BRPI0709368A8 - método para minimizar exploração de vunerabilidades de software e produto de programa de computador - Google Patents
método para minimizar exploração de vunerabilidades de software e produto de programa de computadorInfo
- Publication number
- BRPI0709368A8 BRPI0709368A8 BRPI0709368A BRPI0709368A BRPI0709368A8 BR PI0709368 A8 BRPI0709368 A8 BR PI0709368A8 BR PI0709368 A BRPI0709368 A BR PI0709368A BR PI0709368 A BRPI0709368 A BR PI0709368A BR PI0709368 A8 BRPI0709368 A8 BR PI0709368A8
- Authority
- BR
- Brazil
- Prior art keywords
- exploitation
- message
- minimizing
- evidence
- program product
- Prior art date
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1408—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
- H04L63/1416—Event detection, e.g. attack signature detection
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/16—Implementing security features at a particular protocol layer
- H04L63/166—Implementing security features at a particular protocol layer at the transport layer
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- Theoretical Computer Science (AREA)
- General Engineering & Computer Science (AREA)
- Software Systems (AREA)
- Signal Processing (AREA)
- Computer Networks & Wireless Communication (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Computing Systems (AREA)
- Computer And Data Communications (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
- Information Transfer Between Computers (AREA)
Abstract
método para minimizar exploração de vulnerabilidades de software e produto de programa de computador.a especificação descreve um mecanismo para minimizar exploração de vulnerabilidades em software instalado emum sistema de computação. em uma camada de transporte (por exemplo, camada de soquete de protocolo de comunicação de transmissão (tcp)), o tráfego de rede é monitorado usando um componente de segurança instalado em um computador alvo. quando uma mensagem destinada ao sistema de computação é recebida, os dados incluídos na mensagem são comparados com uma evidência de exploração usada para identificar código malicioso. a evidência de exploração é provida para o componente de segurança pelo serviço de segurança que colhe informações com respeito a códigos maliciosos. com base na comparação de dados na mensagem com a evidência de exploração, identificam-se regras para instruir o componente de segurança a tomar as ações apropriadas com respeito à mensagem recebida.
Applications Claiming Priority (3)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US78572306P | 2006-03-24 | 2006-03-24 | |
| US60/785,723 | 2006-03-24 | ||
| PCT/US2007/064949 WO2007149612A2 (en) | 2006-03-24 | 2007-03-26 | Software vulnerability exploitation shield |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| BRPI0709368A2 BRPI0709368A2 (pt) | 2011-07-12 |
| BRPI0709368A8 true BRPI0709368A8 (pt) | 2018-04-24 |
Family
ID=38834179
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| BRPI0709368A BRPI0709368A8 (pt) | 2006-03-24 | 2007-03-26 | método para minimizar exploração de vunerabilidades de software e produto de programa de computador |
Country Status (11)
| Country | Link |
|---|---|
| US (1) | US8898787B2 (pt) |
| EP (1) | EP2008188B1 (pt) |
| JP (1) | JP5000703B2 (pt) |
| CN (2) | CN101558384B (pt) |
| AU (1) | AU2007261272B2 (pt) |
| BR (1) | BRPI0709368A8 (pt) |
| CA (1) | CA2647337A1 (pt) |
| MY (1) | MY150011A (pt) |
| RU (1) | RU2417429C2 (pt) |
| WO (1) | WO2007149612A2 (pt) |
| ZA (1) | ZA200808923B (pt) |
Families Citing this family (54)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US7971257B2 (en) * | 2006-08-03 | 2011-06-28 | Symantec Corporation | Obtaining network origins of potential software threats |
| US8869268B1 (en) * | 2007-10-24 | 2014-10-21 | Symantec Corporation | Method and apparatus for disrupting the command and control infrastructure of hostile programs |
| US8037536B2 (en) * | 2007-11-14 | 2011-10-11 | Bank Of America Corporation | Risk scoring system for the prevention of malware |
| US8539593B2 (en) * | 2009-01-23 | 2013-09-17 | International Business Machines Corporation | Extraction of code level security specification |
| US8205257B1 (en) * | 2009-07-28 | 2012-06-19 | Symantec Corporation | Systems and methods for preventing threats originating from a non-process based component hosted by a trusted process |
| US20110185353A1 (en) * | 2010-01-27 | 2011-07-28 | Jack Matthew | Mitigating Problems Arising From Incompatible Software |
| KR101055267B1 (ko) * | 2010-03-05 | 2011-08-09 | 한국전자통신연구원 | 액티브엑스 컨트롤의 배포 사이트 식별 방법과 보안 취약점 검출 방법 및 면역화 방법 |
| US8402547B2 (en) * | 2010-03-14 | 2013-03-19 | Virtual Forge GmbH | Apparatus and method for detecting, prioritizing and fixing security defects and compliance violations in SAP® ABAP™ code |
| US10025688B2 (en) | 2010-03-14 | 2018-07-17 | Virtual Forge GmbH | System and method for detecting data extrusion in software applications |
| KR101201622B1 (ko) * | 2010-08-19 | 2012-11-14 | 삼성에스디에스 주식회사 | 보안 기능을 가진 시스템 온 칩 및 이를 이용한 디바이스 및 스캔 방법 |
| US11210674B2 (en) | 2010-11-29 | 2021-12-28 | Biocatch Ltd. | Method, device, and system of detecting mule accounts and accounts used for money laundering |
| US20190057200A1 (en) * | 2017-08-16 | 2019-02-21 | Biocatch Ltd. | System, apparatus, and method of collecting and processing data in electronic devices |
| US10897482B2 (en) | 2010-11-29 | 2021-01-19 | Biocatch Ltd. | Method, device, and system of back-coloring, forward-coloring, and fraud detection |
| US20250016199A1 (en) * | 2010-11-29 | 2025-01-09 | Biocatch Ltd. | Device, System, and Method of Detecting Vishing Attacks |
| US10776476B2 (en) | 2010-11-29 | 2020-09-15 | Biocatch Ltd. | System, device, and method of visual login |
| US11223619B2 (en) | 2010-11-29 | 2022-01-11 | Biocatch Ltd. | Device, system, and method of user authentication based on user-specific characteristics of task performance |
| US10621585B2 (en) | 2010-11-29 | 2020-04-14 | Biocatch Ltd. | Contextual mapping of web-pages, and generation of fraud-relatedness score-values |
| US10917431B2 (en) | 2010-11-29 | 2021-02-09 | Biocatch Ltd. | System, method, and device of authenticating a user based on selfie image or selfie video |
| US12101354B2 (en) * | 2010-11-29 | 2024-09-24 | Biocatch Ltd. | Device, system, and method of detecting vishing attacks |
| US10728761B2 (en) | 2010-11-29 | 2020-07-28 | Biocatch Ltd. | Method, device, and system of detecting a lie of a user who inputs data |
| US10069837B2 (en) | 2015-07-09 | 2018-09-04 | Biocatch Ltd. | Detection of proxy server |
| US10586036B2 (en) | 2010-11-29 | 2020-03-10 | Biocatch Ltd. | System, device, and method of recovery and resetting of user authentication factor |
| US10970394B2 (en) | 2017-11-21 | 2021-04-06 | Biocatch Ltd. | System, device, and method of detecting vishing attacks |
| US10949514B2 (en) | 2010-11-29 | 2021-03-16 | Biocatch Ltd. | Device, system, and method of differentiating among users based on detection of hardware components |
| US20190158535A1 (en) | 2017-11-21 | 2019-05-23 | Biocatch Ltd. | Device, System, and Method of Detecting Vishing Attacks |
| US10474815B2 (en) | 2010-11-29 | 2019-11-12 | Biocatch Ltd. | System, device, and method of detecting malicious automatic script and code injection |
| US10834590B2 (en) | 2010-11-29 | 2020-11-10 | Biocatch Ltd. | Method, device, and system of differentiating between a cyber-attacker and a legitimate user |
| US11269977B2 (en) | 2010-11-29 | 2022-03-08 | Biocatch Ltd. | System, apparatus, and method of collecting and processing data in electronic devices |
| RU2477929C2 (ru) * | 2011-04-19 | 2013-03-20 | Закрытое акционерное общество "Лаборатория Касперского" | Система и способ предотвращения инцидентов безопасности на основании рейтингов опасности пользователей |
| RU2510074C2 (ru) * | 2012-02-24 | 2014-03-20 | Закрытое акционерное общество "Лаборатория Касперского" | Система и способ проверки исполняемого кода перед его выполнением |
| US9208316B1 (en) * | 2012-02-27 | 2015-12-08 | Amazon Technologies, Inc. | Selective disabling of content portions |
| US8844036B2 (en) * | 2012-03-02 | 2014-09-23 | Sri International | Method and system for application-based policy monitoring and enforcement on a mobile device |
| RU2523114C2 (ru) * | 2012-04-06 | 2014-07-20 | Закрытое акционерное общество "Лаборатория Касперского" | Способ анализа вредоносной активности в сети интернет, выявления вредоносных узлов сети и ближайших узлов-посредников |
| CN102799502B (zh) * | 2012-06-28 | 2016-03-30 | 航天恒星科技有限公司 | 一种星载嵌入式软件在轨维护方法 |
| RU2495487C1 (ru) * | 2012-08-10 | 2013-10-10 | Закрытое акционерное общество "Лаборатория Касперского" | Система и способ для определения доверия при обновлении разрешенного программного обеспечения |
| CN103856456A (zh) * | 2012-12-04 | 2014-06-11 | 中山大学深圳研究院 | 一种网络安全的方法和系统 |
| US9298911B2 (en) | 2013-03-15 | 2016-03-29 | Intel Corporation | Method, apparatus, system, and computer readable medium for providing apparatus security |
| US9015839B2 (en) * | 2013-08-30 | 2015-04-21 | Juniper Networks, Inc. | Identifying malicious devices within a computer network |
| US20160127412A1 (en) * | 2014-11-05 | 2016-05-05 | Samsung Electronics Co., Ltd. | Method and system for detecting execution of a malicious code in a web based operating system |
| GB2539705B (en) | 2015-06-25 | 2017-10-25 | Aimbrain Solutions Ltd | Conditional behavioural biometrics |
| RU2613535C1 (ru) * | 2015-11-20 | 2017-03-16 | Илья Самуилович Рабинович | Способ обнаружения вредоносных программ и элементов |
| KR20170135495A (ko) * | 2016-05-31 | 2017-12-08 | 주식회사 씨티아이랩 | 보안 위협 정보 분석 및 관리 시스템 |
| GB2552032B (en) | 2016-07-08 | 2019-05-22 | Aimbrain Solutions Ltd | Step-up authentication |
| US10579784B2 (en) | 2016-11-02 | 2020-03-03 | Biocatch Ltd. | System, device, and method of secure utilization of fingerprints for user authentication |
| RU2668710C1 (ru) | 2018-01-17 | 2018-10-02 | Общество с ограниченной ответственностью "Группа АйБи ТДС" | Вычислительное устройство и способ для обнаружения вредоносных доменных имен в сетевом трафике |
| US11222135B2 (en) * | 2018-05-28 | 2022-01-11 | International Business Machines Corporation | User device privacy protection |
| US11050772B2 (en) * | 2018-12-05 | 2021-06-29 | Bank Of America Corporation | Method and system for identification and prevention of profiling attacks in electronic authorization systems |
| RU2701040C1 (ru) * | 2018-12-28 | 2019-09-24 | Общество с ограниченной ответственностью "Траст" | Способ и вычислительное устройство для информирования о вредоносных веб-ресурсах |
| US11128670B2 (en) * | 2019-02-26 | 2021-09-21 | Oracle International Corporation | Methods, systems, and computer readable media for dynamically remediating a security system entity |
| US12028372B1 (en) * | 2020-12-30 | 2024-07-02 | Proofpoint, Inc. | Identifying threat similarity using forensics clustering |
| US11606353B2 (en) | 2021-07-22 | 2023-03-14 | Biocatch Ltd. | System, device, and method of generating and utilizing one-time passwords |
| NL2031253B1 (en) | 2021-08-19 | 2023-03-24 | Group Ib Tds Ltd | Computing device and method of detecting compromised network devices based on dns tunneling detection |
| US12585767B2 (en) | 2022-12-12 | 2026-03-24 | Fortinet, Inc. | Detecting zero-day malware with tetra code |
| US12613961B2 (en) * | 2022-12-12 | 2026-04-28 | Fortinet, Inc. | Identifying attacks to active resources by trusted devices with fake vulnerabilities on deceptive proxy resources |
Family Cites Families (21)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US6477651B1 (en) * | 1999-01-08 | 2002-11-05 | Cisco Technology, Inc. | Intrusion detection system and method having dynamically loaded signatures |
| RU2179738C2 (ru) * | 2000-04-24 | 2002-02-20 | Вильчевский Никита Олегович | Способ обнаружения удаленных атак в компьютерной сети |
| GB2368233B (en) * | 2000-08-31 | 2002-10-16 | F Secure Oyj | Maintaining virus detection software |
| JP2002342279A (ja) * | 2001-03-13 | 2002-11-29 | Fujitsu Ltd | フィルタリング装置、フィルタリング方法およびこの方法をコンピュータに実行させるプログラム |
| US7308714B2 (en) * | 2001-09-27 | 2007-12-11 | International Business Machines Corporation | Limiting the output of alerts generated by an intrusion detection sensor during a denial of service attack |
| US7197762B2 (en) | 2001-10-31 | 2007-03-27 | Hewlett-Packard Development Company, L.P. | Method, computer readable medium, and node for a three-layered intrusion prevention system for detecting network exploits |
| KR20040069324A (ko) | 2001-12-31 | 2004-08-05 | 시타델 시큐리티 소프트웨어, 인크. | 컴퓨터 취약성 자동 해결 시스템 |
| US20040015719A1 (en) * | 2002-07-16 | 2004-01-22 | Dae-Hyung Lee | Intelligent security engine and intelligent and integrated security system using the same |
| CA2496779C (en) * | 2002-08-26 | 2011-02-15 | Guardednet, Inc. | Determining threat level associated with network activity |
| JP2004139177A (ja) | 2002-10-15 | 2004-05-13 | Sony Corp | 情報検査方法及び装置、並びにプログラム |
| US7454499B2 (en) * | 2002-11-07 | 2008-11-18 | Tippingpoint Technologies, Inc. | Active network defense system and method |
| AU2003211914A1 (en) | 2003-02-04 | 2004-08-30 | Fujitsu Limited | Software maintenance service providing system, software maintenance service method, and program for causing computer to execute the method |
| US7251822B2 (en) | 2003-10-23 | 2007-07-31 | Microsoft Corporation | System and methods providing enhanced security model |
| US7725936B2 (en) * | 2003-10-31 | 2010-05-25 | International Business Machines Corporation | Host-based network intrusion detection systems |
| US7389538B2 (en) * | 2003-11-12 | 2008-06-17 | Fortinet, Inc. | Static code image modeling and recognition |
| US7661123B2 (en) * | 2003-12-05 | 2010-02-09 | Microsoft Corporation | Security policy update supporting at least one security service provider |
| RU2265242C1 (ru) * | 2004-04-12 | 2005-11-27 | Военный университет связи | Способ мониторинга безопасности автоматизированных систем |
| US7748038B2 (en) * | 2004-06-16 | 2010-06-29 | Ironport Systems, Inc. | Method and apparatus for managing computer virus outbreaks |
| JP2006067279A (ja) | 2004-08-27 | 2006-03-09 | Matsushita Electric Ind Co Ltd | 侵入検知システム及び通信装置 |
| WO2006031496A2 (en) * | 2004-09-10 | 2006-03-23 | The Regents Of The University Of California | Method and apparatus for deep packet inspection |
| ATE543295T1 (de) * | 2008-06-05 | 2012-02-15 | Ericsson Telefon Ab L M | Verkehrsüberwachung durch markierung der niedrigsten übertragungsschicht |
-
2007
- 2007-03-26 CA CA002647337A patent/CA2647337A1/en not_active Abandoned
- 2007-03-26 CN CN2007800189492A patent/CN101558384B/zh active Active
- 2007-03-26 JP JP2009503200A patent/JP5000703B2/ja active Active
- 2007-03-26 US US11/691,094 patent/US8898787B2/en active Active
- 2007-03-26 CN CN2012104605752A patent/CN103218563A/zh active Pending
- 2007-03-26 RU RU2008142138/08A patent/RU2417429C2/ru active
- 2007-03-26 BR BRPI0709368A patent/BRPI0709368A8/pt not_active Application Discontinuation
- 2007-03-26 AU AU2007261272A patent/AU2007261272B2/en not_active Ceased
- 2007-03-26 WO PCT/US2007/064949 patent/WO2007149612A2/en not_active Ceased
- 2007-03-26 EP EP07759401.8A patent/EP2008188B1/en active Active
- 2007-03-26 MY MYPI20083741A patent/MY150011A/en unknown
-
2008
- 2008-10-17 ZA ZA200808923A patent/ZA200808923B/xx unknown
Also Published As
| Publication number | Publication date |
|---|---|
| EP2008188B1 (en) | 2017-05-31 |
| MY150011A (en) | 2013-11-15 |
| WO2007149612A2 (en) | 2007-12-27 |
| US20070226797A1 (en) | 2007-09-27 |
| BRPI0709368A2 (pt) | 2011-07-12 |
| AU2007261272B2 (en) | 2012-04-19 |
| US8898787B2 (en) | 2014-11-25 |
| AU2007261272A1 (en) | 2007-12-27 |
| JP2009543163A (ja) | 2009-12-03 |
| CN103218563A (zh) | 2013-07-24 |
| EP2008188A4 (en) | 2012-01-18 |
| JP5000703B2 (ja) | 2012-08-15 |
| CA2647337A1 (en) | 2007-12-27 |
| RU2008142138A (ru) | 2010-04-27 |
| HK1134560A1 (en) | 2010-04-30 |
| CN101558384B (zh) | 2013-01-02 |
| EP2008188A2 (en) | 2008-12-31 |
| WO2007149612A3 (en) | 2008-11-20 |
| CN101558384A (zh) | 2009-10-14 |
| ZA200808923B (en) | 2009-08-26 |
| RU2417429C2 (ru) | 2011-04-27 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| MY150011A (en) | Software vulnerability exploitation shield | |
| BR112018071643A2 (pt) | métodos e sistemas para detectar inteligentemente malware e ataques em dispositivos de computação de cliente e redes corporativas | |
| US9386034B2 (en) | Behavioral model based malware protection system and method | |
| BRPI0414155A (pt) | sistema de segurança de internet de computador pessoal | |
| EP3476101B1 (en) | Method, device and system for network security | |
| CO2018012982A2 (es) | Aislamiento de seguridad virtualizado con base en hardware | |
| WO2007094942A3 (en) | Dynamic threat event management system and method | |
| CN107912064B (zh) | 壳代码检测 | |
| BR112019006489A2 (pt) | serviço de segurança de iot | |
| BR112022004506A2 (pt) | Solução de gerenciamento de feixe para exposição máxima permissível | |
| BR112013004345A2 (pt) | sistema e método para evitar malware acoplado a um servidor | |
| MX2017003826A (es) | Sistema de gestion de trafico distribuido y tecnicas. | |
| HK1243512A1 (zh) | 利用统计分析识别潜在的ddos攻击 | |
| CN106576051A (zh) | 使用主机应用/程序到用户代理的映射的零日威胁检测 | |
| WO2010024606A3 (ko) | 정상 파일 데이터베이스 제공 시스템 및 방법 | |
| US10812466B2 (en) | Using trusted platform module to build real time indicators of attack information | |
| BR112017028210A2 (pt) | sistema de gateway, métodos de processamento de pacote de dados, dispositivos de transferência de gateway, meio e produto de programa de computador | |
| MX2018014378A (es) | Metodo y dispositivo para evitar que un servidor sea atacado. | |
| Kallenberg et al. | Extreme privilege escalation on Windows 8/UEFI systems | |
| CN111262861A (zh) | 一种识别和过滤modbus tcp/udp协议的方法 | |
| BR112023014870A2 (pt) | Comunicações sem fio baseadas em grupo | |
| Lei et al. | Using network attack graph to predict the future attacks | |
| BR112018072377A2 (pt) | método de gerenciamento de tráfego e sistema de gerenciamento de tráfego | |
| Kovah et al. | Are you giving firmware attackers a free pass | |
| JP2009081736A (ja) | パケット転送装置及びパケット転送プログラム |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| B07A | Technical examination (opinion): publication of technical examination (opinion) | ||
| B09B | Decision: refusal | ||
| B09B | Decision: refusal |
Free format text: MANTIDO O INDEFERIMENTO UMA VEZ QUE NAO FOI APRESENTADO RECURSO DENTRO DO PRAZO LEGAL |