Security attack detection and defense
    4.
    发明申请
    Security attack detection and defense 有权
    安全攻击检测和防御

    公开(公告)号:US20050216955A1

    公开(公告)日:2005-09-29

    申请号:US10809111

    申请日:2004-03-25

    IPC分类号: H04L9/00 H04L29/06

    CPC分类号: H04L63/083 H04L63/1408

    摘要: Detecting an attack on an authentication service. A first memory area is configured to store data relating to a plurality of requests communicated to an authentication service from a plurality of user agents. A second memory area is configured to store a predefined pattern of one or more requests. The predefined pattern characterizes an attack. A processor searches the stored data as a function of a query variable to identify at least one of the plurality of the requests communicated from at least one of the plurality of the user agents and compares the stored data associated with each of the identified requests with the predefined pattern to determine whether the identified request indicates the attack characterized by the predefined pattern. Other aspects of the invention are directed to computer-readable media for use with detecting the attack on the authentication service.

    摘要翻译: 检测对身份验证服务的攻击。 第一存储器区域被配置为存储与来自多个用户代理的通信给认证服务的多个请求有关的数据。 第二存储器区域被配置为存储一个或多个请求的预定义模式。 预定义的模式表征攻击。 处理器根据查询变量来搜索存储的数据,以识别从多个用户代理中的至少一个传达的多个请求中的至少一个,并将与每个所识别的请求相关联的存储数据与 以确定所识别的请求是否指示由预定义模式表征的攻击。 本发明的其他方面涉及用于检测对认证服务的攻击的计算机可读介质。

    Security attack detection and defense
    5.
    发明授权
    Security attack detection and defense 有权
    安全攻击检测和防御

    公开(公告)号:US07523499B2

    公开(公告)日:2009-04-21

    申请号:US10809111

    申请日:2004-03-25

    IPC分类号: G06F11/30

    CPC分类号: H04L63/083 H04L63/1408

    摘要: Detecting an attack on an authentication service. A first memory area is configured to store data relating to a plurality of requests communicated to an authentication service from a plurality of user agents. A second memory area is configured to store a predefined pattern of one or more requests. The predefined pattern characterizes an attack. A processor searches the stored data as a function of a query variable to identify at least one of the plurality of the requests communicated from at least one of the plurality of the user agents and compares the stored data associated with each of the identified requests with the predefined pattern to determine whether the identified request indicates the attack characterized by the predefined pattern. Other aspects of the invention are directed to computer-readable media for use with detecting the attack on the authentication service.

    摘要翻译: 检测对身份验证服务的攻击。 第一存储器区域被配置为存储与来自多个用户代理的通信给认证服务的多个请求有关的数据。 第二存储器区域被配置为存储一个或多个请求的预定义模式。 预定义的模式表征攻击。 处理器根据查询变量来搜索存储的数据,以识别从多个用户代理中的至少一个传达的多个请求中的至少一个,并将与每个所识别的请求相关联的存储数据与 以确定所识别的请求是否指示由预定义模式表征的攻击。 本发明的其他方面涉及用于检测对认证服务的攻击的计算机可读介质。

    Remote command framework for devices
    6.
    发明授权
    Remote command framework for devices 有权
    设备的远程命令框架

    公开(公告)号:US07647430B2

    公开(公告)日:2010-01-12

    申请号:US11038632

    申请日:2005-01-19

    IPC分类号: G06F3/00 G06F15/16 G06F11/00

    CPC分类号: H04L12/2823 H04L2012/2849

    摘要: A robust device messaging framework is disclosed that enables a user to send commands to a device. A provisioning service is used to provision unique device identities and maps user web identities to device identities. The provisioning service also limits device per day provisioning attempts to limit denial of service attacks. A command service allows remote users to issue commands to a device, synchronize outgoing commands with incoming results, receive accurate feedback about whether a command was received, and maintain state information about the device. A device layer encrypts and stores device identities, authenticates itself with the command service, establishes a high-availability Internet connection to receive alerts that a command has issued, and reports results to the server-based command service.

    摘要翻译: 公开了一种强大的设备消息传递框架,使得用户能够向设备发送命令。 配置服务用于提供唯一的设备身份,并将用户网络身份映射到设备身份。 配置服务还限制每天的设备配置尝试限制拒绝服务攻击。 命令服务允许远程用户向设备发出命令,将传出命令与传入结果进行同步,接收关于命令是否收到的准确反馈,以及维护有关设备的状态信息。 设备层加密并存储设备标识,使用命令服务对其进行身份验证,建立高可用性Internet连接以接收命令发出的警报,并将结果报告给基于服务器的命令服务。

    Prevention of unauthorized scripts
    7.
    发明授权
    Prevention of unauthorized scripts 有权
    防止未经授权的脚本

    公开(公告)号:US07606915B1

    公开(公告)日:2009-10-20

    申请号:US10374036

    申请日:2003-02-25

    IPC分类号: G06F15/16 G06F7/04

    摘要: Methods and system of preventing unauthorized scripting. The invention includes providing one or more tests to a user for distinguishing the user from a machine when the user requests access to the server. By storing information on a correct solution to the test in a block of data and sending the block of data together with the test, the invention provides stateless operation. Moreover, maintaining a database of previously used correct responses prevents replay attacks. The invention also includes providing combinations of alternative tests, such as visually altered textual character strings, audible character strings, and computational puzzles. Other aspects of the invention are directed to computer-readable media for use with the methods and system.

    摘要翻译: 防止未经授权的脚本的方法和系统。 本发明包括当用户请求访问服务器时向用户提供一个或多个测试以区分用户与机器。 通过在数据块中存储关于正确解决方案的信息并发送数据块以及测试,本发明提供无状态操作。 此外,维护先前使用正确响应的数据库可防止重放攻击。 本发明还包括提供替代测试的组合,例如视觉上改变的文本字符串,可听话字符串和计算拼图。 本发明的其它方面涉及用于方法和系统的计算机可读介质。

    Remote command framework for devices
    8.
    发明申请
    Remote command framework for devices 有权
    设备的远程命令框架

    公开(公告)号:US20060161662A1

    公开(公告)日:2006-07-20

    申请号:US11038632

    申请日:2005-01-19

    IPC分类号: G06F15/16

    CPC分类号: H04L12/2823 H04L2012/2849

    摘要: A robust device messaging framework is disclosed that enables a user to send commands to a device. A provisioning service is used to provision unique device identities and maps user web identities to device identities. The provisioning service also limits device per day provisioning attempts to limit denial of service attacks. A command service allows remote users to issue commands to a device, synchronize outgoing commands with incoming results, receive accurate feedback about whether a command was received, and maintain state information about the device. A device layer encrypts and stores device identities, authenticates itself with the command service, establishes a high-availability Internet connection to receive alerts that a command has issued, and reports results to the server-based command service.

    摘要翻译: 公开了一种强大的设备消息传递框架,使得用户能够向设备发送命令。 配置服务用于提供唯一的设备身份,并将用户网络身份映射到设备身份。 配置服务还限制每天的设备配置尝试限制拒绝服务攻击。 命令服务允许远程用户向设备发出命令,将传出命令与传入的结果进行同步,接收关于命令是否收到的准确反馈,以及维护有关设备的状态信息。 设备层加密并存储设备标识,使用命令服务对其进行身份验证,建立高可用性Internet连接以接收命令发出的警报,并将结果报告给基于服务器的命令服务。