CA, Inc.

United States of America

Back to Profile

1-100 of 2,286 for CA, Inc. and 4 subsidiaries Sort by
Query
Aggregations
IP Type
        Patent 2,098
        Trademark 188
Jurisdiction
        United States 2,123
        Canada 87
        Europe 49
        World 27
Owner / Subsidiary
[Owner] CA, Inc. 2,196
Veracode, Inc. 79
Base Technologies, Inc. 5
Sterling Software, Inc., a Delaware Corporation, 4
NetQoS, Inc. (a Texas corporation) 2
Date
2026 June 1
2026 April 1
2026 (YTD) 3
2025 12
2024 10
See more
IPC Class
H04L 29/06 - Communication control; Communication processing characterised by a protocol 656
G06F 17/30 - Information retrieval; Database structures therefor 227
H04L 29/08 - Transmission control procedure, e.g. data link level control procedure 201
G06F 11/00 - Error detectionError correctionMonitoring 176
G06F 15/16 - Combinations of two or more digital computers each having at least an arithmetic unit, a program unit and a register, e.g. for a simultaneous processing of several programs 162
See more
NICE Class
09 - Scientific and electric apparatus and instruments 155
42 - Scientific, technological and industrial services, research and design 70
16 - Paper, cardboard and goods made from these materials 35
38 - Telecommunications services 14
35 - Advertising and business services 12
See more
Status
Pending 19
Registered / In Force 2,267
  1     2     3     ...     23        Next Page

1.

GENERATING CONTROL FLOW GRAPHS FOR PROGRAMS WRITTEN IN PROCEDURAL PROGRAMMING LANGUAGES

      
Application Number 18983935
Status Pending
Filing Date 2024-12-17
First Publication Date 2026-06-18
Owner CA, Inc. (USA)
Inventor
  • Baranov, Leonid
  • Shchekochikhin, Iurii

Abstract

A computer is configured to generate a control flow graph (CFG) for a program written in a procedural programming language, by performing the steps of: converting original instructions from the program into modified instructions; generating a first runtime environment and executing a first set of the modified instructions in the first runtime environment; generating first state information based on the execution of the first set of modified instructions and storing the first state information in memory; generating a second runtime environment in response to a conditional instruction from the first set of modified instructions; retrieving the first state information from the memory and executing a second set of the modified instructions in the second runtime environment based on the first state information; identifying a plurality of control change instances of the program; and generating the CFG based on the control change instances and displaying the CFG on a display device.

IPC Classes  ?

  • G06T 11/20 - Drawing from basic elements, e.g. lines or circles
  • G06F 8/41 - Compilation
  • G06F 11/3604 - Analysis of software for verifying properties of programs

2.

INFERRING TYPE DEFINITIONS OF USER-DEFINED TYPES OF VARIABLES IN APPLICATION PROGRAM CODE

      
Application Number 19339758
Status Pending
Filing Date 2025-09-25
First Publication Date 2026-04-23
Owner Veracode, Inc. (USA)
Inventor
  • Cockerham, Beth
  • Waddington, Trent Craig George

Abstract

Type definitions of user-defined types in application program code for which definitions are absent (“unknown types”) are inferred. A static analyzer implements two passes of a fixed-point type inference algorithm. Each pass encompasses a plurality of traversals of the application's control flow to build inferred definitions of unknown types until the inferred definitions are maximally built. To build an inferred definition, based on inferring a variable is an unknown type, the static analyzer infers member variables/functions of the unknown type based on contextual information associated with the variable. Type information of unknown types is propagated along control flow paths. After the first pass terminates, unknown types can be assigned known types based on matching of inferred definitions. Inferred definitions of remaining unknown types are incorporated into the application program code. A second pass of type inferencing and data flow analysis are then performed with the inferred definitions incorporated therein.

IPC Classes  ?

3.

AI CONVERSATION DRIVEN LOGIN

      
Application Number 18822601
Status Pending
Filing Date 2024-09-03
First Publication Date 2026-03-05
Owner Veracode, Inc. (USA)
Inventor
  • Schmid, Johannes
  • Milzarek, René Fred

Abstract

A login agent interacts with a foundation model(s) until successful login to an application or an assessment of a failed login can be obtained. Initially, a web page corresponding to login for a web application will be indicated to the login agent. The login agent captures interactive elements of the web page. The login agent prompts a foundation model(s) to select which of the captured interactive elements to interact with and how to interact with the selected elements. The login agent determines commands based on the response(s) and, with the commands, uses a tool to automatically interact with the web page via a browser. The login agent captures a web page resulting from the user emulated interaction and prompts the foundation model(s) to determine whether log in was successful or failed. The response from the foundation model(s) guides the login agent to either retry login or report results.

IPC Classes  ?

4.

DEVELOPMENT PIPELINE INTEGRATED ONGOING LEARNING FOR ASSISTED CODE REMEDIATION

      
Application Number 19193769
Status Pending
Filing Date 2025-04-29
First Publication Date 2025-08-14
Owner Veracode, Inc. (USA)
Inventor
  • Sharma, Asankhaya
  • Xiao, Hao
  • Chua, Hendy Heng Lee
  • Foo, Darius Tsien Wei

Abstract

With invocations of a software development pipeline, organization specific remediations/fixes for a software project can be learned from scanning results of code submissions (e.g., commits or merges) across an organization for a software project(s). Fixes of detected program code flaws can be detected and/or specified across scans and associated with flaw identifiers and used for training machine learning models to identify candidate fixes for detected flaws. This ongoing learning during development propagates fixes created or chosen by experts (e.g., software engineers working on the software project) relevant to the software project. The experts can choose from suggestions mined from the learned fixes of the organization and suggestions generated from a pipeline created with the trained machine learning models. The selections are then used for further training of the machine learning models that form the pipeline.

IPC Classes  ?

  • G06F 11/362 - Debugging of software
  • G06F 8/30 - Creation or generation of source code
  • G06F 8/36 - Software reuse
  • G06F 21/57 - Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
  • G06N 3/0464 - Convolutional networks [CNN, ConvNet]
  • G06N 3/08 - Learning methods
  • G06N 3/09 - Supervised learning
  • G06N 20/00 - Machine learning

5.

SOFTWARE DEFINED WIDE AREA NETWORK MANAGEMENT WITHIN APPLICATION PROGRAMMING INTERFACE RATE LIMITS

      
Application Number 18428848
Status Pending
Filing Date 2024-01-31
First Publication Date 2025-07-31
Owner CA, Inc. (USA)
Inventor
  • Mortha, Srinivas
  • Chevendra, Naga Naveen
  • Kakani, Balram Reddy

Abstract

The technical solutions can provide a timely and consistent monitoring of SD-WAN by combining network topology data acquired via API calls with SD-WAN performance data gathered from one or more network communication protocols. A solution can include a system, having one or more processors coupled with memory to receive, responsive to BFD monitoring, BFD session data in a first format. The BFD session data can correspond to a tunnel between devices of a SD-WAN. The one or more processors can receive, responsive to IPFIX monitoring, flow metrics in a second format, the flow metrics corresponding to one or more flows of a network traffic traversing the tunnel. The one or more processors can aggregate the BFD session data and the flow metrics into aggregated metrics according to a third format and determine an action to take based at least on the aggregated metrics in the third format.

IPC Classes  ?

  • H04L 41/0631 - Management of faults, events, alarms or notifications using root cause analysisManagement of faults, events, alarms or notifications using analysis of correlation between notifications, alarms or events based on decision criteria, e.g. hierarchy, tree or time analysis
  • H04L 41/40 - Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks using virtualisation of network functions or resources, e.g. SDN or NFV entities
  • H04L 43/0876 - Network utilisation, e.g. volume of load or congestion level
  • H04L 43/10 - Active monitoring, e.g. heartbeat, ping or trace-route

6.

APPARATUS FOR SECURE NETWORK COMMUNICATIONS

      
Application Number 18944252
Status Pending
Filing Date 2024-11-12
First Publication Date 2025-07-24
Owner CA, Inc. (USA)
Inventor
  • Du Toit, Roelof
  • Tomic, Gary
  • Taft, James

Abstract

An embodiment of the present invention describes means by which a proxy can maintain visibility between a client and a server when the client initiates a Transport Layer Security connection with Encrypted Client Hello (ECH). The proxy uses intelligence data has the ability to identify connections between clients and servers that are utilizing the Encrypted Client Hello extension to Transport Layer Security (TLS) Protocol Version 1.3 and triggers the client to fallback to utilizing a new connection that does not utilize ECH. This preserves the proxy's ability to determine the true destination of the client and identify the risks and characteristics of the request and response and act based on the administrator's authored policy.

IPC Classes  ?

7.

GENERATING AN EFFICIENT GRAPH DATABASE FOR RELATIONSHIP QUERYING AND CYBERSECURITY ANALYSIS

      
Application Number 19012397
Status Pending
Filing Date 2025-01-07
First Publication Date 2025-07-10
Owner Veracode, Inc. (USA)
Inventor
  • Clements, Cody Allan
  • Lang, Louis
  • Freitag, Eric
  • Donoughe, Matthew

Abstract

In an embodiment, a method for generating a graph database includes identifying at least one new package in at least one source database and generating a download request associated with the at least one new package. The method includes, based on the download request, downloading the at least one new package from the at least one source database associated with the at least one new package. The method includes preprocessing the at least one new package to define at least one text representation of the at least one new package. The method includes cataloging the at least one new package based on the at least one text representation and generating a graph database based on the cataloged at least one package.

IPC Classes  ?

  • G06F 21/56 - Computer malware detection or handling, e.g. anti-virus arrangements
  • G06F 8/36 - Software reuse
  • G06F 16/901 - IndexingData structures thereforStorage structures

8.

Unified topology across domains

      
Application Number 18497503
Grant Number 12413478
Status In Force
Filing Date 2023-10-30
First Publication Date 2025-05-01
Grant Date 2025-09-09
Owner CA, Inc. (USA)
Inventor
  • Mortha, Srinivas
  • Chevendra, Naga Naveen

Abstract

A device to detect a first piece of equipment of a plurality of pieces of equipment, identify a first node of a plurality of nodes that represents the first piece of equipment of the plurality of pieces of equipment, receive an identification of the first piece of equipment of the plurality of pieces of equipment, update a record to include the identification of the first piece of equipment of the plurality of pieces of equipment and an indication that the first node of the plurality of nodes represents the first piece of equipment of the plurality of pieces of equipment, determine that a second piece of equipment of the plurality of pieces of equipment is absent from a first section of the plurality of sections, and query one or more devices of a plurality of devices to identify the second piece of equipment of the plurality of pieces of equipment.

IPC Classes  ?

  • H04L 41/12 - Discovery or management of network topologies
  • H04L 41/0604 - Management of faults, events, alarms or notifications using filtering, e.g. reduction of information by using priority, element types, position or time
  • H04L 41/22 - Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks comprising specially adapted graphical user interfaces [GUI]

9.

SYSTEM AND METHOD FOR CANVAS SANITIZATION

      
Application Number 18479358
Status Pending
Filing Date 2023-10-02
First Publication Date 2025-04-03
Owner CA, Inc. (USA)
Inventor Back, Ophir

Abstract

Novel systems and methods for canvas sanitization are provided. In various embodiments, a system and method include: receiving a request to open a web page from a client device; replacing, via an agent, a first function with a second function, the agent being loaded to a browser; loading the web page from a web server to the browser; in response to an attempt to perform the first function on the web page, performing, via the browser, the second function corresponding to the first function to generate a drawing for a predetermined period of time; converting, via the agent, the drawing to an image; and transmitting the image to the client device. Other aspects, embodiments, and features are also claimed and described.

IPC Classes  ?

10.

AUTO-FIXING CODE VULNERABILITIES WITH ARTIFICIAL INTELLIGENCE

      
Application Number 18973698
Status Pending
Filing Date 2024-12-09
First Publication Date 2025-04-03
Owner Veracode, Inc. (USA)
Inventor
  • Rudenko, Roman
  • Bacher, Anna

Abstract

A generative artificial intelligence (AI) driven code fixing pipeline has been created that uses a large language model (LLM) to recommend fixes for vulnerabilities detected in program code. A scanner generates indications of flaws in program code and weakness types for those flaws. One or more example code pairs are retrieved based on weakness type and programming language, an example code pair including an example flaw and an example fix of that flaw. The LLM is then prompted with a code fragment corresponding to a detected vulnerability, context for the code fragment, and the one or more example code pairs to generate a modification of existing program code that fixes the vulnerability.

IPC Classes  ?

  • G06F 11/36 - Prevention of errors by analysis, debugging or testing of software
  • G06F 8/35 - Creation or generation of source code model driven
  • G06F 8/36 - Software reuse
  • G06N 20/00 - Machine learning

11.

Providing encrypted end-to-end email delivery between secure email clusters

      
Application Number 18465285
Grant Number 12613981
Status In Force
Filing Date 2023-09-12
First Publication Date 2025-03-13
Grant Date 2026-04-28
Owner CA, Inc. (USA)
Inventor Biswas, Dhrubojyoti

Abstract

The systems and methods described provide a seamless end-to-end email delivery between secure email clusters without reliance on prior sharing of encryption keys or protocol configurations. The solution can receive a request to transmit an email to a recipient identified by a domain of the recipient. The solution can transmit a first query to a domain name service (DNS) to fetch one or more records corresponding to the domain of the recipient. The one or more records can identify a key service. The solution can receive, from the key service responsive to a second query to the key service, a key for encrypting the email. The solution can encrypt at least a portion of the email based at least on the key and transmit the encrypted email to the recipient.

IPC Classes  ?

  • G06F 21/60 - Protecting data
  • H04L 51/48 - Message addressing, e.g. address format or anonymous messages, aliases

12.

Network security device

      
Application Number 18362881
Grant Number 12407653
Status In Force
Filing Date 2023-07-31
First Publication Date 2025-02-06
Grant Date 2025-09-02
Owner CA, INC. (USA)
Inventor
  • Du Toit, Roelof Nico
  • Tomic, Gary
  • Zuercher, Chris
  • Elkadri, Nour Alhouda

Abstract

Operations of a security device are provided herein. The operations may include receiving, via a first network interface, a network packet, and evaluating attributes of the received network packet against a ruleset to identify a first rule match, wherein the attributes comprise an identifier of the first network interface, a source address, and a destination address. The operations may further include comparing the attributes of the received network packet against a table listing one or more network devices associated with the first network interface or a second network interface. The operations may further include switching the attributes of the received network packet by changing the identifier of the first network interface to an identifier of the second network interface and swapping the source address and the destination address, and evaluating the switched attributes of the received network packet against the ruleset to identify a second rule match. The switched attributes of the received network packet may be compared against the table, and one of the first rule match or the second rule match may be selected based on the comparisons of the network packet attributes and the switched network packet attributes against the table. The received network packet may be processed according to the selected one of the first rule match or the second rule match.

IPC Classes  ?

13.

Monitoring network volatility

      
Application Number 18362920
Grant Number 12192083
Status In Force
Filing Date 2023-07-31
First Publication Date 2025-01-07
Grant Date 2025-01-07
Owner CA, Inc. (USA)
Inventor
  • Cosgrove, David
  • Murdough, John
  • Normandin, Jason
  • Diep, Tim

Abstract

Novel solutions for monitoring and analyzing networks in terms of the volatility of various devices. Some solutions consider a weighted set of metrics in determining such volatility. Evaluation of devices against peers in view of these factors can produce insight about network conditions.

IPC Classes  ?

  • H04L 43/0817 - Monitoring or testing based on specific metrics, e.g. QoS, energy consumption or environmental parameters by checking availability by checking functioning
  • H04L 43/045 - Processing captured monitoring data, e.g. for logfile generation for graphical visualisation of monitoring data
  • H04L 43/062 - Generation of reports related to network traffic

14.

Generative artificial intelligence driven software fixing

      
Application Number 18464436
Grant Number 12229040
Status In Force
Filing Date 2023-09-11
First Publication Date 2025-01-02
Grant Date 2025-02-18
Owner Veracode, Inc. (USA)
Inventor
  • Rudenko, Roman
  • Bacher, Anna

Abstract

A generative artificial intelligence (AI) driven code fixing pipeline has been created that uses a transformer-based large language model (LLM) to patch flawed program code. A pre-trained LLM is fine-tuned to generate a response that is a modified version of a code fragment in a prompt to the pre-trained model. After fine-tuning, the pre-trained LLM (hereinafter “code fix model”) is integrated into a pipeline that includes a program code cybersecurity scanner and a prompt generator. The scanner generates indications of flaws in program code and weakness types for those flaws. These indications flow into the prompt generator. The prompt generator retrieves reference code pairs based on weakness type and programming language to generate a batch of prompts to run inference on with the code fix model. The responses generated by the code fix model are presented as patching alternatives.

IPC Classes  ?

15.

Machine learning model based ranking of generated code

      
Application Number 18464536
Grant Number 12566593
Status In Force
Filing Date 2023-09-11
First Publication Date 2025-01-02
Grant Date 2026-03-03
Owner Veracode, Inc. (USA)
Inventor
  • Rudenko, Roman
  • Bacher, Anna

Abstract

A generative AI based pipeline has been created that ranks generated responses that are candidate software patches. The ranking is based on predicted quality measures of code fragments within a corresponding prompt to a generated AI model. The predicted quality measures are generated by a machine learning model that has been trained based on features that are values/measures of similarity metrics between code fragments, between code fragment changes, between code structures, and/or between changes of code structures.

IPC Classes  ?

16.

SYSTEMS AND METHODS FOR PRESERVING SYSTEM CONTEXTUAL INFORMATION IN AN ENCAPSULATED PACKET

      
Application Number 18806063
Status Pending
Filing Date 2024-08-15
First Publication Date 2024-12-05
Owner CA, INC. (USA)
Inventor
  • Mcconnaughay, Mark
  • Tomic, Gary
  • Frederick, Ron

Abstract

In some embodiments, a computing system includes a communication interface; and a processor that is coupled to the communication interface. In some embodiments, least one of the communication interface or the processor receives a network packet from the network via a network adapter port; encapsulates the received network packet with a tunnel header, wherein the tunnel header comprises network identifier information identifying the network adapter port; addresses, based on the network identifier information, an outer Internet protocol (IP) header of the encapsulated network packet with an outer IP address corresponding to a network function in a first computing device; and sends the encapsulated network packet toward the network function identified by the outer IP address.

IPC Classes  ?

  • H04L 12/46 - Interconnection of networks
  • H04L 61/251 - Translation of Internet protocol [IP] addresses between different IP versions
  • H04L 67/1001 - Protocols in which an application is distributed across nodes in the network for accessing one among a plurality of replicated servers
  • H04L 69/167 - Adaptation for transition between two IP versions, e.g. between IPv4 and IPv6
  • H04L 69/22 - Parsing or analysis of headers

17.

LANGUAGE-INDEPENDENT APPLICATION MONITORING THROUGH ASPECT-ORIENTED PROGRAMMING

      
Application Number 18789231
Status Pending
Filing Date 2024-07-30
First Publication Date 2024-11-21
Owner Veracode, Inc. (USA)
Inventor
  • Rioux, Christien R.
  • Layzell, Robert Anthony

Abstract

To support adding functionality to applications at a layer of abstraction above language-specific implementations of AOP, a language for implementing AOP facilitates runtime monitoring and analysis of an application independent of the language of the application. Aspects can be created for applications written in any supported language. Program code underlying implementations of aspects can be executed based on detecting triggering events during execution of the application. Routines written with the AOP language comprise event-based aspect code triggers that indicate an event which may occur during execution of the application and the associated aspect code to be executed. An agent deployed to a runtime engine to monitor the application detects events and evaluates contextual information about the detected events against the aspect triggers to determine if aspect code should be executed to perform further monitoring and analysis of the executing application.

IPC Classes  ?

  • G06F 21/57 - Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
  • G06F 8/30 - Creation or generation of source code
  • G06F 8/41 - Compilation
  • G06F 11/36 - Prevention of errors by analysis, debugging or testing of software

18.

RENAMING GLOBAL VARIABLES BASED ON INFERRED TYPES OF VARIABLES IN APPLICATION PROGRAM CODE

      
Application Number 18194596
Status Pending
Filing Date 2023-03-31
First Publication Date 2024-10-03
Owner Veracode, Inc. (USA)
Inventor Cockerham, Beth

Abstract

After a first pass of type inferencing for application program code, global variables that share a name but correspond to different types and thus also correspond to different memory locations are identified and renamed. A static analyzer evaluates identified variables and their inferred types from the first pass of type inferencing and, if two global variables having a same name but different types are identified based on multiple disparate types being inferred for one global variable, the global variables are distinguished via renaming of at least one of the global variables before a second pass of type inferencing and data flow analysis are performed for the program code having the renaming incorporated. Renaming a global variable(s) in the case of same-named but differently typed global variables distinguishes the instances of the global variable to provide for correct propagation of type information and values without ambiguity for improved data flow analysis.

IPC Classes  ?

19.

Inferring type definitions of user-defined types of variables in application program code

      
Application Number 18194599
Grant Number 12436749
Status In Force
Filing Date 2023-03-31
First Publication Date 2024-10-03
Grant Date 2025-10-07
Owner Veracode, Inc. (USA)
Inventor
  • Cockerham, Beth
  • Waddington, Trent Craig George

Abstract

Type definitions of user-defined types in application program code for which definitions are absent (“unknown types”) are inferred. A static analyzer implements two passes of a fixed-point type inference algorithm. Each pass encompasses a plurality of traversals of the application's control flow to build inferred definitions of unknown types until the inferred definitions are maximally built. To build an inferred definition, based on inferring a variable is an unknown type, the static analyzer infers member variables/functions of the unknown type based on contextual information associated with the variable. Type information of unknown types is propagated along control flow paths. After the first pass terminates, unknown types can be assigned known types based on matching of inferred definitions. Inferred definitions of remaining unknown types are incorporated into the application program code. A second pass of type inferencing and data flow analysis are then performed with the inferred definitions incorporated therein.

IPC Classes  ?

20.

Runtime application monitoring without modifying application program code

      
Application Number 18680130
Grant Number 12475232
Status In Force
Filing Date 2024-05-31
First Publication Date 2024-09-26
Grant Date 2025-11-18
Owner Veracode, Inc. (USA)
Inventor
  • Rioux, Christien R.
  • Layzell, Robert Anthony

Abstract

To facilitate runtime monitoring and analysis of an application without modifying the actual application code, an agent monitors and analyzes an application through detection and evaluation of invocations of an API of a runtime engine provided for execution of the application. The agent registers to receive events which are generated upon invocation of target functions of the runtime engine API based on its load. Once loaded, the agent initially determines the language and language version number of the runtime engine. The agent determines associations of events for which to monitor and corresponding analysis code to execute upon detection of the invocations based on the language and version number information. When the agent detects an event during execution of the application based on invocations of the runtime engine API, the agent can monitor and analyze execution of the application based on execution of analysis code corresponding to the detected event.

IPC Classes  ?

  • G06F 11/00 - Error detectionError correctionMonitoring
  • G06F 11/30 - Monitoring
  • G06F 11/3604 - Analysis of software for verifying properties of programs
  • G06F 21/57 - Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities

21.

AUTOMATED TRIAGE OF CODE FLAWS WITH MACHINE LEARNING

      
Application Number 18181951
Status Pending
Filing Date 2023-03-10
First Publication Date 2024-09-12
Owner Veracode, Inc. (USA)
Inventor Tahir, Humza

Abstract

Flaws in a codebase for an organization are triaged with a naïve Bayes classifier that determines likelihoods of triage decisions corresponding to actions (e.g., remediating via code change, deferring to due network mitigation, labeling as false positive) given the context of the flaw, application, and organization. The naïve Bayes classifier is trained on the triage outcomes of previously detected flaw instances in the codebase and provides interpretable results including feature-level likelihood scores of each triage approach. In addition to recommending the highest likelihood triage outcome provided by the naïve Bayes model, a flaw similarity model identifies previously triaged flaw instances from the organization to recommend more granular triage instructions that have been documented alongside the previous flaw instances.

IPC Classes  ?

  • G06F 21/57 - Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities

22.

Systems of and methods for managing tenant and user identity information in a multi-tenant environment

      
Application Number 18307305
Grant Number 12493673
Status In Force
Filing Date 2023-04-26
First Publication Date 2024-07-25
Grant Date 2025-12-09
Owner CA, Inc. (USA)
Inventor
  • Yeh, Wei Jen
  • Tomic, Gary

Abstract

A system and method for managing user identity information in a multi-tenant environment can perform operations including assigning a first address from an address pool for a first user session, storing first information for the first user session in the memory linked to the first address, and assigning a second address from the address pool for a second user session. The operations can also include storing second information for the second user session in the memory linked to the second address from the address pool for the second user session if the second address does not match a third address from the address pool for a third session in the memory, and forwarding communication data for the second user session after the second information has been stored.

IPC Classes  ?

23.

SECOND PARTY SOFTWARE COMPONENTS DISCOVERY

      
Application Number 18153530
Status Pending
Filing Date 2023-01-12
First Publication Date 2024-07-18
Owner Veracode, Inc. (USA)
Inventor
  • Trotter, William Alger
  • Fielding, Anthony Christopher

Abstract

Identifying a second party reusable software component involves analyzing source code of applications to identify an external dependency that does not refer to third party software components and occurs in multiple applications. After identifying second party software components, the occurrence of the external dependencies corresponding to second party software components can be reported and can facilitate triage of flaws found for the second party software components, as well as other component management actions (e.g., increasing collaboration and communication among teams using and creating reusable software components, version awareness, flaw surface awareness, etc.).

IPC Classes  ?

  • G06F 11/36 - Prevention of errors by analysis, debugging or testing of software

24.

Virtual network interface management for network functions using network definitions

      
Application Number 18081533
Grant Number 11979292
Status In Force
Filing Date 2022-12-14
First Publication Date 2024-05-07
Grant Date 2024-05-07
Owner CA, Inc. (USA)
Inventor
  • Mcconnaughay, Mark
  • Frederick, Ronald Andrew
  • Szepesi, Szaniszlo Tyler

Abstract

Network rules established on a device can establish communication protocol between applications running on the device and interfaces connected to the device. For example, a network rule can establish which application(s) can access which interface(s), and when an application is not assigned to an interface, the application is not granted network access to the interface(s). In some instances, interfaces can be aggregated together to create an aggregation (e.g., link aggregation or a bridge aggregation), thus allowing the network rule to use the aggregation for multiple applications. An aggregation, such as a link aggregation, can be established as a shared rule that allows access to the interface by multiple applications. Alternatively, an aggregation, such as a bridge aggregation, can be established as a reserve rule that permits only a particular application, and no other application(s), access to the interface.

IPC Classes  ?

25.

INTERCEPT FOR ENCRYPTED COMMUNICATIONS

      
Application Number 18071435
Status Pending
Filing Date 2022-11-29
First Publication Date 2024-02-08
Owner CA, Inc. (USA)
Inventor
  • Du Toit, Roelof Nico
  • Tomic, Gary
  • Frederick, Ronald Andrew

Abstract

Aspects of the disclosure include replacing, by a DNS proxy in DNS responses, a cryptographic key associated with a client-facing server for an origin content server with another cryptographic key received from a TLS proxy. A device may encrypt an extension of a ClientHello message with the other cryptographic key, such that the encrypted ClientHello (ECH) extension can be decrypted by the TLS proxy. The TLS proxy can then allow or deny the connection using a TLS intercept policy and decrypted information in the ClientHello message, and if the TLS connection is allowed, re-encrypt the ECH with the cryptographic key in the DNS response for the client-facing server to decrypt for establishment of the TLS connection with the origin content server. To preserve selective intercept while using ECH, a TLS Intercept Policy may be used to decide whether the TLS proxy feeds an Application Layer Proxy.

IPC Classes  ?

26.

Systems and methods for preparing a secure search index for securely detecting personally identifiable information

      
Application Number 16427884
Grant Number 11853454
Status In Force
Filing Date 2019-05-31
First Publication Date 2023-12-26
Grant Date 2023-12-26
Owner CA, Inc. (USA)
Inventor
  • Tarsi, Yuval
  • Emiliozzi, Stefano

Abstract

The disclosed computer-implemented method for preparing a secure search index for securely detecting personally identifiable information may include (i) receiving, at a computing device, a dataset including a record, where the record has a field including a value describing personally identifiable information and (ii) performing, at the computing device, a security action. The security action may include (i) generating, using a perfect hash function, a respective hashed key from the value and (ii) adding, to the secure search index (a) the respective hashed key or (b) a subsequent hashed key created from the respective hashed key. Various other methods, systems, and computer-readable media are also disclosed.

IPC Classes  ?

  • G06F 21/62 - Protecting access to data via a platform, e.g. using keys or access control rules
  • H04L 9/32 - Arrangements for secret or secure communicationsNetwork security protocols including means for verifying the identity or authority of a user of the system
  • H04L 9/08 - Key distribution
  • H04L 9/06 - Arrangements for secret or secure communicationsNetwork security protocols the encryption apparatus using shift registers or memories for blockwise coding, e.g. D.E.S. systems
  • G06F 21/60 - Protecting data

27.

Development pipeline integrated ongoing learning for assisted code remediation

      
Application Number 18250794
Grant Number 12306739
Status In Force
Filing Date 2020-10-29
First Publication Date 2023-12-21
Grant Date 2025-05-20
Owner Veracode, Inc. (USA)
Inventor
  • Sharma, Asankhaya
  • Xiao, Hao
  • Chua, Hendy Heng Lee
  • Foo, Darius Tsien Wei

Abstract

With invocations of a software development pipeline, organization specific remediations/fixes for a software project can be learned from scanning results of code submissions (e.g., commits or merges) across an organization for a software project(s). Fixes of detected program code flaws can be detected and/or specified across scans and associated with flaw identifiers and used for training machine learning models to identify candidate fixes for detected flaws. This ongoing learning during development propagates fixes created or chosen by experts (e.g., software engineers working on the software project) relevant to the software project. The experts can choose from suggestions mined from the learned fixes of the organization and suggestions generated from a pipeline created with the trained machine learning models. The selections are then used for further training of the machine learning models that form the pipeline.

IPC Classes  ?

  • G06F 11/36 - Prevention of errors by analysis, debugging or testing of software
  • G06F 8/30 - Creation or generation of source code
  • G06F 8/36 - Software reuse
  • G06F 11/362 - Debugging of software
  • G06F 21/57 - Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
  • G06N 3/0464 - Convolutional networks [CNN, ConvNet]
  • G06N 3/08 - Learning methods
  • G06N 20/00 - Machine learning
  • G06N 3/09 - Supervised learning

28.

AP4z

      
Application Number 018907863
Status Registered
Filing Date 2023-07-31
Registration Date 2023-11-11
Owner CA, Inc. (USA)
NICE Classes  ? 09 - Scientific and electric apparatus and instruments

Goods & Services

Software; Server software; Downloadable software.

29.

O1

      
Application Number 1742432
Status Registered
Filing Date 2023-06-26
Registration Date 2023-06-26
Owner Veracode, Inc. (USA)
NICE Classes  ? 42 - Scientific, technological and industrial services, research and design

Goods & Services

Computer software risk assessment services; computer security services in the nature of network security assessments; providing temporary use of non-downloadable cloud-based software for detecting and identifying access to computer networks and resources, performing vulnerability scans, and/or penetration testing; computer software consultation, namely, providing an online, automated, on-demand service for identifying exploitable vulnerabilities in software.

30.

AP4Z

      
Serial Number 98084095
Status Pending
Filing Date 2023-07-13
Owner CA, INC. ()
NICE Classes  ? 09 - Scientific and electric apparatus and instruments

Goods & Services

Computer software, namely, downloadable computer utility program for analyzing function and performance of other computer programs; server software, namely, downloadable computer utility program for analyzing function and performance of other computer programs

31.

O1

      
Application Number 227193900
Status Registered
Filing Date 2023-06-26
Registration Date 2025-11-07
Owner Veracode, Inc. (USA)
NICE Classes  ? 42 - Scientific, technological and industrial services, research and design

Goods & Services

(1) Computer software risk assessment services; computer security services in the nature of network security assessments; providing temporary use of non-downloadable cloud-based security software for detecting and identifying access to computer networks and resources, performing vulnerability scans, and/or penetration testing; computer software consultation, namely, providing an online, automated, on-demand service for identifying exploitable vulnerabilities in software.

32.

O1

      
Application Number 1734410
Status Registered
Filing Date 2023-04-25
Registration Date 2023-04-25
Owner Veracode, Inc. (USA)
NICE Classes  ? 42 - Scientific, technological and industrial services, research and design

Goods & Services

Computer software risk assessment services; Computer security services in the nature of network security assessments; providing temporary use of non-downloadable cloud-based software for detecting and identifying access to computer networks and resources, performing vulnerability scans, and penetration testing; Computer software consultation, namely, providing an online, automated, on-demand service for identifying exploitable vulnerabilities in software.

33.

DEIDENTIFYING CODE FOR CROSS-ORGANIZATION REMEDIATION KNOWLEDGE

      
Application Number 17754194
Status Pending
Filing Date 2020-11-10
First Publication Date 2023-05-18
Owner Veracode, Inc. (USA)
Inventor
  • Sharma, Asankhaya
  • Xiao, Hao
  • Chua, Hendy Heng Lee
  • Foo, Darius Tsien Wei

Abstract

To preserve privacy when leveraging organization-specific remediation knowledge for flaw remediation across organizations, program code is deidentified to remove code which potentially identifies its source/origin. Deidentification operates based on structure of flaws and fixes at the level of source code constructs based on an abstract syntax tree (AST) or other structural context representation of a fix and corresponding flaw. Potentially identifying portions of a fix indicated in its AST are determined and modified (e.g., removed or obfuscated) without impacting AST structure. Deidentified remediation knowledge originating from different organizations is used to train a fix suggestion model(s) which learns structural context of fixes and corresponding flaws and, once trained, generates predictions indicating suggested fixes to flaws based on structural contexts of the flaws. Deidentification can occur before training of the fix suggestion model(s) or during prediction so potentially identifying program code is removed before suggested fixes are consumed by different organizations.

IPC Classes  ?

  • G06F 21/62 - Protecting access to data via a platform, e.g. using keys or access control rules
  • G06F 8/40 - Transformation of program code

34.

01 O1

      
Application Number 226262200
Status Registered
Filing Date 2023-04-25
Registration Date 2025-11-07
Owner Veracode, Inc. (USA)
NICE Classes  ? 42 - Scientific, technological and industrial services, research and design

Goods & Services

(1) Computer software risk assessment services; Computer security services in the nature of network security assessments; providing temporary use of non-downloadable cloud-based security software for detecting and identifying access to computer networks and resources, performing vulnerability scans, and penetration testing; Computer software consultation, namely, providing an online, automated, on-demand service for identifying exploitable vulnerabilities in software.

35.

Securing cloud applications via isolation

      
Application Number 16354751
Grant Number 11558383
Status In Force
Filing Date 2019-03-15
First Publication Date 2023-01-17
Grant Date 2023-01-17
Owner CA, Inc. (USA)
Inventor
  • Au Yeung, Alex
  • Kanfer, Amit
  • Saha, Arunabha
  • Sharma, Manoj Kumar
  • Kao, Paul
  • Prabhu, Prashanth
  • Daigle, Russell
  • Pischl, Tobias
  • Chen, Yehoshua

Abstract

A method for securing cloud applications is described. The method may include establishing a connection between a cloud application isolation portal, a cloud access security broker, and a cloud application based on an indication of the cloud application and a set of credentials associated with an end user of the cloud application, and managing, via the cloud application isolation portal and the cloud access security broker, a session between the cloud application and a computing device associated with the end user based on the connection between the cloud application isolation portal with the cloud access security broker and the cloud application.

IPC Classes  ?

  • H04L 67/60 - Scheduling or organising the servicing of application requests, e.g. requests for application data transmissions using the analysis and optimisation of the required network resources
  • H04L 67/10 - Protocols in which an application is distributed across nodes in the network
  • H04L 9/40 - Network security protocols

36.

Machine learning adversarial campaign mitigation on a computing device

      
Application Number 16399725
Grant Number 11551137
Status In Force
Filing Date 2019-04-30
First Publication Date 2023-01-10
Grant Date 2023-01-10
Owner CA, Inc. (USA)
Inventor
  • Echauz, Javier
  • Gardner, Andrew B.
  • Kenemer, John Keith
  • Dhaliwal, Jasjeet
  • Shintre, Saurabh

Abstract

Machine learning adversarial campaign mitigation on a computing device. The method may include deploying an original machine learning model in a model environment associated with a client device; deploying a classification monitor in the model environment to monitor classification decision outputs in the machine learning model; detecting, by the classification monitor, a campaign of adversarial classification decision outputs in the machine learning model; applying a transformation function to the machine learning model in the model environment to transform the adversarial classification decision outputs to thwart the campaign of adversarial classification decision outputs; determining a malicious attack on the client device based in part on detecting the campaign of adversarial classification decision outputs; and implementing a security action to protect the computing device against the malicious attack.

IPC Classes  ?

  • G06F 21/00 - Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
  • G06N 20/00 - Machine learning
  • G06F 21/56 - Computer malware detection or handling, e.g. anti-virus arrangements
  • G06K 9/62 - Methods or arrangements for recognition using electronic means

37.

O1

      
Serial Number 97735311
Status Pending
Filing Date 2022-12-29
Owner Veracode, Inc. (USA)
NICE Classes  ? 42 - Scientific, technological and industrial services, research and design

Goods & Services

Computer software cybersecurity vulnerabilities risk assessment services; Computer security services in the nature of network security assessments; providing temporary use of non-downloadable cloud-based software for detecting and identifying access to computer networks and resources, performing vulnerability scans, and application security penetration testing; Computer software consultation, namely, providing an online, automated, on-demand service for identifying exploitable vulnerabilities in software

38.

Knowledge-aware detection of attacks on a client device conducted with dual-use tools

      
Application Number 16367599
Grant Number 11496489
Status In Force
Filing Date 2019-03-28
First Publication Date 2022-11-08
Grant Date 2022-11-08
Owner CA, Inc. (USA)
Inventor
  • Grzonkowski, Slawomir
  • Roturier, Johann
  • Banerjee, Pratyush
  • Silva, David L.

Abstract

Knowledge-aware detection of attacks on a client device conducted with dual-use tools. A method may include obtaining dual-use tool data related to a plurality of dual-use tools; collecting from a client device, by the computing device, user input related to the use of a dual-use tool of the plurality of dual-use tools; determining that the user input contains a feature of the dual-use tool data; creating a behavioral index of the user input, the behavioral index stored on the client device; detecting new input on the client device; determining a similarity level between the user input and the new input; flagging a malicious attack on the client device based on determining that the similarity level does not satisfy a pre-determined threshold; and implementing a security action on the client device based on flagging the malicious attack.

IPC Classes  ?

39.

O1

      
Serial Number 97652623
Status Pending
Filing Date 2022-10-28
Owner Veracode, Inc. (USA)
NICE Classes  ? 42 - Scientific, technological and industrial services, research and design

Goods & Services

Computer software cybersecurity vulnerabilities risk assessment services; Computer security services in the nature of network security assessments; providing temporary use of non-downloadable cloud-based software for detecting and identifying access to computer networks and resources, performing vulnerability scans, and application security penetration testing; Computer software consultation, namely, providing an online, automated, on-demand service for identifying exploitable vulnerabilities in software

40.

Secure access to a corporate web application with translation between an internal address and an external address

      
Application Number 17863998
Grant Number 11665171
Status In Force
Filing Date 2022-07-13
First Publication Date 2022-10-27
Grant Date 2023-05-30
Owner CA, Inc. (USA)
Inventor
  • Patimer, David
  • Lev-Tov, Lior
  • Rudich, Eldad
  • Belkind, Leonid

Abstract

Secure access to a corporate application with translation between an internal address and an external address. In some embodiments, a method may include receiving, at a secure access cloud point of delivery (PoD), from a client application on a client device, a request to access a corporate web application that is deployed in a corporate datacenter. The method may also include forwarding, from the secure access cloud PoD, to a connector that is also deployed in the corporate datacenter, the request to access the corporate web application. The method may further include brokering, by the connector and the secure access cloud PoD, authentication of a user, authorization of access by the user, and a secure communication session between the client application and the corporate web application by translating between an internal address of the corporate web application and an external address of the corporate web application.

IPC Classes  ?

  • G06F 21/33 - User authentication using certificates
  • H04L 9/40 - Network security protocols
  • G06F 9/451 - Execution arrangements for user interfaces
  • G06F 21/30 - Authentication, i.e. establishing the identity or authorisation of security principals

41.

CLARITY

      
Application Number 221805100
Status Registered
Filing Date 2022-10-26
Registration Date 2026-04-22
Owner CA, Inc. (USA)
NICE Classes  ?
  • 09 - Scientific and electric apparatus and instruments
  • 42 - Scientific, technological and industrial services, research and design

Goods & Services

(1) Downloadable computer programs for project management, digital product management, work collaboration, information technology portfolio management, and business process management (1) Software as a service (SaaS) services featuring non-downloadable, cloud-based computer programs for project management, digital product management, work collaboration, information technology portfolio management, and business process management

42.

VALUEOPS

      
Application Number 221804700
Status Registered
Filing Date 2022-10-26
Registration Date 2026-03-02
Owner CA, Inc. (USA)
NICE Classes  ? 42 - Scientific, technological and industrial services, research and design

Goods & Services

(1) Software as a service (SAAS) services featuring software for project management, digital product management, work collaboration, and computer software development and implementation

43.

CLARITY

      
Application Number 018783571
Status Registered
Filing Date 2022-10-25
Registration Date 2025-06-14
Owner CA, Inc. (USA)
NICE Classes  ?
  • 09 - Scientific and electric apparatus and instruments
  • 42 - Scientific, technological and industrial services, research and design

Goods & Services

Downloadable computer programs for project management, product management, work collaboration, information technology portfolio management, and business process management, all aforementioned goods only in the context of financial investment management software and not in the context of security, law-enforcement, defense and military software; none of the aforementioned goods in the context of energy production and distribution; none of the aforementioned goods in the context of chemistry for health sciences, biomedicine, biology, biotechnology, clinical biochemistry, pharmaceutical and pharmacology chemistry. Providing online, non-downloadable, cloud-based computer programs for project management, product management, work collaboration, information technology portfolio management, and business process management, all aforementioned services only in the context of financial investment management software and not in the context of security, law-enforcement, defense and military software; none of the aforementioned services in the context of energy production and distribution; none of the aforementioned services in the context of chemistry for health sciences, biomedicine, biology, biotechnology, clinical biochemistry, pharmaceutical and pharmacology chemistry.

44.

VALUEOPS

      
Application Number 018783575
Status Registered
Filing Date 2022-10-25
Registration Date 2023-04-18
Owner CA, Inc. (USA)
NICE Classes  ? 42 - Scientific, technological and industrial services, research and design

Goods & Services

Software as a service (SAAS) services featuring software for project management, product management, work collaboration, and software development and implementation.

45.

Open source vulnerability prediction with machine learning ensemble

      
Application Number 17809425
Grant Number 11899800
Status In Force
Filing Date 2022-06-28
First Publication Date 2022-10-13
Grant Date 2024-02-13
Owner Veracode, Inc. (USA)
Inventor
  • Sharma, Asankhaya
  • Zhou, Yaqin

Abstract

A system to create a stacked classifier model combination or classifier ensemble has been designed for identification of undisclosed flaws in software components on a large-scale. This classifier ensemble is capable of at least a 54.55% improvement in precision. The system uses a K-folding cross validation algorithm to partition a sample dataset and then train and test a set of N classifiers with the dataset folds. At each test iteration, trained models of the set of classifiers generate probabilities that a sample has a flaw, resulting in a set of N probabilities or predictions for each sample in the test data. With a sample size of S, the system passes the S sets of N predictions to a logistic regressor along with “ground truth” for the sample dataset to train a logistic regression model. The trained classifiers and the logistic regression model are stored as the classifier ensemble.

IPC Classes  ?

  • G06F 21/57 - Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
  • G06N 20/00 - Machine learning
  • G06N 7/01 - Probabilistic graphical models, e.g. probabilistic networks

46.

CLARITY

      
Serial Number 97619256
Status Registered
Filing Date 2022-10-04
Registration Date 2024-06-18
Owner CA, Inc. ()
NICE Classes  ?
  • 09 - Scientific and electric apparatus and instruments
  • 42 - Scientific, technological and industrial services, research and design

Goods & Services

Downloadable computer programs for project management, product management, work collaboration, information technology portfolio management, and business process management; all aforementioned goods/services only in the context of financial investment management software and not in the context of security, law-enforcement, defense and military software Non-downloadable, cloud-based computer programs for project management, product management, work collaboration, information technology portfolio management, and business process management; all aforementioned goods/services only in the context of financial investment management software and not in the context of security, law-enforcement, defense and military software

47.

VALUEOPS

      
Serial Number 97619268
Status Registered
Filing Date 2022-10-04
Registration Date 2024-01-16
Owner CA, Inc. ()
NICE Classes  ? 42 - Scientific, technological and industrial services, research and design

Goods & Services

Software as a service (SAAS) services featuring software for project management, product management, work collaboration, and software development and implementation

48.

Systems and methods for producing adjustments to malware-detecting services

      
Application Number 16138939
Grant Number 11461462
Status In Force
Filing Date 2018-09-21
First Publication Date 2022-10-04
Grant Date 2022-10-04
Owner CA, Inc. (USA)
Inventor
  • Lan, Qichao
  • Zhu, Junda
  • Shu, Shaolong
  • Cheng, Tao
  • Senstad, Rudy

Abstract

The disclosed computer-implemented method for producing adjustments to malware-detecting services may include (1) receiving, from a plurality of malware-detecting services executing on a plurality of client computing devices, a respective plurality of probability scores with corresponding model identifiers for an analyzed file and a plurality of respective identifiers describing the malware-detecting services, (2) building a training dataset from at least a portion of the received plurality of probability scores with corresponding model identifiers, and (3) performing a security action including (A) training, with the training dataset, a malware-detecting linear regression ensemble machine learning model that is specific to an identifier in the plurality of identifiers and (B) sending the trained linear regression ensemble machine learning model to one of the plurality of malware-detecting services executing on one of the client computing devices. Various other methods, systems, and computer-readable media are also disclosed.

IPC Classes  ?

  • G06F 21/55 - Detecting local intrusion or implementing counter-measures
  • G06F 21/56 - Computer malware detection or handling, e.g. anti-virus arrangements
  • G06N 20/00 - Machine learning
  • G06N 7/00 - Computing arrangements based on specific mathematical models
  • G06K 9/62 - Methods or arrangements for recognition using electronic means

49.

Amplification of initial training data

      
Application Number 17840291
Grant Number 11900251
Status In Force
Filing Date 2022-06-14
First Publication Date 2022-09-29
Grant Date 2024-02-13
Owner CA, INC. (USA)
Inventor
  • Cohen, Michael J.
  • Sill, Daniel David

Abstract

Techniques are disclosed relating to increasing the amount of training data available to machine learning algorithms. A computer system may access an initial set of training data that specifies a plurality of sequences, each of which may define a set of data values. The computer system may amplify the initial set of training data to create a revised set of training data. The amplifying may include identifying sub-sequences of data values in ones of the plurality of sequences in the initial set of training data and using an inheritance algorithm to create a set of additional sequences of data values, where each one of the set of additional sequences may include sub-sequences of data values from at least two different sequences in the initial set of training data. The computer system may process the set of additional sequences using the machine learning algorithm to train a machine learning model.

IPC Classes  ?

  • G06K 9/62 - Methods or arrangements for recognition using electronic means
  • G06N 3/08 - Learning methods
  • G06N 20/00 - Machine learning
  • G06F 18/214 - Generating training patternsBootstrap methods, e.g. bagging or boosting
  • G06V 10/82 - Arrangements for image or video recognition or understanding using pattern recognition or machine learning using neural networks

50.

Secure access to a corporate application in an SSH session using a transparent SSH proxy

      
Application Number 16591365
Grant Number 11444925
Status In Force
Filing Date 2019-10-02
First Publication Date 2022-09-13
Grant Date 2022-09-13
Owner CA, Inc. (USA)
Inventor
  • Patimer, David
  • Lev-Tov, Lior
  • Rudich, Eldad
  • Belkind, Leonid

Abstract

Secure access to a corporate application in an SSH session using a transparent SSH proxy. In some embodiments, a method may include receiving, at a secure access cloud point of delivery (PoD), from a client application on a client device, a request to access a corporate application that is deployed in a corporate datacenter. The method may also include forwarding, from the secure access cloud PoD, to a connector that is also deployed in the corporate datacenter, the request. The method may further include brokering, by the connector and the secure access cloud PoD, authentication of a user, authorization of access by the user, and an SSH session between the client application and the corporate application using a transparent SSH proxy, with the client application being unaware that the SSH session is brokered by the connector and the secure access cloud PoD.

IPC Classes  ?

51.

Secure access to a corporate application using a facade

      
Application Number 16591335
Grant Number 11442755
Status In Force
Filing Date 2019-10-02
First Publication Date 2022-09-13
Grant Date 2022-09-13
Owner CA, Inc. (USA)
Inventor
  • Patimer, David
  • Lev-Tov, Lior
  • Rudich, Eldad
  • Belkind, Leonid

Abstract

Secure access to a corporate application using a facade. In some embodiments, a method may include receiving, at a secure access cloud point of delivery (PoD), from a client application on a client device, a request to access a corporate application that is deployed in a corporate datacenter. The method may also include creating, at the secure access cloud PoD, a facade representing the corporate application. The method may further include forwarding, from the facade, to a connector that is also deployed in the corporate datacenter, the request. The method may also include brokering, by the connector and the facade, authentication of a user, authorization of access by the user, and a secure communication session between the client application and the corporate application via the facade, with the client application being unaware that the secure communication session is brokered by the connector and the facade.

IPC Classes  ?

  • G06F 9/451 - Execution arrangements for user interfaces
  • G06F 21/30 - Authentication, i.e. establishing the identity or authorisation of security principals
  • G06F 21/33 - User authentication using certificates

52.

Systems and methods for dynamically augmenting machine learning models based on contextual factors associated with execution environments

      
Application Number 15922280
Grant Number 11429823
Status In Force
Filing Date 2018-03-15
First Publication Date 2022-08-30
Grant Date 2022-08-30
Owner CA, INC. (USA)
Inventor
  • Lan, Qichao
  • Tian, Xuefeng
  • Cheng, Tao
  • Senstad, Rudy

Abstract

The disclosed computer-implemented method for dynamically augmenting machine learning models based on contextual factors associated with execution environments may include (1) generating a base machine learning model and a supplemental set of machine learning models, (2) determining at least one contextual factor associated with an execution environment of a machine learning system that is configured to make predictions regarding a set of input data using at least the base machine learning model, (3) selecting, based on the contextual factor, a continuation set of machine learning models from the supplemental set of machine learning models, and (4) directing the machine learning system to utilize both the base machine learning model and the continuation set of machine learning models when making predictions regarding the set of input data. Various other methods, systems, and computer-readable media are also disclosed.

IPC Classes  ?

  • G06K 9/62 - Methods or arrangements for recognition using electronic means
  • G06F 21/53 - Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems during program execution, e.g. stack integrity, buffer overflow or preventing unwanted data erasure by executing in a restricted environment, e.g. sandbox or secure virtual machine
  • G06F 21/56 - Computer malware detection or handling, e.g. anti-virus arrangements
  • G06N 20/00 - Machine learning

53.

Secure access to a corporate web application with translation between an internal address and an external address

      
Application Number 16591347
Grant Number 11425134
Status In Force
Filing Date 2019-10-02
First Publication Date 2022-08-23
Grant Date 2022-08-23
Owner CA, Inc. (USA)
Inventor
  • Patimer, David
  • Lev-Tov, Lior
  • Rudich, Eldad
  • Belkind, Leonid

Abstract

Secure access to a corporate application with translation between an internal address and an external address. In some embodiments, a method may include receiving, at a secure access cloud point of delivery (PoD), from a client application on a client device, a request to access a corporate web application that is deployed in a corporate datacenter. The method may also include forwarding, from the secure access cloud PoD, to a connector that is also deployed in the corporate datacenter, the request to access the corporate web application. The method may further include brokering, by the connector and the secure access cloud PoD, authentication of a user, authorization of access by the user, and a secure communication session between the client application and the corporate web application by translating between an internal address of the corporate web application and an external address of the corporate web application.

IPC Classes  ?

  • G06F 15/16 - Combinations of two or more digital computers each having at least an arithmetic unit, a program unit and a register, e.g. for a simultaneous processing of several programs
  • H04L 9/40 - Network security protocols

54.

Systems and methods for protecting a cloud computing device from malware

      
Application Number 16574755
Grant Number 11411968
Status In Force
Filing Date 2019-09-18
First Publication Date 2022-08-09
Grant Date 2022-08-09
Owner CA, INC. (USA)
Inventor
  • Banerjee, Ashok
  • Hassall, Susan

Abstract

The disclosed computer-implemented method for protecting a cloud computing device from malware may include (i) intercepting, at a computing device, a malicious attempt by the malware to (A) access sensitive information in an encrypted file stored on the computing device and (B) send the sensitive information to the cloud computing device and (ii) performing, responsive to the attempt to access the encrypted file, a security action. Various other methods, systems, and computer-readable media are also disclosed.

IPC Classes  ?

  • H04L 29/06 - Communication control; Communication processing characterised by a protocol
  • H04L 9/40 - Network security protocols
  • G06F 21/62 - Protecting access to data via a platform, e.g. using keys or access control rules

55.

Universal tracing of side-channel processes in computing environments

      
Application Number 16362009
Grant Number 11409871
Status In Force
Filing Date 2019-03-22
First Publication Date 2022-08-09
Grant Date 2022-08-09
Owner CA, Inc. (USA)
Inventor
  • Naamneh, Bahaa
  • Leder, Felix

Abstract

A method for identifying suspicious activity on a monitored computing device is described. In one embodiment, the method may include monitoring a local procedure call interface of the monitored computing device, identifying, based at least in part on the monitoring, a remote procedure call (RPC) of a suspicious process, the RPC being transmitted over a local procedure call message of the local procedure call interface, analyzing the RPC of the suspicious process, and performing a security action based at least in part on the analyzing.

IPC Classes  ?

56.

Systems and methods for detecting code implanted into a published application

      
Application Number 16368565
Grant Number 11392696
Status In Force
Filing Date 2019-03-28
First Publication Date 2022-07-19
Grant Date 2022-07-19
Owner CA, INC. (USA)
Inventor
  • Umland, Torrey
  • Theis, Nathaniel

Abstract

The disclosed computer-implemented method for detecting code implanted into a published application may include retrieving a published version of an application and a source version of the application, and determining, based on an analysis of the source version and the published version, a transformation process for transforming from the source version to the published version. The method may also include performing the transformation process on the source version to produce a build version, comparing the build version with the published version, and identifying, based on the comparison, implanted code in the published version. The method may further include performing, in response to identifying the implanted code, a security action. Various other methods, systems, and computer-readable media are also disclosed.

IPC Classes  ?

  • G06F 21/56 - Computer malware detection or handling, e.g. anti-virus arrangements
  • G06F 8/40 - Transformation of program code

57.

Systems and methods for malware detection using localized machine learning

      
Application Number 16414341
Grant Number 11386208
Status In Force
Filing Date 2019-05-16
First Publication Date 2022-07-12
Grant Date 2022-07-12
Owner CA, INC. (USA)
Inventor
  • Lan, Qichao
  • Cheng, Tao

Abstract

The disclosed computer-implemented method for malware detection using localized machine learning may include (i) generating a global score for a file using a global machine learning model, (ii) generating a localized score for the file using a localized machine learning model, (iii) determining that the file is malware using the global score, the localized score, and the local conviction threshold, and (iv) in response to determining that the file is malware, performing a security action to protect the computing device against malware. Various other methods, systems, and computer-readable media are also disclosed.

IPC Classes  ?

  • G06F 21/56 - Computer malware detection or handling, e.g. anti-virus arrangements
  • G06K 9/62 - Methods or arrangements for recognition using electronic means
  • G06N 20/00 - Machine learning

58.

DEIDENTIFYING CODE FOR CROSS-ORGANIZATION REMEDIATION KNOWLEDGE

      
Application Number US2020059775
Publication Number 2022/103382
Status In Force
Filing Date 2020-11-10
Publication Date 2022-05-19
Owner VERACODE, INC. (USA)
Inventor
  • Sharma, Asankhaya
  • Xiao, Hao
  • Chua, Hendy Heng Lee
  • Foo, Darius Tsien Wei

Abstract

e.ge.g., removed or obfuscated) without impacting AST structure. Deidentified remediation knowledge originating from different organizations is used to train a fix suggestion model(s) which learns structural context of fixes and corresponding flaws and, once trained, generates predictions indicating suggested fixes to flaws based on structural contexts of the flaws. Deidentification can occur before training of the fix suggestion model(s) or during prediction so potentially identifying program code is removed before suggested fixes are consumed by different organizations.

IPC Classes  ?

  • G06F 9/44 - Arrangements for executing specific programs
  • G06F 11/36 - Prevention of errors by analysis, debugging or testing of software
  • G06F 9/45 - Compilation or interpretation of high level programme languages

59.

Systems and methods for managing a need-to-know domain name system

      
Application Number 16576275
Grant Number 11336639
Status In Force
Filing Date 2019-09-19
First Publication Date 2022-05-17
Grant Date 2022-05-17
Owner CA, Inc. (USA)
Inventor
  • Banerjee, Ashok
  • Belkind, Leonid
  • Daigle, Russell

Abstract

The disclosed computer-implemented method for managing a need-to-know domain name system may include (i) intercepting, by an agent of the computing device, network traffic received on the computing device, (ii) generating, by the agent, a one-time password based on a unique identifier of the agent of the computing device, (iii) wrapping, by the agent, the network traffic with the one-time password, and (iv) pushing, by the agent, the wrapped network traffic to a cloud server using a local domain name system (DNS) of the agent of the computing device, wherein the local DNS comprises a private domain name unpublished in a global DNS. Various other methods, systems, and computer-readable media are also disclosed.

IPC Classes  ?

  • G06F 13/00 - Interconnection of, or transfer of information or other signals between, memories, input/output devices or central processing units
  • H04L 29/06 - Communication control; Communication processing characterised by a protocol
  • H04L 67/10 - Protocols in which an application is distributed across nodes in the network
  • H04L 61/4511 - Network directoriesName-to-address mapping using standardised directoriesNetwork directoriesName-to-address mapping using standardised directory access protocols using domain name system [DNS]
  • H04L 49/90 - Buffering arrangements

60.

DEVELOPMENT PIPELINE INTEGRATED ONGOING LEARNING FOR ASSISTED CODE REMEDIATION

      
Application Number US2020058067
Publication Number 2022/093250
Status In Force
Filing Date 2020-10-29
Publication Date 2022-05-05
Owner VERACODE, INC. (USA)
Inventor
  • Sharma, Asankhaya
  • Xiao, Hao
  • Chua, Hendy Heng Lee
  • Foo, Darius Tsien Wei

Abstract

With invocations of a software development pipeline, organization specific remediations/fixes for a software project can be learned from scanning results of code submissions (e.g., commits or merges) across an organization for a software project(s). Fixes of detected program code flaws can be detected and/or specified across scans and associated with flaw identifiers and used for training machine learning models to identify candidate fixes for detected flaws. This ongoing learning during development propagates fixes created or chosen by experts (e.g., software engineers working on the software project) relevant to the software project. The experts can choose from suggestions mined from the learned fixes of the organization and suggestions generated from a pipeline created with the trained machine learning models. The selections are then used for further training of the machine learning models that form the pipeline.

IPC Classes  ?

  • G06F 9/44 - Arrangements for executing specific programs

61.

Adjudicating files by classifying directories based on collected telemetry data

      
Application Number 16453766
Grant Number 11308212
Status In Force
Filing Date 2019-06-26
First Publication Date 2022-04-19
Grant Date 2022-04-19
Owner CA, INC. (USA)
Inventor
  • Zhu, Qian
  • Lichstein, Alexander
  • Sosa, Daniel

Abstract

Telemetry data from client file reputation queries is collected over time. Directories/sub-directories under which files of queries are located are identified. The files including the reputations for the files under a given directory/sub-directory are identified and used to calculate the reputation score for the directory/sub-directory. The directory/sub-directory is then classified based on the calculated score for the directory/sub-directory. After the classification of directories/sub-directories, reputation for a file with unknown reputation is then determined based on the classification of the directory/sub-directory under which the file is located.

IPC Classes  ?

  • G06F 21/00 - Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
  • G06F 21/56 - Computer malware detection or handling, e.g. anti-virus arrangements
  • G06F 16/185 - Hierarchical storage management [HSM] systems, e.g. file migration or policies thereof

62.

Pre-filtering detection of an injected script on a webpage accessed by a computing device

      
Application Number 16435179
Grant Number 11303670
Status In Force
Filing Date 2019-06-07
First Publication Date 2022-04-12
Grant Date 2022-04-12
Owner CA, Inc. (USA)
Inventor Wueest, Candid Alex

Abstract

Pre-filtering detection of an injected script on a webpage accessed by a computing device. The method may include receiving an indication of access to the webpage at a web browser of the computing device; identifying a web form associated with the webpage; determining that the webpage has been previously visited by the computing device; recording at least one current domain associated with at least one current object request made by the web form; determining a difference of a count of the at least one current domain associated with the at least one current object request and a count of at least one historical domain associated with at least one historical object request previously made by the webpage; identifying the webpage as suspicious based on determining that the difference is greater than zero and less than a domain threshold; and initiating a security action on the webpage based on the identifying.

IPC Classes  ?

  • H04L 29/06 - Communication control; Communication processing characterised by a protocol
  • H04L 67/56 - Provisioning of proxy services
  • G06F 21/53 - Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems during program execution, e.g. stack integrity, buffer overflow or preventing unwanted data erasure by executing in a restricted environment, e.g. sandbox or secure virtual machine
  • G06N 20/00 - Machine learning
  • H04L 67/02 - Protocols based on web technology, e.g. hypertext transfer protocol [HTTP]

63.

Identifying and protecting against an attack against an anomaly detector machine learning classifier

      
Application Number 16541442
Grant Number 11297083
Status In Force
Filing Date 2019-08-15
First Publication Date 2022-04-05
Grant Date 2022-04-05
Owner CA, Inc. (USA)
Inventor
  • Kuppa, Aditya
  • Grzonkowski, Slawomir

Abstract

Identifying and protecting against an attack against an anomaly detector machine learning classifier (ADMLC). In some embodiments, a method may include identifying training data points in a manifold space for an ADMLC, dividing the manifold space into multiple subspaces, merging each of the training data points into one of the multiple subspaces, training a subclassifier for each of the multiple subspaces to determine a decision boundary for each of the multiple subspaces between normal training data points and anomalous training data points, receiving an input data point into the ADMLC, determining whether the input data point is an attack on the ADMLC due to a threshold number of the subclassifiers classifying the input data point as an anomalous input data point, and, in response to identifying the attack against the ADMLC, protecting against the attack.

IPC Classes  ?

  • H04L 29/06 - Communication control; Communication processing characterised by a protocol
  • G06N 20/00 - Machine learning
  • G06K 9/62 - Methods or arrangements for recognition using electronic means

64.

Systems and methods for detecting and protecting against malicious use of legitimate computing-system tools

      
Application Number 16368096
Grant Number 11288369
Status In Force
Filing Date 2019-03-28
First Publication Date 2022-03-29
Grant Date 2022-03-29
Owner CA, INC. (USA)
Inventor
  • Grzonkowski, Slawomir
  • Kuppa, Aditya

Abstract

A computer-implemented method for detecting and protecting against malicious use of legitimate computing-system tools may include (i) identifying a computing-system tool that can perform benign actions and malicious actions on a computing system, (ii) creating a set of recorded actions by recording actions performed by the computing-system tool on the computing system over a predetermined period of time, (iii) analyzing the set of recorded actions via a machine learning method that, for each action in the set of recorded actions, determines whether the action is anomalous compared to other actions in the set, (iv) classifying an action in the set of recorded actions as malicious based at least in part on determining that the action is anomalous, and (v) initiating, in response to classifying the action as malicious, a security action related to the action. Various other methods, systems, and computer-readable media are also disclosed.

IPC Classes  ?

  • G06F 21/55 - Detecting local intrusion or implementing counter-measures
  • G06F 21/56 - Computer malware detection or handling, e.g. anti-virus arrangements
  • G06F 21/60 - Protecting data
  • G06F 21/57 - Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities

65.

Identifying and mitigating harm from malicious network connections by a container

      
Application Number 16450652
Grant Number 11277436
Status In Force
Filing Date 2019-06-24
First Publication Date 2022-03-15
Grant Date 2022-03-15
Owner CA, INC. (USA)
Inventor
  • Smith, Spencer Dale
  • Barajas, Frank X.
  • Hernandez, Paul D.

Abstract

Identifying and mitigating harm from malicious network connections by a container. In some embodiments, a method may include receiving, from a shim, notifications of all network connections that a container has sought to establish through the shim. The method may also include monitoring all actual network connections established by the container. The method may further include comparing the notifications to the actual network connections to determine whether any actual network connection established by the container bypassed the shim. The method may also include, in response to determining that any actual network connection established by the container bypassed the shim, identifying the network connection established by the container that bypassed the shim as a malicious network connection, and performing a security action to mitigate harm from the malicious network connection.

IPC Classes  ?

  • H04L 29/06 - Communication control; Communication processing characterised by a protocol

66.

Language-independent application monitoring through aspect-oriented programming

      
Application Number 17287045
Grant Number 12072983
Status In Force
Filing Date 2020-04-24
First Publication Date 2022-03-10
Grant Date 2024-08-27
Owner Veracode, Inc. (USA)
Inventor
  • Rioux, Christien R.
  • Layzell, Robert Anthony

Abstract

To support adding functionality to applications at a layer of abstraction above language-specific implementations of AOP, a language for implementing AOP facilitates runtime monitoring and analysis of an application independent of the language of the application. Aspects can be created for applications written in any supported language. Program code underlying implementations of aspects can be executed based on detecting triggering events during execution of the application. Routines written with the AOP language comprise event-based aspect code triggers that indicate an event which may occur during execution of the application and the associated aspect code to be executed. An agent deployed to a runtime engine to monitor the application detects events and evaluates contextual information about the detected events against the aspect triggers to determine if aspect code should be executed to perform further monitoring and analysis of the executing application.

IPC Classes  ?

  • G06F 21/57 - Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
  • G06F 8/30 - Creation or generation of source code
  • G06F 8/41 - Compilation
  • G06F 11/36 - Prevention of errors by analysis, debugging or testing of software

67.

Runtime application monitoring without modifying application program code

      
Application Number 17287057
Grant Number 12001564
Status In Force
Filing Date 2020-04-24
First Publication Date 2022-03-10
Grant Date 2024-06-04
Owner Veracode, Inc. (USA)
Inventor
  • Rioux, Christien R.
  • Layzell, Robert Anthony

Abstract

To facilitate runtime monitoring and analysis of an application without modifying the actual application code, an agent monitors and analyzes an application through detection and evaluation of invocations of an API of a runtime engine provided for execution of the application. The agent registers to receive events which are generated upon invocation of target functions of the runtime engine API based on its load. Once loaded, the agent initially determines the language and language version number of the runtime engine. The agent determines associations of events for which to monitor and corresponding analysis code to execute upon detection of the invocations based on the language and version number information. When the agent detects an event during execution of the application based on invocations of the runtime engine API, the agent can monitor and analyze execution of the application based on execution of analysis code corresponding to the detected event.

IPC Classes  ?

  • G06F 11/00 - Error detectionError correctionMonitoring
  • G06F 11/30 - Monitoring
  • G06F 11/36 - Prevention of errors by analysis, debugging or testing of software
  • G06F 21/57 - Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities

68.

Systems and methods for utilizing metadata for protecting against the sharing of images in a computing network

      
Application Number 16433761
Grant Number 11270014
Status In Force
Filing Date 2019-06-06
First Publication Date 2022-03-08
Grant Date 2022-03-08
Owner CA, Inc. (USA)
Inventor
  • Chen, Joseph
  • Song, Qubo
  • Houston, Chris

Abstract

The disclosed computer-implemented method for utilizing metadata for protecting against the sharing of images in a computing network may include (i) identifying an image file stored in a public folder on a computing device, (ii) storing a copy of the image file within a secure data storage application, (iii) encoding metadata for revealing an image in the image file, (iv) performing a security action that protects against sharing the image file from the public folder by masking the image in the image file with the encoded metadata, and (v) rendering the image in the image file as an unmasked version of the image from the image file or the copy of the image file in the secure data storage application by decoding the metadata utilized to mask the image. Various other methods, systems, and computer-readable media are also disclosed.

IPC Classes  ?

  • H04L 29/06 - Communication control; Communication processing characterised by a protocol
  • G06F 21/62 - Protecting access to data via a platform, e.g. using keys or access control rules
  • G06F 16/176 - Support for shared access to filesFile sharing support
  • G06T 11/60 - Editing figures and textCombining figures or text
  • H04L 67/10 - Protocols in which an application is distributed across nodes in the network

69.

LONGBOW

      
Serial Number 97285360
Status Registered
Filing Date 2022-02-25
Registration Date 2023-10-31
Owner VERACODE, INC. ()
NICE Classes  ? 42 - Scientific, technological and industrial services, research and design

Goods & Services

Software as a service (SAAS) services, namely, hosting software for use by others for security data analysis; Computer security consultancy in the field of cyber security

70.

Application behavioral fingerprints

      
Application Number 16408800
Grant Number 11256802
Status In Force
Filing Date 2019-05-10
First Publication Date 2022-02-22
Grant Date 2022-02-22
Owner CA, INC. (USA)
Inventor
  • Forcada, Joao M.
  • Mesropian, Haik A.
  • Danileiko, Alexander
  • Peterson, Christopher J.
  • Chang, Charlotte
  • Xing, Huawei
  • Egoyan, Artem

Abstract

Methods, systems, and devices for protecting against abnormal computer behavior are described. The method may include monitoring a computer process related to an application running on a computing device of one or more computing devices, analyzing a database including a set of digital fingerprints, where a digital fingerprint of the set of digital fingerprints relates to the application, the digital fingerprint including an indication of a set of computer processes related to the application that are classified as normal computer processes for the application, determining that the computer process related to the application is an abnormal computer process based on analyzing, and performing a security action on the computing device to protect the computing device against the abnormal computer process based on the determining.

IPC Classes  ?

  • G06F 21/56 - Computer malware detection or handling, e.g. anti-virus arrangements
  • G06F 21/55 - Detecting local intrusion or implementing counter-measures

71.

Automatically generating malware definitions using word-level analysis

      
Application Number 16363709
Grant Number 11222113
Status In Force
Filing Date 2019-03-25
First Publication Date 2022-01-11
Grant Date 2022-01-11
Owner CA, INC. (USA)
Inventor
  • Li, Weiliang
  • Zeng, Zhicheng

Abstract

Methods and systems are provided for automatically generating malware definitions and using generated malware definitions. One example method generally includes receiving information associated with a malicious application and extracting malware strings from the malicious application. The method further includes filtering the malware strings using a set of safe strings to produce filtered strings and scoring the filtered strings to produce string scores by evaluating words of the filtered strings based on word statistics of a set of known malicious words. The method further includes selecting a set of candidate strings from the filtered strings based on the string scores and generating a malware definition for the malicious application based on the set of candidate strings. The method also includes performing one or more security actions to protect against the malicious application, using the malware definition.

IPC Classes  ?

  • G06F 21/56 - Computer malware detection or handling, e.g. anti-virus arrangements

72.

Systems and methods for safely executing unreliable malware

      
Application Number 16560273
Grant Number 11204992
Status In Force
Filing Date 2019-09-04
First Publication Date 2021-12-21
Grant Date 2021-12-21
Owner CA, INC. (USA)
Inventor
  • Naamneh, Bahaa
  • Leder, Felix

Abstract

The disclosed computer-implemented method for safely executing unreliable malware may include (i) intercepting a call to an application programming interface (API) in a computing operating system, the API being utilized by malware for disseminating malicious code, (ii) determining an incompatibility between the API call and the computing operating system that prevents successful execution of the API call, (iii) creating a proxy container for receiving the API call, (iv) modifying, utilizing the proxy container, the API call to be compatible with the computing operating system, (v) sending the modified API call from the proxy container to the computing operating system for retrieving the API utilized by the malware, and (vi) performing a security action during a threat analysis of the malware by executing the API to disseminate the malicious code in a sandboxed environment. Various other methods, systems, and computer-readable media are also disclosed.

IPC Classes  ?

  • G06F 21/53 - Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems during program execution, e.g. stack integrity, buffer overflow or preventing unwanted data erasure by executing in a restricted environment, e.g. sandbox or secure virtual machine
  • G06F 9/54 - Interprogram communication
  • G06F 21/54 - Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems during program execution, e.g. stack integrity, buffer overflow or preventing unwanted data erasure by adding security routines or objects to programs
  • G06F 21/56 - Computer malware detection or handling, e.g. anti-virus arrangements

73.

Systems and methods for protecting against malicious content

      
Application Number 16452298
Grant Number 11196754
Status In Force
Filing Date 2019-06-25
First Publication Date 2021-12-07
Grant Date 2021-12-07
Owner CA, INC. (USA)
Inventor
  • Lai, Everett
  • Rudnai, Tamas

Abstract

The disclosed computer-implemented method for protecting against malicious content may include intercepting, by a security application installed on the computing device, an original message intended for a target application installed on the same computing device. The original message may include potentially malicious content. The security application may forward the original message to a security service. The computing device may receive a clean message from the security service, wherein the clean message includes a safe representation of the potentially malicious content. Various other methods, systems, and computer-readable media are also disclosed.

IPC Classes  ?

  • H04L 29/06 - Communication control; Communication processing characterised by a protocol

74.

Systems and methods for managing endpoint security states using passive data integrity attestations

      
Application Number 16420016
Grant Number 11176276
Status In Force
Filing Date 2019-05-22
First Publication Date 2021-11-16
Grant Date 2021-11-16
Owner CA, INC. (USA)
Inventor
  • Chen, Joseph
  • Song, Qubo
  • Smith, Spencer
  • Aimoto, Shaun
  • Mesropian, Haik
  • Kane, David
  • Ferrie, Peter
  • Saxonberg, Jordan
  • Ionescu, Costin

Abstract

The disclosed computer-implemented method for managing endpoint security states using passive data integrity attestations may include (i) receiving passively collected network data from an endpoint device of a computing environment, (ii) determining a security state of the endpoint device using the passively collected network data from the endpoint device, (iii) determining that the security state of the endpoint device is below a threshold, and (iv) in response to determining that the security state of the endpoint device is below a threshold, performing a security action to protect the computing environment against malicious actions. Various other methods, systems, and computer-readable media are also disclosed.

IPC Classes  ?

  • H04L 29/06 - Communication control; Communication processing characterised by a protocol
  • G06F 21/64 - Protecting data integrity, e.g. using checksums, certificates or signatures

75.

Discovery of computer system incidents to be remediated based on correlation between support interaction data and computer system telemetry data

      
Application Number 16362369
Grant Number 11163875
Status In Force
Filing Date 2019-03-22
First Publication Date 2021-11-02
Grant Date 2021-11-02
Owner CA, INC. (USA)
Inventor
  • Roundy, Kevin A.
  • Sharif, Mahmood
  • Dell'Amico, Matteo
  • Gates, Christopher
  • Kats, Daniel
  • Chung, Dong

Abstract

The present disclosure relates to using correlations between support interaction data and telemetry data to discover emerging incidents for remediation. One example method generally includes receiving a corpus of support interaction data and a corpus of telemetry data. Topics indicative of underlying problems experienced by users of an application are extracted from the corpus of support interaction data. A topic having a rate of appearance in the support interaction data above a threshold value is identified. A set of telemetry data relevant to the topic is extracted from the corpus of telemetry data, and a subset of the relevant set of telemetry data having a frequency in the relevant set of telemetry data above a second threshold value is identified. The topic and the subset of telemetry data are correlated to an incident to be remediated, and one or more actions are taken to remedy the incident.

IPC Classes  ?

  • G06F 21/55 - Detecting local intrusion or implementing counter-measures
  • G06F 21/56 - Computer malware detection or handling, e.g. anti-virus arrangements

76.

RUNTIME APPLICATION MONITORING WITHOUT MODIFYING APPLICATION PROGRAM CODE

      
Application Number US2020029718
Publication Number 2021/216081
Status In Force
Filing Date 2020-04-24
Publication Date 2021-10-28
Owner VERACODE, INC. (USA)
Inventor
  • Rioux, Christien R.
  • Layzell, Robert Anthony

Abstract

To facilitate runtime monitoring and analysis of an application without modifying the actual application code, an agent monitors and analyzes an application through detection and evaluation of invocations of an API of a runtime engine provided for execution of the application. The agent registers to receive events which are generated upon invocation of target functions of the runtime engine API based on its load. Once loaded, the agent initially determines the language and language version number of the runtime engine. The agent determines associations of events for which to monitor and corresponding analysis code to execute upon detection of the invocations based on the language and version number information. When the agent detects an event during execution of the application based on invocations of the runtime engine API, the agent can monitor and analyze execution of the application based on execution of analysis code corresponding to the detected event.

IPC Classes  ?

  • G06F 9/44 - Arrangements for executing specific programs
  • G06F 15/177 - Initialisation or configuration control
  • G06F 21/55 - Detecting local intrusion or implementing counter-measures
  • G06F 21/62 - Protecting access to data via a platform, e.g. using keys or access control rules

77.

LANGUAGE-INDEPENDENT APPLICATION MONITORING THROUGH ASPECT-ORIENTED PROGRAMMING

      
Application Number US2020029707
Publication Number 2021/216079
Status In Force
Filing Date 2020-04-24
Publication Date 2021-10-28
Owner VERACODE, INC. (USA)
Inventor
  • Rioux, Christien, R.
  • Layzell, Robert, Anthony

Abstract

To support adding functionality to applications at a layer of abstraction above language-specific implementations of AOP, a language for implementing AOP facilitates runtime monitoring and analysis of an application independent of the language of the application. Aspects can be created for applications written in any supported language. Program code underlying implementations of aspects can be executed based on detecting triggering events during execution of the application. Routines written with the AOP language comprise event-based aspect code triggers that indicate an event which may occur during execution of the application and the associated aspect code to be executed. An agent deployed to a runtime engine to monitor the application detects events and evaluates contextual information about the detected events against the aspect triggers to determine if aspect code should be executed to perform further monitoring and analysis of the executing application.

IPC Classes  ?

  • G06F 9/44 - Arrangements for executing specific programs
  • G06F 11/36 - Prevention of errors by analysis, debugging or testing of software
  • G06Q 10/06 - Resources, workflows, human or project managementEnterprise or organisation planningEnterprise or organisation modelling

78.

Systems and methods for executing decision trees

      
Application Number 16111772
Grant Number 11144637
Status In Force
Filing Date 2018-08-24
First Publication Date 2021-10-12
Grant Date 2021-10-12
Owner CA, INC. (USA)
Inventor
  • Curtin, Ryan
  • Kenemer, Keith

Abstract

The disclosed computer-implemented method for executing decision trees may include (i) executing a security classification decision tree that classifies an input data item, (ii) gathering, simultaneously using a gather instruction, values for both a current threshold at a parent node of the security classification decision tree and a subsequent threshold at a child node of the parent node, (iii) gathering, simultaneously using the gather instruction, values for both a current measurement at the parent node and a subsequent measurement at the child node, (iv) comparing, simultaneously using a comparison instruction, the current threshold at the parent node with the current measurement at the parent node and the subsequent threshold at the child node with the subsequent measurement at the child node, and (v) performing a security action to protect the computing device. Various other methods, systems, and computer-readable media are also disclosed.

IPC Classes  ?

  • G06F 21/56 - Computer malware detection or handling, e.g. anti-virus arrangements
  • G06F 21/55 - Detecting local intrusion or implementing counter-measures
  • G06K 9/62 - Methods or arrangements for recognition using electronic means

79.

Systems and methods for protection of storage systems using decoy data

      
Application Number 16362987
Grant Number 11144656
Status In Force
Filing Date 2019-03-25
First Publication Date 2021-10-12
Grant Date 2021-10-12
Owner CA, INC. (USA)
Inventor
  • Banerjee, Ashok
  • Porr, William
  • Hasan, Sahil

Abstract

The disclosed computer-implemented method for protection of storage systems using decoy data may include identifying an original file comprising sensitive content to be protected against malicious access and protecting the sensitive content. Protecting the sensitive content may include (i) processing the original file to identify a structure of the original file and the sensitive content of the original file, (ii) generating a decoy file using the structure of the original file and using substitute content in a location corresponding to the sensitive content of the original file, and (iii) storing the decoy file with the original file. Various other methods, systems, and computer-readable media are also disclosed.

IPC Classes  ?

  • G06F 21/62 - Protecting access to data via a platform, e.g. using keys or access control rules
  • G06F 21/56 - Computer malware detection or handling, e.g. anti-virus arrangements
  • G06F 21/60 - Protecting data

80.

Systems and methods for preserving system contextual information in an encapsulated packet

      
Application Number 17322045
Grant Number 12088430
Status In Force
Filing Date 2021-05-17
First Publication Date 2021-09-09
Grant Date 2024-09-10
Owner CA, INC. (USA)
Inventor
  • Mcconnaughay, Mark
  • Tomic, Gary
  • Frederick, Ron

Abstract

In some embodiments, a computing system includes a communication interface; and a processor that is coupled to the communication interface. In some embodiments, least one of the communication interface or the processor receives a network packet from the network via a network adapter port; encapsulates the received network packet with a tunnel header, wherein the tunnel header comprises network identifier information identifying the network adapter port; addresses, based on the network identifier information, an outer Internet protocol (IP) header of the encapsulated network packet with an outer IP address corresponding to a network function in a first computing device; and sends the encapsulated network packet toward the network function identified by the outer IP address.

IPC Classes  ?

  • H04L 12/46 - Interconnection of networks
  • H04L 61/251 - Translation of Internet protocol [IP] addresses between different IP versions
  • H04L 67/1001 - Protocols in which an application is distributed across nodes in the network for accessing one among a plurality of replicated servers
  • H04L 69/167 - Adaptation for transition between two IP versions, e.g. between IPv4 and IPv6
  • H04L 69/22 - Parsing or analysis of headers

81.

Systems and methods for detecting covert channels structured in internet protocol transactions

      
Application Number 16114732
Grant Number 11095666
Status In Force
Filing Date 2018-08-28
First Publication Date 2021-08-17
Grant Date 2021-08-17
Owner CA, INC. (USA)
Inventor
  • Li, Qing
  • Larsen, Chris
  • Dimaggio, Jon

Abstract

The disclosed computer-implemented method for detecting covert channels structured in Internet Protocol (IP) transactions may include (1) intercepting an IP transaction including textual data and a corresponding address, (2) evaluating the textual data against a model to determine a difference score, (3) determining that the textual data is suspicious when the difference score exceeds a threshold value associated with the model, (4) examining, upon determining that the textual data is suspicious, the address in the transaction to determine whether the address is invalid, (5) analyzing the transaction to determine a frequency of address requests that have been initiated from a source address over a predetermined period, and (6) identifying the transaction as a covert data channel for initiating a malware attack when the address is determined to be invalid and the frequency of the address requests exceeds a threshold value. Various other methods, systems, and computer-readable media are also disclosed.

IPC Classes  ?

  • H04L 29/06 - Communication control; Communication processing characterised by a protocol
  • H04L 29/12 - Arrangements, apparatus, circuits or systems, not covered by a single one of groups characterised by the data terminal

82.

Isolating an iframe of a webpage

      
Application Number 16551440
Grant Number 11089050
Status In Force
Filing Date 2019-08-26
First Publication Date 2021-08-10
Grant Date 2021-08-10
Owner CA, Inc. (USA)
Inventor
  • Horman, Yoav
  • Kasher, Roee
  • Solomon, Tal

Abstract

Isolating an iframe of a webpage. In one embodiment, a method may include targeting an iframe in a webpage for isolation, executing, in a server browser, iframe code, sending, from the remote isolation server to the local client, the webpage with the iframe code of the iframe replaced with isolation code, executing, in a client browser, webpage code and the isolation code, intercepting, in the client browser, webpage messages sent from the webpage code and intended to be delivered to the iframe, sending, to the remote isolation server, the intercepted webpage messages to be injected into the iframe code executing at the server browser, intercepting, at the server browser, iframe messages sent from the iframe code and intended to be delivered to the webpage, and sending, to the local client, the intercepted iframe messages to be injected into the webpage code executing at the client browser.

IPC Classes  ?

  • H04L 29/06 - Communication control; Communication processing characterised by a protocol
  • H04L 29/08 - Transmission control procedure, e.g. data link level control procedure
  • G06F 16/958 - Organisation or management of web site content, e.g. publishing, maintaining pages or automatic linking
  • G06F 21/56 - Computer malware detection or handling, e.g. anti-virus arrangements
  • G06F 21/12 - Protecting executable software
  • G06F 16/951 - IndexingWeb crawling techniques

83.

Threat isolation for documents using distributed storage mechanisms

      
Application Number 16368324
Grant Number 11089061
Status In Force
Filing Date 2019-03-28
First Publication Date 2021-08-10
Grant Date 2021-08-10
Owner CA, INC. (USA)
Inventor
  • Sinha, Nikhil
  • Harris, Alexander
  • Steenbruggen, John
  • Vadlamani, Ananta Krishna

Abstract

A cloud device is configured in an email transmission pathway. The cloud device receives an email attachment whose maliciousness status is determined to be unknown. The cloud device encrypts the email attachment and delivers the encrypted attachment to the recipient. When the recipient attempts to access the encrypted attachment, the cloud device re-determines the maliciousness status of the attachment. If the re-determined maliciousness status is benign, the cloud device allows the encrypted attachment to be decrypted and opened locally on the recipient's device. If the re-determined maliciousness status is still unknown, the cloud device provides a cloud-based viewing solution to the recipient using an isolation service.

IPC Classes  ?

  • H04L 29/06 - Communication control; Communication processing characterised by a protocol
  • H04L 12/58 - Message switching systems

84.

Abnormal user behavior detection

      
Application Number 16366092
Grant Number 11075933
Status In Force
Filing Date 2019-03-27
First Publication Date 2021-07-27
Grant Date 2021-07-27
Owner CA, Inc. (USA)
Inventor
  • Fetters, Brandon
  • Han, Yufei
  • Wang, Xiaolin

Abstract

A method for detecting and protecting against abnormal user behavior is described. The method may include generating a tensor model based on a set of user information within a temporal period. The tensor model may include a behavioral profile associated with a user of a set of users. In some examples, the method may include determining that a behavior associated with the user of the set of users is abnormal based on the tensor model, adapting the tensor model based on feedback from an additional user of a set of additional users different from the set of users, and performing a security action on at least one computing device to protect against the abnormal user behavior based on the adapting.

IPC Classes  ?

  • H04L 29/06 - Communication control; Communication processing characterised by a protocol
  • H04L 29/08 - Transmission control procedure, e.g. data link level control procedure

85.

Systems and methods for preventing data loss from data containers

      
Application Number 16050211
Grant Number 11068611
Status In Force
Filing Date 2018-07-31
First Publication Date 2021-07-20
Grant Date 2021-07-20
Owner CA, Inc. (USA)
Inventor Sarin, Sumit

Abstract

The disclosed computer-implemented method for preventing data loss from data containers may include (1) identifying, at a computing device, a process running in a data container on the computing device, (2) intercepting an attempt by the process to exfiltrate information from the computing device via at least one of a file system operation or a network operation, and (3) performing a security action to prevent the intercepted attempt. Various other methods, systems, and computer-readable media are also disclosed.

IPC Classes  ?

  • H04L 29/06 - Communication control; Communication processing characterised by a protocol
  • G06F 21/62 - Protecting access to data via a platform, e.g. using keys or access control rules
  • G06F 21/60 - Protecting data
  • G06F 16/13 - File access structures, e.g. distributed indices

86.

Detecting and protecting against computing breaches based on lateral movement of a computer file within an enterprise

      
Application Number 16125397
Grant Number 11030311
Status In Force
Filing Date 2018-09-07
First Publication Date 2021-06-08
Grant Date 2021-06-08
Owner CA, Inc. (USA)
Inventor Lopez, Alejandro Mosquera

Abstract

Detecting and protecting against computing breaches based on lateral movement of a computer file within an enterprise. A method may include obtaining data associated with an existence a computer file in a first computing device and a second computing device of an enterprise, detecting a pattern of lateral movement of the computer from the first computing device to the second computing device over a predetermined period of time, based on the data, calculating a likelihood score that the computer file is malicious based on the detected pattern, determining that the likelihood score satisfies a predetermined breach threshold, and in response to determining that the likelihood score satisfies the predetermined breach threshold, initiating remedial action on the computer file to protect the enterprise against the computer file.

IPC Classes  ?

  • G06F 21/00 - Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
  • G06F 21/56 - Computer malware detection or handling, e.g. anti-virus arrangements
  • G06F 21/55 - Detecting local intrusion or implementing counter-measures
  • G06K 9/62 - Methods or arrangements for recognition using electronic means
  • G06F 11/34 - Recording or statistical evaluation of computer activity, e.g. of down time, of input/output operation
  • G06N 20/00 - Machine learning

87.

Systems and methods for preserving system contextual information in an encapsulated packet

      
Application Number 16130977
Grant Number 11012259
Status In Force
Filing Date 2018-09-13
First Publication Date 2021-05-18
Grant Date 2021-05-18
Owner CA, Inc. (USA)
Inventor
  • Mcconnaughay, Mark
  • Tomic, Gary
  • Frederick, Ron

Abstract

The disclosed computer-implemented method for preserving system contextual information in an encapsulated packet may include (1) receiving, at a computing device, a network packet from the network via a network adapter port, (2) encapsulating the received network packet with a tunnel header, where a network identifier field in the tunnel header comprises information identifying the network adapter port, (3) determine an outer Internet protocol (IP) address for the encapsulated network packet, where the destination IP address corresponds to a destination on the network, (4) addressing an outer header of the encapsulated network packet with the IP address, and (5) sending the encapsulated network packet toward the destination identified by the destination IP address. Various other methods, systems, and computer-readable media are also disclosed.

IPC Classes  ?

  • H04L 12/46 - Interconnection of networks
  • H04L 29/06 - Communication control; Communication processing characterised by a protocol
  • H04L 29/12 - Arrangements, apparatus, circuits or systems, not covered by a single one of groups characterised by the data terminal
  • H04L 29/08 - Transmission control procedure, e.g. data link level control procedure

88.

Systems and methods for tuning application network behavior

      
Application Number 16009125
Grant Number 11005867
Status In Force
Filing Date 2018-06-14
First Publication Date 2021-05-11
Grant Date 2021-05-11
Owner CA, Inc. (USA)
Inventor
  • Song, Qu Bo
  • Li, Weiliang

Abstract

The disclosed computer-implemented method for tuning application network behavior may include identifying an application for a closed operating system. The closed operating system may prevent applications from implementing machine-level traffic control for network traffic. The method may include determining an expected network behavior of the application, intercepting network traffic of the application on the closed operating system, determining whether the intercepted network traffic conforms to the expected network behavior, and modifying, based on the determining whether the intercepted network traffic conforms to the expected network behavior, the network traffic. Various other methods, systems, and computer-readable media are also disclosed.

IPC Classes  ?

  • H04L 29/06 - Communication control; Communication processing characterised by a protocol
  • H04W 24/08 - Testing using real traffic

89.

Systems and methods for preventing electronic form data from being electronically transmitted to untrusted domains

      
Application Number 16363936
Grant Number 11003746
Status In Force
Filing Date 2019-03-25
First Publication Date 2021-05-11
Grant Date 2021-05-11
Owner CA, Inc. (USA)
Inventor
  • Vashishtha, Parveen
  • Chandrayan, Siddhesh
  • Kasiviswanathan, Karthikeyan

Abstract

A computer-implemented method for preventing electronic form data from being electronically transmitted to untrusted domains may include (i) identifying a web page that includes an electronic form with field for data entry, (ii) detecting that the web page is electronically sending first and second messages that each include data from the field of the electronic form and that are directed to first and second destinations, respectively, (iii) determining that the first destination includes an untrusted destination, and (iv) blocking the web page from electronically sending the data from the field of the electronic form to the untrusted destination by blocking the first message from being electronically sent. Various other methods, systems, and computer-readable media are also disclosed.

IPC Classes  ?

  • G06F 21/12 - Protecting executable software
  • G06F 21/51 - Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems at application loading time, e.g. accepting, rejecting, starting or inhibiting executable software based on integrity or source reliability
  • H04L 29/06 - Communication control; Communication processing characterised by a protocol
  • H04W 12/106 - Packet or message integrity

90.

Systems and methods for providing an integrated cyber threat defense exchange platform

      
Application Number 16147051
Grant Number 10986117
Status In Force
Filing Date 2018-09-28
First Publication Date 2021-04-20
Grant Date 2021-04-20
Owner CA, Inc. (USA)
Inventor
  • Agbabian, Paul
  • Roupski, Roumen
  • Mulcahy, Lois

Abstract

The disclosed computer-implemented method for providing an integrated cyber threat defense exchange platform may include (i) receiving unnormalized security data from a plurality of disparate security data sources that generate security data in differing formats, (ii) normalizing, using a security data schema, the unnormalized security data into normalized security data, (iii) identifying a security action that is responsive to at least one security event identified within the normalized security data, and (iv) coordinating performance of the security action within a plurality of networked computing devices. Various other methods, systems, and computer-readable media are also disclosed.

IPC Classes  ?

  • H04L 29/06 - Communication control; Communication processing characterised by a protocol
  • G06F 21/55 - Detecting local intrusion or implementing counter-measures
  • G06F 21/62 - Protecting access to data via a platform, e.g. using keys or access control rules

91.

Systems and methods for protecting website visitors

      
Application Number 15919246
Grant Number 10986100
Status In Force
Filing Date 2018-03-13
First Publication Date 2021-04-20
Grant Date 2021-04-20
Owner CA, Inc. (USA)
Inventor
  • Smith, Spencer
  • Viljoen, Petrus Johannes

Abstract

The disclosed computer-implemented method for protecting website visitors may include (i) retrieving an instance of a website that was dynamically generated by aggregating multiple website subcomponents, (ii) decomposing the instance of the website into the multiple website subcomponents, (iii) checking whether a website subcomponent has been previously scanned by a security scanner, (iv) accelerating a review of the instance of the website by reusing results of a previous scan of the website subcomponent that was performed in response to retrieving a different instance of the website subcomponent rather than performing an original scan of the website subcomponent, and (v) protecting a visitor of the website by modifying a display of the instance of the website based on the accelerated review of the instance of the website that reused results of the previous scan of the website subcomponent. Various other methods, systems, and computer-readable media are also disclosed.

IPC Classes  ?

  • H04L 29/06 - Communication control; Communication processing characterised by a protocol
  • H04L 29/08 - Transmission control procedure, e.g. data link level control procedure
  • G06F 16/955 - Retrieval from the web using information identifiers, e.g. uniform resource locators [URL]
  • G06F 16/957 - Browsing optimisation, e.g. caching or content distillation

92.

Method to assess internal security posture of a computing system using external variables

      
Application Number 16010121
Grant Number 10977374
Status In Force
Filing Date 2018-06-15
First Publication Date 2021-04-13
Grant Date 2021-04-13
Owner CA, Inc. (USA)
Inventor
  • Kuppa, Aditya
  • Vervier, Pierre-Antoine
  • Grzonkowski, Slawomir
  • Shen, Yun

Abstract

Methods and systems are provided for generating a security profile for a new computing system. One example method generally includes obtaining, over a network, information associated with a plurality of existing computing systems and generating, by a clustering algorithm, a set of clusters based on the information associated with the plurality of existing computing systems. The method further includes obtaining external data associated with the computing system and classifying the computing system into a cluster in the set of clusters based on the external data associated with the computing system. The method further includes determining the security profile based on statistics associated with the cluster and transmitting, over the network, an indication of the security profile.

IPC Classes  ?

  • G06F 21/57 - Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities

93.

Systems and methods for preventing sharing of sensitive content in image data on a closed computing platform

      
Application Number 16433691
Grant Number 10970532
Status In Force
Filing Date 2019-06-06
First Publication Date 2021-04-06
Grant Date 2021-04-06
Owner CA, Inc. (USA)
Inventor
  • Song, Qubo
  • Chen, Joseph
  • Jeong, Oksoon
  • Liu, Zhe
  • Houston, Chris

Abstract

The disclosed computer-implemented method for preventing sharing of sensitive content in image data on a closed computing platform may include (i) detecting initiation of a network connection for sending network traffic data to a data storage service on the closed computing platform, (ii) monitoring the sending of the network traffic data to identify a target traffic indicator associated with image data, (iii) interrupting the sending of the network traffic data upon identifying the target traffic indicator, (iv) analyzing the image data to identify sensitive content, and (v) performing a security action that protects against the sensitive content being shared to the data storage service on the closed computing platform. Various other methods, systems, and computer-readable media are also disclosed.

IPC Classes  ?

  • G06K 9/00 - Methods or arrangements for reading or recognising printed or written characters or for recognising patterns, e.g. fingerprints
  • H04L 12/24 - Arrangements for maintenance or administration
  • H04L 29/06 - Communication control; Communication processing characterised by a protocol
  • G06N 20/00 - Machine learning

94.

Image quality optimization during remote isolated sessions

      
Application Number 16024492
Grant Number 10949488
Status In Force
Filing Date 2018-06-29
First Publication Date 2021-03-16
Grant Date 2021-03-16
Owner CA, Inc. (USA)
Inventor
  • Kanfer, Amit
  • Horman, Yoav

Abstract

Image quality optimization during remote isolated sessions. In one embodiment, a method may include a remote isolation server receiving, at a remote isolation server, a request from a local browser on a local network device to obtain webpage data from a webserver, requesting, from the webserver, the webpage data, receiving, from the webserver, the requested webpage data, rendering a first image of the requested webpage data, storing a first copy of the first image of the requested webpage data in memory associated with the remote isolation server, compressing a first portion of the first image using a first compression method, sending, from the remote isolation server, the compressed first portion of the first image to the local browser, compressing a second portion of the first image using a second compression method, and sending the compressed second portion of the first image to the local browser.

IPC Classes  ?

  • G06F 16/957 - Browsing optimisation, e.g. caching or content distillation
  • G06F 40/197 - Version control
  • G06F 40/14 - Tree-structured documents
  • G06F 40/146 - Coding or compression of tree-structured data
  • H04L 29/08 - Transmission control procedure, e.g. data link level control procedure

95.

Automated scoring of intra-sample sections for malware detection

      
Application Number 16020632
Grant Number 10929531
Status In Force
Filing Date 2018-06-27
First Publication Date 2021-02-23
Grant Date 2021-02-23
Owner CA, Inc. (USA)
Inventor
  • Kenemer, Keith
  • Curtin, Ryan

Abstract

Methods and systems are provided for detecting malware. One example method generally includes receiving a reference dataset comprising an aggregation of probability distributions of a plurality of intra-file patterns for a plurality of files of at least a first class and applying a logical query to the reference dataset to generate a template distribution with probability distributions of the plurality of intra-file patterns calculated according to one or more logical operators in the logical query. The method further includes detecting a likely presence of malware in a computer file by indicating one or more areas in the computer file based on at least a portion of the calculated probability distributions of the plurality of intra-file patterns in the template distribution.

IPC Classes  ?

  • G06F 11/00 - Error detectionError correctionMonitoring
  • G06F 12/14 - Protection against unauthorised use of memory
  • G06F 12/16 - Protection against loss of memory contents
  • G08B 23/00 - Alarms responsive to unspecified undesired or abnormal conditions
  • G06F 21/55 - Detecting local intrusion or implementing counter-measures
  • G06F 17/18 - Complex mathematical operations for evaluating statistical data
  • G06K 9/62 - Methods or arrangements for recognition using electronic means
  • G06F 21/56 - Computer malware detection or handling, e.g. anti-virus arrangements

96.

Secure quarantine of potentially malicious content

      
Application Number 16143031
Grant Number 10909245
Status In Force
Filing Date 2018-09-26
First Publication Date 2021-02-02
Grant Date 2021-02-02
Owner CA, Inc. (USA)
Inventor
  • Saxonberg, Jordan
  • Chen, Joe H.

Abstract

Secure Quarantine of Potentially Malicious Content. In one embodiment, a method for secure quarantine of potentially malicious content may include receiving a computer file from a third party, preventing the computer file from initially being accessed by a user associated with the computing device, collecting metadata from the computer file, encrypting the file and the collected metadata using a first encryption key, creating an encrypted computer file, encrypting the first encryption key using an asymmetric key, embedding the encrypted computer file into a new computer file, wherein at least one file object that is in the encrypted computer file is removed from the new computer file, enabling user access to the new computer file and the embedded encrypted computer file.

IPC Classes  ?

  • G06F 12/14 - Protection against unauthorised use of memory
  • G06F 21/56 - Computer malware detection or handling, e.g. anti-virus arrangements
  • H04L 9/08 - Key distribution
  • H04L 9/06 - Arrangements for secret or secure communicationsNetwork security protocols the encryption apparatus using shift registers or memories for blockwise coding, e.g. D.E.S. systems
  • G06F 21/60 - Protecting data

97.

Document sanitization

      
Application Number 16143019
Grant Number 10904285
Status In Force
Filing Date 2018-09-26
First Publication Date 2021-01-26
Grant Date 2021-01-26
Owner CA, Inc. (USA)
Inventor
  • Saxonberg, Jordan
  • Chen, Joe H.

Abstract

In one embodiment, a method for electronic document sanitization may include receiving a first request from a client device to send a first electronic document, the first request including a requested usability level of the first electronic document, removing at least one document object from the first electronic document, the document object having potentially malicious content, the removing based at least in part on receiving the first request, and transmitting the first electronic document to the client device after removing the at least one document object therefrom.

IPC Classes  ?

  • G06F 12/14 - Protection against unauthorised use of memory
  • H04L 29/06 - Communication control; Communication processing characterised by a protocol
  • G06F 21/56 - Computer malware detection or handling, e.g. anti-virus arrangements
  • G06F 3/0484 - Interaction techniques based on graphical user interfaces [GUI] for the control of specific functions or operations, e.g. selecting or manipulating an object, an image or a displayed text element, setting a parameter value or selecting a range
  • G06F 40/166 - Editing, e.g. inserting or deleting

98.

Systems and methods for improving performance of cascade classifiers for protecting against computer malware

      
Application Number 15938377
Grant Number 10891374
Status In Force
Filing Date 2018-03-28
First Publication Date 2021-01-12
Grant Date 2021-01-12
Owner CA, INC. (USA)
Inventor
  • Curtin, Ryan
  • Kenemer, Keith

Abstract

The disclosed computer-implemented method for improving performance of cascade classifiers for protecting against computer malware may include receiving a training dataset usable to train a cascade classifier of a machine-learning classification system. A sample to add to the training dataset may be received. A weight for the sample may be calculated. The training dataset may be modified using the sample and the weight. A weighted training for the cascade classifier of the machine-learning classification system may be performed using the modified training dataset. Computer malware may be identified using the cascade classifier. In response to identifying the computer malware, a security action may be performed to protect the one or more computing devices from the computer malware. Various other methods, systems, and computer-readable media are also disclosed.

IPC Classes  ?

  • G06F 21/56 - Computer malware detection or handling, e.g. anti-virus arrangements
  • G06N 20/00 - Machine learning

99.

Detonate targeted malware using environment context information

      
Application Number 16018340
Grant Number 10885191
Status In Force
Filing Date 2018-06-26
First Publication Date 2021-01-05
Grant Date 2021-01-05
Owner CA, Inc. (USA)
Inventor Gupta, Prashant

Abstract

In one embodiment, a computer-implemented method for using customer context to detonate malware may be performed by one or more computing devices, each comprising one or more processors. The method may include receiving an artefact associated with a first device being targeted by malware, simulating in a controlled environment attributes of the first device based at least in part on the artefact, executing the malware in the controlled environment while the attributes of the first device are being simulated, and performing a security action with respect to the malware based at least in part on the execution of the malware in the controlled environment.

IPC Classes  ?

  • G06F 9/455 - EmulationInterpretationSoftware simulation, e.g. virtualisation or emulation of application or operating system execution engines
  • G06F 21/56 - Computer malware detection or handling, e.g. anti-virus arrangements
  • G06F 21/53 - Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems during program execution, e.g. stack integrity, buffer overflow or preventing unwanted data erasure by executing in a restricted environment, e.g. sandbox or secure virtual machine

100.

Systems and methods for identifying users

      
Application Number 16018044
Grant Number 10887307
Status In Force
Filing Date 2018-06-25
First Publication Date 2021-01-05
Grant Date 2021-01-05
Owner CA, INC. (USA)
Inventor
  • Newstadt, Keith
  • Sokolov, Ilya

Abstract

The disclosed computer-implemented method for identifying users may include (i) detecting that a user at an endpoint computing device is connecting to an identity provider, (ii) detecting, after detecting that the user at the endpoint computing device is connecting to the identity provider, that a mobile device has received a second-factor authentication message, (iii) discovering, by a security service, that the user at the endpoint computing device matches a known user profile registered to the mobile device by correlating the user at the endpoint computing device connecting to the identity provider with the mobile device receiving the second-factor authentication message, and (iv) applying a security policy to the user at the endpoint computing device based on the known user profile matched to the user by the security service. Various other methods, systems, and computer-readable media are also disclosed.

IPC Classes  ?

  • H04L 29/06 - Communication control; Communication processing characterised by a protocol
  1     2     3     ...     23        Next Page