Detecting presence of a subject string in a target string and security event qualification based on prior behavior by an end user of a computer system
    2.
    发明授权
    Detecting presence of a subject string in a target string and security event qualification based on prior behavior by an end user of a computer system 有权
    基于计算机系统的最终用户的先前行为来检测目标字符串中的主题字符串的存在和安全事件限定

    公开(公告)号:US08321958B1

    公开(公告)日:2012-11-27

    申请号:US12511307

    申请日:2009-07-29

    CPC classification number: G06F21/51 G06F17/30867

    Abstract: A software-based security agent that hooks into the operating system of a computer device in order to continuously audit the behavior and conduct of the end user of the computer device. The detected actions of the end user can be stored in a queue or log file that can be continuously monitored to detect patterns of behavior that may constitute a policy violation and/or security risk. When a pattern of behavior that may constitute a policy violation and/or security risk is detected, an event may be triggered. A frequency vector string matching algorithm also is disclosed. The frequency vector string matching algorithm may be used to detect the presence or partial presence of subject strings within a target string of alphanumeric characters. The frequency vector string matching algorithm could be used to detect typos in stored computer records or to search for records based on partial information. In addition, the frequency vector string matching algorithm could be used to search communications for sensitive information that has been manipulated, obscured, or partially elided. In addition, an anomaly analysis is disclosed for comparing behavior patterns of one user against the behavior patterns of other users to detect anomalous behaviors.

    Abstract translation: 一种基于软件的安全代理,其挂接到计算机设备的操作系统中,以便不断地审核计算机设备的最终用户的行为和行为。 检测到的最终用户的动作可以存储在可以被连续监视的队列或日志文件中,以检测可能构成策略冲突和/或安全风险的行为模式。 当检测到可能构成违反政策和/或安全风险的行为模式时,可能触发事件。 还公开了一种频率矢量串匹配算法。 频率矢量串匹配算法可用于检测目标字符串中字母数字字符的存在或部分存在。 频率矢量字符串匹配算法可用于检测存储的计算机记录中的拼写错误或基于部分信息搜索记录。 此外,频率矢量串匹配算法可以用于搜索已经被操纵,模糊或部分消除的敏感信息的通信。 另外,公开了一种用于比较一个用户的行为模式与其他用户的行为模式以检测异常行为的异常分析。

    Simple algorithmic cryptography engine
    3.
    发明授权
    Simple algorithmic cryptography engine 有权
    简单的算法加密引擎

    公开(公告)号:US07032100B1

    公开(公告)日:2006-04-18

    申请号:US09466392

    申请日:1999-12-17

    CPC classification number: G06F9/30058 G06F9/322

    Abstract: A processor architecture and instruction set is provided that is particularly well suited for cryptographic processing. A variety of techniques are employed to minimize the complexity of the design and to minimize the complexity of the interconnections within the device, thereby reducing the surface area required, and associated costs. A variety of techniques are also employed to ease the task of programming the processor for cryptographic processes, and to optimize the efficiency of instructions that are expected to be commonly used in the programming of such processes. In a preferred low-cost embodiment, a single-port random-access memory (RAM) is used for operand storage, few data busses and registers are used in the data-path, and the instruction set is optimized for parallel operations within instructions. Because cryptographic processes are characterized by operations on wide data items, particular emphasis is placed on the efficient processing of multi-word operations, including the use of constants having the same width as an instruction word. A simplified arithmetic unit is provided that efficiently supports the functions typically required for cryptographic operations with minimal overhead. A microcode-mapped instruction set is utilized in a preferred embodiment to facilitate multiple parallel operations in each instruction cycle and to provide direct processing control with minimal overhead.

    Abstract translation: 提供了特别适用于加密处理的处理器架构和指令集。 使用各种技术来最小化设计的复杂性并且最小化设备内的互连的复杂性,从而减少所需的表面积以及相关的成本。 还采用各种技术来简化用于加密处理器的编程任务,并且优化预期在这种处理的编程中常用的指令的效率。 在优选的低成本实施例中,单端口随机存取存储器(RAM)用于操作数存储,在数据路径中使用很少的数据总线和寄存器,并且指令集优化用于指令内的并行操作。 由于加密过程的特征在于对宽数据项的操作,特别强调多字操作的有效处理,包括使用与指令字宽度相同的常数。 提供了一种简化的算术单元,可以以最小的开销高效地支持密码操作通常所需的功能。 在优选实施例中使用微代码映射指令集以促进每个指令周期中的多个并行操作,并以最小的开销提供直接的处理控制。

Patent Agency Ranking