Tiered forensics of IoT systems in cloud and time series databases

    公开(公告)号:US11681725B2

    公开(公告)日:2023-06-20

    申请号:US16156803

    申请日:2018-10-10

    IPC分类号: G06F16/27 G06F16/38 G06F11/14

    摘要: One example method includes creating an empty reconstruction stream database, identifying a data time interval, identifying data sources in which data was stored during the data time interval, reading data from the data sources, where the data read out from the data sources are associated with respective timestamps that fall within the data time interval, inserting the read out data into the empty reconstruction stream database so as to create a high resolution data stream, where the data are ordered in the empty reconstruction stream database according to timestamp, processing the data in the high resolution data stream and, based on the processing of the data, identifying and resolving a problem relating to an operating environment in which the data was initially generated.

    RETRIEVAL RESULT PROVIDING DEVICE AND RETRIEVAL RESULT PROVIDING METHOD

    公开(公告)号:US20190251110A1

    公开(公告)日:2019-08-15

    申请号:US16263272

    申请日:2019-01-31

    摘要: A retrieval result providing device includes a retrieval unit which acquires an individual retrieval result having item values of a plurality of items by a retrieval based on a keyword, an unprocessed sentence generation unit which generates an unprocessed sentence where retrieval result corresponding sentences with the item values arranged are arranged, an output sentence generation unit which performs at least one of a first process of erasing some of the sentences on the basis of a commonality between a word and the keyword contained in the retrieval result corresponding sentences, a second process of erasing some of the sentences on the basis of a commonality of the item values of specific items in the different sentences, and a third process of erasing some of the sentences on the basis of a commonality of the item values of a plurality of different items in one sentence so as to generate an output sentence, and an output sentence output unit which outputs a voice based on the output sentence.

    ANOMALY-BASED MALICIOUS-BEHAVIOR DETECTION
    95.
    发明申请

    公开(公告)号:US20190207969A1

    公开(公告)日:2019-07-04

    申请号:US16283599

    申请日:2019-02-22

    申请人: CrowdStrike, Inc.

    发明人: Daniel W. Brown

    IPC分类号: H04L29/06 G06F16/38 G06F21/55

    摘要: Example techniques detect incidents based on events from or at monitored computing devices. A control unit can detect events of various types within a time interval and aggregate the detected events into an incident. The control unit can detect patterns within the events based at least in part on predetermined criterion. In examples, the control unit can determine pattern scores for the patterns based on the probability of occurrence for the patterns and determine a composite score based on the pattern scores. The control unit can determine that an incident indicating malicious activity has been detected based in part determining that the composite score is above a predetermined threshold score. In some examples, the control unit can classify and rank the incidents. The control unit can determine if an incident indicates malicious activity including malware or targeted attack.

    TECHNIQUES FOR CONSISTENT READS IN A SPLIT MESSAGE STORE

    公开(公告)号:US20190205466A1

    公开(公告)日:2019-07-04

    申请号:US15858587

    申请日:2017-12-29

    申请人: Facebook, Inc.

    摘要: Techniques for consistent reads in a split message store are described. In one embodiment, an apparatus may comprise a client front-end component of a messaging system operative to receive a messaging client update request from a messaging client on a client device; and provide a message metadata set and a message body set to the messaging client on the client device in response to the messaging client update request; and a message cache component of the messaging system operative to retrieve the message metadata set from a metadata store of the messaging system, the message metadata set associated with a metadata set most-recent sequence identifier for the message metadata set; and retrieve the message body set from a message store of the messaging system, wherein retrieving the message body set from the message store comprises providing the metadata set most-recent sequence identifier for the message metadata set to the message store. Other embodiments are described and claimed.

    COGNITIVE DECISION SYSTEM FOR SECURITY AND LOG ANALYSIS USING ASSOCIATIVE MEMORY MAPPING IN GRAPH DATABASE

    公开(公告)号:US20190171756A1

    公开(公告)日:2019-06-06

    申请号:US16119461

    申请日:2018-08-31

    IPC分类号: G06F17/30 G06F21/62

    摘要: Methods, systems, and apparatus, including computer programs encoded on a computer storage medium, for a system to create and employ associative memory maps for analysis of security file and/or logs are disclosed. In one aspect, a method includes the actions of receiving, from an external application, a request for a recommended action; extracting information regarding the entities and relationships between the entities from a data source; constructing an associative memory map from the extracted information; selecting a subgraph from the associative memory map based on a result of employing a vector to search nodes in the associative memory map; identifying the nodes most relevant to the requested recommend action base on a shortest paths of traversal in the selected subgraph of nodes; determining the requested recommended action based on an event identified in the relationships between the identified most relevant nodes; and transmitting the recommended action to the external application.

    EVALUATING THE RANKING QUALITY OF A RANKED LIST
    100.
    发明申请
    EVALUATING THE RANKING QUALITY OF A RANKED LIST 审中-公开
    评估排名列表的排名质量

    公开(公告)号:US20160350401A1

    公开(公告)日:2016-12-01

    申请号:US15231423

    申请日:2016-08-08

    IPC分类号: G06F17/30

    摘要: The ranking quality of a ranked list may be evaluated. In an example embodiment, a method is implemented by a system to access log data, ascertain which entries of a ranked list are skipped, and determine a ranking quality metric from the skipped entries. More specifically, log data that reflects user interactions with a ranked list having multiple entries is accessed. The user interactions include at least indications of which of the multiple entries are selected entries. It is ascertained which entries of the multiple entries of the ranked list are skipped entries based on the selected entries. The ranking quality metric for the ranked list is determined responsive to the skipped entries.

    摘要翻译: 可以评估排名列表的排名质量。 在一个示例实施例中,系统通过系统实现访问日志数据的方法,确定排列列表的哪些条目被跳过,并且从跳过的条目确定排序质量度量。 更具体地,访问反映与具有多个条目的排名列表的用户交互的日志数据。 用户交互包括至少指示多个条目中的哪一个是选择的条目。 基于所选择的条目,确定排序列表的多个条目的哪些条目被跳过条目。 响应于跳过的条目来确定排名列表的排名质量度量。