Packet filtering in a NIC to control antidote loading
    2.
    发明授权
    Packet filtering in a NIC to control antidote loading 有权
    在NIC中进行包过滤以控制解毒剂加载

    公开(公告)号:US07752659B2

    公开(公告)日:2010-07-06

    申请号:US11057795

    申请日:2005-02-14

    IPC分类号: G06F17/00

    CPC分类号: H04L63/145

    摘要: A method and system is described for selectively downloading antidotes onto a client computer. The client computer is connected via a network interface card (NIC) to a network that contains an anti-virus server. The NIC is initially logically isolated from the client computer, thus permitting the NIC to autonomously examine packets to and from the client computer and the network. The NIC selectively accepts packets only from trusted Internet Protocol (IP) addresses that conform to a security format such as Internet Protocol Security (IPSec).

    摘要翻译: 描述了用于有选择地将解毒剂下载到客户端计算机上的方法和系统。 客户端计算机通过网络接口卡(NIC)连接到包含防病毒服务器的网络。 NIC最初在逻辑上与客户端计算机隔离,从而允许NIC自主地检查到客户端计算机和网络的数据包。 NIC选择性地仅接收来自符合诸如因特网协议安全(IPSec)之类的安全格式的受信任的因特网协议(IP)地址的分组。

    Automatic virus fix
    4.
    发明授权
    Automatic virus fix 有权
    自动病毒修复

    公开(公告)号:US07587765B2

    公开(公告)日:2009-09-08

    申请号:US10827165

    申请日:2004-04-16

    IPC分类号: G06F11/00

    CPC分类号: G06F8/65 G06F21/568

    摘要: A client computer is connected via a network to an anti-virus server. A signal from the anti-virus server notifies the client computer that an anti-virus needs to be immediately downloaded from the anti-virus server. The client computer disengages from the network, and re-establishes a link with only the trusted anti-virus server. The anti-virus fix is installed, the client computer re-booted, and the client computer is then allowed to reconnect to the full network. If the client's primary operating system (OS) is infected, a secondary OS in the client computer performs the anti-virus download and execution. The disengagement from the network is performed by applying a filter in a network interface card (NIC) driver by the primary OS, the secondary OS, a service processor (SP), or by a virtual machine manager (VMM), depending on which is available at the client computer.

    摘要翻译: 客户端计算机通过网络连接到防病毒服务器。 来自防病毒服务器的信号通知客户端计算机需要立即从防病毒服务器下载防病毒。 客户端计算机与网络脱离联系,并重新建立与唯一可信任的防病毒服务器的链接。 安装了防病毒修复程序,客户端计算机重新启动,然后允许客户端计算机重新连接到完整的网络。 如果客户端的主操作系统(OS)被感染,客户端计算机中的辅助操作系统将执行防病毒下载和执行。 通过由主OS,辅助OS,服务处理器(SP)或虚拟机管理器(VMM)在网络接口卡(NIC)驱动器中应用过滤器来执行从网络的脱离,这取决于哪个是 在客户端计算机上可用。

    Polled automatic virus fix
    7.
    发明授权
    Polled automatic virus fix 有权
    轮询自动病毒修复

    公开(公告)号:US07353428B2

    公开(公告)日:2008-04-01

    申请号:US10848796

    申请日:2004-05-19

    IPC分类号: G06F11/00

    CPC分类号: G06F8/65 G06F21/57

    摘要: A client computer is connected via a network to an anti-virus server and polls the server for indication that an anti-virus needs to be immediately downloaded from the anti-virus server. The client computer disengages from the network, and re-establishes a link with only the trusted anti-virus server. The anti-virus fix is installed, the client computer re-booted, and the client computer is then allowed to reconnect to the full network. If the client's primary operating system (OS) is infected, a secondary OS in the client computer performs the anti-virus download and execution. The disengagement from the network is performed by applying a filter in a network interface card (NIC) driver by the primary OS, the secondary OS, a service processor (SP), or by a virtual machine manager (VMM), depending on which is available at the client computer.

    摘要翻译: 客户端计算机通过网络连接到防病毒服务器,并轮询服务器以指示需要从防病毒服务器立即下载防病毒。 客户端计算机与网络脱离联系,并重新建立与唯一可信任的防病毒服务器的链接。 安装了防病毒修复程序,客户端计算机重新启动,然后允许客户端计算机重新连接到完整的网络。 如果客户端的主操作系统(OS)被感染,客户端计算机中的辅助操作系统将执行防病毒下载和执行。 通过由主OS,辅助OS,服务处理器(SP)或虚拟机管理器(VMM)在网络接口卡(NIC)驱动器中应用过滤器来执行从网络的脱离,这取决于哪个是 在客户端计算机上可用。

    Method and system for secure, one-time password override during password-protected system boot
    10.
    发明授权
    Method and system for secure, one-time password override during password-protected system boot 有权
    在密码保护的系统启动期间安全的一次密码替换的方法和系统

    公开(公告)号:US07210166B2

    公开(公告)日:2007-04-24

    申请号:US10967761

    申请日:2004-10-16

    IPC分类号: H04L9/00 G06F15/177 G06F17/30

    摘要: A method, system, and program product for enabling administrative recovery of a user's lost/forgotten boot-up passwords without compromising the administrative/master password(s). A restricted-use password is dynamically generated from a first hash of a random number generated on a client system and a secret retrieved from a secure device associated with the client system. The restricted-use password operates as a master password but is not the administrative password of the client system. Once the password is generated, it is provided to the user/client system to enable user access to said client system and hardfile and reset of the user passwords.

    摘要翻译: 一种方法,系统和程序产品,用于在不影响管理/主密码的情况下实现对用户丢失/遗忘启动密码的管理恢复。 从客户端系统上产生的随机数的第一个哈希值和从与客户机系统相关联的安全设备检索的秘密,动态地生成受限制的密码。 受限使用的密码作为主密码操作,但不是客户端系统的管理密码。 一旦生成密码,就将它提供给用户/客户端系统,以使用户能够访问所述客户端系统,并且硬文件和用户密码的复位。