System and method for managing files in a distributed system using filtering
    2.
    发明授权
    System and method for managing files in a distributed system using filtering 有权
    使用过滤管理分布式系统中的文件的系统和方法

    公开(公告)号:US06772346B1

    公开(公告)日:2004-08-03

    申请号:US09356770

    申请日:1999-07-16

    IPC分类号: G06F1130

    CPC分类号: H04L63/145 H04L63/0227

    摘要: In a network-connected distributed system including nodes through which digital data flow, one or more of the nodes adapted to process the digital data, a method for efficiently managing the transmission of units of digital data from node to node, includes the steps of receiving, at one of the one or more nodes, units of digital data first transmitted by an originating node; filtering out sufficiently processed units of the digital data based on filtering information; transmitting, to the originating node and/or other nodes, filtered results relating to the sufficiently processed units; queuing, for processing at other nodes, unfiltered units of the digital data which are not filtered out; and updating the filtering information according to results of automatic processing performed in and received from the one of the one or more nodes and/or other nodes in the system.

    摘要翻译: 在包括数字数据流的节点的网络连接的分布式系统中,适于处理数字数据的一个或多个节点,用于有效地管理从节点到节点的数字数据单元的传输的方法包括以下步骤: 在所述一个或多个节点中的一个节点处,由始发节点首先发送的数字数据单元; 基于过滤信息过滤出数字数据的充分处理的单元; 向所述始发节点和/或其他节点发送与所述充分处理的单元相关的滤波结果; 排队,用于在其他节点处处理,未过滤的数字数据的未过滤单元; 以及根据在所述系统中的一个或多个节点和/或其他节点中的一个执行并在其中接收的自动处理的结果来更新所述过滤信息。

    Method and apparatus for securely transporting an information container from a trusted environment to an unrestricted environment
    3.
    发明授权
    Method and apparatus for securely transporting an information container from a trusted environment to an unrestricted environment 失效
    用于将信息容器从可信环境安全地传送到不受信任的环境的方法和装置

    公开(公告)号:US06678822B1

    公开(公告)日:2004-01-13

    申请号:US08937864

    申请日:1997-09-25

    IPC分类号: H04L900

    摘要: A method for operating a data processing system of a type that includes a first data processing entity located within a trusted environment and a second data processing entity located within an untrusted environment. The method includes a first step, executed at the first data processing entity, of operating a first software agent for detecting a presence of an information container of interest and for producing a modified information container by automatically identifying and at least one of removing, masking, or replacing at least one predetermined type of restricted or private information in the information container. A second step of the method transports the modified information container from the first data processing entity to the second data processing entity for further processing. The further processing may entail an analysis of the modified information container to locate and/or identify an undesirable software entity, such as a computer virus.

    摘要翻译: 一种用于操作数据处理系统的方法,所述数据处理系统包括位于可信环境内的第一数据处理实体和位于不可信环境内的第二数据处理实体。 该方法包括在第一数据处理实体中执行的第一步骤,操作第一软件代理,用于检测感兴趣的信息容器的存在,并通过自动识别和删除,屏蔽, 或者在信息容器中替换至少一种预定类型的限制或私人信息。 该方法的第二步将经修改的信息容器从第一数据处理实体传送到第二数据处理实体,用于进一步处理。 进一步的处理可能需要对修改的信息容器的分析以定位和/或识别不期望的软件实体,例如计算机病毒。

    System and method for managing files in a distributed system using prioritization
    4.
    发明授权
    System and method for managing files in a distributed system using prioritization 有权
    使用优先级排序管理分布式系统中的文件的系统和方法

    公开(公告)号:US06560632B1

    公开(公告)日:2003-05-06

    申请号:US09356183

    申请日:1999-07-16

    IPC分类号: G06F1516

    摘要: In a network-connected distributed system including nodes through which digital data flow, one or more of the nodes adapted to process the digital data, a method for efficiently managing the transmission of units of digital data from node to node includes the steps of receiving, at one of the one or more nodes, units of digital data first transmitted by an originating node; queuing, for processing at other nodes, one or more units of the digital data; prioritizing the queued units of digital data for transmission to a next node based on prioritizing information; and updating the prioritizing information according to results of processing performed in and received from the one of the one or more nodes and/or other nodes in the system.

    摘要翻译: 在包括数字数据流的节点的网络连接的分布式系统中,适于处理数字数据的一个或多个节点,用于有效管理数字数据单元从节点到节点的传输的方法包括以下步骤: 在一个或多个节点中的一个节点处,由始发节点首先发送的数字数据单元; 排队,用于在其他节点处处理数字数据的一个或多个单元; 基于优先化信息来优先排列的数字数据单元以传输到下一个节点; 以及根据在所述系统中的所述一个或多个节点和/或其他节点中的一个节点执行并在其中接收的处理结果来更新所述优先级信息。

    Method and apparatus for detecting a presence of a computer virus
    5.
    发明授权
    Method and apparatus for detecting a presence of a computer virus 失效
    用于检测计算机病毒存在的方法和装置

    公开(公告)号:US5907834A

    公开(公告)日:1999-05-25

    申请号:US619866

    申请日:1996-03-18

    CPC分类号: G06F21/564

    摘要: A data string is a sequence of atomic units of data that represent information. In the context of computer data, examples of data strings include executable programs, data files, and boot records consisting of sequences of bytes, or text files consisting of sequences of bytes or characters. The invention solves the problem of automatically constructing a classifier of data strings, i.e., constructing a classifier which, given a string, determines which of two or more class labels should be assigned to it. From a set of (string, class-label) pairs, this invention provides an automated technique for extracting features of data strings that are relevant to the classification decision, and an automated technique for developing a classifier which uses those features to classify correctly the data strings in the original examples and, with high accuracy, classify correctly novel data strings not contained in the example set. The classifier is developed using "adaptive" or "learning" techniques from the domain of statistical regression and classification, such as, e.g., multi-layer neural networks. As an example, the technique can be applied to the task of distinguishing files or boot records that are infected by computer viruses from files or boot records that are not infected.

    摘要翻译: 数据串是表示信息的数据的原子单元的序列。 在计算机数据的上下文中,数据串的示例包括由字节序列组成的可执行程序,数据文件和引导记录,或由字节或字符序列组成的文本文件。 本发明解决了自动构建数据串分类器的问题,即,构建一个分类器,给定一个字符串,确定应该分配两个或多个类标签中的哪一个。 本发明从一组(串,类标签)对提供了一种用于提取与分类决定相关的数据串的特征的自动化技术,以及用于开发分类器的自动化技术,其使用这些特征来正确地分类数据 原始示例中的字符串,并且具有高精度,正确地分类示例集中未包含的新颖数据字符串。 分类器是使用“自适应”或“学习”技术从统计回归和分类领域开发的,例如多层神经网络。 例如,该技术可以应用于区分受计算机病毒感染的文件或引导记录的文件或未被感染的引导记录的任务。

    Adaptive statistical regression and classification of data strings, with
application to the generic detection of computer viruses
    6.
    发明授权
    Adaptive statistical regression and classification of data strings, with application to the generic detection of computer viruses 失效
    数据串的自适应统计回归和分类,应用于计算机病毒的通用检测

    公开(公告)号:US5675711A

    公开(公告)日:1997-10-07

    申请号:US242757

    申请日:1994-05-13

    CPC分类号: G06F21/564

    摘要: A data string is a sequence of atomic units of data that represent information. In the context of computer data, examples of data strings include executable programs, data files, and boot records consisting of sequences of bytes, or text files consisting of sequences of bytes or characters. The invention solves the problem of automatically constructing a classifier of data strings, i.e., constructing a classifier which, given a string, determines which of two or more class labels should be assigned to it. From a set of (string, class-label) pairs, this invention provides an automated technique for extracting features of data strings that are relevant to the classification decision, and an automated technique for developing a classifier which uses those features to classify correctly the data strings in the original examples and, with high accuracy, classify correctly novel data strings not contained in the example set. The classifier is developed using "adaptive" or "learning" techniques from the domain of statistical regression and classification, such as, e.g., multi-layer neural networks. As an example, the technique can be applied to the task of distinguishing files or boot records that are infected by computer viruses from files or boot records that are not infected.

    摘要翻译: 数据串是表示信息的数据的原子单元的序列。 在计算机数据的上下文中,数据串的示例包括由字节序列组成的可执行程序,数据文件和引导记录,或由字节或字符序列组成的文本文件。 本发明解决了自动构建数据串分类器的问题,即,构建一个分类器,给定一个字符串,确定应该分配两个或多个类标签中的哪一个。 本发明从一组(串,类标签)对提供了一种用于提取与分类决定相关的数据串的特征的自动化技术,以及用于开发分类器的自动化技术,其使用这些特征来正确地分类数据 原始示例中的字符串,并且具有高精度,正确地分类示例集中未包含的新颖数据字符串。 分类器是使用“自适应”或“学习”技术从统计回归和分类领域开发的,例如多层神经网络。 例如,该技术可以应用于区分受计算机病毒感染的文件或引导记录的文件或未被感染的引导记录的任务。

    Efficient detection of computer viruses and other data traits
    7.
    发明授权
    Efficient detection of computer viruses and other data traits 失效
    有效检测计算机病毒和其他数据特征

    公开(公告)号:US6016546A

    公开(公告)日:2000-01-18

    申请号:US890013

    申请日:1997-07-10

    IPC分类号: G06F1/00 G06F21/00 G06F13/00

    CPC分类号: G06F21/564

    摘要: The present invention provides a method of reducing the amount of memory required to scan a given data string for the presence of computer viruses or other data traits of interest including the steps of 1) loading into a memory of a computer a set of generic features that are functionally similar to standard computer virus signatures, but tend to be less specific to particular viruses, 2) locating occurrences of the generic features within the data string, 3) applying a first mapping from the occurrences located during step 2) to obtain a subset of standard signatures, 4) loading the subset of standard signatures into a memory of said computer, 5) locating occurrences within the data string of all signatures from the subset of standard signatures, and 6) applying a second mapping from the occurrences located during step 5) to identify a set of computer viruses that are likely to be present in the data string.

    摘要翻译: 本发明提供一种减少扫描给定数据串所需的存储器量的方法,用于存在感兴趣的计算机病毒或其他数据特征,包括以下步骤:1)将一组通用特征加载到计算机的存储器中, 在功能上类似于标准计算机病毒签名,但往往对特定病毒具有较少的特异性,2)定位数据串中的通用特征的出现,3)应用来自位于步骤2)期间出现的第一个映射,以获得子集 的标准签名,4)将标准签名的子集加载到所述计算机的存储器中,5)从标准签名的子集中定位所有签名的数据字符串内的事件,以及6)应用在步骤期间发生的出现的第二映射 5)识别可能存在于数据串中的一组计算机病毒。

    System and method for detecting and repairing document-infecting viruses using dynamic heuristics
    9.
    发明授权
    System and method for detecting and repairing document-infecting viruses using dynamic heuristics 有权
    使用动态启发式检测和修复文件感染病毒的系统和方法

    公开(公告)号:US06711583B2

    公开(公告)日:2004-03-23

    申请号:US09163250

    申请日:1998-09-30

    IPC分类号: G06F700

    摘要: A method for detecting document-infecting computer viruses in a computer system having a plurality of documents, comprises the steps of maintaining a database of information associated with program objects associated with one or more of the documents, comparing one or more of the documents on the system with corresponding database entries in the database to detect certain document changes, and using a set of criteria to determine whether or not the detected document changes are likely to have been caused by viral activity.

    摘要翻译: 一种用于在具有多个文档的计算机系统中检测文件感染计算机病毒的方法,包括以下步骤:维护与一个或多个文档相关联的程序对象相关联的信息的数据库,比较一个或多个文档 系统与数据库中的相应数据库条目以检测某些文档更改,并使用一组标准来确定检测到的文档更改是否可能是由病毒活动引起的。

    Automated assistant for organizing electronic documents
    10.
    发明授权
    Automated assistant for organizing electronic documents 失效
    组织电子文件的自动助理

    公开(公告)号:US07051277B2

    公开(公告)日:2006-05-23

    申请号:US09061706

    申请日:1998-04-17

    IPC分类号: G06F15/00 G06F17/21

    摘要: A method of assisting a user with the task of categorizing a received electronic document into a collection includes the steps of classifying the document to obtain one or more most likely categorical labels; displaying, to the user, a representation of the one or more most likely categorical labels; receiving data, from the user, representative of a selected categorical label; and labeling the document within the collection with the selected categorical label. The electronic document can include an electronic mail message, a web page bookmark, an audio file or a video file.

    摘要翻译: 一种帮助用户将接收到的电子文档分类到集合中的任务的方法包括对文档进行分类以获得一个或多个最可能的分类标签的步骤; 向用户显示一个或多个最可能的分类标签的表示; 从用户接收所选分类标签的代表的数据; 并使用所选的分类标签在集合中标记文档。 电子文档可以包括电子邮件消息,网页书签,音频文件或视频文件。