COUNTERING SERVICE ENUMERATION THROUGH IMPOSTER-DRIVEN RESPONSE

    公开(公告)号:US20190268358A1

    公开(公告)日:2019-08-29

    申请号:US16408186

    申请日:2019-05-09

    Abstract: Techniques for improving computer system security by detecting and responding to attacks on computer systems are described herein. A computer system monitors communications requests from external systems and, as a result of detecting one or more attacks on the computer system, the computer system responds to the attacks by analyzing the behavior of the attacker, relating that behavior to one or more attack profiles and creating a simulated environment to respond to the attack based in part on the attack profiles. The simulated environment responds to the attack by communicating with the attacker.

    Secure execution and transformation techniques for computing executables

    公开(公告)号:US10262161B1

    公开(公告)日:2019-04-16

    申请号:US14580023

    申请日:2014-12-22

    Abstract: Techniques described and suggested herein include the use of transformation parameters, such as mathematical and/or cryptographic operations, to permute various aspects of executables so as to control executable code authorized to run on one or more hosts. For example, a set of transformation parameters, such as a mathematical operation and a specified value upon which the mathematical operation may operate, are associated with a host or group of hosts. The set of transformation parameters may be applied to one or more runtime-related numerical locations associated with an executable that is intended to run on the specified hosts. At runtime, appropriately encoded executables are decoded by the specified hosts and operate normally, while differently encoded or unencoded executables are inoperable by the specified hosts.

    Testing security incident response through automated injection of known indicators of compromise

    公开(公告)号:US10135862B1

    公开(公告)日:2018-11-20

    申请号:US14959618

    申请日:2015-12-04

    Abstract: Disclosed are various embodiments for testing the security incident response of an organization through automated injection of a known indicator of compromise. A stream of event data generated by a network monitoring system of an organization is received. The stream of event data is modified to include data embodying a fabricated indicator of compromise. The stream of event data that has been modified is then provided to an intrusion detection system of the organization. Metrics are then generated that assess the response of the organization to the fabricated indicator of compromise.

    Social networking behavior-based identity system

    公开(公告)号:US10122727B2

    公开(公告)日:2018-11-06

    申请号:US14882881

    申请日:2015-10-14

    Abstract: Disclosed are various embodiments for a social networking behavior-based identity system that employs social networking data that a user has elected to share through an opt-in procedure. First social networking data is stored in association with a user identity. An assertion of the user identity is received from a client after the first social networking data is stored. Second social networking data is received in response to receiving the assertion of the user identity. An identity confidence level as to whether the user identity belongs to a user at the client is generated based at least in part on a comparison of the second social networking data with the first social networking data.

    Data protection using active data
    36.
    发明授权

    公开(公告)号:US09747455B1

    公开(公告)日:2017-08-29

    申请号:US14561044

    申请日:2014-12-04

    CPC classification number: H04L63/1441 G06F21/6227

    Abstract: Data of an organization or other entity may be protected using active data objects. The data may be storage in a storage system maintained by the organization or a separate organization. The data storage system may receive request for data, if the request violates one or more constraint conditions, the storage system may provide in response to the received request active data. The active data may include executable code that, when executed by a computer system, causes depletion of one or more resources used by a computer system executing the code.

    Triggering a request for an authentication
    39.
    发明授权
    Triggering a request for an authentication 有权
    触发身份验证请求

    公开(公告)号:US09426139B1

    公开(公告)日:2016-08-23

    申请号:US14673609

    申请日:2015-03-30

    Abstract: The present disclosure relates to multifactor-based authentication systems. Multifactor authentication occurs during a communication session in response to detecting a trigger event, such as an anomalous condition. Historical metrics, such as performance metrics (e.g., rendering speeds), behavioral metrics (e.g., click-stream behavior), environmental metrics (e.g., noise), etc., can be used as a baseline to compare against metrics for a current communication session. An anomalous condition, such as a current session metric exceeding a threshold, can result in an authentication service transmitting a multifactor authentication request.

    Abstract translation: 本公开涉及基于多因素的认证系统。 响应于检测到诸如异常状况的触发事件,在通信会话期间发生多因素认证。 可以将诸如性能指标(例如渲染速度),行为度量(例如,点击流行为),环境指标(例如噪声)等的历史指标用作与当前通信的指标进行比较的基准 会话 诸如当前会话度量超过阈值的异常状况可能导致认证服务发送多方认证请求。

Patent Agency Ranking