One embodiment comprises a system for artificial intelligence-based evaluation of an agent interaction. The system is operable to generate a transcript of the voice session recording of the call and parse the evaluation form to identify the evaluation question for an intended call participant interaction. The system is further operable to determine, using the machine learning model, that the intended call participant interaction of the evaluation question is present in the transcript. When the intended call participant interaction is present in the transcript, the system records a first answer for to the evaluation question corresponding to the voice session recording, the first answer indicating a presence of the intended call participant interaction in the voice session recording and automatically sets the answer control in the visual display to indicate the presence of the intended call participant interaction in the voice session recording.
Systems and methods are provided for enabling a trusted and secured client-server model in a container orchestration environment. Various embodiments provide a trusted and secured client-server model leverages the concept of self-signed TLS certificates to automate and efficiently manage TLS connections. In some embodiments a Kubernetes API server injects a service token into each pod in a cluster. The Kubernetes API server also injects the certificate used to generate the service token. In a client server model between pods, clients can use the same service token as its identity to the server and the server can use the same certificate for validating the token. In this way, trust is established using token-based authentication between clients and servers.
Systems and methods for extrinsic data driven OCR utilizing multiple OCR engines are disclosed. Embodiments as disclosed herein may determine data on OCR engines employed by an OCR system during an OCR engine evaluation process to generate extrinsic data on each OCR engine. This extrinsic data can then be used by embodiments of OCR systems employing these multiple OCR engines when performing OCR on an image.
G06V 10/75 - Organisation of the matching processes, e.g. simultaneous or sequential comparisons of image or video featuresCoarse-fine approaches, e.g. multi-scale approachesImage or video pattern matchingProximity measures in feature spaces using context analysisSelection of dictionaries
Examples of the present disclosure describe systems and methods for state-based entity behavior analysis. In an example, entities of a computing environment may be represented using a hierarchical entity web. In some examples, an entity may have a state associated with it, which may be modeled using a place/transition (PT) network. Events within the computing environment may be evaluated by transitions of a PT network to determine whether an entity should change state. If an entity transitions from one state to another, one or more actions may be performed, including, but not limited to, taking a remedial action, generating a recommendation, and updating the state of one or more associated entities. Thus, aspects disclosed herein may provide a high-level overview of the state of entities of a computing environment, but may also be used to view in-depth information of entities at lower levels of the hierarchical entity web.
H04L 41/0853 - Retrieval of network configurationTracking network configuration history by actively collecting configuration information or by backing up configuration information
H04L 41/0654 - Management of faults, events, alarms or notifications using network fault recovery
H04L 41/0816 - Configuration setting characterised by the conditions triggering a change of settings the condition being an adaptation, e.g. in response to network events
H04L 41/084 - Configuration by using pre-existing information, e.g. using templates or copying from other elements
5.
Configurable Large Language Model Integration and Management Across Cloud and On-Premises Environments
The present disclosure provides a system for integrating and managing large language models (LLMs) across cloud and on-premises environments. The system allows organizations to flexibly configure and deploy multiple LLMs. Some features include a model administration module for managing execution parameters, an orchestrator service for deploying and maintaining models, and a conversion service for standardizing models into a common format.
The present disclosure provides a system for integrating and managing large language models (LLMs) across cloud and on-premises environments. The system allows organizations to flexibly configure and deploy multiple LLMs. Some features include a model administration module for managing execution parameters, an orchestrator service for deploying and maintaining models, and a conversion service for standardizing models into a common format.
The present disclosure provides a comprehensive solution for seamless integration, customization, and management of LLMs, ensuring optimal performance across diverse platforms.
The present disclosure pertains to dynamic query classification and routing in multi-model AI (Artificial Intelligence) architectures. A method includes receiving a user query at a computing device, generating an embedding representation of the query using a pre-trained language model, and applying a trained classifier to the embedding representation to determine the query's type. The classifier categorizes the query into one of three types: information retrieval, document retrieval, or document summary. A response is then generated based on the classified query type, enhancing the system's ability to provide relevant and accurate results to users.
Systems and methods for context-based annotation analyzation are provided. A system and method provides an artificial intelligence (AI) solution that aims to automate, accelerate, and enhance the accuracy of managing annotations and comments, thereby minimizing the risks associated with manual processing. The system and method leverages AI models to contextually identify and understand annotations within documents, allowing for precise summarization and enabling advanced search capabilities based on these annotations.
Aspects of the present disclosure are operable to protect against malicious objects, such as JavaScript code, which may be encountered, downloaded, or otherwise accessed from a content source by a computing system. In an example, antivirus software implementing aspects disclosed herein may be capable of detecting malicious objects in real-time. Aspects of the present disclosure aim to reduce the amount of time used to detect malicious code while maintaining detection accuracy, as detection delays and/or a high false positive rate may result in a negative user experience. Among other benefits, the systems and methods disclosed herein are operable to identify malicious objects encountered by a computing system while maintaining a high detection rate, a low false positive rate, and a high scanning speed.
Embodiments of the present disclosure provide systems and methods to classify webpages according to phishing risk. Embodiments combine generative AI with a knowledgebase of anti-phishing questions. To classify a webpage, the generative AI processes details from the webpage to answer the anti-phishing questions. The webpage is classified at least in part based on the results generated by the generative AI.
Systems, methods and products for enabling parallelized verification of a forensic copy generated using a non-parallelizable hashing algorithm. Disclosed embodiments generate the forensic copy of a data source using a non-parallelizable algorithm. In addition to generating a hash of the source data, intermediate hash states are stored for successive blocks of data from the data source. During verification of the forensic copy, the intermediate hash states and identifiers of the data blocks are retrieved from a data structure that is saved with the forensic copy. The non-parallelizable algorithm is used to hash each data block using the intermediate hash state preceding the data block as a starting hash state, then the hash of the data block is compared to the intermediate hash state following the data block to verify the data block. If all data blocks are successfully verified, the forensic copy is verified, otherwise verification fails.
H04L 9/06 - Arrangements for secret or secure communicationsNetwork security protocols the encryption apparatus using shift registers or memories for blockwise coding, e.g. D.E.S. systems
H04L 9/00 - Arrangements for secret or secure communicationsNetwork security protocols
11.
RESTRICTING ACCESS TO APPLICATION PROGRAMMING INTERFACES (APIs)
Examples of the present disclosure describe systems and methods for restricting access to application programming interfaces (APIs). For example, when a process calls an API, the API call may be intercepted by a security system for evaluation of its trustfulness before the API is allowed to run. Upon intercepting an API call, the process calling the API may be evaluated to determine if the process is known to the security system, such that known processes that are untrusted may be blocked from calling the API. Further, when the security system cannot identify the process calling the API, the security service may evaluate a call stack associated with the call operation to determine if attributes of the call operation are known to the security system. If the call operation is known to the security system as untrusted, the call operation may be blocked from calling the API.
G06F 21/51 - Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems at application loading time, e.g. accepting, rejecting, starting or inhibiting executable software based on integrity or source reliability
G06F 21/52 - Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems during program execution, e.g. stack integrity, buffer overflow or preventing unwanted data erasure
G06F 21/62 - Protecting access to data via a platform, e.g. using keys or access control rules
A computer-implemented method for browser extension authentication. A browser extension of a web browser on a mobile device requests an authentication key from a remote service. The browser extension receives the authentication key from the remote service. The browser extension provides the authentication key to a native mobile application on the mobile device. The native mobile application sends the remote service data to be mapped to the authentication key as mapped data. The browser extension requests the mapped data corresponding to the authentication key and receives the mapped data. The browser extension authenticates using the mapped data received from the remote service.
Display screen or portion thereof with graphical user interface for visualizing connections between base entities of a story corresponding to a security issue
A web editing environment integrated with a web assessment platform for auditing and ameliorating a web page under design in the context of the editing environment is disclosed.
Presentations are often broadcast or video recorded without handouts, such as the slides presented by a presenter of the presentation. Without handouts it is difficult and resource intensive to identify a particular slide of interest. Systems and methods are provided to automatically convert frames of a presentation video (e.g., a file or broadcast) to images in a document (e.g., Word™, PDF, etc.). Frames of the presentation are included in the document unless excluded. The frames are excluded when determined to be duplicative of a previous frame. Frames are duplicative if they are determined to be identical or nearly identical when hashed via an image hashing function. A non-identical frame is further determined to be duplicative when not identical to a previous frame but the differences are limited to only irrelevant visual content (e.g., the presenter gesturing).
Embodiments provide systems and methods for logging events. A computer-implemented method, for example, includes a syslog connector providing a subscription to a cloud source that collects events from a plurality of data sources, the subscription comprising an event selection criterion, receiving event records from the cloud source according to the subscription, the received event records formatted according to a first format, transforming the event records received from the cloud source from the first format to syslog messages and storing, by the syslog connector, the syslog messages to a syslog data sink.
Embodiments of systems and methods for DNS smart access are disclosed herein. In particular, certain embodiments include a local cache of trusted addresses resolved by a trusted DNS resolver. A DNS smart access agent monitors outbound communications from applications or processes on a client device. The DNS smart access agent blocks access to addresses that were not resolved through the trusted DNS resolver.
H04L 61/4511 - Network directoriesName-to-address mapping using standardised directoriesNetwork directoriesName-to-address mapping using standardised directory access protocols using domain name system [DNS]
Systems, methods and products for performing file retention operations in a system in which a content management system accesses multiple cloud-based data stores that are compliant with a common file transfer protocol, but use different vendor-specific protocols for file retention operations, where a retention framework is coupled between the content management system and the data stores. The content management system performs file access operations by accessing an SDK that generates requests for these operations which follow the common set of protocols. The content management system performs file retention operations by accessing a retention framework that uses the information received from the content management system to identify the targeted file, identify the data store in which the targeted file is stored, and generate a request for a retention operation that is configured according to the data-store-specific retention protocols which correspond to the identified data store.
A client-side anti-phishing solution provides an anti-phishing browser plug-in and an anti-phishing module on a user device for initiating an anti-phishing operation on the user device as a user enters a login credential on a web page originating from a website. The anti-phishing operation comprises generating a random number of phishing credentials based on the login credential, randomly selecting, from the random number of phishing credentials, a phishing credential, and causing a browser application on the user device to submit the phishing credential to the website on behalf of the user. Depending upon whether the phishing credential is accepted by the website, access to the website is blocked or allowed. Since the client-side anti-phishing solution does not need to rely on complex machine learning models to classify unknown websites, active phishing websites can be quickly and effectively blocked from procuring user credentials before submission.
Systems, methods and products for providing a dynamic bookmarks list feature. In one embodiment, a user provides a name and an endpoint to a module that creates a dynamic bookmark in a web browser. When the dynamic bookmark is accessed, an API call is made to the endpoint. The endpoint recognizes a query parameter in the API call and retrieves a list of bookmarks and/or folders of bookmarks and returns them to the browser. The browser presents the bookmarks and/or folders to the user in a list in the same manner as individual, manually created bookmarks are presented. The user then accesses any of the listed bookmarks in the same manner as a conventional, manually created bookmark. The contents of listed folders may not be retrieved until the folder is accessed. These contents are retrieved in the same way the listed bookmarks and folders were retrieved.
Embodiments provide systems and methods for identifying domain name service (DNS) resolvers. A computer-implemented method includes detecting a request from a client device to a destination. The method further includes sending a DNS request from the client device to the destination, receiving, at the client device, a DNS response from the destination, identifying the destination as a DNS resolver based on receiving the DNS response, and based on identifying the destination as a DNS resolver, blocking, at the client device, connections to the destination.
H04L 61/4511 - Network directoriesName-to-address mapping using standardised directoriesNetwork directoriesName-to-address mapping using standardised directory access protocols using domain name system [DNS]
H04L 67/1036 - Load balancing of requests to servers for services different from user content provisioning, e.g. load balancing across domain name servers
H04L 61/30 - Managing network names, e.g. use of aliases or nicknames
Embodiments provide systems and methods for identifying domain name service (DNS) resolvers. A computer-implemented method includes detecting a request from a client device to a destination. The method further includes sending a DNS request from the client device to the destination, receiving, at the client device, a DNS response from the destination, identifying the destination as a DNS resolver based on receiving the DNS response, and based on identifying the destination as a DNS resolver, blocking, at the client device, connections to the destination.
H04L 61/4511 - Network directoriesName-to-address mapping using standardised directoriesNetwork directoriesName-to-address mapping using standardised directory access protocols using domain name system [DNS]
An intelligent integration system runs a workflow implementation in a test mode with an avatar, a set of handlers, and a choreography. The system receives a message from the second entity to the first entity via their respective avatars. The arrival of data in the message triggers the first entity to invoke an integration activity which utilizes the set of handlers. The integration activity follows the choreography and moving the data through the choreography is defined and governed by a choreography key. The system may stop moving the data through the choreography, determine/generate a handler that can meet a requirement of the choreography key that is not met by the set of handlers, and update the workflow implementation to include the handler. The system may then continue or restart the workflow implementation with the handler that can meet the requirement of the choreography key.
Embodiments of document processing systems and methods for intelligent zonal recognition and context mapping are disclosed. These document processing systems and methods may utilize image processing and heuristic techniques to determine key zones from a minimal set of example documents of a document type and map those key zones to a context definition.
A document process automation system includes a user interface for uploading a document and invoking an artificial intelligence (AI) content assistant. When invoked, a chat window for the Al content assistant is displayed. The Al content assistant leverages a chat service to enable querying a status of the document through the chat window. The system further includes a document enrichment module, an inbound application programming interface (API), and a document API. The document enrichment module determines a category of the document and attaches attributes associated with the category to the document. The inbound API reads the document and creates a copy of the document for a document management system. The document API reads status updates to the copy of the document from a document queue and updates the attributes associated with the document. The user interface is configured for presenting the attributes thus updated as properties of the document.
Embodiments extract a layout from a digital image of a document, including performing an analysis of image data to identify areas of content and storing the identified areas as design elements of an electronic document template. Analyzing the image data to identify areas of interest includes testing a plurality of lines of pixels from the digital image against a background color definition to identify boundaries of a content area of interest. Content from the content area of interest is processed using a machine learning model to assign a content type for the content area of interest, where the machine learning model represents multiple types of content and is trained to assign content types to input content. The content area of interest is stored as a design element of a digital page template.
Systems and methods for text analysis are provided. Various embodiments of the present technology provide systems and methods for improved text analysis by providing a comprehensive robust solution that solves character-set identification and print type classification along with text detection from scene text images/documents. Systems and methods for improved text analysis integrate text detection, character-set identification, and print type classification into a unified framework.
Systems and methods are provided for enabling a trusted and secured client-server model in a container orchestration environment. Various embodiments provide a trusted and secured client-server model leverages the concept of self-signed TLS certificates to automate and efficiently manage TLS connections. In some embodiments a Kubernetes API server injects a service token into each pod in a cluster. The Kubernetes API server also injects the certificate used to generate the service token. In a client server model between pods, clients can use the same service token as its identity to the server and the server can use the same certificate for validating the token. In this way, trust is established using token-based authentication between clients and servers.
A computer-implemented method for activity monitoring with respect to online services. The method can include accessing a machine learning multiclass classifier, the machine learning multiclass classifier representing HTTP network request features and associated actions with respect to interacting with websites, receiving an HTTP request, extracting a feature set from the HTTP request, determining a request action classification for the HTTP request, determining the request action classification comprising processing the feature set extracted from the HTTP request to the machine learning multiclass classifier to classify the HTTP request, and providing access to the HTTP request and request action classification via an application programming interface.
Embodiments include an activity monitoring machine learning model method. One embodiment the method includes transforming HTTP network requests into feature vectors, each feature vector representing selected features from a corresponding HTTP network request and an action selected from a plurality of actions to be monitored and inputting the feature vectors into a machine learning model to train the machine learning model to classify new HTTP requests according to the plurality of actions, wherein the plurality of actions include an upload action and a download action.
Integrated document scoring and prioritization systems and methods for enhanced document review in e-discovery are disclosed herein. An example includes combining a first vector of scores from one algorithm and a second vector of scores from another algorithm, both corresponding to a set of documents. Ground truth labels indicating document responsiveness are also acquired. A system calculates blending weights through a supervised learning algorithm, considering the scores and ground truth labels. These weights are then employed to combine the vector scores, yielding final ranking scores for each document. The system culminates in the creation of a sorted document list, where documents with higher final ranking scores are prioritized, signifying their increased relevance within the dataset.
Embodiments of systems and methods for DNS leak prevention and protection, including protection against DNS tunneling attacks, are disclosed herein. In particular, certain embodiments include a local DNS protection agent installed on a system and an associated trusted external DNS protection server. The DNS protection agent prevents DNS leaks from applications on the system such that all DNS requests from the system are confined to requests from the DNS protection agent to the associated DNS protection server. As the DNS leak prevention provided by the DNS protection agent stops applications on the system from circumventing the DNS protection server, all DNS requests originating from the system remain under the control of the DNS protection server and thus desired DNS protection (e.g., as implemented on the DNS protection server) may be maintained. Certain embodiments prevent applications from using certain DNS security protocols, such as DoH and DoT, without going through the DNS protection agent. Embodiments are also capable of detecting and addressing DNS tunneling attacks.
GENERATION OF TRAINING IMAGES MIMICKING HANDWRITTEN TEXT INCLUDING NON-ALPHANUMERIC CHARACTERS FOR TRAINING OPTICAL CHARACTER RECOGNITION (OCR) MACHINE LEARNING MODELS
Training images mimicking handwritten text including one or more non-alphanumeric characters are used at least for training an optical character recognition (OCR) machine learning model. The train images are generated as follows. A character sequence format and the non-alphanumeric characters are specified. Character sequences in the specified character sequence format with the specified non-alphanumeric characters are generated using a regular expression pattern for the specified character sequence format. Synthetic handwritten images are generated for each character sequence. A handwritten text image-generating machine learning model for generating the training images is trained using at least the generated synthetic handwritten images. The training images mimicking the handwritten text including the non-alphanumeric characters are generated using the trained handwritten text image-generating machine learning model.
Systems and methods for event threat prioritization are provided. In some embodiments, an event priority engine receives event data detected by event agents executing on devices. The events are prioritized and ranked according to threat scores for events generated according to threat indicators which are fed event data and threat data. In some embodiments, security systems may take the approach of prioritizing events based on the endpoints from which they originate using attributes associated with those endpoints. In this way, events can be prioritized at least in part based on the damage to the enterprise that may occur if those events were to compromise security, not just the likelihood of those events actually resulting in a security breach.
G06F 21/57 - Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
G06F 21/62 - Protecting access to data via a platform, e.g. using keys or access control rules
A computer-implemented method for parallel downloading of content includes connecting to a server through which a content is available, starting to download the content from the server to a client computer, determining whether to split the downloading of the content based on a set of factors, the set of factors comprising a network latency metric and a remaining download time to download a remaining amount of the content and based on a determination to split the downloading of the content, and in parallel to downloading a first part of the content from the server to the client computer, connecting to the server and downloading an additional part of the content from the server to the client computer.
H04L 67/61 - Scheduling or organising the servicing of application requests, e.g. requests for application data transmissions using the analysis and optimisation of the required network resources taking into account QoS or priority requirements
Examples of the present disclosure describe systems and methods of automatic inline detection based on static data. In aspects, a file being received by a recipient device may be analyzed using an inline parser. The inline parser may identify sections of the file and feature vectors may be created for the identified sections. The feature vectors may be used to calculate a score corresponding to the malicious status of the file as the information is being analyzed. If a score is determined to exceed a predetermined threshold, the file download process may be terminated. In aspects, the received files, file fragments, feature vectors and/or additional data may be collected and analyzed to build a probabilistic model used to identify potentially malicious files.
Document analysis systems and methods for the generation of a content-by-example log that expresses withheld documents in terms of a set of disclosed documents are disclosed. Additionally, document analysis systems and methods for the analysis of such a content-by-example log to determine withheld documents of interest without access to those withheld documents are disclosed.
Systems and methods for text localization are provided. Various embodiments of the present technology provide systems and methods for improved text localization algorithms that will help in enhancing the efficiency of text identification algorithms used for recognizing text in scanned documents prior to performing OCR, or other related applications. In some embodiments, regions of interest are identified on an image document indicating locations on the image document where text may be present. Individual words in the image document are identified based on space identification and region of interest clustering algorithms applied to the regions of interest in the image document.
Systems and methods are provided for more natural human-machine interactions. Artificial intelligence (AI) fails to consider the context of one question that is provided by a previous question. By preserving metadata (e.g., entities, intents, and topics and/or the question itself) for a particular question for use in a second question, which the user may not be aware of, an AI system, can more accurately select a relevant response. If the user changes the topic, a topic detection services will detect the change and exclude the metadata, which is now irrelevant, from influencing the response to the current question.
Disclosed is an anti-fraud message inspection solution that can provide an additional level of protection after incoming messages have been examined, at ingress, by enterprise protection mechanisms (e.g., firewalls, routers, gateways, etc. with virus scanning software) and before the messages arrive in application processing queues. The anti-fraud message inspection solution includes a message inspector downstream from the enterprise protection mechanisms. The message inspector receives an email that has passed a filtering mechanism at ingress, performs a plurality of checks on the email utilizing local database files, and places the email in a suspect queue or an application processing queue depending upon whether the email fails any of the plurality of checks or passes all the plurality of checks.
A document process automation system includes a user interface for uploading a document and invoking an artificial intelligence (AI) content assistant. When invoked, a chat window for the AI content assistant is displayed. The AI content assistant leverages a chat service to enable querying a status of the document through the chat window. The system further includes a document enrichment module, an inbound application programming interface (API), and a document API. The document enrichment module determines a category of the document and attaches attributes associated with the category to the document. The inbound API reads the document and creates a copy of the document for a document management system. The document API reads status updates to the copy of the document from a document queue and updates the attributes associated with the document. The user interface is configured for presenting the attributes thus updated as properties of the document.
Many documents, whether hardcopy or softcopy, require authentication for a particular use. Documents are often copied but knowing whether the contents of a document, even a copy of the document, have been altered can still be critical to the particular use. In one embodiment, a document's content is encoded with a symbolic representation, such as one or more Quick Response (QR) codes, derived from the document's content. Subsequent scanning of the document retrieves the document's content and the symbolic representation. The retrieved document's contents are then used to generate a symbolic representation of the content and compared to the content encoded in the symbolic representation. If the two match, the document has not been altered.
G06F 21/30 - Authentication, i.e. establishing the identity or authorisation of security principals
G06K 19/06 - Record carriers for use with machines and with at least a part designed to carry digital markings characterised by the kind of the digital marking, e.g. shape, nature, code
Many documents, whether hardcopy or softcopy, require authentication for a particular use. Documents are often copied but knowing whether the contents of a document, even a copy of the document, have been altered can still be critical to the particular use. In one embodiment, a document's content is encoded with a symbolic representation, such as one or more Quick Response (QR) codes, derived from the document's content. Subsequent scanning of the document retrieves the document's content and the symbolic representation. The retrieved document's contents are then used to generate a symbolic representation of the content and compared to the content encoded in the symbolic representation. If the two match, the document has not been altered.
H04L 9/32 - Arrangements for secret or secure communicationsNetwork security protocols including means for verifying the identity or authority of a user of the system
G06K 7/14 - Methods or arrangements for sensing record carriers by electromagnetic radiation, e.g. optical sensingMethods or arrangements for sensing record carriers by corpuscular radiation using light without selection of wavelength, e.g. sensing reflected white light
G06K 19/06 - Record carriers for use with machines and with at least a part designed to carry digital markings characterised by the kind of the digital marking, e.g. shape, nature, code
44.
SYSTEM AND METHODS FOR DETECTING ALTERED DOCUMENTS
Systems and methods are provided to validate an image. The image is segmented into a plurality of blocks and scrambled. A hash of the original image and scrambled image is then provided with a hash of the algorithms used (e.g., the segmenting algorithm, the scrambling algorithm, and/or the hashing algorithm). The foregoing hashes may be provided as a single, merged hash, and optionally as a quick response (QR) code. A recipient may then validate the image with a provided hash, which may comprise a merged hash that is separated into its constituent hashes. If the hashes match, the image is determined to be unaltered.
H04L 9/32 - Arrangements for secret or secure communicationsNetwork security protocols including means for verifying the identity or authority of a user of the system
Systems, methods and products for uploading scanned documents for collaboration. A user chooses, prior to uploading a document, whether the user wishes for the document to be converted to a text-searchable PDF and/or processed to recognize objects in the image. When the document is scanned, it is uploaded to the cloud based system with the user-selected options, and the PDF/image is processed. The upload may be a multipart, parallel upload to increase the speed of the upload. When the PDF/image is received at the cloud based system, it is processed according to the user-selected options to generate metadata (text or recognized objects) which is stored with the uploaded document. The PDF/image and metadata are shared with users who can then search the metadata for the PDF/image.
H04L 67/1097 - Protocols in which an application is distributed across nodes in the network for distributed storage of data in networks, e.g. transport arrangements for network file system [NFS], storage area networks [SAN] or network attached storage [NAS]
Systems, methods, and computer program products for adaptively splitting electronic chats are provided. One embodiment includes receiving an electronic chat comprising a set of electronic chat messages, each of the electronic chat messages in the set of electronic chat messages having a timestamp; determining a set of time gaps between the electronic chat messages from the set of electronic chat messages; determining a set of models that model the set of time gaps, selecting an optimum model from the set of models; based on selecting the single Gaussian distribution as the optimum model, determining that the electronic chat comprises a single electronic chat, and storing the set of electronic chat messages as the single electronic chat.
H04L 51/216 - Handling conversation history, e.g. grouping of messages in sessions or threads
H04L 12/18 - Arrangements for providing special services to substations for broadcast or conference
H04L 51/00 - User-to-user messaging in packet-switching networks, transmitted according to store-and-forward or real-time protocols, e.g. e-mail
H04L 51/04 - Real-time or near real-time messaging, e.g. instant messaging [IM]
H04L 51/07 - User-to-user messaging in packet-switching networks, transmitted according to store-and-forward or real-time protocols, e.g. e-mail characterised by the inclusion of specific contents
Examples of the present disclosure describe systems and methods for identifying anomalous network behavior. In aspects, a network event may be observed network sensors. One or more characteristics may be extracted from the network event and used to construct an evidence vector. The evidence vector may be compared to a mapping of previously-identified events and/or event characteristics. The mapping may be represented as one or more clusters of expected behaviors and anomalous behaviors. The mapping may be modeled using analytic models for direction detection and magnitude detection. One or more centroids may be identified for each of the clusters. A “best fit” may be determined and scored for each of the analytic models. The scores may be fused into single binocular score and used to determine whether the evidence vector is likely to represent an anomaly.
Systems, methods and products for intelligent delivery of communications, where a machine learning engine is trained to identify an output channel for delivery of a communication based on received context information and intended recipient information and to route the communication to the selected channel. An intelligent delivery task in a communication flow model is performed by the machine learning engine, which receives customer/recipient data such as age, region, gender, etc., and context data such as communication type, time of day, working hours, etc., and uses this data to determine which of a set of different channels is likely to be most effecting for sending the communication to the recipient. A user therefore does not have to build a complex static communication flow, but simply adds an intelligent delivery task to the flow. The output channel is dynamically selected and may vary for different recipients and communications.
ENTERPRISE CONTENT MANAGEMENT WITH CONTEXTUAL FUNCTIONALITY INCLUDING INTEGRATION WITH AUTOMOTIVE MEDIA SYSTEMS AND ASSOCIATED CONTEXTUAL FUNCTIONALITY
Embodiments of systems and methods for Enterprise Content Management (ECM) systems including ECM mobile applications that can tailor offered functionality based on an operating context of the ECM mobile application are disclosed. In particular, embodiments as disclosed may tailor workflow functionality offered by an ECM mobile application based on the operation of that ECM mobile application in an automotive media environment where the ECM application is connected to a car infotainment system using an automotive media interface.
The present disclosure describes systems and methods for detection and mitigation of malicious encryption. A security agent on an infected computing device may monitor data writes to disk, memory, or network transmission buffers for strings that may represent encryption keys or moduli. The security agent may apply one or more techniques to decode and parse the string to either identify or extract the keys, or rule out the string as containing an encryption key or modulus. If a key is identified, or its presence cannot be excluded, then the security agent may generate an alert and take mitigation actions.
Systems and methods for the design, deployment and utilization of targeted multimedia communications based upon audiences are disclosed. More specifically, embodiments may allow the targeting of communications to users in multiple media formats from the same multimedia communication templates and the delivery of such communications to users through multiple communication channels.
Embodiments of systems and methods for the centralized configuration of distributed heterogeneous services are disclosed herein. Embodiments of such systems and methods may be utilized to configure one or more service instances executing in an enterprise computing environment where each of the set of service instance is one of a set of service types that may be different. These services may, for example, be off-cloud services associated with a cloud based computing platform.
Embodiments of systems and methods for integration of services into the provisioning of functionality for desktop applications on desktop computing devices using an embedded web browser at the desktop computing device adapted to access web pages incorporating libraries adapted for use with such services are disclosed.
Systems, methods, and computer program products for adaptively splitting electronic chats are provided. One embodiment includes receiving, by an electronic discovery system, an electronic chat comprising a set of electronic chat messages, each of the electronic chat messages in the set of electronic chat messages having a timestamp; determining a set of time gaps between the electronic chat messages from the set of electronic chat messages, based on selecting a Gaussian mixture model as a model of the time gaps, splitting the set of electronic chat message into a set of conversations based on the Gaussian mixture model; performing a text analysis on the set of conversations based on a chat subject matter identified in the set of electronic chat messages; and splitting the set of conversations based on the chat subject matter.
G06F 18/2415 - Classification techniques relating to the classification model, e.g. parametric or non-parametric approaches based on parametric or probabilistic models, e.g. based on likelihood ratio or false acceptance rate versus a false rejection rate
According to one aspect of the present disclosure, the voice message analysis system receives a voice message from a voicemail system, performs a voice-to-text transcription, and applies a set of rules to the transcription of the voice message. The actions have associated data that is used when implementing the action. The rules specify criteria for triggering various actions that map to functions of the voicemail system or other functions. The actions have associated data that is used in implementing the actions. A voice message analysis system applies the voice message analysis rules to the transcript of the voice message. Based on a determination that the voice message matches a voice message analysis rule, the voice message system implements the appropriate action, such as by programmatically calling the appropriate function of the voicemail system and providing data for the function based on the data associated with the first action.
The present disclosure pertains to systems and methods for redacting and converting spreadsheet documents within eDiscovery applications. It specifically addresses the challenge of partial cell redaction in spreadsheets and securely embeds these redactions into converted PDF files. A method includes identifying sensitive information, applying redactions using delimiters and regular expressions, and converting the spreadsheet document into an output format, the output format incorporating the redaction in such a way that the redaction is non-reversible. This ensures the permanency of redactions, providing a secure method for handling confidential information in legal proceedings.
Embodiments of systems and methods for DNS leak prevention and protection are disclosed herein. In particular, certain embodiments include a local DNS protection agent installed on a system and an associated trusted external DNS protection server. The DNS protection agent prevents DNS leaks from applications on the system such that all DNS requests from the system are confined to requests from the DNS protection agent to the associated DNS protection server. As the DNS leak prevention provided by the DNS protection agent stops applications on the system from circumventing the DNS protection server, all DNS requests originating from the system remain under the control of the DNS protection server and thus desired DNS protection (e.g., as implemented on the DNS protection server) may be maintained. Certain embodiments prevent applications from using certain DNS security protocols, such as DoH and DoT, without going through the DNS protection agent.
H04L 61/4511 - Network directoriesName-to-address mapping using standardised directoriesNetwork directoriesName-to-address mapping using standardised directory access protocols using domain name system [DNS]
H04L 67/60 - Scheduling or organising the servicing of application requests, e.g. requests for application data transmissions using the analysis and optimisation of the required network resources
58.
Integrated System for Multimodal Media Review and Selective Content Redaction
An integrated system for efficiently managing and reviewing multimodal media content in legal and document review contexts is presented. This system introduces synchronized, four-dimensional interface components that streamline the review of audio and video content. Features include the normalization and compression of media files for optimized playback, conversion of audio into searchable text, and a synchronized timeline view with audio waveforms and video thumbnails for precise navigation. Additionally, the system offers redaction capabilities, allowing for the selective removal of sensitive information from media content without compromising file integrity. The system offers a comprehensive solution for analyzing and managing multimedia content within eDiscovery tools.
An endpoint agent is enhanced with a kernel-level event tracing facility, an event manager having telemetry filters, a persistence manager, and a detection engine. The endpoint agent receives an instruction from a controller system to enable a selection of filters, including a custom-built telemetry filter for the kernel-level event tracing facility which feeds events to the event manager as they are occurring. The event manager determines which enabled telemetry filters are applicable to the events, apply them to identify events of interest, and provide those events to the detection engine which, in turn, applies detection filters to the events of interest to detect possible threats to the endpoint. The telemetry filters are evaluated in memory as the events are occurring. To increase the speed of processing, expression trees representing the telemetry filters can be compiled into machine code just in time of execution. The machine code executes extremely fast natively.
Systems and methods are provided for a device to obtain a query, such as from a user. The query is vectorized to obtain a numerical representation of the query and provided to a vector database to find the nearest vectors corresponding to most relevant context, such as for a particular domain or subject matter. The query, query vector, and context vectors, and optionally past query history and past query responses, are provided to an artificial intelligence, such as a large language model (LLM), to receive a response to the query without providing the context to the LLM.
A data processing system for artificial intelligence-based setting of controls in an evaluation interface comprising a data store storing: a plurality of transactions; a plurality of completed evaluations, each completed evaluation including an indication of a transcript portion associated with an evaluation answer. The system determines a word or phrase common to a first set of transcript portions associated with the evaluation answer; creates a first set of auto answer parameters that includes the word or phrase; auto answers the question for a set of test transactions to generate an auto answer for each test transaction; and based on a determination that the first set of auto answer parameters auto answered the question with a threshold level of accuracy, configures an evaluation system to use the first set of auto answer parameters to preset an answer control in an evaluation operator interface.
A computer-implemented method for content search, comprising accessing an image stored or to be stored in a repository that is searchable using a search index, applying a machine learning model to detect objects and actions in the image and updating the search index to index the image using the objects and actions detected in the image to enable searching of the image by the objects and actions detected in the image.
G06F 16/583 - Retrieval characterised by using metadata, e.g. metadata not derived from the content or metadata generated manually using metadata automatically derived from the content
G06V 10/774 - Generating sets of training patternsBootstrap methods, e.g. bagging or boosting
A firewall monitors network activity and stores information about that network activity in a network activity log. The network activity is analyzed to identify a potential threat. The potential threat is further analyzed to identify other potential threats that are related to the potential threat, and are likely to pose a future risk to a protected network. A block list is updated to include the potential threat and the other potential threats to protect the protected network from the potential threat and the other potential threats.
One embodiment comprises a system for artificial intelligence-based evaluation of an agent interaction. The system is operable to generate a transcript of the voice session recording of the call and parse the evaluation form to identify the evaluation question for an intended call participant interaction. The system is further operable to determine, using the machine learning model, that the intended call participant interaction of the evaluation question is present in the transcript. When the intended call participant interaction is present in the transcript, the system records a first answer for to the evaluation question corresponding to the voice session recording, the first answer indicating a presence of the intended call participant interaction in the voice session recording, and automatically sets the answer control in the visual display to indicate the presence of the intended call participant interaction in the voice session recording.
Embodiments of the present disclosure provides systems and methods for automatically recommending layout information for templates and template elements during template design/editing. A computer-implemented method includes receiving, based on a user interaction with the graphical user interface, a request to add a template element to a template, determining a recommended layout for the template element based on a document event dataset and a layout information dataset, presenting the recommended layout for the template element in the graphical user interface as a first recommendation; adding the template element to the template formatted according to the recommended layout for the template element and storing the new template in a database of templates used to electronically generate documents. The document event dataset comprises data for user action events on electronic documents generated from template and the layout information dataset comprises layout information from the template.
G06F 3/0484 - Interaction techniques based on graphical user interfaces [GUI] for the control of specific functions or operations, e.g. selecting or manipulating an object, an image or a displayed text element, setting a parameter value or selecting a range
G06F 40/106 - Display of layout of documentsPreviewing
66.
SYSTEMS AND METHODS FOR INTELLIGENT DELIVERY OF COMMUNICATIONS
Systems, methods and products for intelligent delivery of communications, where a machine learning engine is trained to identify an output channel for delivery of a communication based on received context information and intended recipient information and to route the communication to the selected channel. An intelligent delivery task in a communication flow model is performed by the machine learning engine, which receives customer/recipient data such as age, region, gender, etc., and context data such as communication type, time of day, working hours, etc., and uses this data to determine which of a set of different channels is likely to be most effecting for sending the communication to the recipient. A user therefore does not have to build a complex static communication flow, but simply adds an intelligent delivery task to the flow. The output channel is dynamically selected and may vary for different recipients and communications.
Methods, devices and computer program products facilitate the storage, access and management of log files that are associated with particular client devices. The log files provide a record of user or client device activities that are periodically sent to a data backup center. A dedicated log file server facilitates the processing and storage of an increasingly large number of log files that are generated by new and existing client devices. A storage server pre-processes the received log files to facilitate the processing and storage of the log files by the log file server. This Abstract is provided for the sole purpose of complying with the Abstract requirement rules. This Abstract is submitted with the explicit understanding that it will not be used to interpret or to limit the scope or the meaning of the claims.
G06F 3/06 - Digital input from, or digital output to, record carriers
G06F 11/14 - Error detection or correction of the data by redundancy in operation, e.g. by using different operation sequences leading to the same result
G06F 11/34 - Recording or statistical evaluation of computer activity, e.g. of down time, of input/output operation
G06F 16/17 - Details of further file system functions
G06F 16/174 - Redundancy elimination performed by the file system
A computer system comprising a processor and a memory storing instructions that, when executed by the processor, cause the computer system to perform a set of operations. The set of operations comprises collecting domain attribute data comprising one or more domain attribute features for a domain, collecting sampled domain profile data comprising one or more domain profile features for the domain and generating, using the domain attribute data and the sampled domain profile data, a domain reputation assignment utilizing a neural network.
A text mining engine running on an artificial platform is trained to perform conversation role identification, semantic analysis, summarization, language detection, etc. The text mining engine analyzes words in a transcript that represent unique characteristics of a conversation and, based on the unique characteristics and utilizing classification predictive modeling, determines a conversation role for each participant of the conversation and metadata describing the conversation such as tonality of words spoken by a participant in a particular conversation role. Outputs from the text mining engine are indexed and useful for various purposes. For instance, because the system can identify which speaker in a customer service call is likely an agent and which speaker is likely a customer, words spoken by the agent can be analyzed for compliance reasons, training agents, providing quality assurance for improving customer service, providing feedback to improve the performance of the text mining engine, etc.
Embodiments disclosed herein relate to systems and methods for providing a smart cache. In embodiments, a variable time to live (TTL) may be calculated and associated with data as it is stored in a cache. The variable TTL may be calculated based upon reputation and/or category information related to the source of the data. The reputation and/or category information may include TTL modifiers for adjusting the TTL for data from a particular data source that is stored in the cache. In further embodiments, a feedback method may be employed to update reputation and/or category information for a particular data source.
H04L 67/5682 - Policies or rules for updating, deleting or replacing the stored data
G06F 12/0802 - Addressing of a memory level in which the access to the desired data or data block requires associative addressing means, e.g. caches
G06F 12/0864 - Addressing of a memory level in which the access to the desired data or data block requires associative addressing means, e.g. caches using pseudo-associative means, e.g. set-associative or hashing
G06F 12/0875 - Addressing of a memory level in which the access to the desired data or data block requires associative addressing means, e.g. caches with dedicated cache, e.g. instruction or stack
G06F 12/128 - Replacement control using replacement algorithms adapted to multidimensional cache systems, e.g. set-associative, multicache, multiset or multilevel
G06F 16/957 - Browsing optimisation, e.g. caching or content distillation
Systems and methods are provided for a device to obtain a query, such as from a user. The query is vectorized to obtain a numerical representation of the query and provided to a vector database to find the nearest vectors corresponding to most relevant context, such as for a particular domain or subject matter. The query, query vector, and context vectors, and optionally past query history and past query responses, are provided to an artificial intelligence, such as a large language model (LLM), to receive a response to the query without providing the context to the LLM.
Methods and systems for determining, presenting and analyzing API usage of an application are disclosed herein. Embodiments of an API monitor as presented herein may serve to provide tightly coupled insight into API usage by an application to ascertain and provide knowledge and visibility into API usage by an application associated with the API monitor, including API calls made by both a frontend and a backend of an application.
A protection module operates to analyze threats, at the protocol level (e.g., at the HTML level), by intercepting all requests that a browser engine resident in a computing device sends and receives, and the protection agent completes the requests without the help of the browser engine. And then the protection module analyzes and/or modifies the completed data before the browser engine has access to it, to, for example, display it. After performing all of its processing, removing, and/or adding any code as needed, the protection module provides the HTML content to the browser engine, and the browser engine receives responses from the protection agent as if it was speaking to an actual web server, when in fact, browser engine is speaking to an analysis engine of the protection module.
Electronic discovery using predictive filtering is disclosed herein. An example method includes receiving a plurality of documents. A selection of a filter value is received, where the filter value comprises a field value or a set of field values for the plurality of documents. A prediction of responsive phrases, responsive concepts, or other meta-data is generated. The plurality of documents is evaluated based on a new filter value. Then, a prediction of other responsive phrases or other responsive concepts is generated. A predictive value is generated. Filter criteria is generated based on the predictive value for each of the other responsive phrases, the other predicted responsive concepts, or other predictive meta-data. A selection is then received of the filter criteria. A filter is built and applied based on the selection, and documents are generated from at least a sub-portion of the received plurality of documents.
Systems, methods and products for synchronization of content and metadata where the content and metadata are shared from a source repository to a target repository. One embodiment of a repository connector system utilizes a monolithic robotic server for scheduled synchronization and a second monolithic manual server for processing manual synchronization requests. A metadata server in the connector system enables sharing and synchronization of mapped metadata between content objects in the source and target repositories. A notification server is provided in the connector system to track notifications of changes to shared content in the target repository, and to replicate these notifications in a local database that is accessible by the synchronization servers to identify changes to the content in the second repository. Each of the servers is coupled to a service registry in the connector system to enable discovery and interaction between the connector system components.
Systems, methods and products for enabling parallelized verification of a forensic copy generated using a non-parallelizable hashing algorithm. Disclosed embodiments generate the forensic copy of a data source using a non-parallelizable algorithm. In addition to generating a hash of the source data, intermediate hash states are stored for successive blocks of data from the data source. During verification of the forensic copy, the intermediate hash states and identifiers of the data blocks are retrieved from a data structure that is saved with the forensic copy. The non-parallelizable algorithm is used to hash each data block using the intermediate hash state preceding the data block as a starting hash state, then the hash of the data block is compared to the intermediate hash state following the data block to verify the data block. If all data blocks are successfully verified, the forensic copy is verified, otherwise verification fails.
H04L 9/06 - Arrangements for secret or secure communicationsNetwork security protocols the encryption apparatus using shift registers or memories for blockwise coding, e.g. D.E.S. systems
H04L 9/00 - Arrangements for secret or secure communicationsNetwork security protocols
77.
DEFINITION AND EXTENSION OF STORIES OF CORE ENTITIES AND CALCULATION OF RISK SCORES THEREOF
Core entities are each defined as a subset of base entities that satisfy one or more core entity connection relationships. Base stories are each defined as a subset of core entities that satisfy one or more story connection relationships. A risk score of each core entity is calculated based on previously calculated risk scores of the base entities. A risk score of each base story is calculated based on the calculated risk score of each core entity of the base story. Selected base stories are extended with external content to generate corresponding extended stories.
G06F 21/57 - Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
78.
SYSTEM AND METHOD FOR EVENT DRIVEN GENERATION OF CONTENT
Systems and methods for content management that allow external events or data to drive the generation of content are disclosed. Specifically, disclosed embodiments allow events generated from external sources (or data determined from those events, or otherwise determined) to drive the generation of content (or metadata associated with that content) in a content management system.
Examples of the present disclosure describe systems and methods for discrete processor feature behavior collection and analysis. In aspects, a monitoring utility may initialize a set of debugging and/or performance monitoring feature sets for a microprocessor. When the microprocessor receives from software content a set of instructions that involves the loading of a set of modules or code segments, the set of modules or code segments may be evaluated by the monitoring utility. The monitoring utility may generate a process trace of the loaded set of modules or code segments. Based on the process trace output, various execution paths may be reconstructed in real-time. The system and/or API calls made by the microprocessor may then be compared to the process trace output to quickly observe the interaction between the software content and the operating system of the microprocessor.
Embodiments of the present disclosure extract a layout from a digital image of a document, including performing an analysis of image data to identify areas of content based on a plurality of test lines of pixels in multiple directions and storing the identified areas as design elements of an electronic document template.
An endpoint protection system implementing a new blocking strategy allows a user to specify an arbitrary number of protection rules through a user interface. In user mode, the protection rules are compiled into a single expression tree, which is then compiled into byte code. In kernel mode, the byte code is dynamically loaded in memory (e.g., kernel space) and the assembler validates the byte code and performs a plurality of security checks, then ultimately assembles the byte code into machine code that is native to the processor. Because complex detection/protection logic is compiled in user mode, the invention allows for highly expressive and powerful protection rules. Further, because complex detection/protection logic is not manually written in kernel mode, but validated then evaluated via simple machine code instructions in the privileged mode, the invention is safer and will not slow down the entire operating system.
Examples of the present disclosure describe systems and methods for providing advanced file modification heuristics. In aspects, software content is selected for monitoring. The monitoring comprises determining when the software content performs file accesses that are followed by read and/or write operations. The read/write operations are analyzed in real-time to determine whether the software content is modifying file content. If the monitoring indicates the software content is modifying accessed files, mathematical calculations are applied to the read-write operations to determine the nature of the modifications. Based on the determined nature of the file modifications, the actions of the software content may be categorized and halted prior to completion; thereby, mitigating malicious cyberattacks and/or unauthorized accesses.
Examples of the present disclosure describe systems and methods of providing real-time scanning of IP addresses. In aspects, input may be received by a real-time IP scanning system. The system may generate one or more work orders based on the input. A scanner associated with the system may access a work order and attempt to communicate with one or more devices identified by the work order. If the attempted communication with a device is successful, a protocol analyzer may be used to provide a predefined payload to the device. If the response from the device matches an expected string, the device may be determined to be a safe and/or legitimate device. If the response from the device does not match an expected string, the device may be determined to be a malicious device.
G06F 21/57 - Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
Systems, methods, and computer program products for adaptively splitting electronic chats are provided. An e-discovery system comprises a computer processor and a non-transitory, computer-readable medium embodying thereon a set of computer instructions executable by the computer processor. The set of computer instructions includes instructions for: sending a chat query to a remote electronic chat service; receiving an electronic chat responsive to the chat query, the electronic chat embodying a set of electronic chat messages; adaptively splitting the set of electronic chat messages into a set of conversations, each conversation in the set of conversations comprising a subset of electronic chat messages from the set of electronic chat messages; and storing each conversation from the set of conversations as a separate document.
Systems, methods and products for uploading scanned documents for collaboration. A user chooses, prior to uploading a document, whether the user wishes for the document to be converted to a text-searchable PDF and/or processed to recognize objects in the image. When the document is scanned, it is uploaded to the cloud based system with the user-selected options, and the PDF/image is processed. The upload may be a multipart, parallel upload to increase the speed of the upload. When the PDF/image is received at the cloud based system, it is processed according to the user-selected options to generate metadata (text or recognized objects) which is stored with the uploaded document. The PDF/image and metadata are shared with users who can then search the metadata for the PDF/image.
H04L 67/1097 - Protocols in which an application is distributed across nodes in the network for distributed storage of data in networks, e.g. transport arrangements for network file system [NFS], storage area networks [SAN] or network attached storage [NAS]
86.
Systems and Methods for Document Analysis to Produce, Consume and Analyze Content-By-Example Logs for Documents
Document analysis systems and methods for the generation of a content-by-example log that expresses withheld documents in terms of a set of disclosed documents are disclosed. Additionally, document analysis systems and methods for the analysis of such a content-by-example log to determine withheld documents of interest without access to those withheld documents are disclosed.
Systems and methods for the design, deployment and utilization of targeted multimedia communications based upon audiences are disclosed. More specifically, embodiments may allow the targeting of communications to users in multiple media formats from the same multimedia communication templates and the delivery of such communications to users through multiple communication channels.
Systems and methods for the design, deployment and utilization of targeted multimedia communications based upon audiences are disclosed. More specifically, embodiments may allow the targeting of communications to users in multiple media formats from the same multimedia communication templates and the delivery of such communications to users through multiple communication channels.
H04N 21/45 - Management operations performed by the client for facilitating the reception of or the interaction with the content or administrating data related to the end-user or to the client device itself, e.g. learning user preferences for recommending movies or resolving scheduling conflicts
89.
Security Privilege Escalation Exploit Detection and Mitigation
Examples of the present disclosure describe systems and methods for monitoring the security privileges of a process. In aspects, when a process is created, the corresponding process security token and privilege information is detected and recorded. At subsequent “checkpoints,” the security token is evaluated to determine whether the security token has been replaced, or whether new or unexpected privileges have been granted to the created process. When a modification to the security token is determined, a warning or indication of the modification is generated and the process may be terminated to prevent the use of the modified security token.
H04L 9/32 - Arrangements for secret or secure communicationsNetwork security protocols including means for verifying the identity or authority of a user of the system
Examples of the present disclosure describe systems and methods for behavioral threat detection definition compilation. In an example, one or more sets of rule instructions may be packaged for distribution and/or use by a behavioral threat detection engine. As an example, a set of rule instructions is compiled into an intermediate language and assembled in to a compiled behavior rule binary. Event linking is performed, wherein other rules launched by the rule and/or events that launch the rule or are processed by the rule are identified, and such information may be stored accordingly. The behavior rule binary may be packaged with other rules associated with identifying a specific behavior. The packaged behavior rule is distributed to one or more computing devices for use with a behavioral threat detection engine. For example, the threat detection engine may execute the behavior rule using a rule virtual machine.
A system comprising a client computer, a data store comprising a content management repository, a server computer coupled to the client computer by a network, the server computer comprising code for: receiving audio data; converting the audio data to text; extracting a specified string from the text as an extracted string; determining an extracted string attribute for the extracted string; storing a media file containing the audio data as a content object; configuring the content object to be searchable by the extracted string; receiving a search query from the client application; searching a plurality of managed objects based on the search query; and based on determining that the extracted string matches a search string, returning an indication of the first media file, the extracted string and the extracted string attribute in a search result.
G06F 16/683 - Retrieval characterised by using metadata, e.g. metadata not derived from the content or metadata generated manually using metadata automatically derived from the content
92.
System and method for content management with intelligent data store access across distributed stores
A configuration object is provided to configure a server. The configuration object has an associated type to which the configuration object applies and information about a plurality of file stores available to the server. A method for data access can include, receiving, by the server, a request to perform a first operation with respect to a content object associated with the associated type to which the configuration object applies, using the configuration object to determine, from the plurality of file stores available to the server, a set of candidate file stores to service the request, and selecting a target file store from the set of candidate file stores and servicing the request using the target file store. Selecting the target file store includes mapping the object identifier to the target file store.
H04L 67/08 - Protocols specially adapted for terminal emulation, e.g. Telnet
H04L 67/1001 - Protocols in which an application is distributed across nodes in the network for accessing one among a plurality of replicated servers
H04L 67/1097 - Protocols in which an application is distributed across nodes in the network for distributed storage of data in networks, e.g. transport arrangements for network file system [NFS], storage area networks [SAN] or network attached storage [NAS]
H04L 67/568 - Storing data temporarily at an intermediate stage, e.g. caching
93.
SYSTEMS AND METHODS FOR IDENTITY AND ACCESS MANAGEMENT WITH EXTENDED TRUST
An identity and access management (IAM) extended trust server (ETS) can work with a cloud-based IAM platform to authorize a user in a home zone to access a resource such as an enterprise application in an enterprise computing network. The IAM ETS receives a request from the user to access another resource, determines that other resource resides in a geographical zone that is different from the home zone, checks with the cloud-based IAM platform on whether the user is authorized to access the resource in the geographical zone, and responsive to an indication from the cloud-based IAM platform that the user is authorized to access the resource in the geographical zone, redirects a browser on the user device to the resource in the geographical zone without initiating a new session for the user, thereby providing the user with seamless access across multiple zones in a single global session.
A system and method are provided for synchronizing read-only folders from a cloud-based server. Users can set permissions when sharing folders with other users. The permissions are enforced by client devices of the users downloading content of the folders from the server. A folder at a user's client from the shared domain may include locally modified content and shared content. Based on an indication of a change by a second user to the folder at the server, the user's client modifies a local folder. To prevent local changes made by the user from being overwritten, the user's client identifies the folder containing locally-modified content as a local content folder not to be synchronized between the plurality of clients.
Peer device protection enables a first device comprising a digital security agent to remedy security issues on (or associated with) a set of devices visible to the first device. In aspects, a first device comprising a digital security agent may identify a set of devices visible to the first device. The first device may monitor the set of devices to collect data, such as types of communications and data points of interest. The digital security agent may apply threat detection to the collected data to identify anomalous network behavior. When anomalous network behavior is detected, the first device may cause an indicator of compromise (IOC) to be generated. Based on the IOC, the first device may facilitate remediation of the anomalous network behavior and/or apply security to one or more devices in the set of devices.
A new declarative approach to business intelligence (BI) and reporting focuses on streamlining the embeddability of BI and reporting (BIR) into an application (e.g., web, mobile, etc.) and allows a developer to use a REST API and declare, via a YAML file, the type of BIR dashboard, report, metric or set of metrics desired. A YAML descriptor interpreter interprets the YAML file, collaborates with a BIR server at the backend to dynamically construct the requested content, and repackages and returns the requested content in a REST API response. This new method allows application developers to avoid any need of pre-designing reports, dashboards, etc., and eliminates the need of application developers to embed client-side scripting libraries, significantly reduces the amount of effort, time, and complexity in using a BI and reporting service. Application developers simply declare what they need, and the service returns the content exactly as described in the request.
A computer-implemented method for parallel downloading of content includes connecting to a server through which a content is available, starting to download the content from the server to a client computer, determining whether to split the downloading of the content based on a set of factors, the set of factors comprising a network latency metric and a remaining download time to download a remaining amount of the content and based on a determination to split the downloading of the content, and in parallel to downloading a first part of the content from the server to the client computer, connecting to the server and downloading an additional part of the content from the server to the client computer.
H04L 67/61 - Scheduling or organising the servicing of application requests, e.g. requests for application data transmissions using the analysis and optimisation of the required network resources taking into account QoS or priority requirements
Systems, methods and products for providing a dynamic bookmarks list feature. In one embodiment, a user provides a name and an endpoint to a module that creates a dynamic bookmark in a web browser. When the dynamic bookmark is accessed, an API call is made to the endpoint. The endpoint recognizes a query parameter in the API call and retrieves a list of bookmarks and/or folders of bookmarks and returns them to the browser. The browser presents the bookmarks and/or folders to the user in a list in the same manner as individual, manually created bookmarks are presented. The user then accesses any of the listed bookmarks in the same manner as a conventional, manually created bookmark. The contents of listed folders may not be retrieved until the folder is accessed. These contents are retrieved in the same way the listed bookmarks and folders were retrieved.
A reusable converter framework provides a set of tools for (1) loading existing data formats and transformation instructions of a source technology and (2) enabling the result of step (1) to be queried through Java code and analyzed. The source technology may follow a particular data transformation strategy such as data-drive, script-driven, or query driven. The reusable converter framework has a Java representation, referred to herein as an interpreted form, that can hold the information of a target technology, which follows a different data transformation strategy. The source and target technologies operate on different computing platforms having different computing environments. The interpreted form is utilized in step (3) to streamline and optimize the information from step (2) and produce a working data map suitable for the target technology.
Examples of the present disclosure describe systems and methods for behavioral threat detection definition. In an example, a behavior rule comprising a set of rule instructions is used to define one or more events indicative of a behavior. For example, a set of events from which one event must be matched may be defined or a set of events from which all events must be matched may be defined. In some examples, events are matched based on an event name or type, or may be matched based on one or more parameters. Exact and/or inexact matching may be used. The set of rule instructions ultimately specifies one or more halt instructions, thereby indicating that a determination as to the presence of the behavior has been made. Example determinations include, but are not limited to, a match determination, a non-match determination, or an indication that additional monitoring should be performed.