Systems, apparatus, articles of manufacture, and methods to self-guardrail large language model responses are disclosed. An example apparatus includes interface circuitry, instructions, and programmable circuitry to at least one of execute or instantiate the instructions to access a first response message provided by a first large language model, the first response message generated based on an initial prompt, cause a second large language model to determine the first response message is inappropriate, modify the initial prompt to create a modified prompt, and provide the modified prompt to the first large language model to trigger generation of a second response message.
Systems, apparatus, articles of manufacture, and methods are disclosed to improve the efficiency of an artificial intelligence-based threat detection model. An example apparatus includes interface circuitry, machine readable instructions, and programmable circuitry to at least one of instantiate or execute the machine readable instructions to: obtain an email address from a group of email addresses to be considered as candidates for adding to the list of non-suspicious email addresses, determine that a domain of the email address is indicative of a non-email service providing entity, determine that the email address has a policy configured for a domain-based message authentication, reporting, and conformance (DMARC) record, add the email address associated to the list of non-suspicious email addresses, and cause the artificial intelligence-based threat detection model to skip an analysis of an email associated with the email address.
H04L 41/16 - Dispositions pour la maintenance, l’administration ou la gestion des réseaux de commutation de données, p. ex. des réseaux de commutation de paquets en utilisant l'apprentissage automatique ou l'intelligence artificielle
3.
METHODS AND APPARATUS FOR VOICE TRANSFORMATION, AUTHENTICATION, AND METADATA COMMUNICATION
Methods and apparatus for voice transformation, authentication, and metadata communication are disclosed. An example apparatus includes interface circuitry, machine readable instructions, and programmable circuitry to identify least significant bits of the voice signal, and embed metadata in the identified least significant bits of the voice signal to produce an embedded voice signal.
G10L 17/02 - Opérations de prétraitement, p. ex. sélection de segmentReprésentation ou modélisation de motifs, p. ex. fondée sur l’analyse linéaire discriminante [LDA] ou les composantes principalesSélection ou extraction des caractéristiques
G10L 17/06 - Techniques de prise de décisionStratégies d’alignement de motifs
G10L 21/007 - Changement de la qualité de la voix, p. ex. de la hauteur tonale ou des formants caractérisé par le procédé utilisé
4.
LARGE LANGUAGE MODEL-ASSISTED FRAUDULENT CALL DETECTION
There is disclosed a system and method for detecting fraudulent intent in a telephonic voice call on a user device. The method includes providing, to a large language model (LLM), a transcript of a portion of an ongoing call between a user and a second party; receiving, from the LLM, respective parameter scores for a plurality of indicia of fraud associated with the transcript of the call; computing a weighted fraud score for the ongoing call via a device-local detector of the user device; and if the weighted fraud score exceeds a threshold, warning the user.
Methods, apparatus, systems, and articles of manufacture are disclosed. An example apparatus includes at least one memory, instructions; and processor circuitry to execute the instructions to train a neural network with a plurality of raw byte data samples, perform feature extraction on ones of the plurality of raw byte data samples, determine whether ones of the plurality of raw byte data samples are clean or malicious using the extracted features, and determine a family of malware to which an identified malicious sample belongs.
A computer-implemented system, method, and apparatus for warning a user of fraudulent call phases may include communicating with a backend analysis engine, wherein the backend analysis engine is to provide a periodically-updated assessment of a voice call, the assessment comprising an inferred call phase and a fraudulence score; and providing a graphical user interface (GUI) visible to a participant of the voice call, wherein the GUI is to display the inferred call phase and a visual fraud indicator based on a likelihood that the voice call is fraudulent.
Methods, apparatus, systems, and articles of manufacture are disclosed to improve offloading of malware scans. An example apparatus is to, based on a trigger to perform a scan of a volume of data, estimate a computational burden associated with performing the scan using the CPU, the volume of data representative of at least one of a file or an object. Additionally, the example apparatus is to determine whether the computational burden satisfies a threshold associated with offloading the scan to the GPU. The example apparatus is also to cause at least one of the CPU or the GPU to perform the scan based on whether the computational burden satisfies the threshold.
Sample classification using natural language processing (NLP) models is disclosed herein. An example apparatus comprises interface circuitry, machine readable instructions, and programmable circuitry to at least one of instantiate or execute the machine readable instructions to access a set of instructions, the set of instructions representing executable instructions, determine an Application Programming Interface (API) call sequence based on the set of instructions, transmit the API call sequence to a NLP model, the NLP model to generate a set of tokens, the set of tokens representing the API call sequence, the set of tokens readable in the NLP model, and classify the API call sequence as clean or malicious based on the tokens, and classify the set of instructions as clean or malicious based on the classification of the API call sequence and at least one other feature of the set of instructions.
G06F 40/284 - Analyse lexicale, p. ex. segmentation en unités ou cooccurrence
G06F 21/53 - Contrôle des utilisateurs, des programmes ou des dispositifs de préservation de l’intégrité des plates-formes, p. ex. des processeurs, des micrologiciels ou des systèmes d’exploitation au stade de l’exécution du programme, p. ex. intégrité de la pile, débordement de tampon ou prévention d'effacement involontaire de données par exécution dans un environnement restreint, p. ex. "boîte à sable" ou machine virtuelle sécurisée
G06F 21/56 - Détection ou gestion de programmes malveillants, p. ex. dispositions anti-virus
An example apparatus includes interface circuitry to obtain data; samples to train an AI-based model; machine readable instructions; and at least one programmable circuit to at least one of instantiate or execute the machine readable instructions to: transform the data samples into features; generate hash signatures for corresponding ones of the features; group the features into clusters based on the hash signatures; generate a filtered data set by filtering out features within a cluster of features having more than a threshold number of features; and train the AI-based model based on the filtered data set.
Systems, apparatus, articles of manufacture, and methods are disclosed to improve the efficiency of an artificial intelligence-based threat detection model. An example apparatus includes interface circuitry, machine readable instructions, and programmable circuitry to at least one of instantiate or execute the machine readable instructions to: obtain an email address from a group of email addresses to be considered as candidates for adding to the list of non-suspicious email addresses, determine that a domain of the email address is indicative of a non-email service providing entity, determine that the email address has a policy configured for a domain-based message authentication, reporting, and conformance (DMARC) record, add the email address associated to the list of non-suspicious email addresses, and cause the artificial intelligence-based threat detection model to skip an analysis of an email associated with the email address.
H04L 41/16 - Dispositions pour la maintenance, l’administration ou la gestion des réseaux de commutation de données, p. ex. des réseaux de commutation de paquets en utilisant l'apprentissage automatique ou l'intelligence artificielle
11.
METHODS AND APPARATUS TO OPTIMIZE ARTIFICIAL INTELLIGENCE INFERENCE WORKLOADS ON AUDIO AND VIDEO DATA STREAMS
Systems, apparatus, articles of manufacture, and methods are disclosed to reduce a use of a compute engine executing dense layers in a model. An example apparatus includes obtain a first vector generated by an initial layer of the model, the first vector corresponding to a first data frame, wherein the initial layer of the model utilizes less computation resources than the dense layer is to utilize, measure a similarity between the first vector and a prior vector, wherein the prior vector has been classified by the model and corresponds to a second data frame occurring before the first data frame represented by the first vector, determine that the first vector satisfies a similarity threshold to the prior vector, and instruct the compute engine to enter an idle state, the idle state to suspend execution of the dense layers in the model.
Systems, apparatus, articles of manufacture, and methods are disclosed to classify data via tiered machine learning analysis. An example apparatus includes interface circuitry to access a latent space representation (LSR) of a first sample of a webpage, machine-readable instructions, and at least one processor circuit to be programmed by the machine-readable instructions. For example, the at least one processor circuit is to initiate a first artificial intelligence (AI) model to classify the webpage as benign or potentially malicious based on the LSR. Additionally, the at least one processor circuit is to, after the first AI model classifies the webpage as potentially malicious, initiate a second AI model to classify the webpage as benign or malicious based on a second sample of the webpage, the first AI model being less precise than the second AI model.
A system and method for detecting fraudulent call activity include segmenting an ongoing voice call between a user and a second party into discrete segments while the call is in progress. The method analyzes respective discrete segments and assigning per-segment weighted fraud scores, where each weighted fraud score accounts for the weighted fraud score of a previous segment. Based on these per-segment weighted fraud scores, the method determines that the voice call is likely a fraudulent call. After making this determination, the method provides a human-perceptible warning to the user before the user discloses sensitive user data.
H04M 3/22 - Dispositions de supervision, de contrôle ou de test
G10L 17/02 - Opérations de prétraitement, p. ex. sélection de segmentReprésentation ou modélisation de motifs, p. ex. fondée sur l’analyse linéaire discriminante [LDA] ou les composantes principalesSélection ou extraction des caractéristiques
G10L 17/26 - Reconnaissance de caractéristiques spéciales de voix, p. ex. pour utilisation dans les détecteurs de mensongeReconnaissance des voix d’animaux
G10L 25/63 - Techniques d'analyse de la parole ou de la voix qui ne se limitent pas à un seul des groupes spécialement adaptées pour un usage particulier pour comparaison ou différentiation pour estimer un état émotionnel
14.
METHODS AND APPARATUS TO ENABLE MESSAGE FILTERING NOTIFICATIONS
Systems, apparatus, articles of manufacture, and methods to enable message filtering notifications are disclosed. Example machine readable instructions cause at least one processor circuit to cause storage of a record of a domain name service request transmitted by a user device, the record of the domain name service request including device identifying information to enable identification of the user device, determine whether a message associated with a message filtering request is to be filtered, the message filtering request transmitted by the user device, provide an indication to the user device indicating whether the message is to be filtered, determine whether the message filtering request is temporally correlated with the record of the domain name service request, and cause transmission of a push notification to the user device based on the device identifying information recorded in connection with the domain name service request.
The present specification provides a system and method for determining that an endpoint device has connected to an untrusted external internet protocol (IP) network; and establishing a secure DNS connection from the endpoint device to a trusted DNS server via a proxy, wherein the proxy authenticates the trusted DNS server via a client identity certificate and a server certificate.
H04L 61/4511 - Répertoires de réseauCorrespondance nom-adresse en utilisant des répertoires normalisésRépertoires de réseauCorrespondance nom-adresse en utilisant des protocoles normalisés d'accès aux répertoires en utilisant le système de noms de domaine [DNS]
H04L 101/663 - Adresses de couche transport, p. ex. aspects des ports du protocole de contrôle de transmission [TCP] ou des ports du protocole de datagramme utilisateur [UDP]
16.
SYSTEM AND METHOD FOR ASSESSMENT OF PRIVACY EXPOSURE AND COMPUTING RISK INDEX FOR ONLINE SERVICE
A method includes receiving privacy information about an entity from a privacy resource; parsing the privacy information to identify a plurality of keywords; determining a plurality of attributes of a user requested by the entity, at least in part based on the plurality of keywords; and transmitting a result, at least in part based on the plurality of attributes.
There is disclosed a method of providing passive phishing remediation for an enterprise, including: displaying, to a user of a mobile device, an email; receiving from the user a one-click request to perform additional analysis of the email; providing the email to a phishing mitigation service; assigning the email a reputation score, generating a human-readable reputation display for the email, wherein the human-readable reputation display includes at least three grades comprising safe, unknown or unreliable, and unsafe or malicious; and providing the human-readable reputation display as a push notification to the mobile device.
A computer-implemented system and method for preventing fraudulent call activity includes detecting a plurality of voice calls from different phone numbers; converting audio content of the calls to text; clustering the calls based on similarity of the converted text and voice characteristics; assigning a shared fraud profile to the clustered calls; and using the shared fraud profile to classify future calls.
G10L 15/02 - Extraction de caractéristiques pour la reconnaissance de la paroleSélection d'unités de reconnaissance
G10L 15/26 - Systèmes de synthèse de texte à partir de la parole
G10L 25/63 - Techniques d'analyse de la parole ou de la voix qui ne se limitent pas à un seul des groupes spécialement adaptées pour un usage particulier pour comparaison ou différentiation pour estimer un état émotionnel
There is disclosed a computer-implemented system and method of analyzing a batch of objects, including bucketizing the batch of objects into a plurality of buckets according to a feature of the objects; for objects within a batch, performing malware analysis on the objects to assign a malware analysis score, and adjusting the malware analysis score based on the batch; and performing respective security actions on the objects within the batch, based on the adjusted malware analysis score.
G06F 21/56 - Détection ou gestion de programmes malveillants, p. ex. dispositions anti-virus
G06F 21/54 - Contrôle des utilisateurs, des programmes ou des dispositifs de préservation de l’intégrité des plates-formes, p. ex. des processeurs, des micrologiciels ou des systèmes d’exploitation au stade de l’exécution du programme, p. ex. intégrité de la pile, débordement de tampon ou prévention d'effacement involontaire de données par ajout de routines ou d’objets de sécurité aux programmes
There is described herein a computer-implemented system and method for providing domain name system (DNS) over hypertext transfer protocol secure (HTTPS) (DoH) resolution for a domain, including forming a DoH query for an entity, comprising inserting an entity access token into a uniform resource identifier (URI) template; sending the DoH query to a DoH service; resolving the DoH query, comprising using the entity access token to determine an entity context policy for the DoH query; and returning a DoH response that enacts the entity context policy.
H04L 61/4511 - Répertoires de réseauCorrespondance nom-adresse en utilisant des répertoires normalisésRépertoires de réseauCorrespondance nom-adresse en utilisant des protocoles normalisés d'accès aux répertoires en utilisant le système de noms de domaine [DNS]
G06F 15/16 - Associations de plusieurs calculateurs numériques comportant chacun au moins une unité arithmétique, une unité programme et un registre, p. ex. pour le traitement simultané de plusieurs programmes
H04L 9/14 - Dispositions pour les communications secrètes ou protégéesProtocoles réseaux de sécurité utilisant plusieurs clés ou algorithmes
H04L 9/32 - Dispositions pour les communications secrètes ou protégéesProtocoles réseaux de sécurité comprenant des moyens pour vérifier l'identité ou l'autorisation d'un utilisateur du système
H04L 12/28 - Réseaux de données à commutation caractérisés par la configuration des liaisons, p. ex. réseaux locaux [LAN Local Area Networks] ou réseaux étendus [WAN Wide Area Networks]
H04L 15/16 - Appareils ou circuits à l'extrémité d'émission avec clavier coopérant avec des disques-code
H04L 29/12 - Dispositions, appareils, circuits ou systèmes non couverts par un seul des groupes caractérisés par le terminal de données
A computer-implemented method protects a user from phishing attacks by managing commands initiated via a web browser. The method includes determining that a user has initiated a command that will send information to a target website, where the information belongs to a class that may include sensitive user data and the target website lacks a device-local phishing reputation. After this determination, the command is paused before the information is sent. While paused, a new reputation for the target website is obtained, and the command is blocked if the new reputation is deemed not safe, thereby preventing potential phishing threats.
Sample classification using natural language processing (NLP) models is disclosed herein. An example apparatus comprises interface circuitry, machine readable instructions, and programmable circuitry to at least one of instantiate or execute the machine readable instructions to access a set of instructions, the set of instructions representing executable instructions, determine an Application Programming Interface (API) call sequence based on the set of instructions, transmit the API call sequence to a NLP model, the NLP model to generate a set of tokens, the set of tokens representing the API call sequence, the set of tokens readable in the NLP model, and classify the API call sequence as clean or malicious based on the tokens, and classify the set of instructions as clean or malicious based on the classification of the API call sequence and at least one other feature of the set of instructions.
G06F 40/284 - Analyse lexicale, p. ex. segmentation en unités ou cooccurrence
G06F 21/53 - Contrôle des utilisateurs, des programmes ou des dispositifs de préservation de l’intégrité des plates-formes, p. ex. des processeurs, des micrologiciels ou des systèmes d’exploitation au stade de l’exécution du programme, p. ex. intégrité de la pile, débordement de tampon ou prévention d'effacement involontaire de données par exécution dans un environnement restreint, p. ex. "boîte à sable" ou machine virtuelle sécurisée
G06F 21/56 - Détection ou gestion de programmes malveillants, p. ex. dispositions anti-virus
Systems, apparatus, articles of manufacture, and methods to utilize cached generative artificial intelligence responses are disclosed. An example apparatus includes interface circuitry to access a request to a generative artificial intelligence model, computer readable instructions, and programmable circuitry to at least one of execute or instantiate the instructions to replace a named entity within the request with a generic tag to generate a modified request, tokenize the modified request to create an array of tokens, detect a similar prior request based on the array of tokens, and after detection of the similar prior request, cause output of a cached response to the request without execution of the generative artificial intelligence model.
09 - Appareils et instruments scientifiques et électriques
37 - Services de construction; extraction minière; installation et réparation
42 - Services scientifiques, technologiques et industriels, recherche et conception
Produits et services
(1) Computer utility software, namely, security software, computer utility virus protection programs and computer utility programs for providing details on devices installed in a computer system; computer anti-virus software; computer software and hardware for providing network, internet, and computer security; computer software for the detection, blocking and removal of computer viruses, malware and other threats; computer communications software for monitoring, managing, filtering and regulating electronic and wireless communications transmitted and received via local and global computer networks; computer software for protecting and securing computer networks and applications; computer software for encrypting and authenticating data; computer software for detecting and repairing computer software and hardware; computer software and hardware for automatically confirming and enforcing computer security policies, for identifying computer security policy violations, and for generating computer security policy compliance reports; computer software and hardware for the management, administration and optimization of computer networks and applications; computer software and hardware for use in the monitoring and control of, and generating reports on, computer and online activity; computer software for creating and maintaining firewalls; computer hardware and software for protecting and securing computer systems, and computer networks and applications; intrusion detection, prevention and repair software; computer software and hardware for encrypting and authenticating data; computer software for identity protection, authentication of users, and privacy control; computer software for secure storage and management of usernames and passwords; content filtering software; computer hardware and software for automatically updating computer utility and security software; computer hardware and software for rating the security level of internet sites, and manuals therefore packaged as a unit (1) Installation, maintenance and repair services in the fields of computers, computer systems and electronic communication networks; maintenance of computer hardware and software
(2) Providing temporary use of non-downloadable security software; providing temporary use of non-downloadable software in the field of computer, data, and network security; providing temporary use of non-downloadable software for detecting, blocking and removing computer viruses, malware and threats, encrypting and authenticating data, managing and filtering electronic communications, and detecting and repairing computer software and hardware problems; consulting, testing, research and advisory services in the field of computer, data, and network security; research, development and design of computer hardware and software; technical support services for others in the fields of computer, data, and network security; automatic updating of computer software; troubleshooting of computer hardware and software; collecting, compiling, and analyzing data for the purpose of generating and transmitting reports on and ratings of the level of security of third party software residing on the computers of others; computer programming services for others in the fields of computer, data, and network security; computer forensics services; providing temporary use of non-downloadable computer anti-virus software; computer network security services, namely, intrusion detection services, vulnerability assessment services, and services in the nature of detecting computer viruses and threats; technical support services for others in the fields of computer, data, and network security, namely, troubleshooting in the nature of diagnosing computer hardware and software problems; providing information in the fields of network, data, and computer security
(3) Monitoring of computer systems for security purposes; security services, namely, intrusion detection services, intrusion prevention services, vulnerability assessment services, and services in the nature of detecting and removing computer viruses and threats
25.
Secure DNS Using Delegated Credentials and Keyless SSL
There is disclosed in an example a gateway device, including a hardware computing platform, and a secure domain name system (DNS) engine having circuitry and stored instructions to-program the circuitry, the secure DNS engine to communicatively couple to an endpoint via a local network, begin a secure DNS transaction with the endpoint, determine whether the endpoint supports delegated credentials, and after determining that the endpoint supports delegated credentials, establish a secure DNS session with the endpoint using a delegated credential.
H04L 9/30 - Clé publique, c.-à-d. l'algorithme de chiffrement étant impossible à inverser par ordinateur et les clés de chiffrement des utilisateurs n'exigeant pas le secret
H04L 61/4511 - Répertoires de réseauCorrespondance nom-adresse en utilisant des répertoires normalisésRépertoires de réseauCorrespondance nom-adresse en utilisant des protocoles normalisés d'accès aux répertoires en utilisant le système de noms de domaine [DNS]
H04L 67/568 - Stockage temporaire des données à un stade intermédiaire, p. ex. par mise en antémémoire
26.
Methods and apparatus to self-guardrail large language model responses
Systems, apparatus, articles of manufacture, and methods to self-guardrail large language model responses are disclosed. An example apparatus includes interface circuitry, instructions, and programmable circuitry to at least one of execute or instantiate the instructions to access a first response message provided by a first large language model, the first response message generated based on an initial prompt, cause a second large language model to determine the first response message is inappropriate, modify the initial prompt to create a modified prompt, and provide the modified prompt to the first large language model to trigger generation of a second response message.
Systems, apparatus, articles of manufacture, and methods to self-guardrail large language model responses are disclosed. An example apparatus includes interface circuitry, instructions, and programmable circuitry to at least one of execute or instantiate the instructions to access a first response message provided by a first large language model, the first response message generated based on an initial prompt, cause a second large language model to determine the first response message is inappropriate, modify the initial prompt to create a modified prompt, and provide the modified prompt to the first large language model to trigger generation of a second response message.
H04L 51/212 - Surveillance ou traitement des messages utilisant un filtrage ou un blocage sélectif
H04L 51/02 - Messagerie d'utilisateur à utilisateur dans des réseaux à commutation de paquets, transmise selon des protocoles de stockage et de retransmission ou en temps réel, p. ex. courriel en utilisant des réactions automatiques ou la délégation par l’utilisateur, p. ex. des réponses automatiques ou des messages générés par un agent conversationnel
H04L 51/04 - Messagerie en temps réel ou quasi en temps réel, p. ex. messagerie instantanée [IM]
H04L 51/046 - Interopérabilité avec d'autres applications ou services réseau
28.
Methods and apparatus to identify structural similarity between webpages
Systems, apparatus, articles of manufacture, and methods are disclosed. An example apparatus includes interface circuitry; machine readable instructions; and programmable circuitry to at least one of instantiate or execute the machine readable instructions to: remove content data from a file corresponding to a first webpage, the file to include structure determiners after the removal of the content data; normalize data within the structure determiners; group the normalized structure determiners into tiles; compute a first output of a hashing algorithm using the tiles; and compare the first output to a second output of the hashing algorithm to generate a similarity value, the second output corresponding to a second webpage, the similarity value representing a structural similarity between the first webpage and the second webpage.
There is disclosed herein a computer-implemented software system and method. The method is to execute within a non-kernel space of a host computer and includes asynchronously monitoring network activity of network-enabled applications of the host computer. Responsive to the monitoring, and based on network behavior of a userspace application, the software creates one or more firewall rules for a kernel-mode firewall and causes the kernel-mode firewall to enforce the one more firewall rules.
There is disclosed computer-implemented system and method of providing a wireless access point (WAP), including dividing the WAP into at least two virtual networks, wherein a first virtual network is for devices that authenticate using a first authentication protocol and a second virtual network is for devices that authenticate using a second authentication protocol, wherein the second authentication protocol is more secure than the first authentication protocol; and onboarding devices to the WAP, and assigning the devices to the at least two virtual networks according to the authentication protocols they use to authenticate to the WAP.
There is disclosed a computer-implemented method of assigning reputations to objects, including: for respective samples in a dataset, extracting n features from a sample into a feature vector, where n is an integer greater than 1; assigning the sample a globally unique or pseudo-unique identifier (GUID); according to a clustering algorithm, mapping the feature vector into an n-dimensional space and computing distances between the sample and other samples in the n-dimensional space; assigning groups of objects to clusters according to their distances in the n-dimensional space; correlating the clusters to cluster tags based on the GUIDs of the samples, wherein the cluster tags are stored in a persistent cluster tag storage; and assigning the sample a reputation based on reputations of other samples in a cluster that the sample clustered with.
G06F 16/28 - Bases de données caractérisées par leurs modèles, p. ex. des modèles relationnels ou objet
H04L 9/32 - Dispositions pour les communications secrètes ou protégéesProtocoles réseaux de sécurité comprenant des moyens pour vérifier l'identité ou l'autorisation d'un utilisateur du système
32.
METHODS AND APPARATUS TO IMPROVE DEEPFAKE DETECTION WITH EXPLAINABILITY
Methods, apparatus, systems and articles of manufacture to improve deepfake detection with explainability are disclosed. An example apparatus includes interface circuitry to receive a media file, machine readable instructions, and at least one processor circuit to be programmed by the instructions to generate, based on a deepfake classification model, a classification score for the media file, obtain a class output from a final convolution feature map of the deepfake classification model, generate an explainability map based on a pooled weighted feature map along a channel dimension of the feature map, and identify the media file as a real or a deepfake media file based on the classification score and the explainability map.
H04N 21/44 - Traitement de flux élémentaires vidéo, p. ex. raccordement d'un clip vidéo récupéré d'un stockage local avec un flux vidéo en entrée ou rendu de scènes selon des graphes de scène du flux vidéo codé
G06F 16/41 - IndexationStructures de données à cet effetStructures de stockage
G06N 3/04 - Architecture, p. ex. topologie d'interconnexion
G06V 10/764 - Dispositions pour la reconnaissance ou la compréhension d’images ou de vidéos utilisant la reconnaissance de formes ou l’apprentissage automatique utilisant la classification, p. ex. des objets vidéo
G06V 10/778 - Apprentissage de profils actif, p. ex. apprentissage en ligne des caractéristiques d’images ou de vidéos
G06V 10/82 - Dispositions pour la reconnaissance ou la compréhension d’images ou de vidéos utilisant la reconnaissance de formes ou l’apprentissage automatique utilisant les réseaux neuronaux
G06V 20/00 - ScènesÉléments spécifiques à la scène
33.
Methods and apparatus for voice transformation, authentication, and metadata communication
Methods and apparatus for voice transformation, authentication, and metadata communication are disclosed. An example apparatus includes interface circuitry, machine readable instructions, and programmable circuitry to identify an enrollment voice associated with the account, a first voice transformation applied to a first voice input to produce the enrollment voice, the first voice transformation to cause the enrollment voice to include first voice-specific features different from second voice-specific features of the first voice input, access a transformed voice associated with a second voice input provided in association with a request to access the account from a user device, the first voice transformation or a second voice transformation to cause the transformed voice to have third voice-specific features different from fourth voice-specific features of the second voice input, and determine whether to provide the user device access to the account based on the first voice-specific features and the third voice-specific features.
G10L 17/02 - Opérations de prétraitement, p. ex. sélection de segmentReprésentation ou modélisation de motifs, p. ex. fondée sur l’analyse linéaire discriminante [LDA] ou les composantes principalesSélection ou extraction des caractéristiques
G10L 17/06 - Techniques de prise de décisionStratégies d’alignement de motifs
G10L 21/007 - Changement de la qualité de la voix, p. ex. de la hauteur tonale ou des formants caractérisé par le procédé utilisé
34.
Methods and apparatus to augment classification coverage for low prevalence samples through neighborhood labels proximity vectors
Disclosed examples include obtaining malicious neighbor samples based on a non-classified sample; obtaining clean neighbor samples based on the non-classified sample; generating a malicious proximity vector representing first distances between the non-classified sample and a first malicious neighbor sample from the malicious neighbor samples; generating a clean proximity vector representing second distances between the non-classified sample and a first clean neighbor sample from the clean neighbor samples; and classifying the non-classified sample as a clean sample or a malicious sample based on at least one of the malicious proximity vector or the clean proximity vector.
A computing apparatus includes a hardware platform having a processor and a memory; an operating system (OS) having a GUI with a user-initiatable share function, and an interface to register a share target for the share function; and instructions encoded within the memory to provide a security agent, the instructions to instruct the processor to: receive from the OS a notification that an object has been shared to the security agent via the share function; responsive to the notification, initiate a security scan or reputation action for the shared object; receive a security or reputation response from the security scan or reputation action; and based at least in part on the security scan or reputation response, display a security or reputation notification via the GUI.
G06F 21/56 - Détection ou gestion de programmes malveillants, p. ex. dispositions anti-virus
G06F 21/54 - Contrôle des utilisateurs, des programmes ou des dispositifs de préservation de l’intégrité des plates-formes, p. ex. des processeurs, des micrologiciels ou des systèmes d’exploitation au stade de l’exécution du programme, p. ex. intégrité de la pile, débordement de tampon ou prévention d'effacement involontaire de données par ajout de routines ou d’objets de sécurité aux programmes
G06F 21/55 - Détection d’intrusion locale ou mise en œuvre de contre-mesures
G06F 21/62 - Protection de l’accès à des données via une plate-forme, p. ex. par clés ou règles de contrôle de l’accès
There is disclosed a computer-implemented system and method for categorizing unclassified websites, including computing a data sketch of an unclassified website, wherein the data sketch is a probabilistic data structure that represents text of the unclassified website; computing an intersection value between the data sketch and a comparison set, wherein the comparison set comprises data sketches of known, classified websites; assigning matches for a subset of websites from the comparison set, wherein the subset includes intersections above an intersection threshold; classifying the website into a category of a website from the subset; and performing web traffic management based on the classification.
Mechanisms for sharing user-provided information from an original equipment manufacturer (OEM) application and a vendor application are provided, the mechanisms including: receiving the user-provided information at the OEM application; determining a system identifier of a system on which the OEM application is executing at the OEM application using a hardware processor; providing the user-provided information and the system identifier to a vendor cloud server from the OEM application; determining the system identifier at vendor application; providing the system identifier from the vendor application to the vendor cloud server; receiving the user-provided information at the vendor application from the vendor cloud server in response to providing the system identifier to the vendor cloud server; and using the user-provided information to configure the vendor application.
There is disclosed a method of mitigating phishing, including extracting text from a website under analysis; using a spell check algorithm to compare extracted words or phrases to a language dictionary of words or phrases selected from web pages known to be phishing targets, and using a spell counter to count misspell hits from the spell check algorithm; comparing the extracted words or phrases to a case-sensitive usage reference, and using a usage counter to count mismatched usage hits from the case-sensitive usage reference; combining the spell counter and the usage counter into a combined counter; and using the combined counter to identify the website under analysis as a suspected phishing website and taking a phishing mitigation action.
Methods, apparatus, systems, and articles of manufacture are disclosed to improve offloading of malware scans. An example apparatus is to, based on a trigger to perform a scan of a volume of data, estimate a computational burden associated with performing the scan using the CPU, the volume of data representative of at least one of a file or an object. Additionally, the example apparatus is to determine whether the computational burden satisfies a threshold associated with offloading the scan to the GPU. The example apparatus is also to cause at least one of the CPU or the GPU to perform the scan based on whether the computational burden satisfies the threshold.
There is disclosed in one example a ransomware mitigation engine, including: a processor; a convolutional neural network configured to provide file type identification (FTI) services including: identifying an access operation of a file as a write to the file or newly creating the file; computing a byte correlation factor for the file; classifying the file as belonging to a file type; determining with a screening confidence that the file type is correct for the file; determining that the screening confidence is below a screening confidence threshold; and circuitry and logic to provide heuristic analysis including: receiving notification that the confidence is below the confidence threshold; performing a statistical analysis of the file to determine a difference between an expected value and a computed value; determining from the difference, with a detection confidence, that the file has been compromised; and identifying the file as having been compromised by a ransomware attack.
There is disclosed a computer-implemented system and method of classifying a target sample, wherein the target sample is a computer object having a feature vector, the method comprising: creating n sorted containers, comprising sorting a universe of samples based on feature vector distances from the samples to n vantage points, wherein n is a positive integer; storing the n sorted containers to a computer memory; bucketizing the n sorted containers; for the n vantage points, selecting, from the n bucketized sorted containers, n meta-buckets of that the target sample belongs to; creating an intersection container, comprising samples that appear in all n meta-buckets; selecting, as a target cluster, samples from the intersection container that have a feature vector distance from the target sample less than a threshold; and acting on the target cluster.
A computer-implemented system and method of clustering a universe of featurized objects into micro-clusters includes selecting a vantage point having a feature vector; computing, for the featurized objects in the universe, respective distances from the vantage point, and sorting the featurized objects into a sorted container based on their distances from the vantage point; clustering adjacent objects into a plurality of micro-clusters based on determining that objects have a distance from a next adjacent object less than a maximum distance; and storing the micro-clusters onto a tangible computer-readable medium to modify operation of a computing apparatus based on objects in the micro-clusters.
Methods, apparatus, systems and articles of manufacture are disclosed to detect deepfake content. An example apparatus to determine whether input media is authentic includes a classifier to generate a first probability based on a first output of a local binary model manager, a second probability based on a second output of a filter model manager, and a third probability based on a third output of an image quality assessor, a score analyzer to obtain the first, second, and third probabilities from the classifier, and in response to obtaining a first result and a second result, generate a score indicative of whether the input media is authentic based on the first result, the second result, the first probability, the second probability, and the third probability.
G06V 40/16 - Visages humains, p. ex. parties du visage, croquis ou expressions
G06V 10/44 - Extraction de caractéristiques locales par analyse des parties du motif, p. ex. par détection d’arêtes, de contours, de boucles, d’angles, de barres ou d’intersectionsAnalyse de connectivité, p. ex. de composantes connectées
G06V 10/54 - Extraction de caractéristiques d’images ou de vidéos relative à la texture
G06V 20/40 - ScènesÉléments spécifiques à la scène dans le contenu vidéo
G06V 40/40 - Détection d’usurpation, p. ex. détection d’activité
There is disclosed in one example a computer apparatus, including: a hardware platform including a central processor unit (CPU) and a memory; and instructions encoded within the memory to instruct the CPU to: enumerate a plurality of running processes, and associate resource demands with the running processes; predict a resource starvation condition for at least one process; rank the plurality of running processes according to a dynamic ranking algorithm, wherein the ranking algorithm includes user engagement as an input for ranking a process; and according to the ranking and a safeguard algorithm, deallocate resources from a process ranked lower than the at least one process and assign the deallocated resources to the at least one process to mitigate the predicted resource starvation condition.
There is disclosed a computer-implemented system and method of analyzing a batch of objects, including bucketizing the batch of objects into a plurality of buckets according to a feature of the objects; for objects within a batch, performing malware analysis on the objects to assign a malware analysis score, and adjusting the malware analysis score based on the batch; and performing respective security actions on the objects within the batch, based on the adjusted malware analysis score.
G06F 21/56 - Détection ou gestion de programmes malveillants, p. ex. dispositions anti-virus
G06F 21/54 - Contrôle des utilisateurs, des programmes ou des dispositifs de préservation de l’intégrité des plates-formes, p. ex. des processeurs, des micrologiciels ou des systèmes d’exploitation au stade de l’exécution du programme, p. ex. intégrité de la pile, débordement de tampon ou prévention d'effacement involontaire de données par ajout de routines ou d’objets de sécurité aux programmes
There is disclosed a computer-implemented system and method for protecting a user from phishing attacks, including detecting that the user has opened a website associated with a uniform resource locator (URL), and determining that the URL does not have a known good reputation; rendering a test version of the website in a headless web browser, including abstracting the website into at least one visual element of the test version; visually inspecting the test version of the website with a digital eye, and determining that the test version of the web looks like a known legitimate website not associated with the URL; and based on the visual inspection, warning the user that the website is or may be a phishing website.
G06F 16/955 - Recherche dans le Web utilisant des identifiants d’information, p. ex. des localisateurs uniformisés de ressources [uniform resource locators - URL]
There is disclosed herein a computer-implemented system and method of remediating malicious events on a computing apparatus, including identifying a plurality of events on the computing apparatus that together accomplish malicious work and that were caused by a single parent actor; designating the single parent actor as a fileless attack; and taking a remedial action against the single parent actor.
G06F 21/55 - Détection d’intrusion locale ou mise en œuvre de contre-mesures
G06F 21/52 - Contrôle des utilisateurs, des programmes ou des dispositifs de préservation de l’intégrité des plates-formes, p. ex. des processeurs, des micrologiciels ou des systèmes d’exploitation au stade de l’exécution du programme, p. ex. intégrité de la pile, débordement de tampon ou prévention d'effacement involontaire de données
48.
Sharing cryptographic session keys among a cluster of network security platforms monitoring network traffic flows
An example apparatus disclosed herein is to select a first network security platform based on a first value associated with a first message associated a client and a second value associated with a second message associated with a server, the first message and the second message associated with establishment of an encrypted network traffic flow between the client and the server. The disclosed example apparatus is also to cause a cryptographic session key associated with the encrypted network traffic flow to be sent to the first network security platform.
H04L 9/32 - Dispositions pour les communications secrètes ou protégéesProtocoles réseaux de sécurité comprenant des moyens pour vérifier l'identité ou l'autorisation d'un utilisateur du système
There is disclosed a computer-implemented system and method A computer-implemented method for rating wireless networks, including crowd-sourcing, from a plurality of end users, WiFi access point (WAP) reputation data for a plurality of WAPs, wherein the WAP reputation data comprise WAP records including an identifier for a WAP, a geographic location of the WAP, and a user-supplied rating for the WAP; receiving, from an end user device, a device geolocation; and supplying, to the end user device, one or more WAP records for one or more WAPs near the device geolocation.
G01S 19/05 - Éléments coopérantsInteraction ou communication entre les différents éléments coopérants ou entre les éléments coopérants et les récepteurs fournissant des données d'assistance
G01C 21/20 - Instruments pour effectuer des calculs de navigation
G06F 3/01 - Dispositions d'entrée ou dispositions d'entrée et de sortie combinées pour l'interaction entre l'utilisateur et le calculateur
G06T 19/00 - Transformation de modèles ou d'images tridimensionnels [3D] pour infographie
H04W 4/029 - Services de gestion ou de suivi basés sur la localisation
H04W 48/16 - ExplorationTraitement d'informations sur les restrictions d'accès ou les accès
There is disclosed a computer-implemented system and method of detecting a device that deceptively misidentifies itself on a home network, including sending, to the device, discovery probes, and receiving in response to the discovery probes a self-reported identity; performing a verification of the self-reported identity, comprising over a time greater than one hour, monitoring network traffic from the device to determine whether network traffic over the time is consistent with expected network traffic for the self-reported identity; and upon determining that the network traffic is not consistent, designating the device as potentially deceptively misidentified, and acting to mitigate the device's activity.
H04L 12/28 - Réseaux de données à commutation caractérisés par la configuration des liaisons, p. ex. réseaux locaux [LAN Local Area Networks] ou réseaux étendus [WAN Wide Area Networks]
H04L 67/025 - Protocoles basés sur la technologie du Web, p. ex. protocole de transfert hypertexte [HTTP] pour la commande à distance ou la surveillance à distance des applications
H04L 67/1025 - Adaptation dynamique des critères sur lesquels repose la sélection du serveur
H04L 67/51 - Découverte ou gestion de ceux-ci, p. ex. protocole de localisation de service [SLP] ou services du Web
51.
METHODS, SYSTEMS, ARTICLES OF MANUFACTURE AND APPARATUS TO BUILD PRIVACY PRESERVING MODELS
Methods, apparatus, systems and articles of manufacture are disclosed to build privacy preserving models. An example apparatus disclosed herein includes processor circuitry to initialize a local model with tokenized parameters associated with server telemetry data, the tokenized parameters included in a first modeling plan retrieved from a server, cause the local model to train based on trigger parameters from the first modeling plan, the local model to train with (a) the tokenized parameters associated with the server telemetry data and (b) client telemetry data, calculate an accuracy metric of the local model based on client-side ground truth data, and label the local model as one of valid or invalid based on a comparison between the accuracy metric and an accuracy threshold.
G06F 18/21 - Conception ou mise en place de systèmes ou de techniquesExtraction de caractéristiques dans l'espace des caractéristiquesSéparation aveugle de sources
G06F 18/214 - Génération de motifs d'entraînementProcédés de Bootstrapping, p. ex. ”bagging” ou ”boosting”
There is disclosed in one example a computer-implemented system and method, including upon determining that an application has a non-benign reputation, selectively installing the application based on a user input; and personalizing the application by running the application concurrently with a personalization engine to limit the application to benign behavior.
Methods, apparatus, systems and articles of manufacture for detecting malware via analysis of a screen capture are disclosed. An example apparatus includes at least one memory, instructions, and processor circuitry to execute the instructions. The processor circuitry is to detect execution of a process, capture a portion of a screen buffer as a captured image, after the execution of the process is detected, analyze the captured image to determine an image similarity to a stored image in a database, the database to at least store malicious images, and perform a responsive action when the image similarity satisfies a similarity threshold.
G06F 21/56 - Détection ou gestion de programmes malveillants, p. ex. dispositions anti-virus
G06F 11/32 - Surveillance du fonctionnement avec indication visuelle du fonctionnement de la machine
G06F 21/54 - Contrôle des utilisateurs, des programmes ou des dispositifs de préservation de l’intégrité des plates-formes, p. ex. des processeurs, des micrologiciels ou des systèmes d’exploitation au stade de l’exécution du programme, p. ex. intégrité de la pile, débordement de tampon ou prévention d'effacement involontaire de données par ajout de routines ou d’objets de sécurité aux programmes
G06F 21/55 - Détection d’intrusion locale ou mise en œuvre de contre-mesures
A computer-implemented method provides phishing mitigation. Upon a human user accessing a website, request from a cloud reputation service a reputation for a uniform resource locator (URL) associated with the website; determine that the URL does not have a reliable reputation; determine that the human user has entered data into the website, and that the data comprise sensitive data; log a data packet in a user sensitive information data store, wherein the data packet includes the URL and at least some of the sensitive data; periodically query the cloud reputation service to determine whether the URL has received a reliable reputation; and upon determining that the URL has received a reputation as a phishing website, notify the human user and provide a recommendation for a remedial action to protect the sensitive data.
A computer-implemented method of updating a malware signature data structure includes classifying an object under analysis as malicious, and computing an object signature of the object under analysis; and validating the classification, including dividing a clean object signatures data structure into a plurality of subunits; assigning the subunits to dedicated data structures; scanning the dedicated data structures, in parallel, with a plurality of scanner instances; and upon at least one scanner instance determining, above a threshold, that the object signature for the object under analysis matches the clean objects signatures data structure, rejecting the object signature for inclusion in the malware signature data structures and terminating the scanner instances.
Methods, apparatus, systems, and articles of manufacture are disclosed for suppression of false positive malware detection. An example apparatus includes at least one memory, machine-readable instructions, and processor circuitry to at least one of instantiate or execute the machine-readable instructions to execute a machine-learning model based on a feature associated with an executable file to generate a malware detection output. The processor circuitry is further to, identify, after a first determination that the malware detection output identifies the executable file as malware, the malware detection output as a false positive malware detection output based on the feature invoking a false positive suppression rule. Additionally, the processor circuitry is to cause execution of the executable file based on the identification of the malware detection.
G06F 21/53 - Contrôle des utilisateurs, des programmes ou des dispositifs de préservation de l’intégrité des plates-formes, p. ex. des processeurs, des micrologiciels ou des systèmes d’exploitation au stade de l’exécution du programme, p. ex. intégrité de la pile, débordement de tampon ou prévention d'effacement involontaire de données par exécution dans un environnement restreint, p. ex. "boîte à sable" ou machine virtuelle sécurisée
G06F 21/56 - Détection ou gestion de programmes malveillants, p. ex. dispositions anti-virus
There is disclosed in one example an enrollment over secure transport (EST)-capable gateway device, including: a hardware platform including a processor and a memory; a first network interface to communicatively couple to an external network, including an external DNS server; a second network interface to communicatively couple to a home network; a caching DNS server including a local DNS cache, and logic to provide DNS services to the home network; and an EST proxy to authenticate to a local endpoint on the home network, provision a DNS server certificate on the local endpoint, provision an authentication domain name (ADN) on the local endpoint, and provide encrypted domain name system (DNS) services to the local endpoint.
H04L 61/4511 - Répertoires de réseauCorrespondance nom-adresse en utilisant des répertoires normalisésRépertoires de réseauCorrespondance nom-adresse en utilisant des protocoles normalisés d'accès aux répertoires en utilisant le système de noms de domaine [DNS]
H04L 101/663 - Adresses de couche transport, p. ex. aspects des ports du protocole de contrôle de transmission [TCP] ou des ports du protocole de datagramme utilisateur [UDP]
There is disclosed a system and method of providing services on a home gateway, including providing a set of security scans for traffic to and from a plurality of devices on a home network; cryptographically verifying that a secured device from the plurality of devices provides for itself internal security services; and based on the cryptographic verification, skipping at least one security scan of the set of security scans for traffic of the secured device.
G06F 21/57 - Certification ou préservation de plates-formes informatiques fiables, p. ex. démarrages ou arrêts sécurisés, suivis de version, contrôles de logiciel système, mises à jour sécurisées ou évaluation de vulnérabilité
H04L 9/32 - Dispositions pour les communications secrètes ou protégéesProtocoles réseaux de sécurité comprenant des moyens pour vérifier l'identité ou l'autorisation d'un utilisateur du système
Example methods, apparatus, systems and articles of manufacture (e.g., physical storage media) to implement contextual key management for data encryption are disclosed. Example apparatus disclosed herein are to identify a combination of context rules mapped to a key associated with encrypted data, the combination of context rules including at least two context rules. Disclosed example apparatus are also to discover first context information and second context information associated with the combination of context rules, the first context information obtained from a request to access the encrypted data, the second context information separate from the request. Disclosed example apparatus are further to evaluate the combination of context rules based on the first context information and the second context information to validate the request.
There is disclosed in one example a mobile telephone, including: a hardware platform including a processor and a memory; a telecommunication transceiver; and instructions encoded within the memory to instruct the processor to: identify a call made via the telecommunication transceiver; analyze the call and assign the call a predicted local reputation according to the analysis, including a legitimacy confidence score; if the legitimacy confidence score is less than a first threshold, terminate the call; if the legitimacy confidence score is greater than a second threshold, cease analysis of the call; and if the legitimacy confidence score is between the first and second thresholds, continue analysis of the call.
G10L 15/02 - Extraction de caractéristiques pour la reconnaissance de la paroleSélection d'unités de reconnaissance
G10L 15/26 - Systèmes de synthèse de texte à partir de la parole
G10L 25/63 - Techniques d'analyse de la parole ou de la voix qui ne se limitent pas à un seul des groupes spécialement adaptées pour un usage particulier pour comparaison ou différentiation pour estimer un état émotionnel
61.
Secure DNS using delegated credentials and keyless SSL
There is disclosed in an example a gateway device, including a hardware computing platform, and a secure domain name system (DNS) engine having circuitry and stored instructions to-program the circuitry, the secure DNS engine to communicatively couple to an endpoint via a local network, begin a secure DNS transaction with the endpoint, determine whether the endpoint supports delegated credentials, and after determining that the endpoint supports delegated credentials, establish a secure DNS session with the endpoint using a delegated credential.
H04L 9/30 - Clé publique, c.-à-d. l'algorithme de chiffrement étant impossible à inverser par ordinateur et les clés de chiffrement des utilisateurs n'exigeant pas le secret
H04L 29/08 - Procédure de commande de la transmission, p.ex. procédure de commande du niveau de la liaison
H04L 29/12 - Dispositions, appareils, circuits ou systèmes non couverts par un seul des groupes caractérisés par le terminal de données
H04L 61/4511 - Répertoires de réseauCorrespondance nom-adresse en utilisant des répertoires normalisésRépertoires de réseauCorrespondance nom-adresse en utilisant des protocoles normalisés d'accès aux répertoires en utilisant le système de noms de domaine [DNS]
H04L 67/568 - Stockage temporaire des données à un stade intermédiaire, p. ex. par mise en antémémoire
There is disclosed in one example a computing apparatus, including: a hardware platform including a processor and a memory; and an anomaly detection engine including instructions encoded within the memory to instruct the processor to: periodically collect telemetry for a performance parameter; compute and maintain a local trend line for the performance parameter; receive from a cloud service a global trend line for the performance parameter for a class of devices including the computing apparatus; and perform anomaly detection including analyzing the local trend line and the global trend line to detect an anomaly.
Disclosed examples include causing transmission of an indication to a server. The indication indicates that a file on a host storage location is designated as a favorite file. The indication causes a copy of the file to be stored in a favorites storage device. Disclosed examples also include generating a modified copy of the file by modifying the file at the host storage location, and causing synchronization of the modified copy of the file from the host storage location to replace the copy of the file at the favorites storage device.
Apparatus, systems, articles of manufacture, and methods for improving anti-malware scan responsiveness and effectiveness using user symptoms feedback are disclosed. An example method includes detecting a performance issue on a computing device, presenting a user interface on a display of the computing device requesting user feedback regarding the performance issue, and synthesizing user input related to the performance issue to identify, on the computing device, a scan parameter associated with the performance issue. The example method further includes, in response to failing to identify the scan parameter on the computing device, transmitting the user input to a symptom analysis server to identify the scan parameter based on anti-malware scans from other computing devices, and, in response to determining the scan parameter, performing a targeted anti-malware scan on the computing device.
There is disclosed herein a computer-implemented system and method of providing wellness detect and response (WDR) security services for an enterprise, including computing, for the enterprise, a quantitative user-centric security posture, wherein computing the quantitative user-centric security posture comprises calculating, for a user, a quantitative user risk profile according to a combination of user role, user privileges, user behavior, and digital assets assigned to a user and owned by the enterprise.
By way of example, a method includes, responsive to a user request to download, from the internet, a downloadable file with executable content, downloading a portion of the downloadable file, wherein the downloadable file is not executable with the portion; after download the portion of the downloadable file, scanning the portion of the downloadable file for malware characteristics to classify the downloadable file; and completing downloading the downloadable file only after determining, based on the scanning of the portion of the downloadable file, that the downloadable file is not malware.
G06F 21/56 - Détection ou gestion de programmes malveillants, p. ex. dispositions anti-virus
G06F 16/28 - Bases de données caractérisées par leurs modèles, p. ex. des modèles relationnels ou objet
G06F 21/54 - Contrôle des utilisateurs, des programmes ou des dispositifs de préservation de l’intégrité des plates-formes, p. ex. des processeurs, des micrologiciels ou des systèmes d’exploitation au stade de l’exécution du programme, p. ex. intégrité de la pile, débordement de tampon ou prévention d'effacement involontaire de données par ajout de routines ou d’objets de sécurité aux programmes
G06F 21/57 - Certification ou préservation de plates-formes informatiques fiables, p. ex. démarrages ou arrêts sécurisés, suivis de version, contrôles de logiciel système, mises à jour sécurisées ou évaluation de vulnérabilité
H04L 29/06 - Commande de la communication; Traitement de la communication caractérisés par un protocole
H04L 65/402 - Prise en charge des services ou des applications dans laquelle les services impliquent une session principale en temps réel et une ou plusieurs sessions parallèles additionnelles non-temps-réel, p. ex. le téléchargement d’un fichier lors d’une session FTP parallèle, l’introduction d’un courriel ou de services combinés
67.
Methods and apparatus to disable select processes for malware prevention
Methods, apparatus, systems, and articles of manufacture are disclosed to disable select processes for malware prevention, an apparatus comprising: at least one memory; instructions; and at least one processor to execute the instructions to cause the at least one processor to at least: identify execution of a computer process on a computing device; determine whether the identified computer process is in a list of computer processes to be monitored; in response to the identified computer process being listed in the list of computer processes to be monitored, determine an amount of time since last execution of the identified computer process; and suspend, in response to the amount of time since last execution meeting or exceeding a threshold time, execution of the identified computer process.
G06F 21/56 - Détection ou gestion de programmes malveillants, p. ex. dispositions anti-virus
G06F 21/57 - Certification ou préservation de plates-formes informatiques fiables, p. ex. démarrages ou arrêts sécurisés, suivis de version, contrôles de logiciel système, mises à jour sécurisées ou évaluation de vulnérabilité
A computer-implemented method provides security services to an enterprise. The method computes, for a plurality of enterprise users, a plurality of user health scores based on respective protection statuses for a plurality of enterprise assets owned by respective users; computes, for the enterprise, an overall enterprise security status score based on the plurality of user health scores; graphically displays to an enterprise administrator the overall enterprise security status score; and presents to the enterprise administrator a plurality of action recommendations to improve the overall enterprise security status score.
Mechanisms for protecting an application programming interface (API) are provided. The mechanisms include: receiving a combined API message containing sensor data from an API client and an API message; separating the sensor data and the API message; classifying the sensor data; determining that the API message is not to be blocked based on the classifying; and processing the API message. In some embodiments, the mechanisms further include preparing the sensor data for classification. In some embodiments, preparing the sensor data for classification comprises formatting the sensor data as an image. In some embodiments, classifying the sensor data comprises classifying the sensor data using a convolutional neural network (CNN). In some embodiments, the CNN is a ResNet CNN. In some embodiments, separating the sensor data and the API message comprises removing the sensor data from a header of the API message.
G06F 21/54 - Contrôle des utilisateurs, des programmes ou des dispositifs de préservation de l’intégrité des plates-formes, p. ex. des processeurs, des micrologiciels ou des systèmes d’exploitation au stade de l’exécution du programme, p. ex. intégrité de la pile, débordement de tampon ou prévention d'effacement involontaire de données par ajout de routines ou d’objets de sécurité aux programmes
Methods, apparatus, systems, and articles of manufacture are disclosed to implement trusted transfer learning on transformer-based phishing detection. In some examples, an apparatus includes processor circuitry to perform instructions to instantiate circuitry. The instantiated circuitry provides a uniform resource locator (URL) matrix corresponding to at least a portion of a URL address to a first transformer model and provide a web content data matrix corresponding to web content data on a web page at the URL address to a second transformer model. The instantiated circuitry performs data fusion on a first output from the first transformer model and a second output from the second transformer model to create a combined result. The instantiated circuitry determines at least whether phishing is detected at the URL address based at least in part on the combined result.
G06F 21/00 - Dispositions de sécurité pour protéger les calculateurs, leurs composants, les programmes ou les données contre une activité non autorisée
G06F 21/56 - Détection ou gestion de programmes malveillants, p. ex. dispositions anti-virus
In an example, there is disclosed a method of a remote device receiving a pushed over-the-air (OTA) payload from a push server, comprising: periodically collecting, on the remote device, telemetry data from telemetry sensors of the remote device, comprising storing the telemetry data in a local telemetry cache, and mirroring the telemetry data to a telemetry storage service; receiving from the push server the pushed OTA payload; authenticating the push server, comprising proving that the push server has access to the telemetry storage service; and based on the authenticating, accepting the pushed OTA payload.
Methods, apparatus, systems, and articles of manufacture are disclosed to translate hash-based signature signals for machine learning applications. In one example, the apparatus includes a processor to execute instructions to determine an element count for a plurality of hash elements of a locality sensitivity hash, preserve ones of hash elements of the plurality of hash elements that satisfy an element count threshold, and produce a cluster of encoded feature vectors of the preserved ones of the hash elements. The processor further to execute instructions to determine an occurrence frequency of hash elements in the cluster and create a synthetic hash of the cluster based on a subset of the hash elements in the cluster that satisfy an occurrence frequency threshold.
A method includes determining first data stored in a clipboard of an operating system, determining second data is stored in the clipboard, performing a comparison of the second data against malicious data, at least in part based on a determination that the first data has changed to the second data, and performing a first security operation, at least in part based on the comparison.
A method includes receiving privacy information about an entity from a privacy resource; parsing the privacy information to identify a plurality of keywords; determining a plurality of attributes of a user requested by the entity, at least in part based on the plurality of keywords; and transmitting a result, at least in part based on the plurality of attributes.
A method includes receiving privacy information about an entity from a privacy resource; parsing the privacy information into a plurality of attributes of a user; calculating a privacy exposure index, at least in part based on each of the plurality of attributes; and transmitting the privacy exposure index.
There is disclosed a method and system therefor, the method for validating a machine learning (ML) model, wherein the ML model is a binary classifier, the method including training the ML model on a training set comprising labeled objects from a first class and a second class; and validating the ML model on a training set, wherein the training set comprises at least some unlabeled objects, and for unlabeled objects, using an estimated classification as a proxy for a known label, wherein the estimated classification is based on computing a smallest distance to respective known feature vector clusters for the first and second classes.
Methods, apparatus, systems and articles of manufacture are disclosed to detect deepfake content. An example apparatus to determine whether input media is authentic includes a classifier to generate a first probability based on a first output of a local binary model manager, a second probability based on a second output of a filter model manager, and a third probability based on a third output of an image quality assessor, a score analyzer to obtain the first, second, and third probabilities from the classifier, and in response to obtaining a first result and a second result, generate a score indicative of whether the input media is authentic based on the first result, the second result, the first probability, the second probability, and the third probability.
G06V 20/40 - ScènesÉléments spécifiques à la scène dans le contenu vidéo
G06V 10/44 - Extraction de caractéristiques locales par analyse des parties du motif, p. ex. par détection d’arêtes, de contours, de boucles, d’angles, de barres ou d’intersectionsAnalyse de connectivité, p. ex. de composantes connectées
G06V 10/54 - Extraction de caractéristiques d’images ou de vidéos relative à la texture
G06V 40/16 - Visages humains, p. ex. parties du visage, croquis ou expressions
G06V 40/40 - Détection d’usurpation, p. ex. détection d’activité
78.
Methods, systems, and media for protected near-field communications
Methods, systems, and media for protected near-field communications are provided. In some embodiments, the method comprises: receiving, from an NFC tag device, a request for an NFC reader device identifier (ID); transmitting the NFC reader device ID to the NFC tag device; receiving an NFC tag device ID; determining whether the NFC tag device ID matches an NFC tag device ID stored in memory of the NFC reader device; in response to determining that the NFC tag device ID matches the NFC tag device ID, transmitting a password to the NFC tag device; receiving, from the NFC tag device, a shared secret; determining whether the received shared secret matches a shared secret stored in the memory of the NFC reader device; and in response to determining that the received shared secret matches the shared secret, causing an action to be performed by a device associated with the NFC reader device.
Methods, apparatus, systems, and articles of manufacture are disclosed to determine mutex entropy for malware classification. An example apparatus includes interface circuitry to access a mutex associated with a software application, the mutex to include a mutex identifier string, normalizer circuitry to normalize the mutex identifier string, character probability circuitry to determine character probabilities of characters within the normalized mutex identifier string, the character probabilities based on a historical mutex character distribution, entropy calculator circuitry to calculate an entropy value for the mutex based on the character probabilities, classifier circuitry to classify the mutex as clean or malicious based on the entropy value, and protector circuitry to mitigate malicious attacks based on the classification.
There is disclosed herein a computing apparatus having a hardware platform, including a processor circuit and a memory; a web-enabled application; and stored instructions within the memory to instruct the processor circuit to: determine that an input field of the web-enabled application has requested a password or personal data from a user; receive an input value; apply a deterministic function to the input value to create an obfuscated value; and provide the obfuscated value as an input to the input field.
Methods, apparatus, systems, and articles of manufacture are disclosed. An example apparatus to categorize web content includes interface circuitry to receive first results data from a pre-trained model; model tuner circuitry to: determine, based on the first results data, an adjustment to a parameter of the pre-trained model; and provide, via the interface circuitry, the adjustment to the pre-trained model; and feature extractor circuitry to: receive, via the model tuner circuitry, second results data that satisfies a performance threshold; and identify, from the second results data, at least one application specific feature from a tuned version of the pre-trained model.
A computing apparatus, including: a hardware platform including a processor circuit and a memory; and instructions encoded within the memory to instruct the processor circuit to: extract human readable text from a plurality of known websites, the known websites having known classifiers; apply a MinHash algorithm to respective human readable text of the known websites; generate a plurality of different locality sensitive hashing (LSH) indexes for the respective websites; extract human readable text from a test website; apply the MinHash algorithm to the human readable text of the test website to provide a MinHash of the test website; query the plurality of different LSH indexes with the MinHash of the test website; and according to a result of the query, assign a category the test website, wherein the category matches a known category of at least one of the plurality of known website found to have a containment with the test website above a threshold.
Methods, apparatus, systems and articles of manufacture to defend against adversarial machine learning are disclosed. An example apparatus includes memory; computer readable instructions; and processor circuitry to execute the computer readable instructions to: generate a first output indicating a feature that contributed to the generation of a classification by a machine learning model; compare the first output with a second output generated by a server that trained the machine learning model; and flag the machine learning model as corresponding to at least one of model drift or an adversarial attack when first output differs from the second output by more than a threshold.
Methods, apparatus, systems, and articles of manufacture are disclosed that determine a dynamic password update notification interval based on a breach risk classification and an automatic password update mechanism of an online service with which a user has an account. The disclosed methods, apparatus, systems, and articles of manufacture generate a password update suggestion and/or an automatic password update for the user at the dynamic password update notification interval determined by the processor circuitry.
G06F 21/45 - Structures ou outils d’administration de l’authentification
G06F 21/57 - Certification ou préservation de plates-formes informatiques fiables, p. ex. démarrages ou arrêts sécurisés, suivis de version, contrôles de logiciel système, mises à jour sécurisées ou évaluation de vulnérabilité
85.
SELECTIVE SECURITY SCAN TO REDUCE SIGNATURE CANDIDATES
A computing apparatus includes a hardware platform having a processor circuit and a memory; a network interface; and instructions encoded within the memory to instruct the processor circuit to: extract data from an object under analysis; compute a partial match value according to a partial match algorithm of the extracted data; send the partial match value to a remote service via the network interface; receive from the remote service, via the network interface, a list of candidate signatures that correspond to the partial match value, wherein the candidate signatures are a superset of true matches to the object under analysis; compare the object under analysis to the candidate signatures; and if the compare identifies one or more matching signature, classify the object under analysis as belonging to a same class as at least one second object that is a source of a matching signature.
G06F 21/55 - Détection d’intrusion locale ou mise en œuvre de contre-mesures
G06F 16/28 - Bases de données caractérisées par leurs modèles, p. ex. des modèles relationnels ou objet
G06F 21/54 - Contrôle des utilisateurs, des programmes ou des dispositifs de préservation de l’intégrité des plates-formes, p. ex. des processeurs, des micrologiciels ou des systèmes d’exploitation au stade de l’exécution du programme, p. ex. intégrité de la pile, débordement de tampon ou prévention d'effacement involontaire de données par ajout de routines ou d’objets de sécurité aux programmes
G06F 21/64 - Protection de l’intégrité des données, p. ex. par sommes de contrôle, certificats ou signatures
86.
Methods and apparatus to generate dynamic password update notifications
Methods, apparatus, systems, and articles of manufacture are disclosed that determine a dynamic password update notification interval based on a breach risk classification and an automatic password update mechanism of an online service with which a user has an account. The disclosed methods, apparatus, systems, and articles of manufacture generate a password update suggestion and/or an automatic password update for the user at the dynamic password update notification interval determined by the processor circuitry.
G06F 21/57 - Certification ou préservation de plates-formes informatiques fiables, p. ex. démarrages ou arrêts sécurisés, suivis de version, contrôles de logiciel système, mises à jour sécurisées ou évaluation de vulnérabilité
G06F 21/46 - Structures ou outils d’administration de l’authentification par la création de mots de passe ou la vérification de la solidité des mots de passe
87.
SYSTEMS, METHODS, AND APPARATUS TO OPTIMIZE TELEMETRY COLLECTION AND PROCESSING OF TRANSPORT LAYER SECURITY PARAMETERS
Methods, apparatus, systems and articles of manufacture are disclosed to optimize telemetry collection and processing of Transport Layer Security (TLS) parameters. An example apparatus includes at least one memory, instructions, and at least one processor to execute the instructions to generate a TLS client sub-profile based on first telemetry data associated with a client device, generate a TLS server sub-profile based on second telemetry data associated with a first server, generate a hash value based on at least one of the TLS client sub-profile or the TLS server sub-profile, compare the hash value to a plurality of hash values corresponding to known TLS profiles, and, in response to identifying the at least one of the TLS client sub-profile or the TLS server sub-profile as a unique TLS profile based on the comparisons, transmit the at least one of the first or second telemetry data to a second server.
H04L 29/06 - Commande de la communication; Traitement de la communication caractérisés par un protocole
H04L 9/06 - Dispositions pour les communications secrètes ou protégéesProtocoles réseaux de sécurité l'appareil de chiffrement utilisant des registres à décalage ou des mémoires pour le codage par blocs, p. ex. système DES
H04L 9/32 - Dispositions pour les communications secrètes ou protégéesProtocoles réseaux de sécurité comprenant des moyens pour vérifier l'identité ou l'autorisation d'un utilisateur du système
An apparatus for detecting a phishing website based on website icons is disclosed. A disclosed example apparatus includes parser circuitry to parse code of a first website, detector circuitry to detect, based on the parsed code, a first website icon and a first Uniform Resource Locator (URL) corresponding to the first website, and hash generator circuitry to generate a first hash of the first website icon, and store the first hash in association with the first URL in a hash entry of an icon hash database, the hash entry to be used for determining that a second website is a phishing website when (a) the first hash matches a second hash of a second website icon corresponding to the second website, and (b) a first portion of the first URL matches a second portion of a second URL corresponding to the second website.
H04L 9/06 - Dispositions pour les communications secrètes ou protégéesProtocoles réseaux de sécurité l'appareil de chiffrement utilisant des registres à décalage ou des mémoires pour le codage par blocs, p. ex. système DES
89.
Systems, methods, and media for sharing information with vendor applications in secure environments
Mechanisms for sharing user-provided information from an original equipment manufacturer (OEM) application and a vendor application are provided, the mechanisms including: receiving the user-provided information at the OEM application; determining a system identifier of a system on which the OEM application is executing at the OEM application using a hardware processor; providing the user-provided information and the system identifier to a vendor cloud server from the OEM application; determining the system identifier at vendor application; providing the system identifier from the vendor application to the vendor cloud server; receiving the user-provided information at the vendor application from the vendor cloud server in response to providing the system identifier to the vendor cloud server; and using the user-provided information to configure the vendor application.
There is disclosed in one example a computing apparatus, including: a hardware platform, including a processor, a memory, and a network interface; a bucketized reputation modifier table; and instructions encoded within the memory to instruct the processor to: perform a feature-based malware analysis of an object; assign the object a malware reputation according to the feature-based malware analysis; query and receive via the network interface a complementary score for a complementary property of the object; query the bucketized reputation modifier table according to the complementary score to receive a reputation modifier for the object; adjust the object's reputation according to the reputation modifier; and take a security action according to the adjusted reputation.
G06F 21/56 - Détection ou gestion de programmes malveillants, p. ex. dispositions anti-virus
G06F 21/54 - Contrôle des utilisateurs, des programmes ou des dispositifs de préservation de l’intégrité des plates-formes, p. ex. des processeurs, des micrologiciels ou des systèmes d’exploitation au stade de l’exécution du programme, p. ex. intégrité de la pile, débordement de tampon ou prévention d'effacement involontaire de données par ajout de routines ou d’objets de sécurité aux programmes
Methods, apparatus, systems and articles of manufacture to implement a virtual private network with probe for network connectivity are disclosed. An example non-transitory computer readable storage medium is disclosed comprising instructions which, when executed, cause a machine to at least, in response to a first instruction from an operating system to establish a network tunnel, transmit a probe request to a server; and in response to not receiving, from the server, a probe response to the probe request, report that the network tunnel has been established to prevent the operating system from transmitting subsequent instructions to establish the network connection until a response to a probe request is received.
H04L 43/0811 - Surveillance ou test en fonction de métriques spécifiques, p. ex. la qualité du service [QoS], la consommation d’énergie ou les paramètres environnementaux en vérifiant la disponibilité en vérifiant la connectivité
92.
System for authenticating a phone number using a phone number certificate
An apparatus, related devices and methods, having a memory element operable to store instructions; and a processor operable to execute the instructions, such that the apparatus is configured to identify, on an electronic device, a phone number of an incoming caller device; request, via an out-of-band control channel, a digital certificate for the phone number from the incoming caller device; receive, via the out-of-band control channel, the digital certificate for the phone number from the incoming caller device; determine whether the digital certificate for the phone number is authentic; and indicate, on the electronic device, based on a determination that the digital certificate for the phone number is authentic or not authentic, whether the phone number is authentic or not authentic.
Methods, apparatus, systems and articles of manufacture for detecting malware via analysis of a screen capture are disclosed. An example apparatus includes at least one memory, instructions, and processor circuitry to execute the instructions. The processor circuitry is to detect execution of a process, capture a portion of a screen buffer as a captured image, after the execution of the process is detected, analyze the captured image to determine an image similarity to a stored image in a database, the database to at least store malicious images, and perform a responsive action when the image similarity satisfies a similarity threshold.
G06F 21/54 - Contrôle des utilisateurs, des programmes ou des dispositifs de préservation de l’intégrité des plates-formes, p. ex. des processeurs, des micrologiciels ou des systèmes d’exploitation au stade de l’exécution du programme, p. ex. intégrité de la pile, débordement de tampon ou prévention d'effacement involontaire de données par ajout de routines ou d’objets de sécurité aux programmes
G06F 11/32 - Surveillance du fonctionnement avec indication visuelle du fonctionnement de la machine
G06F 21/55 - Détection d’intrusion locale ou mise en œuvre de contre-mesures
G06F 21/56 - Détection ou gestion de programmes malveillants, p. ex. dispositions anti-virus
94.
Methods and apparatus to augment classification coverage for low prevalence samples through neighborhood labels proximity vectors
Methods, apparatus, systems, and articles of manufacture are disclosed that augment classification for low prevalence samples. An example non-transitory computer readable medium comprises instructions that, when executed, causes a machine to at least classify a data sample using a first classifier, classify the data sample using a second classifier different from the first classifier, the second classifier using a plurality of sensitive hashing (LSH) forests to analyze a sorted plurality of neighbor samples, determine whether a first classification result of the first classifier meets or exceeds a confidence threshold, in response to the first classification result of the first classifier meeting or exceeding the confidence threshold, output the first classification result, and in response to the first classification result of the first classifier not meeting or exceeding the confidence threshold, output a second classification result of the second classifier.
Methods, apparatus, systems, and articles of manufacture are disclosed to classify a sample as clean or malicious. An example apparatus includes instruction identifies circuitry to convert a sample into a sequence of instructions, abstract language circuitry to transform the sequence of instructions into an abstract language representation, transition matrix circuitry to create a Markov transition matrix, the Markov transition matrix to represent transitions within the abstract language representation, and classifier circuitry to classify an unknown sample as clean or malicious, the classification in response to whether the Markov transition matrix is closer to a clean group of Markov transition matrices or a malicious group of Markov transition matrices.
Methods and apparatus are disclosed to detect malware using micro-forests with customer trust seeds. A false positive correction apparatus includes processor circuitry to perform at least one of the first operations, the second operations or the third operations to instantiate classifier circuitry to access a malicious sample, the malicious sample having a first feature vector, sample comparison circuitry to compare the malicious sample to a known sample, the known sample collected from customer data, the known sample having a second feature vector, calculator circuitry to calculate a distance value between the first feature vector and the second feature vector, threshold comparator circuitry to compare the distance value to a threshold, and change the classification of the malicious sample to clean in response to the distance value satisfying the threshold.
G06F 21/56 - Détection ou gestion de programmes malveillants, p. ex. dispositions anti-virus
G06F 21/00 - Dispositions de sécurité pour protéger les calculateurs, leurs composants, les programmes ou les données contre une activité non autorisée
G06N 7/01 - Modèles graphiques probabilistes, p. ex. réseaux probabilistes
There is disclosed a method of providing passive phishing remediation for an enterprise, including: displaying, to a user of a mobile device, an email; receiving from the user a one-click request to perform additional analysis of the email; providing the email to a phishing mitigation service; assigning the email a reputation score, generating a human-readable reputation display for the email, wherein the human-readable reputation display includes at least three grades comprising safe, unknown or unreliable, and unsafe or malicious; and providing the human-readable reputation display as a push notification to the mobile device.
G06F 15/16 - Associations de plusieurs calculateurs numériques comportant chacun au moins une unité arithmétique, une unité programme et un registre, p. ex. pour le traitement simultané de plusieurs programmes
A computing includes a hardware platform having a processor and a memory; and instructions encoded within the memory to instruct the processor to: on behalf of a human user, scan a social media platform for which the user has an account, and compute a proactive privacy risk score, wherein the proactive privacy risk score is a quantitative value based at least in part on an inherent risk of the social media platform according to data types that may be collected and exposed by the social media platform, and at least in part on privacy settings for the social media platform in relation to the data types; and recommend or initiate an action to improve the proactive privacy risk score.
G06F 21/57 - Certification ou préservation de plates-formes informatiques fiables, p. ex. démarrages ou arrêts sécurisés, suivis de version, contrôles de logiciel système, mises à jour sécurisées ou évaluation de vulnérabilité
Methods, apparatus, systems, and articles of manufacture are disclosed. An example apparatus comprises at least one memory, instructions, and processor circuitry to execute the instructions. The processor circuitry executes the instructions to provide a neural network a plurality of raw bytes for malware classification. The processor circuitry executes the instructions to generate a visualization of features extracted from the plurality of raw bytes. The processor circuitry executes the instructions to generate a heatmap for the plurality of raw bytes based on gradient activations of the neural networks. The processor circuitry executes the instructions to perform a dimensionality reduction based on features of the plurality of raw bytes identified in the heatmap.
Security risk evaluation across user devices is disclosed herein. An example method includes identifying a user and one or more devices associated with the user, collecting information identifying applications used by the user on the one or more devices, determining respective security sub-scores for each item of the one or more devices, computing an overall security score for the user based, at least in part, on an aggregation of the security sub-scores, and creating a user profile based on the overall security score, the user profile to enable the at least one of the one or more devices to exchange data with an external device when the overall security score meets a security score threshold, the user profile to prevent the at least one of the one or more devices from exchanging data with the external device when the overall security score does not meet the security score threshold.
G06F 21/44 - Authentification de programme ou de dispositif
G06F 21/55 - Détection d’intrusion locale ou mise en œuvre de contre-mesures
G06F 21/57 - Certification ou préservation de plates-formes informatiques fiables, p. ex. démarrages ou arrêts sécurisés, suivis de version, contrôles de logiciel système, mises à jour sécurisées ou évaluation de vulnérabilité