a Sandbox host. The common difference is determined using an actual one of the systems.

    System and method for searching a database or data sharing system for the presence of data

    公开(公告)号:US10803075B2

    公开(公告)日:2020-10-13

    申请号:US14017190

    申请日:2013-09-03

    摘要: A database search system ensures the privacy of a search request and the security of a database with high processing efficiency. The system comprises a database server residing on a network that stores predetermined data, and a client terminal issuing to the database server a search request for inquiring for desired data while keeping the desired data secret. The database server further comprises: a database storing predetermined data; and a search response message generation unit for receiving through a network the data search request in which data to be searched for is kept secret, searching the database by a predetermined computation based on the search request and a list of the data stored in the database while a data item involved with the search request is kept secret, and generating a response to the search request.

    PRIVACY-AWARE ID GATEWAY
    40.
    发明申请

    公开(公告)号:US20200067910A1

    公开(公告)日:2020-02-27

    申请号:US16671778

    申请日:2019-11-01

    IPC分类号: H04L29/06

    摘要: At least one processor device is configured to receive a first authentication request for authenticating a first user, the first user having been authenticated on a first application with a first user identification (ID) using a first ID federation between the first application and a federation server, determine that the first user is authorized to access information of a second user on a second application based on the first user ID, the second user being associated with a second user ID, and send a second authentication request for authenticating the first user to the second application with the second user ID using a second ID federation between the federation server and the second application.