-
公开(公告)号:US10896085B2
公开(公告)日:2021-01-19
申请号:US15974625
申请日:2018-05-08
Applicant: Hewlett-Packard Development Company, L.P.
Inventor: Ronny Chevalier , David Plaquin , Guillaume Hiet , Adrian Baldwin
Abstract: In an example there is provided a method of applying a mitigation action to a computing system. The method comprises receiving notification of an intrusion event on a computing system. The notification identifies one or more of data, and a process affected by the intrusion event. The method comprises accessing state data corresponding to a state of the computing system prior to the intrusion event, accessing a policy specifying one or more mitigation actions to be applied to the one or more of data, and a process in response to an intrusion event, restoring the one or more of data, and the process on the basis of the state data, and applying a mitigation action according to the policy.
-
公开(公告)号:US20200089870A1
公开(公告)日:2020-03-19
申请号:US16486331
申请日:2018-06-07
Applicant: Hewlett-Packard Development Company, L.P.
Inventor: Ronny Chevalier , David Plaquin , Maugan Villatel , Guillaume Hiet
Abstract: An intrusion detection system, comprising a monitor to receive messages from a target over a low-latency communication link comprising a controlled access memory structure logically positioned between the target and the monitor using point-to-point interconnects, the controlled access memory structure to receive a message from the target indicating that the target has entered a controlled mode of operation.
-
公开(公告)号:US11556645B2
公开(公告)日:2023-01-17
申请号:US16077688
申请日:2018-06-06
Applicant: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Inventor: Ronny Chevalier , Guillaume Hiet , Maugan Villatel , David Plaquin
Abstract: A method for monitoring control-flow integrity in a low-level execution environment, the method comprising receiving, at a monitor, a message from the execution environment indicating that the execution environment has entered a controlled mode of operation, receiving, at the monitor, a data packet representing execution of a selected portion of a control-flow process at the execution environment, identifying, using the data packet, a pathway corresponding to the selected portion of the control-flow process from a set of permissible control-flow pathways and determining whether the identified pathway corresponds to an expected control-flow behaviour.
-
公开(公告)号:US11308202B2
公开(公告)日:2022-04-19
申请号:US16486331
申请日:2018-06-07
Applicant: Hewlett-Packard Development Company, L.P.
Inventor: Ronny Chevalier , David Plaquin , Maugan Villatel , Guillaume Hiet
Abstract: An intrusion detection system, comprising a monitor to receive messages from a target over a low-latency communication link comprising a controlled access memory structure logically positioned between the target and the monitor using point-to-point interconnects, the controlled access memory structure to receive a message from the target indicating that the target has entered a controlled mode of operation.
-
公开(公告)号:US20210382991A1
公开(公告)日:2021-12-09
申请号:US17055836
申请日:2019-09-27
Applicant: Hewlett-Packard Development Company, L.P.
Inventor: Ronny Chevalier , David Plaquin , Christopher Ian Dalton , Guillaume Hiet
Abstract: The disclosure relates to a data processing apparatus. The data processing apparatus may comprise a memory storing a candidate service level response to an intrusion to an operating system having a plurality of operating system services. The data processing apparatus may comprise processing circuitry coupled to the memory. The data processing apparatus may comprise an output coupled to the processing circuitry. It may be that the processing circuitry is to, depending on an alert indicative of the intrusion: select from the memory, for an operating system service of the said plurality of operating systems, the said operating system service being related to the alert, the candidate service level response to the intrusion; and provide a signal to the output depending on the candidate service level response selected in respect of the said operating system service.
-
-
-
-