Labeling/names of themes
    1.
    发明授权

    公开(公告)号:US11954140B2

    公开(公告)日:2024-04-09

    申请号:US17666388

    申请日:2022-02-07

    发明人: Roni Romano

    摘要: By formulizing a specific company's internal knowledge and terminology, the ontology programming accounts for linguistic meaning to surface relevant and important content for analysis. The ontology is built on the premise that meaningful terms are detected in the corpus and then classified according to specific semantic concepts, or entities. Once the main terms are defined, direct relations or linkages can be formed between these terms and their associated entities. Then, the relations are grouped into themes, which are groups or abstracts that contain synonymous relations. The disclosed ontology programming adapts to the language used in a specific domain, including linguistic patterns and properties, such as word order, relationships between terms, and syntactical variations. The ontology programming automatically trains itself to understand the domain or environment of the communication data by processing and analyzing a defined corpus of communication data.

    System and method for monitoring security of a computer network

    公开(公告)号:US11888879B2

    公开(公告)日:2024-01-30

    申请号:US17531723

    申请日:2021-11-20

    IPC分类号: H04L9/40 H04L61/4511

    摘要: Methods and systems to identify the domain names that can potentially be used for delivering instructions to a bot, before bots on a computer network succeed in obtaining the instructions. The system maintains a device rating for each device that reflects a likelihood that the device is infected by malware. The system also maintains a domain-name rating for each device that reflects a likelihood that the domain name is malicious. When a device attempts to access a particular domain name, the domain-name rating of the domain name is updated in light of the device rating of the device, and/or update the device rating of the device in light of the domain-name rating.

    System and method for identifying associated subjects from location histories

    公开(公告)号:US11622231B2

    公开(公告)日:2023-04-04

    申请号:US17236461

    申请日:2021-04-21

    发明人: Shlomo Rothschild

    IPC分类号: H04W4/02 H04W4/029

    摘要: Systems and methods to track the respective locations of subjects over time. The system identifies subjects who, overtime, were co-located with one another suggesting they are associated with one another, and the pairs are analyzed. For each of the subjects, the system produces a vector that quantifies the subject's location history by including a respective weight for each combination of a time interval with a geographical area. The vectors are compared using a distance metric, and any pair of subjects whose vectors are sufficiently close are flagged as being an associated pair. The respective vector belonging to each subject is normalized to account for the total number of other subjects who were co-located with the subject. For each interval-area pair, the system may compute the frequency of the interval-area pair, and then divide each weight that corresponds to the interval-area pair by the frequency of the interval-area pair.

    System and method for storing and querying document collections

    公开(公告)号:US11442973B2

    公开(公告)日:2022-09-13

    申请号:US16658323

    申请日:2019-10-21

    IPC分类号: G06F16/33 G06F16/31

    摘要: A system for storing document collections in a manner that facilitates efficient querying. Each document vector is hashed, by applying a suitable hash function to the components of the vector. The hash function maps the vector to a particular hash value, corresponding to a particular hyperbox in the multidimensional space to which the vectors belong. The vector, or a pointer to the vector, is then stored in a hash table in association with the vector's hash value. Subsequently, given a document of interest, documents similar to the document of interest may be found by hashing the vector of the document of interest, and then returning the vectors that are associated, in the hash table, with the resulting hash value.

    System and method for combined network-side and off-air monitoring of wireless networks

    公开(公告)号:US11432139B2

    公开(公告)日:2022-08-30

    申请号:US16703241

    申请日:2019-12-04

    发明人: Eithan Goldfarb

    摘要: A monitoring system monitors authentication sessions both on the air interface between the terminals and the network, and on at least one wired network-side interface between network-side elements of the network. The monitoring system constructs a database of sets of network-side authentication parameters using network-side monitoring. Each set of network-side authentication parameters originates from a respective authentication session and is associated with the International Mobile Station Identity (IMSI) of the terminal involved in the session. In order to start decrypting the traffic of a given terminal, the system obtains the off-air authentication parameters of that terminal using off-air monitoring, and finds an entry in the database that matches the air-interface authentication parameters. From the combination of correlated network-side and off-air authentication parameters, the processor is able to extract the parameters needed for decryption.

    System and method for maintaining a dynamic dictionary

    公开(公告)号:US11386135B2

    公开(公告)日:2022-07-12

    申请号:US16752955

    申请日:2020-01-27

    发明人: Yitshak Yishay

    摘要: An apparatus and techniques for constructing and utilizing a “dynamic dictionary” that is not a compiled dictionary, and therefore does not need to be recompiled in order to be updated. The dynamic dictionary includes respective data structures that represent (i) a management automaton that includes a plurality of management nodes, and (ii) a runtime automaton that is derived from the management automaton and includes a plurality of runtime nodes. The runtime automaton may be used to search input data, such as communication traffic over a network, for keywords of interest, while the management automaton manages the addition of keywords to the dynamic dictionary. Typically, at least two (e.g., exactly two) such dynamic dictionaries are used in combination with a static dictionary.

    SYSTEM AND METHOD FOR IDENTIFYING DEVICES BEHIND NETWORK ADDRESS TRANSLATORS

    公开(公告)号:US20220174008A1

    公开(公告)日:2022-06-02

    申请号:US17518879

    申请日:2021-11-04

    摘要: An apparatus for monitoring a plurality of devices that use a plurality of networks includes a network interface and a processor. The processor is configured to receive, via the network interface, a plurality of packets that were collectively communicated, from the devices, via all of the networks, to aggregate the packets, using at least one field that is included in respective packet headers of the packets, into a plurality of packet aggregations, such that all of the packets in each one of the packet aggregations were collectively communicated from no more than one of the devices, to group the packet aggregations into a plurality of groups, such that there is a one-to-one correspondence between the groups and the devices, in that all of the packets in each of the groups were collectively communicated from a different respective one of the devices, and to generate an output in response thereto.

    System and method for identifying pairs of related application users

    公开(公告)号:US11336609B2

    公开(公告)日:2022-05-17

    申请号:US17159544

    申请日:2021-01-27

    摘要: Systems and methods for passive monitoring of computer communication that does not require performing any decryption. A monitoring system receives the traffic exchanged with each relevant application server, and identifies, in the traffic, sequences of messages—or “n-grams”—that appear to belong to a communication session between a pair of users. Subsequently, based on the numbers and types of identified n-grams, the system identifies each pair of users that are likely to be related to one another via the application, in that these users used the application to communicate (actively and/or passively) with one another. The system may identify those sequences of messages that, by virtue of the sizes of the messages in the sequence, and/or other properties of the messages that are readily discernable, indicate a possible user-pair relationship.