Graph-based approach to deterring persistent security threats
    2.
    发明授权
    Graph-based approach to deterring persistent security threats 有权
    以图为基础的方法来阻止持续的安全威胁

    公开(公告)号:US08813234B1

    公开(公告)日:2014-08-19

    申请号:US13171759

    申请日:2011-06-29

    IPC分类号: G06F21/00

    摘要: A processing device comprises a processor coupled to a memory and implements a graph-based approach to protection of a system comprising information technology infrastructure from a persistent security threat. Attack-escalation states of the persistent security threat are assigned to respective nodes in a graph, and defensive costs for preventing transitions between pairs of the nodes are assigned to respective edges in the graph. A minimum cut of the graph is computed, and a defensive strategy is determined based on the minimum cut. The system comprising information technology infrastructure subject to the persistent security threat is configured in accordance with the defensive strategy in order to deter the persistent security threat.

    摘要翻译: 处理设备包括处理器,其耦合到存储器并且实现基于图的方法以保护包括信息技术基础设施的系统免受持久的安全威胁。 持续性安全威胁的攻击升级状态被分配给图中的相应节点,并且用于防止节点对之间的转换的防御成本被分配给图中的相应边缘。 计算图的最小值,并根据最小值确定防御策略。 包含受到持续安全威胁的信息技术基础架构的系统是根据防御策略配置的,以便阻止持续的安全威胁。

    Distributed storage system with efficient handling of file updates
    3.
    发明授权
    Distributed storage system with efficient handling of file updates 有权
    具有高效处理文件更新的分布式存储系统

    公开(公告)号:US08984384B1

    公开(公告)日:2015-03-17

    申请号:US12827097

    申请日:2010-06-30

    IPC分类号: G06F21/62 H04L29/08

    摘要: A client device or other processing device comprises a file encoding module, with the file encoding module being configured to separate a file into a plurality of sets of file blocks, to assign sets of the file blocks to respective ones of a plurality of servers, to define a plurality of parity groups each comprising a different subset of the plurality of servers, to assign, for each of the servers, each of its file blocks to at least one of the defined parity groups, and to compute one or more parity blocks for each of the parity groups. The file blocks are stored on their associated servers, and the parity blocks computed for each of the parity groups are stored on respective ones of the servers other than those within that parity group. Such an arrangement advantageously ensures that only a limited number of parity block recomputations are required in response to file block updates.

    摘要翻译: 客户端设备或其他处理设备包括文件编码模块,文件编码模块被配置为将文件分离成多组文件块,以将多个文件块的集合分配给多个服务器中的相应的服务器, 定义多个奇偶校验组,每个奇偶校验组包括多个服务器的不同子集,为每个服务器将其每个文件块分配给所定义的奇偶校验组中的至少一个,并计算一个或多个奇偶校验块用于 每个奇偶校验组。 文件块存储在其相关联的服务器上,并且为每个奇偶校验组计算的奇偶校验块存储在除了该奇偶校验组内的那些服务器之外的相应服务器上。 这种安排有利地确保了响应于文件块更新仅需要有限数量的奇偶校验块重新计算。

    Soft token posture assessment
    4.
    发明授权
    Soft token posture assessment 有权
    软令牌姿势评估

    公开(公告)号:US08683563B1

    公开(公告)日:2014-03-25

    申请号:US13435616

    申请日:2012-03-30

    IPC分类号: G06F7/04

    摘要: An improved technique for assessing the security status of a device on which a soft token is run collects device posture information from the device running the soft token and initiates transmission of the device posture information to a server to be used in assessing whether the device has been subjected to malicious activity. The device posture information may relate to the software status, hardware status, and/or environmental context of the device. In some examples, the device posture information is transmitted to the server directly. In other examples, the device posture information is transmitted to the server via auxiliary bits embedded in passcodes displayed to the user, which the user may read and transfer to the server as part of authentication requests. The server may apply the device posture information in a number of areas, including, for example, authentication management, risk assessment, and/or security analytics.

    摘要翻译: 用于评估其上运行软令牌的设备的安全状态的改进技术从运行软令牌的设备收集设备姿态信息,并且发起设备姿态信息传输到服务器以用于评估设备是否已经被 遭受恶意活动。 设备姿态信息可以涉及设备的软件状态,硬件状态和/或环境上下文。 在一些示例中,设备姿态信息被直接发送到服务器。 在其他示例中,设备姿态信息通过嵌入在显示给用户的密码中的辅助位发送到服务器,用户可以作为认证请求的一部分读取和传送到服务器。 服务器可以在多个区域中应用设备姿态信息,包括例如认证管理,风险评估和/或安全分析。

    Distributed storage system with enhanced security
    5.
    发明授权
    Distributed storage system with enhanced security 有权
    具有增强安全性的分布式存储系统

    公开(公告)号:US08132073B1

    公开(公告)日:2012-03-06

    申请号:US12495189

    申请日:2009-06-30

    IPC分类号: H03M13/00

    摘要: A client device or other processing device separates a file into blocks and distributes the blocks across multiple servers for storage. In one aspect, subsets of the blocks are allocated to respective primary servers, a code of a first type is applied to the subsets of the blocks to expand the subsets by generating one or more additional blocks for each subset, and the expanded subsets of the blocks are stored on the respective primary servers. A code of a second type is applied to groups of blocks each including one block from each of the expanded subsets to expand the groups by generating one or more additional blocks for each group, and the one or more additional blocks for each expanded group are stored on respective secondary servers. The first and second codes are advantageously configured to provide security against an adversary that is able to corrupt all of the servers over multiple periods of time but fewer than all of the servers within any particular one of the periods of time.

    摘要翻译: 客户端设备或其他处理设备将文件分成块并将块分布在多个服务器上进行存储。 在一个方面,将块的子集分配给相应的主服务器,将第一类型的代码应用于块的子集,以通过为每个子集生成一个或多个附加块来扩展子集,并且扩展子集 块存储在相应的主服务器上。 第二类型的代码被应用于每个包括来自每个扩展子集的一个块的块组,以通过为每个组生成一个或多个附加块来扩展组,并且存储每个扩展组的一个或多个附加块 在相应的辅助服务器上。 有利地,第一和第二代码被配置为提供抵御对手的安全性,所述对手能够在多个时间段内破坏所有服务器,但是比所述时间段内的任何特定时间段内的所有服务器更少。

    Methods and apparatus for knowledge-based authentication using historically-aware questionnaires
    6.
    发明授权
    Methods and apparatus for knowledge-based authentication using historically-aware questionnaires 有权
    使用历史感知调查表进行知识认证的方法和设备

    公开(公告)号:US09009844B1

    公开(公告)日:2015-04-14

    申请号:US13436080

    申请日:2012-03-30

    IPC分类号: H04L29/06

    CPC分类号: H04L9/0675 H04L9/3271

    摘要: Knowledge-based authentication (KBA) is provided using historically-aware questionnaires. The KBA can obtain a plurality of historically different answers from the user to at least one question; challenge the user with the question for a given period of time; receive a response from the user to the question; and grant access to the restricted resource if the response is accurate for the given period of time based on the historically different answers. Alternatively, the KBA can be based on historically aware answers to a set of inter-related questions. The user is challenged with the inter-related questions for a given period of time. Historically different answers can comprise answers with applicable dates, or correct answers to the question over time. Historically aware answers can comprise an answer that is accurate for an indicated date or period of time. An accurate response demonstrates knowledge of multiple related personal events.

    摘要翻译: 基于知识的认证(KBA)是使用历史感知的问卷调查表提供的。 KBA可以从用户获得多个历史上不同的答案至少一个问题; 在给定的时间内质疑用户的问题; 接收用户对该问题的回复; 并且如果响应在给定时间段内基于历史上不同的答案准确,则授予对受限资源的访问。 或者,KBA可以基于历史上意识到的一系列相互关联的问题的答案。 用户在给定的时间内受到相互关联的问题的挑战。 历史上不同的答案可以包括适用日期的答案,或者随着时间的推移对问题的正确答案。 历史上意识到的答案可以包含对于指定的日期或时间段的准确的答案。 准确的答复表明了多个相关个人事件的知识。

    Methods and apparatus for embedding auxiliary information in one-time passcodes
    7.
    发明授权
    Methods and apparatus for embedding auxiliary information in one-time passcodes 有权
    将辅助信息嵌入一次性密码的方法和装置

    公开(公告)号:US08984609B1

    公开(公告)日:2015-03-17

    申请号:US13404780

    申请日:2012-02-24

    IPC分类号: G06F9/00

    摘要: Methods and apparatus are provided for embedding auxiliary information in one-time passcode authentication tokens. Auxiliary information is embedded in authentication information transmitted to a receiver by obtaining the auxiliary information; and mapping the auxiliary information to a codeword using a secret key, wherein the secret key is shared between the security token and an authentication authority; and combining the codeword with a tokencode generated by a security token to generate a one-time passcode. The one-time passcode can then be transmitted to the receiver.

    摘要翻译: 提供了将辅助信息嵌入一次性密码认证令牌中的方法和装置。 辅助信息被嵌入到通过获取辅助信息发送到接收器的认证信息中; 以及使用秘密密钥将所述辅助信息映射到码字,其中所述秘密密钥在所述安全令牌和认证机构之间共享; 以及将码字与由安全令牌生成的令牌代码组合以生成一次性密码。 然后可以将一次性密码传送到接收器。

    Methods and apparatus for authenticating a user using multi-server one-time passcode verification
    8.
    发明授权
    Methods and apparatus for authenticating a user using multi-server one-time passcode verification 有权
    使用多服务器一次性密码验证认证用户的方法和装置

    公开(公告)号:US09118661B1

    公开(公告)日:2015-08-25

    申请号:US13404737

    申请日:2012-02-24

    IPC分类号: H04L29/06

    CPC分类号: H04L63/0838 H04L63/0853

    摘要: Methods and apparatus are provided for authenticating a user using multi-server one-time passcode verification. A user is authenticated by receiving authentication information from the user; and authenticating the user based on the received authentication information using at least two authentication servers, wherein the received authentication information is based on a secret shared between a security token associated with the user and an authentication authority that provides the at least two authentication servers. For example, the authentication information can comprise a passcode comprised of a tokencode from the security token and a password from the user. The user can be authenticated only if, for example, all of the at least two authentication servers authenticate the received authentication information.

    摘要翻译: 提供了使用多服务器一次性密码验证来验证用户的方法和装置。 通过从用户接收认证信息来认证用户; 以及使用至少两个认证服务器基于所接收的认证信息来认证所述用户,其中,所接收的认证信息基于与所述用户相关联的安全令牌和提供所述至少两个认证服务器的认证机构之间共享的秘密。 例如,认证信息可以包括由来自安全令牌的令牌代码和来自用户的密码组成的密码。 只有在例如所有至少两个认证服务器中的所有认证服务器对接收到的认证信息进行认证时,才可以认证用户。

    Methods and apparatus for fraud detection and remediation in knowledge-based authentication
    9.
    发明授权
    Methods and apparatus for fraud detection and remediation in knowledge-based authentication 有权
    基于知识的认证欺诈检测和修复的方法和设备

    公开(公告)号:US09021553B1

    公开(公告)日:2015-04-28

    申请号:US13436125

    申请日:2012-03-30

    IPC分类号: H04L29/06 G06F21/31

    CPC分类号: G06F21/31 G06F2221/2133

    摘要: Methods and apparatus are provided for fraud detection and remediation in knowledge-based authentication (KBA). A knowledge-based authentication method is performed by a server for restricting access of a user to a restricted resource. The exemplary knowledge-based authentication method comprises challenging the user with one or more questions requiring knowledge by the user; receiving a response from the user to the one or more questions, wherein at least a portion of the response is encoded by the user using an encoding scheme defined between the server and the user to signal a fraudulent access attempt; and granting access to the restricted resource if one or more predefined response criteria are satisfied, wherein the one or more predefined response criteria comprises an assessment of whether the encoded portion of the response satisfies the encoding scheme. A number of exemplary encoding schemes are disclosed.

    摘要翻译: 提供了基于知识的认证(KBA)中的欺诈检测和修复的方法和装置。 基于知识的认证方法由服务器执行,用于限制用户对受限资源的访问。 示例性的基于知识的认证方法包括用用户需要知识的一个或多个问题来挑战用户; 从所述用户接收对所述一个或多个问题的响应,其中所述响应的至少一部分由所述用户使用在所述服务器和所述用户之间定义的编码方案进行编码以用信号通知欺诈性接入尝试; 以及如果满足一个或多个预定义的响应准则则允许对所述受限资源的访问,其中所述一个或多个预定义的响应标准包括所述响应的编码部分是否满足所述编码方案的评估。 公开了许多示例性编码方案。

    Methods and apparatus for secure, stealthy and reliable transmission of alert messages from a security alerting system
    10.
    发明授权
    Methods and apparatus for secure, stealthy and reliable transmission of alert messages from a security alerting system 有权
    用于安全,隐身和可靠地传输来自安全警报系统的警报消息的方法和装置

    公开(公告)号:US09160539B1

    公开(公告)日:2015-10-13

    申请号:US13537981

    申请日:2012-06-29

    IPC分类号: H04L9/32

    摘要: Methods and apparatus are provided for secure transmission of alert messages over a message locking channel. An alert message is transmitted from a Security Alerting System indicating a potential compromise of a protected resource by obtaining the alert message from the Security Alerting System; authenticating the alert message using a secret key known by a server, wherein the secret key evolves in a forward-secure manner; storing the authenticated alert message in a buffer; and transmitting the buffer to the server. The alert message is authenticated by digitally signing the alert message or applying a message authentication code and is possibly encrypted using a secret key known by a server, wherein the secret key evolves in a forward-secure manner. The authenticated alert message can be maintained in the buffer after the transmitting step. The buffer optionally has a fixed-size and alert messages can be stored in a round-robin manner, for example, from a random position. The buffer can be encrypted prior to transmission to the server.

    摘要翻译: 提供了用于通过消息锁定通道安全地传送警报消息的方法和装置。 通过从安全警报系统获取警报消息,从安全警报系统发送指示受保护资源的潜在危害的警报消息; 使用服务器已知的密钥对所述警报消息进行认证,其中所述秘密密钥以前向安全的方式演进; 将经认证的警报消息存储在缓冲器中; 并将缓冲区发送到服务器。 警报消息通过对警报消息进行数字签名或应用消息认证码进行认证,并且可以使用服务器已知的秘密密钥加密,其中秘密密钥以前向安全的方式发展。 在发送步骤之后,可以在缓冲器中维护认证的警报消息。 缓冲器可选地具有固定大小,并且警报消息可以以循环方式存储,例如从随机位置存储。 缓冲区可以在传输到服务器之前进行加密。