发明公开
- 专利标题: USING TRUSTED PLATFORM MODULE TO BUILD REAL TIME INDICATORS OF ATTACK INFORMATION
- 专利标题(中): 使用可信平台模块构建攻击信息的实时指标
-
申请号: EP16789723.0申请日: 2016-04-05
-
公开(公告)号: EP3292498A1公开(公告)日: 2018-03-14
- 发明人: SINGH, Balbir , MOHINDER, Preet , SHARMA, Manish , KHALI, Rahul, Chandra
- 申请人: McAfee, LLC
- 申请人地址: 2821 Mission College Boulevard Santa Clara, CA 95054 US
- 专利权人: McAfee, LLC
- 当前专利权人: McAfee, LLC
- 当前专利权人地址: 2821 Mission College Boulevard Santa Clara, CA 95054 US
- 代理机构: Maiwald Patentanwalts GmbH
- 优先权: US201514704510 20150505
- 国际公布: WO2016178767 20161110
- 主分类号: G06F21/44
- IPC分类号: G06F21/44 ; H04L9/32 ; H04L9/08
摘要:
Managed devices containing a Trusted Platform Module (TPM) to provide a trusted environment generate a device certificate at initialization of the TPM and send the device certificate to a management console for storing in a certificate database. Upon detecting a file of interest, the TPM signs the file, adding to a signature list created by previous managed devices. The signature list can be used to analyze the spread of the file across the system of managed devices, including tracking the file to the first managed device to have had a copy, without requiring real-time access to the managed devices during the spread of the file. In some embodiments, additional security measures may be taken responsive to determining the first managed device and the path the file has taken across the system of managed devices.
信息查询