Binary function database system
    11.
    发明授权
    Binary function database system 有权
    二进制函数数据库系统

    公开(公告)号:US07802299B2

    公开(公告)日:2010-09-21

    申请号:US11784801

    申请日:2007-04-09

    IPC分类号: G06F11/00

    CPC分类号: G06F21/564 G06F21/566

    摘要: A binary function database system is provided in which binary functions are extracted from compiled and linked program files and stored in a database as robust abstractions which can be matched with others using one or more function matching heuristics. Such abstraction allows for minor variations in function implementation while still enabling matching with an identical stored function in the database, or with a stored function with a given level of confidence. Metadata associated with each function is also typically generated and stored in the database. In an illustrative example, a structured query language database is utilized that runs on a central database server, and that tracks function names, the program file from which the function is extracted, comments and other associated information as metadata during an analyst's live analysis session to enable known function information that is stored in the database to be applied to binary functions of interest that are disassembled from the program file.

    摘要翻译: 提供了一种二进制功能数据库系统,其中从编译和链接的程序文件中提取二进制函数,并将其存储在数据库中作为鲁棒抽象,可以使用一个或多个函数匹配启发式与其他抽象匹配。 这种抽象允许功能实现中的微小变化,同时仍然能够与数据库中的相同存储功能匹配,或者具有给定的置信度的存储的功能。 与每个功能相关联的元数据也通常生成并存储在数据库中。 在说明性的示例中,使用在中央数据库服务器上运行的结构化查询语言数据库,并且在分析人员的实时分析会话期间跟踪功能名称,提取功能的程序文件,作为元数据的其他关联信息作为元数据 使得存储在数据库中的已知功能信息能够应用于从程序文件反汇编的感兴趣的二进制功能。

    Automated malware signature generation
    12.
    发明申请
    Automated malware signature generation 有权
    生成自动恶意软件签名

    公开(公告)号:US20080127336A1

    公开(公告)日:2008-05-29

    申请号:US11523199

    申请日:2006-09-19

    IPC分类号: G06F21/00

    CPC分类号: G06F21/566 G06F21/564

    摘要: Automated malware signature generation is disclosed. Automated malware signature generation includes monitoring incoming unknown files for the presence of malware and analyzing the incoming unknown files based on both a plurality of classifiers of file behavior and a plurality of classifiers of file content. An incoming file is classified as having a particular malware classification based on the analyzing of incoming unknown files and a malware signature is generated for the incoming unknown file based on the particular malware classification. Access is provided to the malware signature.

    摘要翻译: 公开了自动恶意软件签名生成。 自动恶意软件签名生成包括监视传入的未知文件以存在恶意软件,并基于文件行为的多个分类器和文件内容的多个分类器分析传入的未知文件。 根据传入的未知文件的分析,传入文件被分类为具有特定的恶意软件分类,并且基于特定恶意软件分类为传入的未知文件生成恶意软件签名。 访问被提供给恶意软件签名。

    APPLICATION BEHAVIORAL CLASSIFICATION
    13.
    发明申请
    APPLICATION BEHAVIORAL CLASSIFICATION 有权
    应用行为分类

    公开(公告)号:US20070136455A1

    公开(公告)日:2007-06-14

    申请号:US11608625

    申请日:2006-12-08

    IPC分类号: G06F15/173

    CPC分类号: G06F21/564

    摘要: The present invention is directed to a method and system for automatically classifying an application into an application group which is previously classified in a knowledge base. More specifically, a runtime behavior of an application is captured as a series of events which are monitored and recorded during the execution of the application. The series of events are analyzed to find a proper application group which shares common runtime behavior patterns with the application. The knowledge base of application groups is previously constructed based on a large number of sample applications. The construction of the knowledge base is done in such a manner that each sample application can be classified into application groups based on a set of classification rules in the knowledge base. The set of classification rules are applied to a new application in order to classify the new application into one of the application groups.

    摘要翻译: 本发明涉及一种用于将应用程序自动分类为先前分类到知识库中的应用组的方法和系统。 更具体地,应用程序的运行时行为被捕获为在应用程序的执行期间被监视和记录的一系列事件。 分析一系列事件,以找到与应用程序共享公共运行时行为模式的正确应用程序组。 基于大量示例应用程序,先前构建了应用程序组的知识库。 以知识库中的一组分类规则将每个样本应用程序分类到应用组中的方式进行知识库的构建。 将一组分类规则应用于新应用程序,以便将新应用程序分类到其中一个应用程序组中。

    Swimming goggle buckle
    15.
    发明授权
    Swimming goggle buckle 失效
    游泳护目镜扣

    公开(公告)号:US07143484B2

    公开(公告)日:2006-12-05

    申请号:US10909415

    申请日:2004-08-03

    申请人: Tony Lee

    发明人: Tony Lee

    IPC分类号: A61F9/02

    摘要: A swimming goggle buckle includes a goggle main body, two single buckle complexes, and a headband, wherein the goggle main body includes a nose pad, a rim, face contacting pads, a glass lens formed in the rim, and an opening formed at each end. One end of each single buckle complex is fastened at an opening thereof and the other end connecting to the headband, thereby enabling the goggle buckle to be easy to assemble, difficult to disassemble, convenient to adjust, while still containing relatively few individual parts.

    摘要翻译: 游泳护目镜扣包括护目镜主体,两个单个扣环配合物和头带,其中护目镜主体包括鼻垫,边缘,面接触垫,形成在边缘中的玻璃透镜以及形成在每个边缘上的开口 结束。 每个单扣组合体的一端固定在其开口处,另一端连接到头带,从而使得护目镜扣易于组装,难以拆卸,方便调节,同时仍然包含相对较少的单个部件。

    Swimming goggle buckle
    18.
    发明申请
    Swimming goggle buckle 失效
    游泳护目镜扣

    公开(公告)号:US20060026804A1

    公开(公告)日:2006-02-09

    申请号:US10909415

    申请日:2004-08-03

    申请人: Tony Lee

    发明人: Tony Lee

    IPC分类号: A44B11/00

    摘要: The present invention is an improvement of a swimming goggle buckle, including a goggle main body, two single buckle complexes, and a headband, wherein the goggle main body having a nose pad, a rim, face contacting pads, glass lens formed in the rim, and an opening formed at each end, wherein one end of each single buckle complex being fastened at an opening thereof and the other end connecting to the headband, thereby enabling the present invention being easy in assembling, difficult in disassembling, convenient in adjusting the headband, and less in parts quantity.

    摘要翻译: 本发明是一种游泳护目镜带扣的改进,其包括护目镜主体,两个单个搭扣和头带,其中护目镜主体具有鼻垫,边缘,面接触垫,形成在边缘中的玻璃透镜 以及每个端部形成的开口,其中每个单个扣环复合体的一端被紧固在其开口处,另一端连接到头带,从而使得本发明易于组装,难以拆卸,方便调节 头带,零件数量少。

    Upper cover plate for an air-tight chamber and a tool for removing the same
    19.
    发明授权
    Upper cover plate for an air-tight chamber and a tool for removing the same 有权
    用于气密室的上盖板和用于移除它的工具

    公开(公告)号:US06491178B1

    公开(公告)日:2002-12-10

    申请号:US09711926

    申请日:2000-11-15

    IPC分类号: B65D4326

    CPC分类号: H01L21/67126

    摘要: An upper cover plate for an air-tight chamber and a tool for removing the upper cover plate from the chamber are introduced. The upper cover plate integrates a chamber body to form the air-tight chamber, in which the chamber body further includes a top surface for air-tightly matching with a bottom surface of the upper cover plate. The upper cover plate further includes a plurality of thread holes engageable respectively with a plurality of the tools. The present invention is characterized on that at least one of the thread holes is formed as a through thread hole connecting to the bottom surface, and that the respective tool for engaging with the through thread hole includes a portion for penetrating the through thread hole and going beyond the bottom surface. By providing the present invention, the top surface of the chamber body can be utilized as a pivotal plane for the tool to easily perform a helical lifting application upon the upper cover plate through the engaged threads, so that the air-tight state of the chamber can be easily removed.

    摘要翻译: 引入用于气密室的上盖板和用于从该室移除上盖板的工具。 上盖板集成了一个室主体以形成气密室,其中室主体还包括用于与上盖板的底表面进行气密匹配的顶表面。 上盖板还包括可分别与多个工具接合的多个螺纹孔。 本发明的特征在于,至少一个螺纹孔形成为连接到底面的贯通孔,并且与贯通孔接合的各个工具包括用于穿透通孔的部分, 超出底面。 通过提供本发明,室主体的顶表面可以用作工具的枢转平面,以容易地通过接合的螺纹在上盖板上执行螺旋提升施加,使得室的气密状态 可以很容易地去除。

    Structure of the keypad for keyboard
    20.
    发明授权
    Structure of the keypad for keyboard 失效
    键盘键盘的结构

    公开(公告)号:US5406277A

    公开(公告)日:1995-04-11

    申请号:US45113

    申请日:1993-04-12

    申请人: Tony Lee

    发明人: Tony Lee

    摘要: An improved keypad includes a plurality of apertured bases in the keyboard, a pressing rod and a keypad for each of the apertured bases. The pressing rod has opposing projected tracks and the apertured base has slots on its interior wall. This structure allows the pressing rod to be housed inside the apertured base so as to reduce the friction during the keypad operation. The reduction of friction provides a smooth keyboard operation. Moreover, the gap between the exterior wall of the pressing rod and the interior wall of the aperture base is wider, therefore, the keypad resonance is lessened during operation.

    摘要翻译: 改进的键盘包括键盘中的多个有孔基座,用于每个有孔底座的按压杆和键盘。 按压杆具有相对的突出轨道,并且有孔底座在其内壁上具有槽。 这种结构允许按压杆容纳在多孔基底内,以便在键盘操作期间减小摩擦力。 减少摩擦提供了平滑的键盘操作。 此外,按压杆的外壁与孔径基座的内壁之间的间隙较宽,因此在操作期间小键盘谐振减小。