SYSTEM AND METHOD FOR SECURITY AGENT MONITORING AND PROTECTION
    1.
    发明申请
    SYSTEM AND METHOD FOR SECURITY AGENT MONITORING AND PROTECTION 审中-公开
    用于安全代理监控和保护的系统和方法

    公开(公告)号:US20090165132A1

    公开(公告)日:2009-06-25

    申请号:US11962235

    申请日:2007-12-21

    IPC分类号: G06F21/24

    摘要: A security agent monitoring and protection system is provided. A security agent on an end point computing device can be accompanied by or can load into the device's memory at startup one or more independent software processes whose primary function is to directly protect the security agent itself and take protective actions against the end point computing device should a security agent protecting the device become disabled. Protection of the security agent can be achieved in several ways, including installing the security agent with restricted permissions, making it difficult to shutdown, restarting the security agent automatically if it is halted without authorization, disabling network connectivity of the end point device if the security agent does not successfully start or restart, protecting executable and dynamic link library (DLL) files of the security agent, and controlling access to the security agent's Common Object Model (COM) interfaces. These protective aspects can also be used by the monitoring agent itself to protect it from unauthorized access or disabling, further providing protection to the device.

    摘要翻译: 提供安全代理监控和保护系统。 端点计算设备上的安全代理可以在启动时伴随或可以加载到设备的存储器中,一个或多个独立的软件进程,其主要功能是直接保护安全代理本身并对端点计算设备采取保护措施 保护设备的安全代理变得禁用。 可以通过多种方式实现安全代理的保护,包括以有限的权限安装安全代理,使其难以关闭,如果未经授权中止,则自动重新启动安全代理,如果安全性失效,则终止终端设备的网络连接 代理没有成功启动或重新启动,保护安全代理的可执行和动态链接库(DLL)文件,并控制对安全代理的通用对象模型(COM)接口的访问。 这些保护方面也可以由监视代理本身使用,以防止未经授权的访问或禁用,进一步向设备提供保护。

    System, Method, Apparatus, and Computer Program Product for Facilitating Digital Communications
    2.
    发明申请
    System, Method, Apparatus, and Computer Program Product for Facilitating Digital Communications 有权
    系统,方法,设备和计算机程序产品促进数字通信

    公开(公告)号:US20080222696A1

    公开(公告)日:2008-09-11

    申请号:US12105674

    申请日:2008-04-18

    IPC分类号: G06F21/00

    摘要: A computer-implemented method and apparatus prevents unsecured access to a computer over a network by a client running on a remote computer. In one aspect of the present invention, a client policy is stored on the remote computer. The client policy includes a configuration of the remote computer that reduces the likelihood of a security breach of the computer as a result of the remote computer accessing the computer. A request is received from a user for access to the computer. It is verified that the remote computer conforms with the client policy, and the client is connected to said computer.

    摘要翻译: 计算机实现的方法和装置防止在远程计算机上运行的客户端通过网络对计算机的非安全访问。 在本发明的一个方面,客户端策略被存储在远程计算机上。 客户端策略包括远程计算机的配置,从而降低由于远程计算机访问计算机而导致计算机安全漏洞的可能性。 从用户接收到访问计算机的请求。 验证远程计算机是否符合客户端策略,并且客户端连接到所述计算机。

    RULES BASED ACTIONS FOR MOBILE DEVICE MANAGEMENT
    4.
    发明申请
    RULES BASED ACTIONS FOR MOBILE DEVICE MANAGEMENT 有权
    基于规则的移动设备管理行动

    公开(公告)号:US20130007245A1

    公开(公告)日:2013-01-03

    申请号:US13540142

    申请日:2012-07-02

    IPC分类号: G06F15/173

    摘要: Utilizing a server-based rules-based action framework, methods and systems gather status and configuration information about each of a plurality of mobile devices, which include devices from different mobile platforms. At the server, software processes monitor status information and respond automatically to changes, causing administrator-selected rules to be evaluated to determine if an action should automatically be initiated.

    摘要翻译: 利用基于服务器的基于规则的动作框架,方法和系统收集关于包括来自不同移动平台的设备的多个移动设备中的每一个的状态和配置信息。 在服务器上,软件进程监视状态信息并自动响应更改,从而导致管理员选择的规则被评估,以确定是否应该自动启动一个操作。

    Automated Test Management System and Method
    6.
    发明申请
    Automated Test Management System and Method 审中-公开
    自动化测试管理系统和方法

    公开(公告)号:US20090307763A1

    公开(公告)日:2009-12-10

    申请号:US12134099

    申请日:2008-06-05

    CPC分类号: G06F9/44505 G06F11/2294

    摘要: A test management application on a test management server includes a user interface on a Web-based portal by which a user can define one or more tests, selecting any desired configuration of operating system, connection type, and/or application, which are then saved in a test management database in the central server. Multiple tests involving the same configuration can be defined and saved for later selection, either individually or as a group of tests. A client agent engine on a test device can query the test management server for tests that can be conducted using the device's current configuration. If no such tests are found, the device can then query the test management server for the next available test. Upon allocation of the next available test to the device, the necessary system configuration for that test can be automatically retrieved, installed, and verified by the device. The device under test is automatically rebuilt to have the proper configuration for the test to be run.

    摘要翻译: 测试管理服务器上的测试管理应用程序包括基于Web的门户的用户界面,用户可以通过该界面定义一个或多个测试,选择任何所需的操作系统配置,连接类型和/或应用程序,然后保存 在中央服务器的测试管理数据库中。 可以定义并保存涉及相同配置的多个测试以供以后选择,单独测试或作为一组测试。 测试设备上的客户端代理引擎可以向测试管理服务器查询可以使用设备当前配置进行的测试。 如果没有找到这样的测试,设备可以向测试管理服务器查询下一个可用的测试。 在将下一个可用测试分配给设备后,该测试所需的系统配置可以由设备自动检索,安装和验证。 被测设备被自动重建,以便运行测试的正确配置。

    API TRANSLATION FOR NETWORK ACCESS CONTROL (NAC) AGENT
    7.
    发明申请
    API TRANSLATION FOR NETWORK ACCESS CONTROL (NAC) AGENT 审中-公开
    网络访问控制(NAC)代理的API翻译

    公开(公告)号:US20090158302A1

    公开(公告)日:2009-06-18

    申请号:US11955995

    申请日:2007-12-13

    IPC分类号: G06F13/00 G06F21/00

    摘要: An application programming interface (API) translation agent and method for converting a message from one application configured according to a first API to a message configured according to a second API so that the first application, which is configured to communicate only in accordance with the first API, can communicate with a second application, which is configured to communicate only in accordance with the second API. The first and second applications can include a security application and a network access control (NAC) agent installed on an end point computing device, and the API translation agent can be used by the NAC agent to obtain information regarding a security status of the end point computing device, the information being used to determine whether the end point computing device is in compliance with the security policies of a network.

    摘要翻译: 一种应用编程接口(API)翻译代理和方法,用于将根据第一API配置的一个应用程序的消息转换为根据第二API配置的消息,使得第一应用程序被配置为仅根据第一API进行通信 API可以与被配置为仅根据第二API进行通信的第二应用进行通信。 第一和第二应用可以包括安装在端点计算设备上的安全应用和网络访问控制(NAC)代理,并且可以由NAC代理使用API​​翻译代理来获得有关端点的安全状态的信息 计算设备,用于确定终点计算设备是否符合网络的安全策略的信息。

    Client-side network access policies and management applications
    10.
    发明授权
    Client-side network access policies and management applications 有权
    客户端网络访问策略和管理应用程序

    公开(公告)号:US08200773B2

    公开(公告)日:2012-06-12

    申请号:US10490103

    申请日:2002-09-30

    IPC分类号: G06F15/16

    摘要: A remote access client is provided for enabling communication between a remote data terminal configured to access a public network, and an enterprise network by way of a VPN tunnel through the public network. The remote access client includes at least one application program interface (API) to receive a first verification of the operating state of a predetermined application of the remote data terminal to enable a connection agent for establishing a point of presence on the public network. Upon connection to the point of presence, the API exchanges data between the remote access client and the predetermined application of the remote data terminal. The remote access client receives a second periodic verification of the operating state of the predetermined application via the API for terminating the connection to the point of presence upon the absence of the second verification. The point of presence enables the VPN tunnel for transporting data from the remote data terminal to the enterprise network across the public network.

    摘要翻译: 提供远程访问客户端,用于通过公共网络通过VPN隧道实现配置为访问公共网络的远程数据终端与企业网络之间的通信。 远程访问客户端包括至少一个应用程序接口(API),用于接收远程数据终端的预定应用的操作状态的第一验证,以使得连接代理能够在公共网络上建立存在点。 在连接到存在点之后,API在远程访问客户端和远程数据终端的预定应用之间交换数据。 远程访问客户端经由API接收对于预定应用的操作状态的第二次定期验证,用于在不存在第二验证的情况下终止与存在点的连接。 存在点使VPN隧道能够将数据从远程数据终端传输到整个公共网络的企业网络。