- US No. 8,528,091 – Detecting covert malware using decoys
- US No. 8,769,684 – Host UBA for Masquerade detection
- US No. 8,819,825 – Generating decoy network traffic
- US No. 9,009,829 – Embedding beacons into decoy network traffic
- US No. 9,275,345 – Automatic feature selection for UBA
- US No. 9,356,957 – Automatic generation of bait information
- US No. 9,501, 639 – Generating beacon documents, real and fake
- US No. 9,870,455 – System level user behavior biometrics
- US No. 9,971,891 – Identifying malware through change in behavior