BRPI0709368A8 - método para minimizar exploração de vunerabilidades de software e produto de programa de computador - Google Patents

método para minimizar exploração de vunerabilidades de software e produto de programa de computador

Info

Publication number
BRPI0709368A8
BRPI0709368A8 BRPI0709368A BRPI0709368A BRPI0709368A8 BR PI0709368 A8 BRPI0709368 A8 BR PI0709368A8 BR PI0709368 A BRPI0709368 A BR PI0709368A BR PI0709368 A BRPI0709368 A BR PI0709368A BR PI0709368 A8 BRPI0709368 A8 BR PI0709368A8
Authority
BR
Brazil
Prior art keywords
exploitation
message
minimizing
evidence
program product
Prior art date
Application number
BRPI0709368A
Other languages
English (en)
Inventor
Andrew Mosher Gregory
John Thompson Roger
Original Assignee
Avg Tech Cy Limited
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Avg Tech Cy Limited filed Critical Avg Tech Cy Limited
Publication of BRPI0709368A2 publication Critical patent/BRPI0709368A2/pt
Publication of BRPI0709368A8 publication Critical patent/BRPI0709368A8/pt

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1408Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
    • H04L63/1416Event detection, e.g. attack signature detection
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/55Detecting local intrusion or implementing counter-measures
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/16Implementing security features at a particular protocol layer
    • H04L63/166Implementing security features at a particular protocol layer at the transport layer

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Hardware Design (AREA)
  • Theoretical Computer Science (AREA)
  • General Engineering & Computer Science (AREA)
  • Software Systems (AREA)
  • Signal Processing (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Computing Systems (AREA)
  • Computer And Data Communications (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)
  • Information Transfer Between Computers (AREA)

Abstract

método para minimizar exploração de vulnerabilidades de software e produto de programa de computador.a especificação descreve um mecanismo para minimizar exploração de vulnerabilidades em software instalado emum sistema de computação. em uma camada de transporte (por exemplo, camada de soquete de protocolo de comunicação de transmissão (tcp)), o tráfego de rede é monitorado usando um componente de segurança instalado em um computador alvo. quando uma mensagem destinada ao sistema de computação é recebida, os dados incluídos na mensagem são comparados com uma evidência de exploração usada para identificar código malicioso. a evidência de exploração é provida para o componente de segurança pelo serviço de segurança que colhe informações com respeito a códigos maliciosos. com base na comparação de dados na mensagem com a evidência de exploração, identificam-se regras para instruir o componente de segurança a tomar as ações apropriadas com respeito à mensagem recebida.
BRPI0709368A 2006-03-24 2007-03-26 método para minimizar exploração de vunerabilidades de software e produto de programa de computador BRPI0709368A8 (pt)

Applications Claiming Priority (3)

Application Number Priority Date Filing Date Title
US78572306P 2006-03-24 2006-03-24
US60/785,723 2006-03-24
PCT/US2007/064949 WO2007149612A2 (en) 2006-03-24 2007-03-26 Software vulnerability exploitation shield

Publications (2)

Publication Number Publication Date
BRPI0709368A2 BRPI0709368A2 (pt) 2011-07-12
BRPI0709368A8 true BRPI0709368A8 (pt) 2018-04-24

Family

ID=38834179

Family Applications (1)

Application Number Title Priority Date Filing Date
BRPI0709368A BRPI0709368A8 (pt) 2006-03-24 2007-03-26 método para minimizar exploração de vunerabilidades de software e produto de programa de computador

Country Status (11)

Country Link
US (1) US8898787B2 (pt)
EP (1) EP2008188B1 (pt)
JP (1) JP5000703B2 (pt)
CN (2) CN101558384B (pt)
AU (1) AU2007261272B2 (pt)
BR (1) BRPI0709368A8 (pt)
CA (1) CA2647337A1 (pt)
MY (1) MY150011A (pt)
RU (1) RU2417429C2 (pt)
WO (1) WO2007149612A2 (pt)
ZA (1) ZA200808923B (pt)

Families Citing this family (54)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7971257B2 (en) * 2006-08-03 2011-06-28 Symantec Corporation Obtaining network origins of potential software threats
US8869268B1 (en) * 2007-10-24 2014-10-21 Symantec Corporation Method and apparatus for disrupting the command and control infrastructure of hostile programs
US8037536B2 (en) * 2007-11-14 2011-10-11 Bank Of America Corporation Risk scoring system for the prevention of malware
US8539593B2 (en) * 2009-01-23 2013-09-17 International Business Machines Corporation Extraction of code level security specification
US8205257B1 (en) * 2009-07-28 2012-06-19 Symantec Corporation Systems and methods for preventing threats originating from a non-process based component hosted by a trusted process
US20110185353A1 (en) * 2010-01-27 2011-07-28 Jack Matthew Mitigating Problems Arising From Incompatible Software
KR101055267B1 (ko) * 2010-03-05 2011-08-09 한국전자통신연구원 액티브엑스 컨트롤의 배포 사이트 식별 방법과 보안 취약점 검출 방법 및 면역화 방법
US8402547B2 (en) * 2010-03-14 2013-03-19 Virtual Forge GmbH Apparatus and method for detecting, prioritizing and fixing security defects and compliance violations in SAP® ABAP™ code
US10025688B2 (en) 2010-03-14 2018-07-17 Virtual Forge GmbH System and method for detecting data extrusion in software applications
KR101201622B1 (ko) * 2010-08-19 2012-11-14 삼성에스디에스 주식회사 보안 기능을 가진 시스템 온 칩 및 이를 이용한 디바이스 및 스캔 방법
US11210674B2 (en) 2010-11-29 2021-12-28 Biocatch Ltd. Method, device, and system of detecting mule accounts and accounts used for money laundering
US20190057200A1 (en) * 2017-08-16 2019-02-21 Biocatch Ltd. System, apparatus, and method of collecting and processing data in electronic devices
US10897482B2 (en) 2010-11-29 2021-01-19 Biocatch Ltd. Method, device, and system of back-coloring, forward-coloring, and fraud detection
US20250016199A1 (en) * 2010-11-29 2025-01-09 Biocatch Ltd. Device, System, and Method of Detecting Vishing Attacks
US10776476B2 (en) 2010-11-29 2020-09-15 Biocatch Ltd. System, device, and method of visual login
US11223619B2 (en) 2010-11-29 2022-01-11 Biocatch Ltd. Device, system, and method of user authentication based on user-specific characteristics of task performance
US10621585B2 (en) 2010-11-29 2020-04-14 Biocatch Ltd. Contextual mapping of web-pages, and generation of fraud-relatedness score-values
US10917431B2 (en) 2010-11-29 2021-02-09 Biocatch Ltd. System, method, and device of authenticating a user based on selfie image or selfie video
US12101354B2 (en) * 2010-11-29 2024-09-24 Biocatch Ltd. Device, system, and method of detecting vishing attacks
US10728761B2 (en) 2010-11-29 2020-07-28 Biocatch Ltd. Method, device, and system of detecting a lie of a user who inputs data
US10069837B2 (en) 2015-07-09 2018-09-04 Biocatch Ltd. Detection of proxy server
US10586036B2 (en) 2010-11-29 2020-03-10 Biocatch Ltd. System, device, and method of recovery and resetting of user authentication factor
US10970394B2 (en) 2017-11-21 2021-04-06 Biocatch Ltd. System, device, and method of detecting vishing attacks
US10949514B2 (en) 2010-11-29 2021-03-16 Biocatch Ltd. Device, system, and method of differentiating among users based on detection of hardware components
US20190158535A1 (en) 2017-11-21 2019-05-23 Biocatch Ltd. Device, System, and Method of Detecting Vishing Attacks
US10474815B2 (en) 2010-11-29 2019-11-12 Biocatch Ltd. System, device, and method of detecting malicious automatic script and code injection
US10834590B2 (en) 2010-11-29 2020-11-10 Biocatch Ltd. Method, device, and system of differentiating between a cyber-attacker and a legitimate user
US11269977B2 (en) 2010-11-29 2022-03-08 Biocatch Ltd. System, apparatus, and method of collecting and processing data in electronic devices
RU2477929C2 (ru) * 2011-04-19 2013-03-20 Закрытое акционерное общество "Лаборатория Касперского" Система и способ предотвращения инцидентов безопасности на основании рейтингов опасности пользователей
RU2510074C2 (ru) * 2012-02-24 2014-03-20 Закрытое акционерное общество "Лаборатория Касперского" Система и способ проверки исполняемого кода перед его выполнением
US9208316B1 (en) * 2012-02-27 2015-12-08 Amazon Technologies, Inc. Selective disabling of content portions
US8844036B2 (en) * 2012-03-02 2014-09-23 Sri International Method and system for application-based policy monitoring and enforcement on a mobile device
RU2523114C2 (ru) * 2012-04-06 2014-07-20 Закрытое акционерное общество "Лаборатория Касперского" Способ анализа вредоносной активности в сети интернет, выявления вредоносных узлов сети и ближайших узлов-посредников
CN102799502B (zh) * 2012-06-28 2016-03-30 航天恒星科技有限公司 一种星载嵌入式软件在轨维护方法
RU2495487C1 (ru) * 2012-08-10 2013-10-10 Закрытое акционерное общество "Лаборатория Касперского" Система и способ для определения доверия при обновлении разрешенного программного обеспечения
CN103856456A (zh) * 2012-12-04 2014-06-11 中山大学深圳研究院 一种网络安全的方法和系统
US9298911B2 (en) 2013-03-15 2016-03-29 Intel Corporation Method, apparatus, system, and computer readable medium for providing apparatus security
US9015839B2 (en) * 2013-08-30 2015-04-21 Juniper Networks, Inc. Identifying malicious devices within a computer network
US20160127412A1 (en) * 2014-11-05 2016-05-05 Samsung Electronics Co., Ltd. Method and system for detecting execution of a malicious code in a web based operating system
GB2539705B (en) 2015-06-25 2017-10-25 Aimbrain Solutions Ltd Conditional behavioural biometrics
RU2613535C1 (ru) * 2015-11-20 2017-03-16 Илья Самуилович Рабинович Способ обнаружения вредоносных программ и элементов
KR20170135495A (ko) * 2016-05-31 2017-12-08 주식회사 씨티아이랩 보안 위협 정보 분석 및 관리 시스템
GB2552032B (en) 2016-07-08 2019-05-22 Aimbrain Solutions Ltd Step-up authentication
US10579784B2 (en) 2016-11-02 2020-03-03 Biocatch Ltd. System, device, and method of secure utilization of fingerprints for user authentication
RU2668710C1 (ru) 2018-01-17 2018-10-02 Общество с ограниченной ответственностью "Группа АйБи ТДС" Вычислительное устройство и способ для обнаружения вредоносных доменных имен в сетевом трафике
US11222135B2 (en) * 2018-05-28 2022-01-11 International Business Machines Corporation User device privacy protection
US11050772B2 (en) * 2018-12-05 2021-06-29 Bank Of America Corporation Method and system for identification and prevention of profiling attacks in electronic authorization systems
RU2701040C1 (ru) * 2018-12-28 2019-09-24 Общество с ограниченной ответственностью "Траст" Способ и вычислительное устройство для информирования о вредоносных веб-ресурсах
US11128670B2 (en) * 2019-02-26 2021-09-21 Oracle International Corporation Methods, systems, and computer readable media for dynamically remediating a security system entity
US12028372B1 (en) * 2020-12-30 2024-07-02 Proofpoint, Inc. Identifying threat similarity using forensics clustering
US11606353B2 (en) 2021-07-22 2023-03-14 Biocatch Ltd. System, device, and method of generating and utilizing one-time passwords
NL2031253B1 (en) 2021-08-19 2023-03-24 Group Ib Tds Ltd Computing device and method of detecting compromised network devices based on dns tunneling detection
US12585767B2 (en) 2022-12-12 2026-03-24 Fortinet, Inc. Detecting zero-day malware with tetra code
US12613961B2 (en) * 2022-12-12 2026-04-28 Fortinet, Inc. Identifying attacks to active resources by trusted devices with fake vulnerabilities on deceptive proxy resources

Family Cites Families (21)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6477651B1 (en) * 1999-01-08 2002-11-05 Cisco Technology, Inc. Intrusion detection system and method having dynamically loaded signatures
RU2179738C2 (ru) * 2000-04-24 2002-02-20 Вильчевский Никита Олегович Способ обнаружения удаленных атак в компьютерной сети
GB2368233B (en) * 2000-08-31 2002-10-16 F Secure Oyj Maintaining virus detection software
JP2002342279A (ja) * 2001-03-13 2002-11-29 Fujitsu Ltd フィルタリング装置、フィルタリング方法およびこの方法をコンピュータに実行させるプログラム
US7308714B2 (en) * 2001-09-27 2007-12-11 International Business Machines Corporation Limiting the output of alerts generated by an intrusion detection sensor during a denial of service attack
US7197762B2 (en) 2001-10-31 2007-03-27 Hewlett-Packard Development Company, L.P. Method, computer readable medium, and node for a three-layered intrusion prevention system for detecting network exploits
KR20040069324A (ko) 2001-12-31 2004-08-05 시타델 시큐리티 소프트웨어, 인크. 컴퓨터 취약성 자동 해결 시스템
US20040015719A1 (en) * 2002-07-16 2004-01-22 Dae-Hyung Lee Intelligent security engine and intelligent and integrated security system using the same
CA2496779C (en) * 2002-08-26 2011-02-15 Guardednet, Inc. Determining threat level associated with network activity
JP2004139177A (ja) 2002-10-15 2004-05-13 Sony Corp 情報検査方法及び装置、並びにプログラム
US7454499B2 (en) * 2002-11-07 2008-11-18 Tippingpoint Technologies, Inc. Active network defense system and method
AU2003211914A1 (en) 2003-02-04 2004-08-30 Fujitsu Limited Software maintenance service providing system, software maintenance service method, and program for causing computer to execute the method
US7251822B2 (en) 2003-10-23 2007-07-31 Microsoft Corporation System and methods providing enhanced security model
US7725936B2 (en) * 2003-10-31 2010-05-25 International Business Machines Corporation Host-based network intrusion detection systems
US7389538B2 (en) * 2003-11-12 2008-06-17 Fortinet, Inc. Static code image modeling and recognition
US7661123B2 (en) * 2003-12-05 2010-02-09 Microsoft Corporation Security policy update supporting at least one security service provider
RU2265242C1 (ru) * 2004-04-12 2005-11-27 Военный университет связи Способ мониторинга безопасности автоматизированных систем
US7748038B2 (en) * 2004-06-16 2010-06-29 Ironport Systems, Inc. Method and apparatus for managing computer virus outbreaks
JP2006067279A (ja) 2004-08-27 2006-03-09 Matsushita Electric Ind Co Ltd 侵入検知システム及び通信装置
WO2006031496A2 (en) * 2004-09-10 2006-03-23 The Regents Of The University Of California Method and apparatus for deep packet inspection
ATE543295T1 (de) * 2008-06-05 2012-02-15 Ericsson Telefon Ab L M Verkehrsüberwachung durch markierung der niedrigsten übertragungsschicht

Also Published As

Publication number Publication date
EP2008188B1 (en) 2017-05-31
MY150011A (en) 2013-11-15
WO2007149612A2 (en) 2007-12-27
US20070226797A1 (en) 2007-09-27
BRPI0709368A2 (pt) 2011-07-12
AU2007261272B2 (en) 2012-04-19
US8898787B2 (en) 2014-11-25
AU2007261272A1 (en) 2007-12-27
JP2009543163A (ja) 2009-12-03
CN103218563A (zh) 2013-07-24
EP2008188A4 (en) 2012-01-18
JP5000703B2 (ja) 2012-08-15
CA2647337A1 (en) 2007-12-27
RU2008142138A (ru) 2010-04-27
HK1134560A1 (en) 2010-04-30
CN101558384B (zh) 2013-01-02
EP2008188A2 (en) 2008-12-31
WO2007149612A3 (en) 2008-11-20
CN101558384A (zh) 2009-10-14
ZA200808923B (en) 2009-08-26
RU2417429C2 (ru) 2011-04-27

Similar Documents

Publication Publication Date Title
MY150011A (en) Software vulnerability exploitation shield
BR112018071643A2 (pt) métodos e sistemas para detectar inteligentemente malware e ataques em dispositivos de computação de cliente e redes corporativas
US9386034B2 (en) Behavioral model based malware protection system and method
BRPI0414155A (pt) sistema de segurança de internet de computador pessoal
EP3476101B1 (en) Method, device and system for network security
CO2018012982A2 (es) Aislamiento de seguridad virtualizado con base en hardware
WO2007094942A3 (en) Dynamic threat event management system and method
CN107912064B (zh) 壳代码检测
BR112019006489A2 (pt) serviço de segurança de iot
BR112022004506A2 (pt) Solução de gerenciamento de feixe para exposição máxima permissível
BR112013004345A2 (pt) sistema e método para evitar malware acoplado a um servidor
MX2017003826A (es) Sistema de gestion de trafico distribuido y tecnicas.
HK1243512A1 (zh) 利用统计分析识别潜在的ddos攻击
CN106576051A (zh) 使用主机应用/程序到用户代理的映射的零日威胁检测
WO2010024606A3 (ko) 정상 파일 데이터베이스 제공 시스템 및 방법
US10812466B2 (en) Using trusted platform module to build real time indicators of attack information
BR112017028210A2 (pt) sistema de gateway, métodos de processamento de pacote de dados, dispositivos de transferência de gateway, meio e produto de programa de computador
MX2018014378A (es) Metodo y dispositivo para evitar que un servidor sea atacado.
Kallenberg et al. Extreme privilege escalation on Windows 8/UEFI systems
CN111262861A (zh) 一种识别和过滤modbus tcp/udp协议的方法
BR112023014870A2 (pt) Comunicações sem fio baseadas em grupo
Lei et al. Using network attack graph to predict the future attacks
BR112018072377A2 (pt) método de gerenciamento de tráfego e sistema de gerenciamento de tráfego
Kovah et al. Are you giving firmware attackers a free pass
JP2009081736A (ja) パケット転送装置及びパケット転送プログラム

Legal Events

Date Code Title Description
B07A Technical examination (opinion): publication of technical examination (opinion)
B09B Decision: refusal
B09B Decision: refusal

Free format text: MANTIDO O INDEFERIMENTO UMA VEZ QUE NAO FOI APRESENTADO RECURSO DENTRO DO PRAZO LEGAL