The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Nov. 10, 2020

Filed:

Aug. 23, 2017
Applicant:

Nec Laboratories America, Inc., Princeton, NJ (US);

Inventors:

Xusheng Xiao, Cleveland, OH (US);

Zhichun Li, Princeton, NJ (US);

Mu Zhang, Plainsboro, NJ (US);

Guofei Jiang, Princeton, NJ (US);

Jiaping Gui, Los Angeles, CA (US);

Ding Li, West Windsor, NJ (US);

Assignee:
Attorney:
Primary Examiner:
Int. Cl.
CPC ...
G06F 7/00 (2006.01); G06F 16/2453 (2019.01); G06F 21/62 (2013.01); G06F 16/245 (2019.01); G06F 21/57 (2013.01); G06F 16/22 (2019.01);
U.S. Cl.
CPC ...
G06F 16/24532 (2019.01); G06F 16/245 (2019.01); G06F 16/24535 (2019.01); G06F 16/24545 (2019.01); G06F 21/57 (2013.01); G06F 21/6227 (2013.01); G06F 16/22 (2019.01); G06F 2221/034 (2013.01);
Abstract

Automated security systems and methods include a set monitored systems, each having one or more corresponding monitors configured to record system state information. A progressive software behavioral query language (PROBEQL) database is configured to store the system state information from the monitored systems. A query optimizing module is configured to optimize a database query for parallel execution using spatial and temporal information relating to elements in the PROBEQL database. The optimized database query is split into sub-queries with sub-queries being divided spatially according to host and temporally according to time window. A parallel execution module is configured to execute the sub-queries on the PROBEQL database in parallel. A results module is configured to output progressive results of the database query. A security control system is configured to perform a security control action in accordance with the progressive results.


Find Patent Forward Citations

Loading…