Detecting a compromised system using an integrated management controller

    公开(公告)号:US10997288B2

    公开(公告)日:2021-05-04

    申请号:US15933929

    申请日:2018-03-23

    IPC分类号: G06F21/55 G06F21/56

    摘要: Detecting a compromised system using an integrated management controller including receiving a workload characterization for an expected hardware utilization of a computing system, wherein the workload characterization is a pattern of expected hardware utilization of computing hardware on the computing system, and wherein the workload characterization comprises hardware utilization thresholds; storing the workload characterization on an integrated management controller communicatively coupled to the computing hardware on the computing system; monitoring the computing hardware of the computing system using the integrated management controller, including comparing the hardware utilization thresholds of the workload characterization to measured hardware utilization of the computing hardware; determining that the computing system is compromised based on detecting that the measured hardware utilization of the computing hardware has exceeded one of the hardware utilization thresholds of the workload characterization; and performing a notification action in response to determining that the computing system is compromised.

    Authorizing file access with user I/O and hardware usage patterns

    公开(公告)号:US10853462B2

    公开(公告)日:2020-12-01

    申请号:US15944704

    申请日:2018-04-03

    摘要: An apparatus for authorizing file access events includes a processor and a memory that stores code executable by the processor. The code is executable by the processor to record hardware usage patterns prior to a file access event of a file, and correlate the hardware usage patterns with file access events targeting the file. The code is also executable to receive a file access event targeting the file, compare a hardware usage pattern preceding the received file access event targeting the file to the hardware usage patterns correlated with file access events targeting the file, and authorize the received file access event in response to the hardware usage pattern preceding the received file access event targeting the file matching a hardware usage pattern correlated to a file access event targeting the file.

    CONDITIONALLY PROVIDING NETWORK ACCESS TO ALLOW A NETWORK SESSION TO REACH COMPLETION

    公开(公告)号:US20210409422A1

    公开(公告)日:2021-12-30

    申请号:US16915880

    申请日:2020-06-29

    IPC分类号: H04L29/06

    摘要: A computer program product and a networking device, such as a router or firewall, including a processor for executing the computer program product to cause the processor to perform various operations. The operations may include providing network access to a computing device, establishing a default rule to change the network access at a first time-of-day, and establishing a conditional rule that the network access will remain unchanged in response an ongoing network session at the first time-of-day that will reach completion before the second time-of-day. The operations may further include obtaining session progress data for the ongoing session, continue providing the network access until completing the session in response to determining that the ongoing session can reach completion before the second time-of-day, and changing the network access before the session reaches completion in response to determining that the ongoing session will not reach completion before the second time-of-day.

    PROVIDING CONFIGURATION DATA TO A CONNECTED NETWORK SWITCH

    公开(公告)号:US20220321411A1

    公开(公告)日:2022-10-06

    申请号:US17219220

    申请日:2021-03-31

    IPC分类号: H04L12/24 H04L12/933

    摘要: A computer program product and a network switch are provided. The network switch may include network ports, memory and a processor for processing program instructions to perform various operations. The computer program product may provide the program instructions for a network switch. The operations may include detecting a first neighbor network switch connection to a first port of the first network switch, accessing first neighbor network switch configuration data that is stored by the first network switch in association with the first port, and providing the configuration data that is stored in association with the first port of the first network switch to the first neighbor network switch over the first neighbor network switch connection to the first port. In one example, the configuration data is obtained from a second neighbor network switch that was previously connected to the first port prior to the first neighbor network switch.

    Conditionally providing network access to allow a network session to reach completion

    公开(公告)号:US11212293B1

    公开(公告)日:2021-12-28

    申请号:US16915880

    申请日:2020-06-29

    IPC分类号: H04L29/06

    摘要: A computer program product and a networking device, such as a router or firewall, including a processor for executing the computer program product to cause the processor to perform various operations. The operations may include providing network access to a computing device, establishing a default rule to change the network access at a first time-of-day, and establishing a conditional rule that the network access will remain unchanged in response an ongoing network session at the first time-of-day that will reach completion before the second time-of-day. The operations may further include obtaining session progress data for the ongoing session, continue providing the network access until completing the session in response to determining that the ongoing session can reach completion before the second time-of-day, and changing the network access before the session reaches completion in response to determining that the ongoing session will not reach completion before the second time-of-day.