Method and system for dynamic network intrusion monitoring, detection and response
    1.
    发明授权
    Method and system for dynamic network intrusion monitoring, detection and response 有权
    动态网络入侵监测,检测和响应的方法和系统

    公开(公告)号:US07159237B2

    公开(公告)日:2007-01-02

    申请号:US09766343

    申请日:2001-01-19

    摘要: A probe attached to a customer's network collects status data and other audit information from monitored components of the network, looking for footprints or evidence of unauthorized intrusions or attacks. The probe filters and analyzes the collected data to identify potentially security-related events happening on the network. Identified events are transmitted to a human analyst for problem resolution. The analyst has access to a variety of databases (including security intelligence databases containing information about known vulnerabilities of particular network products and characteristics of various hacker tools, and problem resolution databases containing information relevant to possible approaches or solutions) to aid in problem resolution. The analyst may follow a predetermined escalation procedure in the event he or she is unable to resolve the problem without assistance from others. Various customer personnel can be alerted in a variety of ways depending on the nature of the problem and the status of its resolution. Feedback from problem resolution efforts can be used to update the knowledge base available to analysts for future attacks and to update the filtering and analysis capabilities of the probe and other systems.

    摘要翻译: 连接到客户网络的探头从网络的受监视组件收集状态数据和其他审核信息,寻找未经授权的入侵或攻击的脚印或证据。 探测器过滤和分析收集的数据,以识别网络上发生的潜在安全相关事件。 识别的事件被传送给人类分析人员以解决问题。 分析人员可以访问各种数据库(包括安全情报数据库,其中包含有关特定网络产品的已知漏洞和各种黑客工具的特征的信息,以及包含与可能的方法或解决方案相关的信息的问题解决数据库),以帮助解决问题。 如果分析人员无法在没有他人协助的情况下解决问题,分析师可能会遵循预定的升级程序。 可以根据问题的性质和其解决状况,以各种方式提醒各种客户人员。 解决问题的反馈可用于更新分析人员可用于未来攻击的知识库,并更新探测器和其他系统的过滤和分析功能。

    Method and system for dynamic network intrusion monitoring, detection and response
    2.
    发明授权
    Method and system for dynamic network intrusion monitoring, detection and response 有权
    动态网络入侵监测,检测和响应的方法和系统

    公开(公告)号:US07895641B2

    公开(公告)日:2011-02-22

    申请号:US11551606

    申请日:2006-10-20

    IPC分类号: G06F7/04 G08B23/00

    摘要: A probe attached to a customer's network collects status data and other audit information from monitored components of the network, looking for footprints or evidence of unauthorized intrusions or attacks. The probe filters and analyzes the collected data to identify potentially security-related events happening on the network. Identified events are transmitted to a human analyst for problem resolution. The analyst has access to a variety of databases (including security intelligence databases containing information about known vulnerabilities of particular network products and characteristics of various hacker tools, and problem resolution databases containing information relevant to possible approaches or solutions) to aid in problem resolution. The analyst may follow a predetermined escalation procedure in the event he or she is unable to resolve the problem without assistance from others. Various customer personnel can be alerted in a variety of ways depending on the nature of the problem and the status of its resolution. Feedback from problem resolution efforts can be used to update the knowledge base available to analysts for future attacks and to update the filtering and analysis capabilities of the probe and other systems.

    摘要翻译: 连接到客户网络的探头从网络的受监视组件收集状态数据和其他审核信息,寻找未经授权的入侵或攻击的脚印或证据。 探测器过滤和分析收集的数据,以识别网络上发生的潜在安全相关事件。 识别的事件被传送给人类分析人员以解决问题。 分析人员可以访问各种数据库(包括安全情报数据库,其中包含有关特定网络产品的已知漏洞和各种黑客工具的特征的信息,以及包含与可能的方法或解决方案相关的信息的问题解决数据库),以帮助解决问题。 如果分析人员无法在没有他人协助的情况下解决问题,分析师可能会遵循预定的升级程序。 可以根据问题的性质和其解决状况,以各种方式提醒各种客户人员。 解决问题的反馈可用于更新分析人员可用于未来攻击的知识库,并更新探测器和其他系统的过滤和分析功能。

    Method and device for generating a single-use financial account number
    10.
    发明授权
    Method and device for generating a single-use financial account number 有权
    用于生成一次性金融帐号的方法和设备

    公开(公告)号:US07177835B1

    公开(公告)日:2007-02-13

    申请号:US09542676

    申请日:2000-04-03

    IPC分类号: G06F17/60

    摘要: A device for facilitating financial account transactions is described which includes a processing unit including a cryptographic processor. The device also includes an input unit, a display unit and a memory device connected to the processing unit. The memory device contains a private cryptographic key, a first data element and a second data element. The processing unit encrypts the first data element using the private cryptographic key and the second data element, modifies the second data element, combines the encrypted first data element and the second data element to generate a single-use financial account identifier, and displays the single-use financial account identifier. This identifier is then transmitted to a central processor for authorization of the transaction. The central processor extracts and decrypts data elements from the transmitted identifier using the private cryptographic key, compares those data elements with data elements stored in a memory, and verifies the single-use financial account identifier in accordance with the comparison.

    摘要翻译: 描述了一种用于促进金融账户交易的装置,其包括包括密码处理器的处理单元。 该设备还包括连接到处理单元的输入单元,显示单元和存储设备。 该存储装置包含专用加密密钥,第一数据元素和第二数据元素。 处理单元使用专用密钥和第二数据元素对第一数据元素进行加密,修改第二数据元素,组合加密的第一数据元素和第二数据元素以生成一次性金融账户标识符,并显示单个 - 使用财务帐户标识符。 然后,该标识符被传送到中央处理器以授权交易。 中央处理器使用专用密钥从所发送的标识符中提取和解密数据元素,将这些数据元素与存储在存储器中的数据元素进行比较,并根据比较验证一次性金融帐户标识符。