EP1917757A2 - Verfahren und systeme für die intelligente zugangskontrolle zu computerressourcen - Google Patents
Verfahren und systeme für die intelligente zugangskontrolle zu computerressourcenInfo
- Publication number
- EP1917757A2 EP1917757A2 EP06847879A EP06847879A EP1917757A2 EP 1917757 A2 EP1917757 A2 EP 1917757A2 EP 06847879 A EP06847879 A EP 06847879A EP 06847879 A EP06847879 A EP 06847879A EP 1917757 A2 EP1917757 A2 EP 1917757A2
- Authority
- EP
- European Patent Office
- Prior art keywords
- policy
- endpoint
- compliance
- computing system
- conditions
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Withdrawn
Links
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/60—Protecting data
- G06F21/62—Protecting access to data via a platform, e.g. using keys or access control rules
- G06F21/6218—Protecting access to data via a platform, e.g. using keys or access control rules to a system of files or objects, e.g. local or distributed file system or database
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/57—Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
- G06F21/577—Assessing vulnerabilities and evaluating computer system security
Definitions
- the present invention relates generally to electronic computer security, and more specifically to methods and systems for controlling access to computing resources and further for controlling access to computing resources based on known computing security vulnerabilities.
- the first generation of endpoint access control included operating system services that controlled user access to one or more system resources, such as applications, data files, configuration settings, etc. Users were permitted or denied access to these resources based on a variety of factors, such as their login ID (which was authenticated using a secret) and a secured profile of policy settings identifying permissions and/or restrictions. These permissions were generally static in that they were not context sensitive in any other dimension than the user ID. There was no consideration of environmental factors. This static nature of security services embedded into the operating system remains relatively unchanged in many environments, to the present day.
- point solutions that address point security concerns by providing point access control capabilities.
- point solutions include: personal firewalls that restrict inbound and/or outbound access to specified applications, ports, addresses and/or communication protocols; antivirus agents, anti-spyware agents and application white-list management agents that monitor, detect and/or restrict access to specific system resources such as memory, registry keys, etc.; software update agents that automatically update an application if it is not a specified version; data encryption agents that encrypt specific files, the complete contents of specific folders, etc.; and physical access control agents that restrict access to floppy drives, USB drives, CD-ROM drives, etc.
- These security agents are one-dimensional in that they look at a single aspect of the endpoint' s security posture and make decisions on that basis. There is no integration of data across these security agents - all of these security solutions operate autonomously and completely independent of each other, with little or no communications between them or awareness of the state of other applications running on the endpoint. As with operating system security services, these point solutions are also static. The business logic and configurations of these point solutions are not context sensitive. They typically apply the same rules regardless of the user ID, user location, time of day, presence or absence of other security applications on the endpoint, configuration and state of other security or management applications on the endpoint, etc. While providing relatively stable and secure access control, such static endpoint controls remain inflexible and not adaptable to user and business needs. They are very much in use today in many environments.
- context awareness has been introduced into the field of endpoint security control.
- Functional examples of context awareness capabilities on the market today include: if a named application is not running or is not of a specified minimum version, access to network connectivity or certain applications will be restricted or blocked altogether; if a user is in location X (as determined by an assigned IP address, reachability of a network host, or some other method of automated location determination), the user is permitted outbound access using application X and Y to network servers on subnet Z, however if the user is in location Y (alternatively an unknown location), the user is permitted outbound access using application X and W to network servers on subnet V.
- access to a resource in the first case an application, in the second case the network and communications protocols
- access privilege is conditional on the current state of the endpoint (in the first case a certain application running, in the second case the current location).
- these solutions are limited in that they are only able to assess a limited set of inputs and affect a narrow set of access privileges.
- the decision is rarely revisited over the life of the user's connection or access session, i.e. they could come out of compliance subsequent to granting of access and will still retain access.
- Today's access control solutions still lack significant functions and capabilities. As one example, they lack the ability to form context-based access control decisions using as decision inputs state information provided by point solutions that are not context aware. Further lacking is the ability to collect endpoint state information from multiple point solutions, collect endpoint state information from the environment itself (e.g. information obtained from the operating system), and integrate the collected information to form a higher-level holistic and intelligent view of the overall endpoint state. [009] Today's solutions farther fail to provide extensibility of the endpoint state information integration function so as to enable the collection and integration of endpoint state information from a wide range of existing and future point solutions, applications and the endpoint environment itself. They lack the ability to define and enforce more granular access control permissions and restrictions, including the extensibility of this granular access control function to future access control objectives.
- an exemplary method comprising: identifying within at least one of the endpoint and host computing systems a plurality of conditions, each condition having a state; establishing a policy based upon the state of each of the plurality of conditions for access to the resource by the endpoint computing system, the policy including at least one rule and an analysis method for determining compliance with the rule; collecting the state of each of the plurality of conditions; processing the state of each of the plurality of conditions using the analysis method; determining, based on the processing, the compliance of the conditions with the rule; and controlling, based on the determining, the access of the endpoint computing system to the resource.
- an exemplary method comprising: identifying within at least one of the endpoint and host computing systems a plurality of conditions, each condition having a state; establishing a policy based upon the state of each of the plurality of conditions for access to the resource by the endpoint computing system, the policy including at least one rule and an analysis method for determining compliance with the rule; collecting the state of each of the plurality of conditions; processing the state of each of the plurality of conditions using the analysis method; determining, based on the processing, the compliance of the conditions with the rule; and controlling, based on the determining, the access of the endpoint computing system to the resource.
- an exemplary method comprising: identifying a plurality of conditions in at least one of the endpoint computing system and the host computing system, each of the plurality of conditions including an associated state; developing at least one rule; developing a policy for determining the compliance of each of the plurality of conditions with the at least one rule, the policy including at least one analysis method for processing each of the condition states to determine if the plurality of conditions are in compliance with the at least one rule.
- one exemplary method comprising: the computing system running software subject to at least one security vulnerability; establishing a policy based on the status of the at least one security vulnerability including at least one rule and an analysis method for determining compliance with the rule; receiving information relating to the status of the at least one security vulnerability of the software program; processing the information relating to the status using the analysis method; determining, based on the processing, the compliance of the at least one security vulnerability in relation to the rule; and controlling, based on the determining, the operation of the computing system.
- an exemplary method comprising: identifying within at least one of the endpoint and host systems a plurality of conditions, each condition having a state; operating on at least one of the host computing system and the endpoint computing system a software program subject to at least one security vulnerability; establishing a policy, based on the status of the at least one security vulnerability and the state of each of the plurality of conditions, the policy including at least one rule and an analysis method for determining compliance with the rule; receiving information relating to the status of the at least one known security vulnerability of the software program; receiving information relating to the state of each of the plurality of conditions; processing the information relating to the status of the at least one known security vulnerability and the state of each of the plurality of conditions using the analysis method; determining, based on the processing, the compliance of the at least one security vulnerability and the plurality of conditions with the rule; and controlling, based on the
- an exemplary method comprising: collecting a state for each of a plurality of conditions in at least one of the endpoint computing system and the host computing system; collecting a status of a known security vulnerability for a software program operating on at least one of the host computing system and the endpoint computing system; identifying a policy for determining access of the endpoint computing system to the resource, the policy including at least one rule and an analysis method for determining compliance with the rule; processing, using the analysis method, the state of each of the plurality of conditions and the status of the known security vulnerability; determining, based upon the processing, if the conditions and the known security vulnerability are in compliance with the rule; and generating, based upon the determining, a signal usable to control the access of the endpoint computing system to the resource.
- an exemplary method comprising: identifying a plurality of conditions in at least one of the endpoint computing system and the host computing system, each of the plurality of conditions including an associated state, at least one of the plurality of conditions relating to a risk of a known security vulnerability; and developing a policy for determining the access of the endpoint computing system to the resource, the policy including a rule and at least one analysis method for processing the states of the plurality of conditions to determine if the plurality of conditions are in compliance with the rule.
- Figure 1 is a block diagram showing features of a security compliance system in accordance with one embodiment of the present invention.
- Figure 2 is a flow chart showing a process for managing security compliance in accordance with an embodiment of the invention.
- Figure 3 is a functional block diagram showing the interaction of agents, managers, monitors and compliance engine in a security compliance system
- Figure 4 is a flow chart showing the flow of information between agents, managers, monitors, and the policy management system;
- Figure 5 is a block diagram showing an alternate embodiment of the invention wherein various components of the policy management system are incorporated with in the other computing systems;
- Figure 6 is a flow chart showing a process for integrating known security risks into a compliance system.
- Figure 7 is a flow chart showing the operation of the analysis engine to analyze agent data and develop a compliance policy.
- the present invention provides new and improved methods and systems for flexibly monitoring, evaluating, and initiating actions to enforce security compliance policies.
- benefits and advantages of the present invention include: o The collection of a wide range of endpoint state information. The enumeration of state policies regarding preferred, required and prohibited states. • o The enumeration of action policies regarding required, permitted and prohibited actions to take when the endpoint is partially or entirely in or out of compliance with state policies. o An analysis engine enabling comparing current states, state policies and action policies and reaching decisions on actions to permit, prevent, or automatically initiate.
- o A flexible methodology for assigning numerical values to current state information, state policies and action policies so that a variety of quantitatively-based analysis models can be used to determine security compliance.
- An enforcement capability that can operate persistently, constantly measuring compliance, with an ability to dynamically adjust access privileges subsequent to an initial granting of privileges.
- a compliance analysis engine that supports use of a range of different analytical methods and models so that optimum models can be invoked and applied, depending on situational factors.
- a system 100 including a host system 102, an endpoint system 104, and a policy management system 106.
- host system 102 comprises a secure, access-controlled processing system where-to remote systems such as endpoint system 104 connect to access data, processing capacity and host-accessible resources.
- Policy management system 106 provides rules and policies concerning the connection of remote endpoint systems 104 to host system 102.
- Host system 102, endpoint system 104, and policy management system 106 are interconnected to communicate through a conventional electronic network 108, such as the Internet.
- host system 102 the system is seen to include, in a conventional manner, a processor and user Sc communications interface 102A, as well as conventional storage components 102B, operating systems and software (typically contained in storage and operated by the processor) and other conventional components.
- resources indicated at 102G, accessible directly or indirectly through the host, including, for example: user data, user applications, physical ports, data storage devices, dial adaptors, network interfaces, and other resources as will be apparent to the reader.
- a plurality of conditions 102F are monitored by agents 102E, the agents collecting and transmitting information to agent managers 102D for aggregation by agent monitor 102F.
- Host 102 may comprise, for example, a processing system of the type typically owned, managed and/or operated by a business to support the operation of its employees. It may comprise a server, enterprise system, personal computer, laptop, personal digital assistant, mobile communications device such as a 'smart' telephone, or any other type of remotely accessible system. In a conventional manner, host system 102 may include conventional security features for controlling access to the data and resources thereon.
- Host system 102 may be consolidated at a single location or comprise a plurality of systems dispersed over multiple locations.
- endpoint system 104 comprises any processing system capable of interconnecting with host system 102, for example: a laptop computer, personal computer, server system, enterprise system, personal digital assistant, cellular telephone, 'smart' telephone or other personal device, or any other processing system capable of remotely accessing host system 102 for the purpose of accessing the resources available there on.
- Endpoint system 104 is seen to include, in a conventional manner, a processor and user & communications interface 104A, as well as conventional storage components 104B, operating systems and software (typically contained in storage and operated by the processor) and other conventional components.
- Further contained within host 104 are a plurality of conditions 104F. These conditions are monitored by agents 104E, the agents collecting and transmitting information to agent managers 104D for aggregation by agent monitor ⁇ 04F. The various conditions, as well as the agent functions, are described in detail herein below.
- the system comprises a conventional processing system, for example a server computer, enterprise computer, personal computer or a notebook computer. Accordingly, the system is seen to include, in a conventional manner, a processor and user & communications interface 106A 5 as well as conventional storage components 106B, operating systems and software (typically contained in storage and operated by the processor) and other conventional components.
- policy management system 106 is seen to include a compliance analysis engine 106C as well as various policy information stored within storage system 106B.
- compliance analysis engine 106C typically comprising software in data store 106B running on hardware 106A, functions to receive system condition information and process that condition information in accordance with the security policies, such as are stored within data storage 106B, in order to generate security rules.
- Analysis engine 106C can comprise a portion of the capacity of processor 106A and/or one or more dedicated and/or shared separate processor(s).
- the policy data stored within data store 106B can contain multiple sets of policy data for use by different endpoint systems 104, for use by different host systems 102 and for use by the policy management system 106 itself.
- policy management system 106 may be - contained i) within endpoint system 104, ii) within host system 102, iii) as a stand-alone network device otherwise connected to network 108, and/or iv) distributed in various combinations of the foregoing. See, for example, Figure 5 wherein a compliance analysis engine 106C is shown in each of endpoint systems 104 (engine 106C) and host system 102 (engine 106C").
- policy management system 106 may be performed by the existing components of the endpoint and host systems, or otherwise duplicated, replicated, or omitted within those systems as required to perform the appropriate functions as described herein. Further, as used here in, references to the policy management system includes where appropriate only those components and functions necessary to perform the described functions.
- host system 102 is used to control access to a network, for example a private network.
- host 102 comprises a gateway or other type of access control system to a network such as a private network.
- host 102 functions to make compliance and access assessments in accordance with the present invention, and forwards the results of such assessments to another access controller.
- the present invention is used to control access by an endpoint such as endpoint system 104, to a network, limiting or permitting endpoint system 104 to access specific network resources based on its current level of compliance.
- FIG. 2 there is shown a process 200 in accordance with the present invention for controlling the access of a user such as endpoint system to a computing resource.
- the present invention may be used to control access between different systems such as an endpoint system and a host system, or within a system, such as to particular resources available within the system.
- agents operate to determine the status of particular conditions in a system, as described herein the host system 102 and endpoint system 104. It will be understood by the reader that the invention is equally applicable to controlling access to resources within a single system as to between systems. For purposes of explanation, the invention will be described with respect to controlling the access of endpoint system 104 to host system 102. However, as described above, the invention is equally applicable to controlling access within host system 102 and/or endpoint system 104, as well as other computing systems.
- an “agent manager” operates to control the function of as well as to aggregate data collected by the various agents.
- An “agent monitor” functions to aggregate the data collected by various agent managers.
- the various agents, managers and monitors can be implemented in hardware, software, and/or combinations thereof.
- step 202 Considering first the selection of conditions to monitor within endpoint 104 (step 202), there are many different data sources and data elements that can be examined to assess the state of the endpoint, form compliance assessments, and ultimately make policy-based access control decisions regarding local and remote computing resources.
- Individual configuration data elements such as antivirus heuristics scanning status, and state data elements such as ⁇ is antivirus currently operating', can be obtained by establishing an interface to an agent specifically designed to collect and report that piece of information.
- Such configuration states and data elements are indicated in the drawing Figure 1 as conditions 104F.
- the agents 104E can comprise a component of the endpoint system or an external service provided by third party software.
- the endpoint system includes one or more agent managers 104D. These agent managers collect state information from individual agents 104E or the general computing environment, including the operating system version, registry settings, and others as will now be apparent to the reader.
- An- agent monitor 104C functions to collect and process information from the various agent managers 104 D, in the manner described below.
- a given inspection agent may provide a granular or broad means to indirectly assess configuration state and data elements and may provide numerous pieces of state configuration and state information to the endpoint's agent managers 104D. For example the response to a query regarding the state of a configuration setting might simply be true or false, whereas the response to a query regarding what viruses are currently being monitored for could be an enumerated list of thousands of virus names.
- Agents running on endpoint 104 and performing related or similar functions can generally be grouped into categories. For example, an antivirus client/agent, an anti- spyware agent, a content filtering agent and an applications white-list agent can be grouped into a 'security agent' category.
- endpoint 104 is configured so as to be able to add, modify, or remove agents on a per user basis and to further customize or adapt a given configuration of the endpoint's software components over time.
- Illustrative conditions 104F that are available and may be used for assessing endpoint state information are as follows. Note that not all of these conditions will be needed at any one point in time, i.e. when different system events occur, different pieces of endpoint state information become relevant. It will be understood that different items of interest may be monitored at different times, and different users will have different items they are interested in monitoring.
- User state information includes:
- User ID User group(s) membership (e.g. reseller, customer, business unit, division, department, etc.),
- Authentication state information includes:
- Authentication method e.g. no authentication, reusable password, one time password, biometrics, smart card, etc.
- Authentication source E.g. local to the machine or to a remote authentication database across a network
- Endpoint hardware Information includes:
- Hardware configuration and state such as: o CPU type o Total system memory o Free memory o Etc.
- BIOS o Vendor o Version o Individual settings • Drive mappings
- Endpoint Operating System Information includes:
- Operating System Services Information includes:
- Network Services Information includes:
- DNS o Current primary and secondary DNS servers o Size of DNS cache o Number of DNS queries o DNS queries serviced by local DNS cache
- ARP o Contents of ARP cache o Number of ARP requests o Number of RARP requests
- IP settings o Current TTL setting for outbound IP packets o IP address o Default gateway o Subnet mask
- Number of requests to a given IP address or address rangeFile System Information includes:
- Application Information includes:
- Application-Specific Information includes:
- Email o Version in use o Max number of emails per minute o Number of emails received and in inbox or other mail folders ⁇ Email arrival rate o Email reception rate o Email attachment count o Email attachment size o Number of recipients in emails sent
- Data Information includes:
- Data Backup Information includes:
- Antivirus Agent Information includes:
- Antivirus-specif ⁇ c configuration settings e.g. scan whole system, specific folders, specific files, run scan at startup, run scan every X days, signatures update frequency, etc.
- Antivirus scanning state e.g. active, idle
- Personal Firewall Agent information includes:
- Personal firewall-specific configuration settings e.g. user notify, silently discard, event logging, event log uploads, blocking enabled/disabled, etc.
- Personal firewall state e.g. actively blocking, blocking disabled, etc.
- VPN Client Information includes:
- VPN client-specific configuration settings e.g. default profile, split tunneling, authentication method, etc.
- VPN tunnel state e.g. connecting, connected, disconnecting, disconnected
- Anti-Spyware Agent Information includes:
- Anti-spyware-specific configuration settings e.g. scan, whole system, specific folders, specific files, run scan at startup, run scan every X days, signatures update frequency, etc.
- Anti-spyware agent scanning state (e.g. active, idle)
- Data Encryption Agent Information includes:
- Data encryption agent state (e.g. active, idle)
- Content Filtering Agent Information includes:
- Content filtering agent state (e.g. active, idle)
- Asset Management Agent Information includes:
- Asset management agent state (e.g. active, idle)
- Location Information includes:
- Location category o Directly connected to corporate network o Home o Public wireless location o Hotel o Approved kiosk o Public wired broadband location
- Time-Based Information includes:
- Wireless Connection Information includes:
- Available Connection Information includes:
- Active connection information includes:
- the various agents 104E and agent managers 104D and agent monitor(s) 104C are identified and configured for monitoring those various conditions (step 204).
- an agent manager 104D may be configured to query a vendor-specific API exposed by a third party antivirus agent, may be configured to query an operating system service periodically to determine if the endpoint has an active network interface and if so, the IP address of that interface, etc.
- Multiple managers 104D may be separately configured to monitor multiple agents 104E and multiple monitors 104C configured to aggregate manager data.
- agent managers are configured to monitor the conditions of interest such as one or more of those described above.
- Agents can be free standing external software applications, system services provided by the operating system or dedicated, special-purpose monitoring processes that are part of the monitored system itself. Agents can monitor both software activity and hardware activity. A typical method for monitoring hardware information is through the use of hardware device drivers and other similar operating system services. Examples of freestanding agents are antivirus client, personal firewall, anti-spyware, anti-phishing agents, data backup agents, etc. Agent monitor 104C can comprise software, hardware and/or a combination thereof, and is functional to collect or aggregate the input from the various agents, through the agent managers, and communicate that data for processing as described herein.
- FIG. 3 there is illustrated diagrammatically an exemplary series of agents 104E connected to monitor exemplary endpoint conditions 104F such as those listed above.
- the agent monitors 104C perform overall endpoint monitoring through the use of individual agent mangers 104D, each of which monitors one or more specific agents 104E, the individual agent managers 104D aggregated by an agent management service 104D'.
- agent management service 104D' As previously mentioned, different configurations and policies will require the use of different individual agent managers and different specific agents.
- FIG. 3 is the communication of the agent data to the compliance analysis engine 106C for processing in accordance with the methods described herein below.
- Endpoint inspection management policies including:
- the event e.g. an application being launched, a network connection being established, a user opening a file, a system login event, an application login event, an antivirus agent compliance violation, etc.
- a threshold value and type e.g. 5 times a minute when antivirus compliance score is below 75%, email transmission rates above 5 per minute, etc.
- a threshold value and type e.g. 5 times a minute when antivirus compliance score is below 75%, email transmission rates above 5 per minute, etc.
- Number of samples to collect for a compliance evaluation cycle o Sampling interval (if applicable) o Acceleration window interval (if applicable) o Whether sampling and results reporting method should utilize a successive stop/start windowing method or a sliding window method (e.g. for moving average-type calculations).
- Compliance Engine Management including:
- Type of information to send to management application e.g. raw collected data, compliance analysis results, compliance actions scheduled to occur, etc.
- Action Management information including:
- Enumerated State Policies information including: • Endpoint Hardware Configuration Policies
- Email o Permitted and/or restricted source email addresses or domains o Permitted and/or restricted destination email addresses or domains o Maximum number of outbound emails per minute o Maximum number of inbound emails per minute o Permitted recipients when email contains a specific text string (support for wildcards and logical combinations of AND, OR 5 NOT, ELSE, IF, etc. is supported) o Rate of outbound emails
- Permitted wireless network connectivity modes e.g. Wi-Fi ad hoc mode, Wi-Fi infrastructure mode, 802. Ix authentication required, 802. Ix authentication type
- the invention includes a graphical user interface application accessable through 106A that allows an administrator to: view available options for endpoint inspection using centralized policy management system 106, view compliance policies and policy enforcement actions, specify the policies of interest to them, and specify specific values for each policy of interest. All changes made by the administrator are saved to the policy database 106B and made available for all endpoint systems 104 or host systems 102 in the policy group to which those policy settings apply. Alternatively, this functionality could be included in a graphical user interface application on the endpoint system 104 or a graphical user interface application on the host system 102, when users or local administrators of those computing devices are responsible for configuring their own policy settings locally.
- One additional function of the policy management system 106 is the ability to receive and respond to policy update requests from endpo ⁇ nts 104 and hosts 102.
- the endpoint system 104 and/or host system 102 are configured via a policy setting to periodically query one or more remote policy database(s) 106B residing on the policy management system 106 and retrieve updated information about new policies and updated policy settings.
- the processor then stores this information in a local data repository.
- the policy management system user interface 106A can provide a control that allows an administrator to effectively summarize on a sliding scale, e.g. 1-5, High/Medium/Low, 1- 100, etc. their desired security posture, or conversely their security posture noncompliance tolerance.
- a set of data tables in the policy management database maps each setting on this sliding scale to the enablement and/or disablement of specific policies and policy actions, as well as specific compliance thresholds or scores. This greatly simplifies the administrator's task when establishing and configuring policies.
- a 'Custom' or comparable user interface control is also made available that allows an administrator to bypass the summary control and directly access the complete set of granular policy settings.
- the values in the data tables used to map a summary security level to specific policies and compliance thresholds are of course able to be changed by the database administrator at any time.
- references to software and software programs to describe a security vulnerability are to be interpreted in their broadest sense, including software such as application programs, operating systems and drivers, combinations of software and hardware and hardware.
- information that may be published about each vulnerability includes information such as descriptive parameters that describe the hardware or software at risk (e.g. Intel-based hardware running Windows XP Service Pack 2), possible system impacts (e.g. memory buffer overflow, unauthorized remote control of the computer, etc), severity type, severity level, sources of more information, date vulnerability was first reported, etc.
- descriptive parameters that describe the hardware or software at risk (e.g. Intel-based hardware running Windows XP Service Pack 2)
- possible system impacts e.g. memory buffer overflow, unauthorized remote control of the computer, etc
- severity type e.g., severity level
- sources of more information e.g., date vulnerability was first reported, etc.
- Vendors often use this information to prioritize their responses to vulnerabilities in their products. Responses typically take the form of customer notifications, often accompanied by specific interim remedial actions to take (e.g. disable a service, shut down a TCP port, etc.) and/or information on currently available patches that can be applied to eliminate the vulnerability.
- the vendor will normally begin scheduling internal activities to develop a solution to the vulnerability and make the solution available to customers and product users as a 'patch' or 'update'. Once this becomes available, customers may receive notification, and/or find notification information on a vendor's web site.
- IT managers also referred to herein as administrators, access vulnerability information by either receiving a notification from a vendor or industry group, going to the vendor or industry web site and querying the vulnerability database, or by establishing an electronic communications link with the remote database and electronically receiving vulnerability database updates on a periodic basis.
- IT managers typically use a combination of industry risk assessment and vendor risk assessment information to prioritize which vulnerabilities and patches to focus on first, and to prioritize remediation activities relative to other routine IT operating activities and other IT projects.
- the exploit window the endpoints remain exposed to a security attack unless some temporary securing action is taken to protect the endpoint.
- Attack exposure may be from the local machine only, from a remote machine, or both, depending on the nature of the vulnerability.
- the attack may utilize only the new exploit or more commonly utilize a combination of exploits to gain control of the system, gain reliable access to the system, take an action on the local system, or have the local system initiate a communications session with a remote computer of the hacker's choosing.
- a vulnerability policy directory including but not limited to the following information: Description of hardware and/or software that is vulnerable, descriptive attributes (e.g. whether it is exploitable locally or remotely, whether it impacts data confidentiality, data integrity or computing resource availability, etc.) specific remedial or corrective actions to take to eliminate the vulnerability (e.g. halt an operating service, block a port, block an application, disable a network interface, etc.), and the vulnerability severity level (e.g. high/medium/low, 4 out of 5, 7.5 out of 10, 65%, etc.).
- the present invention uses this information in accordance with the process shown and described with respect to Figure 6.
- the present invention is able to provide almost immediate protection for any computing device against vulnerability-specific exploits or security attacks during the period of time between when the security attack is created and used, and when the IT manager or end user has received the software patch from the software vendor and applied that same patch/repair to the computing device.
- the security risk information is stored on a data repository, for example within policy management system 106, that is accessible to remote endpoints via communications links, e.g. the Internet (step 602).
- the client software is configured via a policy setting to periodically query one or more remote vulnerability policy database(s) and retrieve updated information about new vulnerabilities and updated information about existing vulnerabilities (step 604). The client then stores this information in a local data repository (step 606).
- the client software is configured via policy settings to examine each vulnerability stored in the local data repository on a periodic basis, or whenever a particular system or policy compliance event warrants (step 608).
- the client software can subsequently utilize this information in one or more of several different ways to diminish this security risk (step 610), depending on how its policy settings are configured:
- the client can inspect each entry in the vulnerability directory, inspect the endpoint to see if the vulnerability is applicable, and if so, take the corrective action specified. Such capabilities are readily commercially available today.
- the client can inspect each entry in the vulnerability directory, inspect the endpoint to see if the vulnerability is applicable, and if so, examine the severity level and compare that to a policy-defined severity level, and corresponding policy-defined actions to take when a vulnerability with the specified severity level or a higher severity level is found. o If the severity level equals or exceeds a specified policy-defined value, then take the corrective action specified.
- the client can subsequently inspect the endpoint to determine whether the corrective action succeeded or the vulnerable condition still exists.
- the client can inspect the one or more vulnerability characteristics present in the collective set of information, such as the access vector, (e.g. is the vulnerability exploitable locally or remotely, does it effect confidentiality, integrity or availability, etc.) and compare that to a policy-defined list of characteristics to be on the lookout for, and corresponding policy-defined actions to take when a vulnerability with the specified characteristic is found:
- the access vector e.g. is the vulnerability exploitable locally or remotely, does it effect confidentiality, integrity or availability, etc.
- the client can subsequently inspect the endpoint to determine whether the corrective action succeeded or the vulnerable condition still exists. o If the corrective action taken does not succeed, consider the endpoint out of compliance and take one or more policy-defined corrective actions, e.g. block access to a file, a folder, an application, network connectivity, establishing a VPN tunnel, etc. o If the corrective action taken does not succeed, consider the endpoint out of compliance and adjust one or more security compliance scores where applicable. The revised scores when fed into the compliance analysis engine along with other endpoint state data may result in one or more policy-defined corrective actions being taken, e.g. block access to a file, a folder, an application, network connectivity, establishing a VPN tunnel, etc.
- policy-defined corrective actions e.g. block access to a file, a folder, an application, network connectivity, establishing a VPN tunnel, etc.
- the various condition data described above is collected by the agent managers through the agents (step 208) and then analyzed (step 210).
- FIG 4 there is shown in block diagram format the functional aspects 400 of collecting agent data from various exemplary agents 104E, collected through various exemplary agent managers 104D, aggregated by the agent monitoring service 104C for processing by analysis engine 106C, subsequently resulting in one or more actions being taken by various exemplary agents 104E.
- the output of analysis engine 106C is a series of actions to take, block and/or permit, the actions communicated back to the agents through the various managers.
- the aggregated set of actions is passed to the agent management service as a set of instructions.
- the agent management service parses the instructions, identifies for each instruction the appropriate individual agent manager 104D capable of executing the instruction and passes selected instructions to the appropriate agent manager 104D.
- the agent manager 104D passes the instructions tt> the particular agent 104E it relies on to take a particular action.
- the actions taken by the various agents 104E for example the control system services, system resources, system hardware, system applications and system data, in endpoint system 104 or host system 102, depend on where the various security functionalities of the invention are installed
- the data collected from various exemplary agents 104E and aggregated by the agent monitoring service 104C can be communicated over a data communications network to the policy management system 106 which can also process the collected data using the compliance analysis engine 106C.
- the policy management system 106 can also process the collected data using the compliance analysis engine 106C.
- One embodiment (call it embodiment 1) has all data collected at the end point analyzed by a compliance analysis engine residing on the end point, (whether that end point be a laptop or a host system web server).
- An alternative embodiment has all data collected at the end point analyzed by a compliance analysis engine residing on the policy management server. In this latter embodiment, the question is what happens when the policy management server completes the compliance analysis and determines that some policy violations exist and one or more policy compliance actions must be taken.
- Embodiment 2A Policy management server sends policy action instructions (block this application, permit that application, etc.) back to end point for execution. Note that a best practice would be to digitally sign the instructions sent to the end point using the policy management server's digital certificate. The end point must validate the digital signature before considering the policy action instructions
- Embodiment 2B Policy management server sends instructions (block this end point, permit that end point, limit that end point to only host systems residing on the the 192.168.10.x subnet, etc.) to a network access control device for execution.
- Embodiment 2C Policy management server sends instructions (block this end point, permit that end point, limit that end point to only the following applications or application transactions) to a host system for execution.
- the host system will as a result of these instructions add an Access Control List (ACL) entry to its session management table that subsequently effects what applications or application transactions residing on that host system may be accessed or used by the end point when the end point is requesting services from that host system.
- ACL Access Control List
- the policy management server creates a list of permitted host systems, applications, and/or application transactions that the end point is permitted to contact, based on its current degree of compliance. Policy management server then digitally signs the 'permitted actions list' and returns the permitted actions list to the end point.
- end point wants to access a host system
- the end point presents the digitally signed permitted actions list to the host system.
- the host validates the policy manager's digital signature on the signed permitted actions list and then creates an ACL that allows the end point to access specific resources (e.g. files, folders, types of transactions) on the host system.
- An alternative and complementary embodiment is that when packets from the end point have to pass through a network access control device residing between the end point and the host system, the end point must authenticate to the network access control device. As part of the authentication process at the network access control device, the end point must present the digitally signed permitted actions list to the network access control device. The network access control device then validates the policy manager's digital signature on the signed permitted actions list and then creates an ACL that allows the end point to access specific host systems (e.g. a single or range of IP addresses) and/or to use specific communication protocols (e.g. FTP, HTTP, SMTP, etc).
- specific host systems e.g. a single or range of IP addresses
- specific communication protocols e.g. FTP, HTTP, SMTP, etc.
- the policy management system 106 shown connected to the Internet, can be implemented alongside a network access control device, e.g. a router, switch VPN server, etc. or can remotely communicate with the network access control device via a data communications network.
- the policy management system 106 is able to communicate access permission and/or access restrictions to the network access control device, restricting what host systems 102 the endpoint system 104 is able to access, restricting what endpoint systems 104 are able to access host systems 102, and/or restricting what remote systems host system 102 is able to access.
- the policy management system 106 when it has received aggregated information from the agent monitor 104C on endpoint system 104 is also able to send access instructions to host system 102 identifying what permissions or restrictions should be applied to an endpoint system 104 when endpoint system 104 tries to access host system 102 via the network 108. Note that this last embodiment does not require the system 104 to have or be running security-related software such as this invention. Rather, the host system 102 can be protected and/or restrict access with respect to any endpoint 104 that tries to communicate with it.
- Analysis engine 106C ( Figure 1) contains one or more analytical methods or models and enables the selection of the optimum model or models for a given set of conditions 104F as determined by the various agents 104E.
- a feature and advantage of analysis engine 106C is its support for multiple models, its extensibility to support future models, and the ability to use multiple different models simultaneously either in parallel or in series while performing compliance analysis of conditions 104F.
- the analysis engine analytical model compares current condition information 104F, policies regarding those conditions 106B and makes action decisions resulting from those conditions and policies, using one or more analytical models. Analysis engine 106C subsequently initiates actions to permit, deny or control access to local and/or remote computing resources based on additional policies that identified permitted and/or denied actions when a noncompliance condition exists.
- Analytical model selections are based on one or more policy-based configuration settings stored in the policy store 106B. These policies, or rules, may alternatively and/or additionally be locally stored on the endpoint system 104 and/or host system 102, accessed by an endpoint system 104 or a host system 102 from a remote policy management system 106 via a data communications network, or a combination of the two. As with all other policies, the policy setting controlling what analytical models are used and when they are used can be dynamically changed at any time by changing the values of the policy settings in accordance with the processes described above.
- Policy management system 106 is designed to allow analytical models operated by analysis engine 106C to be added in the future, individually upgraded or modified, or removed.
- Conventional software distribution methods are used to communicate new or modified analytical models and new versions of the analysis engine 106C.
- analysis engine 106C is also architected to allow the inputs and/or actions associated with a given policy to be modified or customized as required.
- Conventional software distribution methods are used to communicate new or modified policies or policy values.
- Policies incorporating combination rules are also supported through the logical combining of multiple individual rules using conventional logic clauses such as AND, OR, NOT, ELSE, IF, WHEN, UNLESS, etc.
- the analysis engine 106C is the central and primary destination for all collected or received condition state information collected by the local endpoint system 104. Some or all condition state information to be collected may be requested by the analysis engine on a periodic basis, requested by the analysis engine as a direct result of a detected event, requested by the analysis engine as a direct result of completed analysis of previously received condition state information, sent to the analysis engine by agents and agent managers on a periodic basis, and/or sent from agents or agent managers to the analysis engine as a direct result of a detected event. This holds true for instances of local analysis of condition state information on the endpoint system 104 as well as remote analysis of condition state information on the policy management system 106.
- Capabilities of the analysis engine also include the ability to query the policy data store 106B (Figure 1) to collect compliance policies and their associated value(s). This query could occur on a fixed periodic basis or be based on a specified system event, for example system startup, client startup, application start event, network interface event, authentication event, notification of received policy updates, receipt of a specific endpoint data element, receipt of a specific endpoint data element having a specific value, etc.
- Capabilities of the analysis engine further include the ability to query the policy data store 106B to collect action policies and their associated value(s). This query occurs whenever needed by the analysis engine.
- Capabilities of the analysis engine further include the ability to output status and event messages to local processes or remote computers accessible across a network. These messages may be used to trigger the display of a message to a user on the local endpoint system 104 user interface, the display of a message on the policy management system 106, the updating of status information on an already open display or may be logged to a local or remote data store for use in reports.
- condition data regarding the status of conditions 104F are collected through the above described system of agent managers and monitors, and input into analysis engine 106C through the processor and communications interface 106A (step 702).
- a compliance assessment process, or algorithm is selected to process the condition data (step 704).
- numeric risk values can be assigned to non-numeric condition state data and numeric weightings applied to numeric values (step 705).
- the effective and appropriate security policy is retrieved from data storage 106B (step 706), the condition data is processed using the selected compliance process (step 708), and the results of the processed condition data compared to the compliance policy (step 710).
- the details of this process, including the various algorithms, are described in detail herein below.
- the policy action rules comprise a number of endpoint states that must be assessed, because there is a desire to be able to manage and change many policy settings using a finite number of data values and because of the number of possible combinations of endpoint states that could warrant invocation of the defined action, a simple rules based approach to processing this information may be unwieldy and not scale well.
- an algorithmic approach is provided by the present invention. As part of step 706 above, the algorithmic approach involves treating the non-numeric endpoint state information as real time values that are converted to numerical risk weightings, e.g. 1-100.
- Non-numeric endpoint state information listed above, includes those states not communicated as a number, e.g. is an application running, what level of anti-virus program is running, etc.
- the policy data store 106B contains a numeric value to assign to each non- numeric endpoint condition 104F.
- the analysis engine 106C receives endpoint condition state information 104F from ' the agent monitors 104C, the analysis engine 106C makes one or more queries to the policy data store 106B for each endpoint condition and retrieves the numeric value to assign to that particular endpoint condition.
- the process is repeated as needed for each non-numeric endpoint condition data element the analysis engine must convert from a non-numeric value to a numeric weighting. This process may also be repeated as needed for each numeric endpoint condition data element the analysis engine must convert from a raw numeric value to a normalized numeric weighting, e.g. converting the number of calendar days since antivirus was last updated (e.g. 0-365 days) to a normalized value in the e.g. 0-100 range.
- One analytical model operable by analysis engine 106C involves treating endpoint condition state information 104F as a matrix of numeric values where as mentioned above and as implied in each of the subsequent analytical models described herein, the real time state information is converted to numerical values or risk weightings, e.g. 1-100.
- the standalone and business intelligence rules can be treated as a second matrix where rules are given relative importance ratings.
- the analysis engine 106C generates a third matrix as the result.
- This third matrix contains numerical compliance scores that can be converted to security compliance ratings for different enforcement actions.
- Each rating can subsequently be compared to a predefined score threshold stored in the policy data store 106B for each possible enforcement action to determine whether or not to invoke the action. If the derived score is above the threshold, the endpoint is deemed sufficiently (while not necessarily completely) compliant with those particular endpoint configuration policies.
- the security score thresholds, the input matrix elements, the input matrix security scores and the items to be included in the endpoint inputs list are all data values stored in the policy data storel06B and as such are configurable and extensible so as to allow tailoring to an individual user's need. Configuration is performed using a user interface 106A, from which new or revised matrix elements, thresholds, weightings and factors can be created and modified. When implemented in a distributed fashion, changes to these data values made in the policy management system 106 can be distributed to the software agent residing on the endpoint system 104 using conventional software distribution methods. Examples of different matrix analysis methods are shown herein below.
- One analytical model operable by analysis engine 106C in accordance with the present invention utilizes descriptive business rules.
- the rules specify a specific action to take if specified prerequisite conditions are true.
- different actions will be initiated.
- the universe of possible actions will expand and evolve over time, as will the tests used to determine whether a given action should be initiated. For example, new operating system services may come available, new categories of security or endpoint management applications may emerge, security point solutions may become integrated, transport technologies will continue to evolve, features of security point solutions will evolve, etc. Additionally, different operational needs will warrant creating new actions and new tests.
- This analytical model is extensible and allows the addition, removal, tailoring, and/or changing the values of prerequisite conditions or actions for different customers and policy groups. Note that this rules-based analysis may or may not require the assignment of numeric risk scores to non-numeric conditions, depending on the desired rules.
- ⁇ Day of week is Mon, Tues, Wed, Thurs or Fri AND
- Time of day is between 8 AM and 8 PM o Prevent named application from opening
- Disconnect wireless adapter o When active wireless connection is ad hoc OR o When authentication method is not PEAP and 802. Ix
- Boolean Table-Based Analytical Model for Policy Enforcement Another analytical model operable by analysis engine 106C in accordance with the present invention utilizes a table of Boolean logic rules. This will be understood to be an extension of the business rules-based model described above, with the inclusion of Boolean logic combinations. The rules specify specific actions to take when specified conditions are true. The universe of possible actions will expand and evolve over time, as will the tests used to determine whether a given action should be initiated. Additionally, different users may prefer different rules, new actions and/or new conditions to determine. This analytical model is extensible both in terms of inputs and actions and allows a user to add, remove, tailor, and/or change the values of inputs and/or actions for different systems.
- Endpoint state information collected by the agent can be assigned relative importance weightings or quantitative scores, as described above, to develop a composite security 'score' for the security dimension or dimensions associated with that endpoint attribute.
- the score can subsequently be used as a proxy for a numeric endpoint security health metric for a particular aspect of the endpoint's configuration or health.
- an antivirus agent monitors the endpoint from a virus protection dimension and has certain attributes that must be in place to provide effective antivirus protection. Examples of attributes the antivirus agent must have in order to provide effective end point security and that is desired to be externally assessable state information to the invention includes: o The antivirus agent must be running to provide any protection at all.
- the antivirus agent must be of a recent version to be able to recognize certain new virus patterns.
- the antivirus agent receives periodic virus signature updates used in the virus scanning and protection process. Frequent updates, or more precisely a recent update (which is assumed to have brought the antivirus agent fully up to date) is necessary to have protection against the latest threats.
- the antivirus agent has configuration settings that can be enabled or disabled to provide more or less protection. [0143] Each of these attributes of the antivirus agent can be assigned an absolute score or a relative weighting by a user, based on the relative importance of that particular attribute to that user. For example as is shown in Table 2:
- Different operators may have different views on the relative importance of these attributes and/or may wish to use different or more granular attributes in their scoring model. For example, a different user may want to replace the version attribute with a real-time file system monitoring enabled attribute or add this as an additional attribute in their scoring model. Similarly, another user may assign more relative importance, hence assign a higher weight or score to how recently the antivirus signature files were updated. Another user might want to assign each of 4 specific configuration settings 5 'points' if the setting is enabled, for a total of 20 possible points when all antivirus scans options of interest to that user are enabled.
- attributes may be different for different users depending on the capabilities of their particular endpoint security solution. For example, if a particular commercially available antivirus agent has no configurable options to enable/disable, this attribute would not be relevant and would not be a consideration in the scoring process. In fact, one of the attributes could easily be the specific product being used, if a user has high confidence in 1-2 specific antivirus agents and much lower confidence in other antivirus agents. Support for variability across different end points having different hardware/software configurations is managed using policy settings as previously described. [0146] Attributes and weightings can be similarly established for each of the endpoint security agents previously identified. The approach can similarly be adapted to other existing and future endpoint security solutions using this same approach.
- the total score obtained by querying the agent and/or its externally viewable attributes can be used as a trigger for one or more general or context- specific predefined actions to be taken. For example, assuming the following is the list of actions to be taken if the antivirus agent score does not meet or exceed a threshold of 81 points or 81%:
- a different operator may wish to take additional or alternative predefined actions, for example:
- the corrective actions may vary by agent.
- the corrective actions when the firewall agent score is below the firewall threshold might be:
- an antivirus agent was the single agent under evaluation. Multiple agents can be simultaneously assessed in a similar fashion and the individual agent scores combined in different ways to create a holistic view of the endpoint state from multiple perspectives. For example, a user could define the following agent score combination logic as the basis for determining whether the end point is or is not in compliance:
- Antivirus agent score equal to or greater than 80%
- Antispyware agent score equal to or greater than 50%
- the individual agents of interest would be periodically queried or assessed at a configurable interval, individual agent scores calculated and then this business logic applied to determine if a noncompliance exists and if any predefined corrective, restrictive and/or notification actions (such as those previously defined) are required.
- the composite score is 79.95 points or 79.95%.
- the composite score would then be compared to a predefined composite threshold residing as a data value in the policy data store 106B to determine if any predefined corrective, restrictive and/or notification actions (such as those previously defined) are required.
- Different users may have different views on the relative importance of individual agents and may wish to use fewer, additional or different agents in their composite scoring model. For example, a different user may want to replace the content filtering agent with a patch management agent in their composite scoring model or add the patch management agent to the above composite scoring model. Similarly, another user may assign more or less relative importance, hence assign a higher or lower relative weight to the personal firewall. Such differences are accommodated by the invention through the use of policy settings and values that specify the agents of interest, the compliance thresholds, the relative weightings and other relevant considerations.
- composite corrective actions can be defined independently of individual agent corrective actions (e.g. antivirus agent corrective actions, personal firewall corrective actions, etc.) if defined values exist in the policy data storel06B.
- agent corrective actions e.g. antivirus agent corrective actions, personal firewall corrective actions, etc.
- the overall composite score exceeds the composite threshold, thereby not requiring invocation of previously defined composite corrective actions.
- the individual score for the antivirus agent is below the antivirus threshold, thus requiring invocation of previously defined agent-specific antivirus corrective actions. Examples of corrective actions were previously defined above.
- ⁇ IF local IP address is 1023.1023.1023.x AND IF endpoint is able to send ICMP ping to host 1023.1023.1023.56, THEN permit only wired Ethernet access, ELSE block all outbound network access on all transports o 91%:
- the individual raw scores for antivirus, personal firewall, anti-spyware agent, and content filtering must be fed into the composite scoring software process in order for the composite score to be determined.
- the composite scoring software routine assumes the individual agent thresholds have been met, (e.g. the antivirus agent score is 75, the personal firewall agent score is 90, the antispyware agent score is 70 and the content filtering agent score is 60) unless informed otherwise.
- the exception when reported is used to update the composite score data set and a revised composite score is calculated. This exception-based approach is also supported by the invention.
- the methods can be combined when so enabled via a policy setting.
- the composite scoring software routine assumes that the antivirus agent score is 75 points and assumes the personal firewall agent score is assumed to be 90, unless otherwise notified.
- the composite scoring software routine makes no assumption regarding the anti-spyware agent score or the content filtering agent score and requires that the antivirus compliance scoring software routine as well as the content filtering compliance scoring software routine both report actual raw compliance scores. Combinations of this type are also supported by the invention.
- Matrix Algebra-Based Analytical Model for Policy Enforcement utilize different matrix algebra methods. This model extends upon the scoring based analytical model previously described.
- Relative weights regarding the importance of compliance for each attribute can be assigned for each monitored condition.
- the collection of information can then be represented in tabular form in anticipation of making the data available for matrix algebra or other linear and nonlinear analysis methods.
- Table 7 shows how one operator has identified 3 data sources of interest, identified 3 attributes of interest, and assigned levels of relative importance to each data source/attribute pairing.
- These data sources, attributes and values are stored in the policy data store.
- the policy data store also contains the specific target values or thresholds for each of these attributes, e.g. the desired antivirus agent is product XYZ, the maximum age in days of the most recent anti-spyware agent is 30 days, the required configuration settings and values for the personal firewall are: no inbound access permitted, outbound access using HTTP protocol permitted, etc.
- the antivirus agent is running, is from an approved vendor and has been updated recently. However one or more critical configuration settings are not set correctly.
- the matrix determinant can be calculated using the following Formula 1 :
- Formula 1 [0174] The determinant derived from assessing the current state of the endpoint can be compared against a minimum threshold defined in the policy data store 106B that must be met in order for the endpoint to be considered in compliance.
- the matrix method described above can be further extended by assigning relative weightings to the data sources, treating the resulting values as a row or column vector matrix, and performing matrix multiplication of the data source relative importance matrix and the current state matrix. This allows the evaluation of compliance in a given dimension or attribute across a number of data sources, factoring in the relative • compliance importance of the different data sources.
- the endpoint is out of compliance with regards to currently running security agents and their vendor, in compliance with regards to current configuration settings, and in compliance with regard to configuration settings.
- scores, thresholds, weightings, etc. may be scaled up or down using a global weighting adjustment or discrete weighting adjustments stored as policy values in the policy data store.
- situation-specific policy-based adjustments can be made to scores and thresholds for other analytical models that may be added to the policy management system in the future.
- a user directly connected to the corporate network likely benefits from levels of protection or compliance monitoring systems integrated by the employer into the local network, reducing the criticality that one or more security applications are running or correctly configured on the user's machine.
- the analysis engine would query the policy data store for the minimum compliance score required to allow a certain system event to occur, determine the user's location (e.g. on the corporate network or not), if on the corporate network determine if the minimum compliance threshold should be adjusted by retrieving the policy value for the on-campus network security adjustment policy, adjust the compliance threshold as necessary, and then finally assess the compliance state of the endpoint using this adjusted threshold.
- Additional analytical methods supported by policy management system 106 are based on statistical analysis methods. These methods differ from methods previously described herein in that compliance analysis methods described below are based on evaluation of a population sample comprised of multiple data points collected over a period of time, rather than a evaluation of a single collected data point.
- This value can be passed immediately to the compliance analysis engine upon collection as an indicator of the instant CPU utilization.
- the sample size is one.
- Email arrival rate (e.g. emails arriving per minute)
- the analysis engine 106C is able to apply these methods to ratings or scores that are derived from inspecting numeric or non-numeric attributes of the endpoint, evaluating their state, comparing the current state with policy values that define numeric weightings or scores for a given state of a given endpoint attribute, and assigning a numeric value to that state. The assigned numeric value then becomes one data sample of a sample population.
- the analysis engine 106C is able to utilize statistical analysis methods for assessing compliance against a single, related group or arbitrary group of numeric conditions for the purposes of calculating a central tendency value of raw (i.e. reported directly from one of various exemplary agents 104E) and/or computed (i.e.
- the central tendency of a value given a sample population is commonly termed an 'average', however that is a general term and there are in fact several statistical analysis methods for calculating the central tendency of a sample population.
- the analysis engine 106C does in fact support several methods as described below. The specific method used for calculating the central tendency value of a given data element is selected by the operator. It will be apparent to the reader that the nature of the distribution makes certain methods more or less appropriate or optimal.
- the average or mean value is determined by summing the values of the collected samples and then dividing the sum by the number of samples.
- This calculated average or mean is the value passed to the compliance assessment routine at the completion of the sampling window and used in subsequent compliance analyses.
- An updated average or mean is passed to the compliance assessment routine at a frequency roughly equivalent to the sampling window size, immediately following calculation of the mean.
- the average or mean value is determined by summing the values of the collected samples and then dividing the sum by the number of samples.
- This calculated average or mean is the value passed to the compliance assessment process at the completion of the sampling window and used in subsequent compliance analyses.
- An updated average or mean is passed to the compliance assessment routine at a frequency roughly equivalent to the sampling interval, immediately following calculation of the moving average over the last X samples.
- This median value is the value passed to the compliance assessment routine at the completion of the sampling window and used in subsequent compliance analyses.
- This mode value is the value passed to the compliance assessment routine at the completion of the sampling window and used in subsequent compliance analyses.
- the compliance analysis engine will pass the average or mean value to the compliance assessment routine at the completion of the sampling window.
- This geometric mean value is the value passed to the compliance assessment routine at the completion of the sampling window and used in subsequent compliance analyses.
- the analysis engine performs a calculation of the difference between the two sampled values (or calculated compliance scores), performs a calculation of the difference between the two sampling times (or alternatively uses the policy-defined sampling interval), and divides the value difference by the time difference to obtain a rate, e.g. emails per second, change in CPU temperature per second, number of HTTP requests to a given DNS domain per minute, change in antivirus compliance score per minute, authentication failures per minute, etc.
- This rate value is the value passed to the compliance assessment routine at the completion of the sampling window and used in subsequent compliance analyses.
- This rate calculation result can also be used by the client to predict the value of the data element (either raw data or calculated score) at a future time. This predicted value can be used in subsequent compliance analysis. It will be understood that rates can be determined from many other sampling processes.
- the compliance analysis engine performs a calculation of the difference between the two values, performs a calculation of the difference between the two sampling times (or alternatively uses the policy-defined sampling interval), and divides the value difference by the time difference to obtain a rate (e.g. emails per second, change in CPU temperature per second, number of HTTP requests to a given DNS domain per minute, change in antivirus compliance score per minute, authentication failures per minute, etc.
- a rate e.g. emails per second, change in CPU temperature per second, number of HTTP requests to a given DNS domain per minute, change in antivirus compliance score per minute, authentication failures per minute, etc.
- the compliance analysis engine repeats this activity at a later time, where the time interval between the first rate sampling window (which collects two samples at a policy-defined sampling interval) and the second rate sampling window (which collects two additional samples at the same policy-defined sampling interval) is defined as an acceleration policy setting in the client policy data store.
- the compliance analysis engine performs a calculation of the difference between the two rate values, performs a calculation of the difference between the two sampling times (or alternatively uses the policy-defined acceleration sampling interval), and divides the value difference by the time difference to obtain a change in rate per unit time (i.e. just as the physical property acceleration is the measurement of change in velocity per unit time, where velocity itself is the measurement of the change in distance (the raw value being measured) per unit time.
- This acceleration value is the value passed to the compliance assessment routine at the completion of the acceleration sampling window and used in subsequent compliance analyses.
- This acceleration calculation result is also able to be used by the client to predict the value of the rate at a future time. This predicted value can be used in subsequent compliance analysis.
- the compliance analysis engine is able to utilize statistical analysis methods for assessing compliance against a single, related group or arbitrary group of data elements for the purposes of calculating the variability value of raw, computed and/or mapped data element(s), comparing the calculated variability value to corresponding policy values that define compliance value(s) and/or ranges for the data element(s), and making an assessment about compliance of that/those data element(s).
- Specific variability methods supported by the client are set out below. The specific method that should be used for calculating the variability value of a given data element or combination of data elements is selected by the administrator, as the nature of the distribution makes certain methods more or less appropriate or optimal for evaluating compliance of a given data element or combination of data elements.
- a system query e.g. CPU utilization, antivirus agent compliance, etc.
- a system query e.g. CPU utilization, antivirus agent compliance, etc.
- the calculated variance is passed to the compliance assessment routine at the completion of the sampling window and used in subsequent compliance analyses.
- a system query e.g. CPU utilization, antivirus agent compliance, etc.
- the calculated standard deviation is passed to the compliance assessment routine at the completion of the sampling window and used in subsequent compliance analyses.
- the compliance analysis engine is configured to perform a system query (e.g. CPU utilization, antivirus agent compliance, etc.) a policy-defined number of times, (e.g. count
- sample standard deviation is equal to the square root of the sample variance
- sample variance is equal to:
- sample mean is determined by summing the values of the collected samples and then dividing the sum by the number of samples.
- the calculated COV is passed to the compliance assessment routine at the completion of the sampling window and used in subsequent compliance analyses.
- a system query e.g. CPU utilization, antivirus agent compliance, etc.
- the number of occurrences of a given value is divided by the number of samples to determine the relative frequency of occurrence of that value. This will normally be expressed as a decimal value or a percentage.
- the list of values and their frequency of occurrence is then passed to the compliance assessment routine at the completion of the sampling window and used in subsequent compliance analyses. This method is useful in situations where the action policy is triggered based on the relative frequency of occurrences of a specific value or values of a given data element in a sampling window.
- the compliance analysis engine then calculates the cumulative frequency distribution of each value by adding the relative frequency of that value to the sum of the relative frequencies of all lesser values.
- the list of values and their cumulative frequency of occurrence is then passed to the compliance assessment routine at the completion of the sampling window and used in subsequent compliance analyses.
- This method is useful in situations where the action policy is triggered when the relative cumulative frequency exceeds a policy-defined threshold. For example, analysis of a sample of 100 transactions of type X concludes for this population sample that 90% of the transactions completed within 3.5 seconds. This result is compared to a predefined policy in the policy data store that specifies that 90% of type X transactions must complete within 4 seconds to determine whether or not a condition exists that warrants taking a policy-defined action on the endpoint.
- an administrator may measure successive values of a data element of interest a large number of times in either a controlled or typical endpoint environment to determine the distribution type, mean, variance and standard deviation of the values of that data element.
- an administrator may define a target mean and standard deviation he believes reasonably describes the distribution of the values of the data element of interest.
- These values are stored in the client policy data store as policy values such that they can be changed in the future as needed.
- a policy can be enabled in the compliance analysis engine that causes the compliance analysis engine to monitor a particular data element for a period of time until a sufficiently large sample to accurately represent the population of possible data values is collected, and then calculate a mean and standard deviation for the very large sample.
- These values also can be stored in the client policy data store as target policy values that represent the steady state behavior of that particular data element.
- the monitoring and data collection activity performed by the client can be started or stopped at any time using policy settings or commands issued to the client.
- the calculated properties e.g. mean, standard deviation, etc
- These values can further be used to calculate the probability of a sample event having a value greater than a specified policy value, less than a specified policy value, or within a specified range of policy values.
- This capability is supported in the client by transforming the sample value into a normal random variable with mean equal to zero and a variance of one. This transformation is done by subtracting the population mean specified value and dividing the result by the population standard deviation.
- the client includes a standard normal distribution data table in its local data store for looking up the probability of a given value or range of values of this transformed or normalized random variable.
- the compliance analysis engine also allows an administrator to specify a mean and/or variance threshold relative to the population's mean and/or variance for a given value of a given data element or group of data elements.
- the mean, variance and/or standard deviation of the sample can be calculated using standard methods such as those previously described.
- the calculated properties of the sample e.g.
- the compliance assessment routine is then passed to the compliance assessment routine at the completion of the sampling window and compared by the compliance analysis engine to the policy-defined values that describe the population and that were previously defined by the administrator or calculated by the client.
- This method is useful in situations where the action policy is triggered when the properties of a sample, e.g. the mean or standard deviation, exceeds a policy-defined threshold. For example, the client locally observes a population sample of 100,000 events of a particular type, calculates the mean and the standard
- an administrator may define target coefficients he believes reasonably describes the fitted relationship of the values of the data pair of interest. These values are stored in the client policy data store as policy values such that they can be changed in the future as needed.
- a mathematical analysis is performed to calculate the actual regression coefficients of the sample. The calculated coefficients of the sample are then passed to the compliance assessment routine and compared by the client to the policy-defined values. A compliance assessment is subsequently made.
- the policy- defined coefficients are combined with the sampled value of the independent variable (x) to determine an estimated value of the dependent variable (y).
- the actual value of the dependent variable (y) is then compared to the estimated value of the dependent variable (y). If the actual value differs from the estimated value by more than a specified, policy- defined difference (positive, negative and/or absolute magnitude), a policy violation is deemed to have occurred.
- the actual regression coefficients of the sample are used to predict the value of the dependent variable given a value of the independent variable.
- the predicted value of the dependent variable can then be used as a dynamically derived policy value. Should the specified value of the independent variable occur in the future, the actual value of the dependent variable at that time is compared by the compliance analysis engine with the dynamically derived policy value. If the actual value differs from the predicted value by more than a specified, policy-defined difference (positive, negative and/or absolute magnitude), a policy violation is deemed to have occurred. Filtering Analysis
- a filter in this context is a piece of purpose-built software that analyzes a particular data set, applies a threshold function of some type to that data set, and extracts only information of interest. Filtering in this context therefore is the act of extracting interesting data by applying a threshold against individual data points within a data set. Examples of the types of data the client can collect and policy-based thresholds the client can evaluate were previously described above.
- the compliance analysis engine supports several different filtering approaches and is extensible to support future additional filtering approaches as well.
- One supported filtering method previously described involves by collecting a specific type of data from the environment, comparing the data point against policy-defined thresholds, and taking a policy-based action when a compliance threshold is exceeded.
- the compliance analysis module assumes a particular aspect of the endpoint is in compliance unless otherwise notified by the data collection module.
- the filtering method continuously collects a specific type of data from the environment and performs a comparison of that single point of data against the policy-defined threshold for that single point of data. Only when a compliance violation is detected, is the data, or alternatively a descriptive message identifying the compliance violation, passed to an alternate compliance analysis engine responsible for combining the results of assessments of individual data points, i.e. performing a holistic compliance assessment.
- the overall compliance analysis module assumes complete compliance with respect to any given data element unless it is informed otherwise. This is commonly referred to as an exception- based notification system.
- the state of the antivirus agent and a review of policy settings might result in an antivirus compliance score of 65 points or 65%. Rather than treat this as a single data point and form an immediate compliance assessment, it might be preferable to sample the antivirus agent state information at a periodic interval for a period of time, where both the sampling interval and sampling window are policy-defined values, calculate the compliance score at each sampling, and treat the collection of compliance scores as a population sample.
- Such capabilities are supported by the policy management system. While this example cites the translation of antivirus agent state information into an antivirus compliance score, translation of other endpoint state information such as those data elements previously identified herein into compliance scores is also supported by the present invention. Collection of population samples of numeric compliance scores for other pieces of endpoint state information is likewise supported by the present invention.
- the policy management system is able to use statistical and other analysis methods to calculate one or more raw score inputs into this composite score.
- the policy management system is also able to use statistical analysis methods cited above, including but not limited to mean, median, mode, moving average and geometric mean to calculate a composite score by applying a statistical analysis method to a population sample of individual composite scores calculated at different times. Sampling intervals and sample count are controlled via policy settings.
- the policy management system is able to perform this function using all of the statistical analysis methods previously described.
- the client is able to perform this function for all monitored data elements and all composite scoring functions.
- the instant CPU utilization, the average CPU utilization, or moving average CPU utilization can be reported every time the value is determined, or only reported when it exceeds a policy defined threshold.
- the instant CPU utilization, average CPU utilization, moving average, etc. are distinctly different data elements, however the different data elements can be used simultaneously for different compliance evaluation purposes, i.e. collection and usage of instant CPU utilization and average CPU utilization are not mutually exclusive.
- one compliance evaluation method may require the instant CPU utilization value in order to perform a compliance evaluation
- a different compliance evaluation method may simultaneously require the average CPU utilization in order to perform a compliance evaluation.
- the present invention supports the ability to use these different measurement methods for different compliance tests using the same data source simultaneously.
- the present invention further supports this simultaneous use capability for all other supported monitored data sources as well, including both numeric sources and non-numeric sources that are converted to numeric values or scores.
- File open rate policy Mean of past 5 consecutive samples must be less than 100 AND standard deviation on those same samples must be less than 7.
- Antivirus compliance policy Most recent calculation of antivirus compliance based on most recent antivirus state inspection must have a compliance score greater than 50 OR mean of past 5 consecutive samples must be greater than 70.
- the policy management system supports this simultaneous use capability for all other supported monitored data elements as well, including both numeric sources and non-numeric sources that are mapped to numeric values or scores.
- condition data relating to monitored items e.g. CPU utilization, antivirus compliance score, security agents composite compliance score, etc.
- the policy management system provides the ability to support this very capability through the use of policy settings where these parameters can be specified and configured.
- step 212 when policy violations are detected it may be desired to take one or more discrete actions to either bring the endpoint into compliance, prevent harm from coming to the local and/or remote computers, restrict user actions, or perform any number of different actions.
- the solution is extensible to allow additional actions to be added in the future and configurable to allow different groups to customize different actions to best meet their needs. It will be understood that that the process of managing the endpoint and host operations repeats as frequently as necessary (step 214).
- Policy actions may be endpoint actions allowed to take place because the endpoint system 104 is in compliance with security policies, actions to take to partially or wholly restrict access to endpoint resources because the endpoint system 104 is not in compliance with security policies, or a combination thereof. Additionally, the invention may log event information locally in the policy data store and/or create and transmit event and state information across a data communications network to a remote policy management system 106 or a remote computer for logging, operator notification, transaction triggering, reporting, or other administrative purposes.
- Figure 4 in particular illustrates the notion of endpoint agent closed loop control feedback as a central part of the invention where endpoint policy actions taken may be targeted to a one or more specific endpoint agents 104E as a direct result of endpoint condition information 104F obtained from that endpoint agent 104E and other various exemplary agents.
- the antivirus agent may be queried for its current state. That information may then be combined with other information from other endpoint agents and analyzed by the analysis engine 106C to determine if any noncompliance conditions exist. If so, the invention may direct the antivirus agent to take specific actions, change internal configuration settings, etc. to bring the endpoint back into compliance or to block or permit certain system or operator activities.
- Email o Adjust bandwidth available to email application o Remove recipients from outbound emails o Discard email o etc.
- the analysis engine 106C determines what actions to initiate (step 212).
- the analysis engine 106C and it's operative models and algorithms provide the ability to proactively take an exhaustive and extensible list of permissive, corrective or restrictive actions.
- the actions can be taken immediately, scheduled to occur at some future point in time, upon completion of some predefined system event, or as a prerequisite to some predefined system event.
- the actions when taken can also be logged by the agent and made available to a central management reporting console. Also, the actions may result in notifications or alerts being displayed to the end user, and/or uploaded to a central management reporting console.
- the analysis engine can initiate the following actions:
- Endpoint system 104 components o Endpoint state data collection of conditions o Endpoint state data analysis o " Compliance analysis engine o Policy-based actions o Policy data store o Policy management functions o Reporting functions o (all as described above)
- Implementation Method 2 Centralized endpoint system policy management
- a central management user interface 106A on the policy management system 106 is used to configure policies that are then saved to a central policy data store 106B.
- the policies are synchronized or replicated to local policy databases residing in the endpoint system 104, for example in data store 104B, on a periodic basis when the endpoint system 104 checks in with the policy management system 106 to see if updates are available.
- An analysis engine, performing generally the same functions as engine 106C, residing on the endpoint system 104 is responsible for enforcing all compliance policies on the endpoint system 104 in accordance with policies received from the policy management system 106.
- This implementation is representative of a corporate-type offering or a managed services-type offering as might be provided by a service provider firm, where the endpoint system user is different from the endpoint system administrator or invention administrator roles.
- an exemplary distribution of invention components across different systems is as follows: o Endpoint system 104 components: o Endpoint state data collection of conditions o Endpoint state data analysis o Compliance analysis engine o Policy-based actions o Policy data store o Policy management console o Reporting console o (all as described above) o Policy management system 106 components: o Policy data store o Policy management functions o Reporting functions • Host system 102 components: o None
- conditions information, compliance violations and policy enforcement actions can be logged locally on the endpoint system 104 and/or uploaded to any remote computer over a data communications network for centralized management reporting purposes. Data received from multiple endpoint systems 104 can also be aggregated for additional management reports. Information logged locally on the endpoint system 104 can also be viewed locally on the endpoint system by an operator of that system.
- Implementation Method 3 Centralized host system policy management
- a central management user interface 106A on the policy management system 106 is used to configure policies that are then saved to a central policy data store 106B.
- the policies are synchronized or replicated to a local policy database residing on the host system 102, for example in data store 102B, on a periodic basis when the host system 102 checks in with the policy management system 106 to see if updates are available.
- An analysis engine residing on the host system 102 performing generally the same functions as described with respect to engine 106B, is responsible for enforcing all compliance policies on the host system 102 in accordance with policies received from the policy management system 106.
- This implementation is representative of a client-server type application environment where client applications (e.g. web browser, database client, etc.) residing on endpoint systems 104 initiate communication sessions with server applications (e.g. web server, database management system, etc.) residing on host system 102 to upload and/or download application-specific data.
- client applications e.g. web browser, database client, etc.
- server applications e.g. web server, database management system, etc.
- host system 102 it is important to ensure the host system 102 is protected at all times so that the host system 102 can not be compromised by a rogue endpoint system 104, or so that the host system 102 is prevented from sending malicious data or software code to endpoint system 104.
- an exemplary distribution of invention components across different systems is as follows: o Endpoint system 104 components: o None o Policy management system 106 components: o Policy data store o Policy management functions o Reporting functions • Host system 102 components: o Endpoint state data collection of conditions o Endpoint state data analysis o Compliance analysis engine o Policy-based actions o Policy data store o Policy management functions o Reporting functions o (all as described above)
- conditions information, compliance violations and policy enforcement actions can be logged locally on the host system 102 and/or uploaded to any remote computer over a data communications network for centralized management reporting purposes. Data received from multiple host systems 102 can also be aggregated for additional management reports. Information logged locally on the host system 102 can also be viewed locally on the endpoint system by an operator of that system.
- a policy management system 106 is used to configure compliance policies that are then saved to a policy data store 106B.
- Policies are also defined that identify what conditions 104F should be monitored by the agent monitoring components 104D, E residing on endpoint system 104 and/or host system 102. These policies are also stored in the policy data store 106B. Monitoring policies are subsequently distributed to endpoint system 104 and/or host system 102 periodically.
- An agent monitoring module residing on the endpoint system 104 performing generally this same functions as described with respect to engine 106B 3 collects endpoint condition information 104F and transmits it to the policy management system 106 where compliance analysis is performed using an analysis engine 106C.
- the analysis engine residing on the endpoint system does not perform compliance analysis.
- the analysis engine 106B in the policy management system 106 decides what policy enforcement actions are necessary.
- the policy enforcement decisions are sent from the policy management system 106 to the endpoint system 104 or the host system 104 as appropriate where the local system executes the policy enforcement actions as instructed by the policy management system 106.
- an exemplary distribution of invention components across different systems is as follows: o Endpoint system 104 components: o Endpoint state data collection of conditions o Policy-based actions o Policy management system 106 components: o Policy data store o Policy management functions o Reporting functions o Compliance analysis engine o . Identification of policy-based actions to take • Host system 102 components: o Endpoint state data collection of conditions o Policy-based actions
- a policy management system 106 is used to configure compliance policies that are then saved to a policy data store 106B.
- the policy management system 106 can create one set of compliance policies it uses locally in its own analysis engine 106B and one or more sets of compliance policies it distributes to endpoint systems. Different sets of compliance policies may have the same or different values regarding items monitored, compliance thresholds, analysis methods to use, etc.
- Policies are also defined that identify what conditions 104F should be monitored by the agent monitoring components 104C, D residing on endpoint system 104 and/or host system 102. These policies are also stored in the policy data store 106B. Monitoring policies are subsequently distributed to endpoint system 104 and/or host system 102 periodically.
- An agent monitoring module residing on the endpoint system 104 performing generally the same functions as described with respect to engine 106C, collects endpoint condition information 104F and forwards the aggregate data set of endpoint condition information 104 to the local analysis engine residing on the endpoint system.
- a host system 102 if similarly configured would behave in a similar way.
- the analysis engine local to the endpoint system collects endpoint state data, performs local compliance analysis and makes local policy action decisions.
- the local system uploads the information to the policy management system 106.
- the analysis engine 106C residing in the policy management system 106 examines the aggregated set of condition information across multiple or all endpoint systems simultaneously using one or more analytical methods previously described herein, e.g.
- the policy management system 106 will subsequently identify one or more policy enforcement actions that need to be taken, identify specific endpoint systems 104, 102 on which those actions need to be taken and send messages to the appropriate endpoint systems containing policy enforcement instructions.
- the policy management system will also send one or more policy enforcement action instructions to network access control devices such as VPN gateway, router, switch, remote access server, etc.
- an exemplary distribution of invention components across different systems is as follows: o Endpoint system 104 components: o Endpoint state data collection of conditions o Endpoint state data analysis o Compliance analysis o Policy-based actions o Policy data store o Policy management functions o Reporting functions o Policy management system 106 components: o Policy data store o Policy management functions o Reporting functions o Endpoint state data collection of conditions o Endpoint state data analysis o Compliance analysis engine o Identification of policy-based actions to take and identification of specific endpoint and/or host systems that should take those actions. • Host system 102 components: o Endpoint state data collection of conditions o Endpoint state data analysis o Compliance analysis o Policy-based actions o Policy data store o Policy management functions o Reporting functions
- a policy management system 106 is used to configure compliance policies that are then saved to a policy data store 106B.
- Policies identify what conditions 104F should be monitored by the agent monitoring components 104C, D residing on endpoint system 104 and/or host system 102.
- the policy management system is integrated with a network access control function such that user or application data exchanged between endpoint system 104 and host system 102 must pass through the combined policy management system/network access control function.
- the access control function challenges the endpoint system 104 to provide condition information (i.e. inputs to the endpoint analysis engine) and/or compliance evaluation results (i.e. outputs from the endpoint analysis engine).
- condition information i.e. inputs to the endpoint analysis engine
- compliance evaluation results i.e. outputs from the endpoint analysis engine
- the policy management system 106 evaluates the compliance state of the endpoint system 104 based on information provided by the endpoint system 104 and policy data residing in the policy management system policy data store 106B. The policy management system 106 then makes one or more access control decisions. Access decisions might result result in unrestricted access, total denial of access or partially restricted access (e.g. specific destination IP addresses, address ranges, applications, protocols, etc.) to network resources such as applications residing on host system 102. The access control decisions made by the policy management system 106 are passed to the access control function. The access control function then automatically configures one or more access control rules for that endpoint system 104.
- Access decisions might result result in unrestricted access, total denial of access or partially restricted access (e.g. specific destination IP addresses, address ranges, applications, protocols, etc.) to network resources such as applications residing on host system 102.
- the access control decisions made by the policy management system 106 are passed to the access control function.
- the access control function then automatically configures one or
- the access control function periodically issues challenges to the endpoint system 104 over the life of a communications session.
- the challenge requires the endpoint system 104 to re-submit compliance information in order to be permitted to maintain an active session with the network access function.
- policy management system functionality and the access control function are two separate functions, they can be installed together on a shared computing device or alternatively can be installed separately on two different computing devices interconnected by a data communications network.
- the raw condition information collected by the agent monitor 104C, the compliance analysis conclusions reached by the analysis engine 106C, and/or compliance actions identified as necessary by the analysis engine 106C is available to external security-centric or other software agents running on the same system via the invention's API.
- the information is also available to remote systems via data communications networks and traditional client-server communication protocols (e.g. HTTP) or peer-to- peer communications protocols. This allows information collected or conclusions created by the invention to be utilized by other software and network access agents as part of their host or network assessment process.
- client-server communication protocols e.g. HTTP
- peer-to- peer communications protocols peer-to- peer communications protocols. This allows information collected or conclusions created by the invention to be utilized by other software and network access agents as part of their host or network assessment process.
- the various endpoint, host and policy management systems are described as communicating directly with one — another, it will be understood that the invention is not thus limited. Numerous intermediary parties may be associated with the collection and forwarding of agent information from endpoint system 104 to policy management system
- the analysis engine 106C can be configured via policy settings to send a message to an administrator via a conventional data communications network and a commonly available data communications protocol, (e.g. via POP 3 SMTP, FTP, HTTP, etc.) when a specific policy event occurs, for example a specific noncompliance condition. Additionally, messages can be sent to an administrator when an unrecognized event occurs.
- a message could be sent from the client to a policy- defined server using email or any other communication method.
- the server would in term create or forward an email message to a policy defined email address.
- the email can contain a description of the event and 2 links: One to approve the action and one to deny the action.
- the present invention applies one or more compliance assessment algorithms to collected system conditions, comparing the results to a security policy to determine if the system is in compliance with a security policy. One or more actions may be taken responsively.
- the present invention can use one or more of a variety of algorithms to assess large numbers of state conditions, making decisions based upon an essentially infinitely flexible security policy.
- the invention has commercial application in the field of electronic resource security.
- Having a policy management system alert a host system regarding conditions on the network as a whole (i.e. a plurality of end points) or specific end points and either A) explicitly instruct the host system regarding what local resources can be accessed by remote systems, or B) alert the host of conditions such that the host is able to incorporate this data into its own self assessment and subsequently self- modulate what local resources are allowed to be accessed by remote systems based on its own self-assessment of conditions
Landscapes
- Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- General Engineering & Computer Science (AREA)
- Software Systems (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Databases & Information Systems (AREA)
- Bioethics (AREA)
- Health & Medical Sciences (AREA)
- Computing Systems (AREA)
- General Health & Medical Sciences (AREA)
- Computer And Data Communications (AREA)
- Debugging And Monitoring (AREA)
- Telephonic Communication Services (AREA)
Applications Claiming Priority (4)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US75242405P | 2005-12-21 | 2005-12-21 | |
| US11/451,950 US20070143851A1 (en) | 2005-12-21 | 2006-06-13 | Method and systems for controlling access to computing resources based on known security vulnerabilities |
| US11/451,689 US20070143827A1 (en) | 2005-12-21 | 2006-06-13 | Methods and systems for intelligently controlling access to computing resources |
| PCT/US2006/048720 WO2007075850A2 (en) | 2005-12-21 | 2006-12-20 | Methods and systems for controlling access to computing resources |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP1917757A2 true EP1917757A2 (de) | 2008-05-07 |
Family
ID=38218591
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP06847879A Withdrawn EP1917757A2 (de) | 2005-12-21 | 2006-12-20 | Verfahren und systeme für die intelligente zugangskontrolle zu computerressourcen |
Country Status (2)
| Country | Link |
|---|---|
| EP (1) | EP1917757A2 (de) |
| WO (1) | WO2007075850A2 (de) |
Families Citing this family (20)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20090165132A1 (en) * | 2007-12-21 | 2009-06-25 | Fiberlink Communications Corporation | System and method for security agent monitoring and protection |
| US8707385B2 (en) | 2008-02-11 | 2014-04-22 | Oracle International Corporation | Automated compliance policy enforcement in software systems |
| US8707384B2 (en) | 2008-02-11 | 2014-04-22 | Oracle International Corporation | Change recommendations for compliance policy enforcement |
| WO2009102653A1 (en) * | 2008-02-11 | 2009-08-20 | Oracle International Corporation | Compliance policy enforcement in computer systems |
| CN102771146B (zh) | 2009-08-24 | 2016-01-20 | 株式会社东芝 | 用于多接口用户的plmn选择和系统间移动性策略冲突化解 |
| US9544143B2 (en) | 2010-03-03 | 2017-01-10 | Duo Security, Inc. | System and method of notifying mobile devices to complete transactions |
| US9532222B2 (en) | 2010-03-03 | 2016-12-27 | Duo Security, Inc. | System and method of notifying mobile devices to complete transactions after additional agent verification |
| US8869307B2 (en) * | 2010-11-19 | 2014-10-21 | Mobile Iron, Inc. | Mobile posture-based policy, remediation and access control for enterprise resources |
| US9467463B2 (en) | 2011-09-02 | 2016-10-11 | Duo Security, Inc. | System and method for assessing vulnerability of a mobile device |
| RU2477520C1 (ru) | 2012-03-14 | 2013-03-10 | Закрытое акционерное общество "Лаборатория Касперского" | Система и способ динамической адаптации функционала антивирусного приложения на основе конфигурации устройства |
| US10129607B2 (en) * | 2012-12-19 | 2018-11-13 | Arris Enterprises Llc | Using analytical models to inform policy decisions |
| US9680864B2 (en) | 2013-06-18 | 2017-06-13 | Empire Technology Development Llc | Remediating rogue applications |
| EP2881885A1 (de) * | 2013-12-05 | 2015-06-10 | Kaspersky Lab, ZAO | System und Verfahren zur Bewertung von Ressourcen in einem Computernetzwerk zum Einhalten der Anforderungen für ein Computersystem |
| US9721112B2 (en) * | 2014-09-29 | 2017-08-01 | Airwatch Llc | Passive compliance violation notifications |
| ES2758755T3 (es) | 2015-06-01 | 2020-05-06 | Duo Security Inc | Método para aplicar normas de salud de punto final |
| EP3479222A4 (de) | 2016-06-29 | 2020-01-15 | Duo Security, Inc. | Systeme und verfahren zur klassifizierung von endpunktverwaltung |
| US10333965B2 (en) | 2016-09-12 | 2019-06-25 | Qualcomm Incorporated | Methods and systems for on-device real-time adaptive security based on external threat intelligence inputs |
| US10412113B2 (en) | 2017-12-08 | 2019-09-10 | Duo Security, Inc. | Systems and methods for intelligently configuring computer security |
| US11658962B2 (en) | 2018-12-07 | 2023-05-23 | Cisco Technology, Inc. | Systems and methods of push-based verification of a transaction |
| DE102020212405A1 (de) * | 2020-09-30 | 2022-03-31 | Siemens Aktiengesellschaft | Verfahren zum Betreiben eines Netzwerks und Computerprogrammprodukt |
Family Cites Families (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| GB2382419B (en) * | 2001-11-22 | 2005-12-14 | Hewlett Packard Co | Apparatus and method for creating a trusted environment |
| GB2405232B (en) * | 2003-08-21 | 2007-01-03 | Hewlett Packard Development Co | A method of and apparatus for controlling access to data |
| US8230480B2 (en) * | 2004-04-26 | 2012-07-24 | Avaya Inc. | Method and apparatus for network security based on device security status |
-
2006
- 2006-12-20 WO PCT/US2006/048720 patent/WO2007075850A2/en not_active Ceased
- 2006-12-20 EP EP06847879A patent/EP1917757A2/de not_active Withdrawn
Non-Patent Citations (1)
| Title |
|---|
| See references of WO2007075850A3 * |
Also Published As
| Publication number | Publication date |
|---|---|
| WO2007075850A2 (en) | 2007-07-05 |
| WO2007075850A3 (en) | 2008-04-03 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US9923918B2 (en) | Methods and systems for controlling access to computing resources based on known security vulnerabilities | |
| US20070143827A1 (en) | Methods and systems for intelligently controlling access to computing resources | |
| US11888890B2 (en) | Cloud management of connectivity for edge networking devices | |
| US7526800B2 (en) | Administration of protection of data accessible by a mobile device | |
| US8020192B2 (en) | Administration of protection of data accessible by a mobile device | |
| JP7730377B2 (ja) | サイバーセキュリティシステム | |
| US7636936B2 (en) | Administration of protection of data accessible by a mobile device | |
| WO2007075850A2 (en) | Methods and systems for controlling access to computing resources | |
| US12418512B2 (en) | Alias domains for accessing ZTNA applications | |
| US7308703B2 (en) | Protection of data accessible by a mobile device | |
| CN101375285B (zh) | 基于用户的网络活动动态调整计算机安全的方法和系统 | |
| US20080109679A1 (en) | Administration of protection of data accessible by a mobile device | |
| US9912638B2 (en) | Systems and methods for integrating cloud services with information management systems | |
| US9654507B2 (en) | Cloud application control using man-in-the-middle identity brokerage | |
| US8392972B2 (en) | Protected access control method for shared computer resources | |
| US9119017B2 (en) | Cloud based mobile device security and policy enforcement | |
| US11916907B2 (en) | Federated security for multi-enterprise communications | |
| US20240106863A1 (en) | Systems and methods for network security | |
| WO2004057834A2 (en) | Methods and apparatus for administration of policy based protection of data accessible by a mobile device | |
| US12526290B2 (en) | Traffic scanning with context-aware threat signatures | |
| US12207092B2 (en) | System and method for rogue device detection | |
| US12341672B2 (en) | Logging configuration system and method | |
| Whitelisting et al. | Application Whitelisting: Enhancing Host Security |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| 17P | Request for examination filed |
Effective date: 20080312 |
|
| AK | Designated contracting states |
Kind code of ref document: A2 Designated state(s): AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HU IE IS IT LI LT LU LV MC NL PL PT RO SE SI SK TR |
|
| AX | Request for extension of the european patent |
Extension state: AL BA HR MK RS |
|
| R17D | Deferred search report published (corrected) |
Effective date: 20080403 |
|
| REG | Reference to a national code |
Ref country code: HK Ref legal event code: DE Ref document number: 1120683 Country of ref document: HK |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWN |
|
| 18D | Application deemed to be withdrawn |
Effective date: 20110701 |
|
| REG | Reference to a national code |
Ref country code: HK Ref legal event code: WD Ref document number: 1120683 Country of ref document: HK |