Classification of malware using clustering that orders events in accordance with the time of occurance
    1.
    发明授权
    Classification of malware using clustering that orders events in accordance with the time of occurance 有权
    使用根据发生时间对事件进行排序的群集进行恶意软件分类

    公开(公告)号:US07809670B2

    公开(公告)日:2010-10-05

    申请号:US11608625

    申请日:2006-12-08

    IPC分类号: G06F17/00

    CPC分类号: G06F21/564

    摘要: The present invention is directed to a method and system for automatically classifying an application into an application group which is previously classified in a knowledge base. More specifically, a runtime behavior of an application is captured as a series of events which are monitored and recorded during the execution of the application. The series of events are analyzed to find a proper application group which shares common runtime behavior patterns with the application. The knowledge base of application groups is previously constructed based on a large number of sample applications. The construction of the knowledge base is done in such a manner that each sample application can be classified into application groups based on a set of classification rules in the knowledge base. The set of classification rules are applied to a new application in order to classify the new application into one of the application groups.

    摘要翻译: 本发明涉及一种将应用程序自动分类为先前分类为知识库的应用组的方法和系统。 更具体地,应用程序的运行时行为被捕获为在应用程序的执行期间被监视和记录的一系列事件。 分析一系列事件,以找到与应用程序共享公共运行时行为模式的正确应用程序组。 基于大量示例应用程序,先前构建了应用程序组的知识库。 基于知识库中的一组分类规则,完成知识库的构建,使得每个样本应用程序可以分类为应用组。 将一组分类规则应用于新应用程序,以便将新应用程序分类到其中一个应用程序组中。

    COLLECTING AND ANALYZING MALWARE DATA
    2.
    发明申请
    COLLECTING AND ANALYZING MALWARE DATA 有权
    收集和分析恶意软件数据

    公开(公告)号:US20100077481A1

    公开(公告)日:2010-03-25

    申请号:US12234717

    申请日:2008-09-22

    IPC分类号: G06F21/00

    CPC分类号: G06F21/552 G06F21/568

    摘要: A malware analysis system is described that provides information about malware execution history on a client computer and allows automated back-end analysis for faster creation of identification signatures and removal instructions. The malware analysis system collects threat information on client computers and sends the threat information to a back-end analysis component for automated analysis. The back-end analysis component analyzes the threat information by comparing the threat information to information about known threats. The system builds a signature for identifying the threat family and a mitigation script for neutralizing the threat. The system sends the signature and mitigation data to client computers, which use the information to mitigate the threat. Thus, the malware analysis system detects and mitigates threats more quickly than previous systems by reducing the burden on technicians to manually create environments for reproducing the threats and manually analyze the threat behavior.

    摘要翻译: 描述了恶意软件分析系统,其提供关于客户端计算机上的恶意软件执行历史的信息,并允许自动后端分析,以更快地创建身份签名和删除指令。 恶意软件分析系统在客户端计算机上收集威胁信息,并将威胁信息发送到后端分析组件进行自动分析。 后端分析组件通过将威胁信息与已知威胁信息进行比较来分析威胁信息。 该系统构建一个用于识别威胁系列的签名和用于中和威胁的缓解脚本。 系统将签名和缓解数据发送到客户端计算机,客户端计算机使用该信息来减轻威胁。 因此,恶意软件分析系统通过减轻技术人员手动创建用于再现威胁的环境并手动分析威胁行为的负担,可以更快地检测和减轻威胁。

    Collecting and analyzing malware data
    3.
    发明授权
    Collecting and analyzing malware data 有权
    收集和分析恶意软件数据

    公开(公告)号:US08667583B2

    公开(公告)日:2014-03-04

    申请号:US12234717

    申请日:2008-09-22

    CPC分类号: G06F21/552 G06F21/568

    摘要: A malware analysis system is described that provides information about malware execution history on a client computer and allows automated back-end analysis for faster creation of identification signatures and removal instructions. The malware analysis system collects threat information on client computers and sends the threat information to a back-end analysis component for automated analysis. The back-end analysis component analyzes the threat information by comparing the threat information to information about known threats. The system builds a signature for identifying the threat family and a mitigation script for neutralizing the threat. The system sends the signature and mitigation data to client computers, which use the information to mitigate the threat. Thus, the malware analysis system detects and mitigates threats more quickly than previous systems by reducing the burden on technicians to manually create environments for reproducing the threats and manually analyze the threat behavior.

    摘要翻译: 描述了恶意软件分析系统,其提供关于客户端计算机上的恶意软件执行历史的信息,并允许自动后端分析,以更快地创建身份签名和删除指令。 恶意软件分析系统在客户端计算机上收集威胁信息,并将威胁信息发送到后端分析组件进行自动分析。 后端分析组件通过将威胁信息与已知威胁信息进行比较来分析威胁信息。 该系统构建一个用于识别威胁系列的签名和用于中和威胁的缓解脚本。 系统将签名和缓解数据发送到客户端计算机,客户端计算机使用该信息来减轻威胁。 因此,恶意软件分析系统通过减轻技术人员手动创建用于再现威胁的环境并手动分析威胁行为的负担,可以更快地检测和减轻威胁。

    Protective relay capable of protection applications without protection settings
    7.
    发明申请
    Protective relay capable of protection applications without protection settings 有权
    保护继电器,无需保护设置即可保护应用

    公开(公告)号:US20070035902A1

    公开(公告)日:2007-02-15

    申请号:US11582257

    申请日:2006-10-16

    IPC分类号: H02H3/00

    CPC分类号: H02H3/286 H02H7/30

    摘要: The current differential relay operates without adjustable settings, and includes a phase current differential element with a predetermined threshold, responsive to local phase current values and remote phase current values, to detect three-phase faults and producing a first output signal if the threshold value is exceeded. Either a negative sequence current differential element or two phase current differential elements, also having predetermined threshold values and responsive to the local and remote phase currents, detect phase-to-phase faults and phase-to-phase-to-ground faults and produces a second output signal if the predetermined threshold is exceeded. A negative sequence or zero sequence current differential current element, with a predetermined threshold value is responsive to the local and remote phase currents to detect phase-to-ground faults and to produce a third output signal if the threshold is exceeded. If any one of the first, second and third output signals occurs, a trip signal is generated and directed to the associated circuit breaker. The thresholds are selected to permit use of the relay in a wide range of possible applications.

    摘要翻译: 电流差动继电器在没有可调设置的情况下运行,并且包括具有预定阈值的相电流差动元件,响应于局部相电流值和远端相电流值,以检测三相故障并产生第一输出信号,如果阈值为 超过了 还具有预定阈值并且响应于局部和远端相电流的负序电流差分元件或两相电流差动元件检测相间故障和相间到地层故障,并产生一个 如果超过预定阈值,则输出第二输出信号。 具有预定阈值的负序或零序电流差动电流元件响应于本地和远端相电流来检测相对地故障,并且如果超过阈值则产生第三输出信号。 如果发生第一,第二和第三输出信号中的任何一个,则产生跳闸信号并将其引导到相关联的断路器。 选择阈值以允许在广泛的可能应用中使用继电器。

    Surface-mounted type clamping force strain meter associated with a locating seat
    8.
    发明授权
    Surface-mounted type clamping force strain meter associated with a locating seat 失效
    与定位座相关的表面安装式夹紧力应变仪

    公开(公告)号:US06935188B2

    公开(公告)日:2005-08-30

    申请号:US10732420

    申请日:2003-12-11

    申请人: Tony Lee

    发明人: Tony Lee

    IPC分类号: G01L5/00 G01N3/02

    CPC分类号: G01L5/0076

    摘要: A surface-mounted type clamping force strain meter is mounted via a locating seat to a loaded surface of a load-bearing column of a forming machine, so as to measure any stretch, tension, and surface stress of the load-bearing column. The strain meter includes a sensing element having two signal lines extended therefrom, and the locating seat includes a seat body and a plurality of cushion pads. The seat body is provided at two opposite surfaces with communicable first and second receiving recesses. An amplifier base board is fitted in the first receiving recess, and the cushion pads are fitted in the second receiving recesses. The signal lines of the strain meter are upward extended through the cushion pad and the seat body to connect with the amplifier base board, and the sensing element is partially exposed from a bottom of the locating seat to contact with the forming machine.

    摘要翻译: 表面安装型夹紧力应变仪通过定位座安装到成形机的承载柱的承载表面上,以测量承载柱的任何拉伸,拉伸和表面应力。 应变计包括具有从其延伸的两条信号线的感测元件,并且定位座包括座椅本体和多个缓冲垫。 座椅本体设置在具有可连接的第一和第二容纳凹槽的两个相对的表面上。 放大器基板安装在第一容纳凹槽中,缓冲垫安装在第二容纳凹槽中。 应变计的信号线向上延伸穿过缓冲垫和座体与放大器基板连接,并且感测元件从定位座的底部部分露出以与成形机接触。

    Push to talk user interface
    9.
    发明申请
    Push to talk user interface 有权
    一键通用户界面

    公开(公告)号:US20050143135A1

    公开(公告)日:2005-06-30

    申请号:US11008340

    申请日:2004-12-08

    摘要: A push to talk (PTT) user interface for a wireless communications device utilizes a single all contacts database. The database is updated and utilized by the user in either a “PTT contacts” list screen or in an “all contacts” list screen. These screens are used for direct PTT calls, group PTT calls, alert calls, and standard cellular voice calls. Push to talk contacts are defined by the user and are stored on the wireless device. A direct PTT call allows a user to place a PTT call to another party or to a group with more than one party. The user can create a group “ad hoc” PTT call by selecting multiple contacts from the PTT contacts list screen. The PTT contact screen also is utilized to send an “alert” message to an individual with a PTT contact number. The alert message is either a brief text message or simply an “Alert” without text. During a PTT call, the user can view a variety of screens to add another party to the active PTT call and to save or edit participant information. When a user has missed a group call, the user can join the call late by using a call history list. During an active PTT call, the wireless communications device provides notification of other incoming PTT calls, and allows the user to “answer”, i.e., switch, to the new call.

    摘要翻译: 用于无线通信设备的一键通(PTT)用户界面利用单个全部联系人数据库。 用户在“PTT联系人”列表屏幕或“所有联系人”列表屏幕中更新和使用数据库。 这些屏幕用于直接PTT呼叫,组PTT呼叫,警报呼叫和标准蜂窝语音呼叫。 一键通联系人由用户定义并存储在无线设备上。 直接PTT呼叫允许用户将PTT呼叫发送到另一方或具有多方的组。 用户可以通过从PTT联系人列表屏幕中选择多个联系人来创建组“即席”PTT呼叫。 PTT联系人屏幕也用于向具有PTT联系号码的个人发送“警报”消息。 警报消息是简短的短信,也可以是简短的“警报”,无文本。 在PTT呼叫期间,用户可以查看各种屏幕以将另一方添加到活动的PTT呼叫并保存或编辑与会者信息。 当用户错过了群组呼叫时,用户可以通过使用呼叫历史列表加入呼叫。 在活动的PTT呼叫期间,无线通信设备提供其他进入的PTT呼叫的通知,并且允许用户“回答”,即切换到新呼叫。

    SURFACE-MOUNTED TYPE CLAMPING FORCE STRAIN METER ASSOCIATED WITH A LOCATING SEAT
    10.
    发明申请
    SURFACE-MOUNTED TYPE CLAMPING FORCE STRAIN METER ASSOCIATED WITH A LOCATING SEAT 失效
    表面安装式夹紧力应变仪与定位座椅相关

    公开(公告)号:US20050126303A1

    公开(公告)日:2005-06-16

    申请号:US10732420

    申请日:2003-12-11

    申请人: Tony Lee

    发明人: Tony Lee

    IPC分类号: G01L5/00 G01N3/02

    CPC分类号: G01L5/0076

    摘要: A surface-mounted type clamping force strain meter is mounted via a locating seat to a loaded surface of a load-bearing column of a forming machine, so as to measure any stretch, tension, and surface stress of the load-bearing column. The strain meter includes a sensing element having two signal lines extended therefrom, and the locating seat includes a seat body and a plurality of cushion pads. The seat body is provided at two opposite surfaces with communicable first and second receiving recesses. An amplifier base board is fitted in the first receiving recess, and the cushion pads are fitted in the second receiving recesses. The signal lines of the strain meter are upward extended through the cushion pad and the seat body to connect with the amplifier base board, and the sensing element is partially exposed from a bottom of the locating seat to contact with the forming machine.

    摘要翻译: 表面安装型夹紧力应变仪通过定位座安装到成形机的承载柱的承载表面上,以测量承载柱的任何拉伸,拉伸和表面应力。 应变计包括具有从其延伸的两条信号线的感测元件,并且定位座包括座椅本体和多个缓冲垫。 座椅本体设置在具有可连接的第一和第二容纳凹槽的两个相对的表面上。 放大器基板安装在第一容纳凹槽中,缓冲垫安装在第二容纳凹槽中。 应变计的信号线向上延伸穿过缓冲垫和座体与放大器基板连接,并且感测元件从定位座的底部部分露出以与成形机接触。