Systems and Methods for Enhanced Security in Wireless Communication
    2.
    发明申请
    Systems and Methods for Enhanced Security in Wireless Communication 有权
    无线通信中增强安全性的系统和方法

    公开(公告)号:US20120216242A1

    公开(公告)日:2012-08-23

    申请号:US13323340

    申请日:2011-12-12

    IPC分类号: G06F17/00 G06F11/00 H04L9/00

    摘要: A communication system having a policy server coupled to a communications network for managing secure communication with and among end instruments (EI). The EI comprises a memory, and a processor coupled to the memory with processor-executable instructions, including instructions for an operating system kernel; and instructions for a protection core that monitors operations of the operating system kernel in accordance with a security policy for the EI. Security policies can intercept calls to an operating system kernel and for each call, determining whether the call is allowed under the security policy(ies). Policies are stored in a policy library and transmitted to an EI over a wireless communication network.

    摘要翻译: 一种通信系统,具有耦合到通信网络的策略服务器,用于管理与终端设备(EI)之间的安全通信。 EI包括存储器和处理器可执行指令耦合到存储器的处理器,包括用于操作系统内核的指令; 以及根据EI的安全策略监视操作系统内核的操作的保护核心的指令。 安全策略可以拦截对操作系统内核和每个呼叫的呼叫,确定呼叫是否被允许在安全策略下。 策略存储在策略库中,并通过无线通信网络传输到EI。

    Systems and methods for enhanced security in wireless communication
    3.
    发明授权
    Systems and methods for enhanced security in wireless communication 有权
    用于增强无线通信安全性的系统和方法

    公开(公告)号:US09514300B2

    公开(公告)日:2016-12-06

    申请号:US13323340

    申请日:2011-12-12

    摘要: A communication system having a policy server coupled to a communications network for managing secure communication with and among end instruments (EI). The EI comprises a memory, and a processor coupled to the memory with processor-executable instructions, including instructions for an operating system kernel; and instructions for a protection core that monitors operations of the operating system kernel in accordance with a security policy for the EI. Security policies can intercept calls to an operating system kernel and for each call, determining whether the call is allowed under the security policy(ies). Policies are stored in a policy library and transmitted to an EI over a wireless communication network.

    摘要翻译: 一种通信系统,具有耦合到通信网络的策略服务器,用于管理与终端设备(EI)之间的安全通信。 EI包括存储器和处理器可执行指令耦合到存储器的处理器,包括用于操作系统内核的指令; 以及根据EI的安全策略监视操作系统内核的操作的保护核心的指令。 安全策略可以拦截对操作系统内核和每个呼叫的呼叫,确定呼叫是否被允许在安全策略下。 策略存储在策略库中,并通过无线通信网络传输到EI。

    Systems and Methods for Providing a Computing Device Having a Secure Operating System Kernel
    4.
    发明申请
    Systems and Methods for Providing a Computing Device Having a Secure Operating System Kernel 审中-公开
    提供具有安全操作系统内核的计算设备的系统和方法

    公开(公告)号:US20120216281A1

    公开(公告)日:2012-08-23

    申请号:US13315531

    申请日:2011-12-09

    IPC分类号: G06F21/24

    摘要: A method and apparatus for resisting malicious code in a computing device. A software component corresponding to an operating system kernel is analyzed prior to executing the software component to detect the presence of one or more specific instructions such as malicious code, a change in mode permissions or instructions to modify or turn off security monitoring software, and taking a graduated action in response to the detection of one or more specific instructions. The graduated action taken is specified by a security policy (or policies) stored on the computing device. The analyzing may include off-line scanning of a particular code or portion of code for certain instructions, op codes, or patterns, and includes scanning in real-time as the kernel or kernel module is loading while the code being scanned is not yet executing (i.e., it is not yet “on-line”). Analysis of other code proceeds according to policies.

    摘要翻译: 一种用于在计算设备中抵抗恶意代码的方法和装置。 在执行软件组件之前分析对应于操作系统内核的软件组件以检测一个或多个特定指令的存在,例如恶意代码,模式许可的改变或修改或关闭安全监控软件的指令,以及采取 响应于检测到一个或多个特定指令的分级动作。 所采取的分级动作由存储在计算设备上的安全策略(或策略)指定。 分析可以包括用于某些指令,操作代码或模式的特定代码或代码部分的离线扫描,并且包括当正在扫描的代码尚未执行时内核或内核模块正在加载时实时扫描 (即,它还没有“在线”)。 根据政策对其他代码进行分析。

    Enhanced security SCADA systems and methods
    5.
    发明授权
    Enhanced security SCADA systems and methods 有权
    增强安全性SCADA系统和方法

    公开(公告)号:US09298917B2

    公开(公告)日:2016-03-29

    申请号:US13350599

    申请日:2012-01-13

    IPC分类号: G06F21/56 G06F21/57

    CPC分类号: G06F21/56 G06F21/577

    摘要: A system and method for a secure supervisory control and data acquisition (SCADA) system. Secure SCADA elements (SSEs) have individual system security monitoring and enforcement of policies throughout the SCADA system. And isolation core ensures that a system security monitor monitors and takes appropriate action with respect to untrusted applications that may impact an SSE. The system security server provides policy enforcement on all of the SSEs that exist on the system. New security policies are created that are populated to individual SSEs in the system. Biomorphing algorithms allow for system uniqueness to be derived over time further enhancing security of SSEs.

    摘要翻译: 一种用于安全监控和数据采集(SCADA)系统的系统和方法。 安全的SCADA元素(SSEs)在整个SCADA系统中都有单独的系统安全监控和策略执行。 并且隔离核心可确保系统安全监视器对可能影响SSE的不受信任的应用程序进行监控并采取适当的措施。 系统安全服务器为系统上存在的所有SSE提供策略强制。 创建新的安全策略,将其填充到系统中的各个SSE。 生物识别算法允许随着时间推移系统唯一性进一步增强SSEs的安全性。

    Enhanced Security SCADA Systems and Methods
    6.
    发明申请
    Enhanced Security SCADA Systems and Methods 有权
    增强安全SCADA系统和方法

    公开(公告)号:US20130081103A1

    公开(公告)日:2013-03-28

    申请号:US13350599

    申请日:2012-01-13

    IPC分类号: G06F21/00

    CPC分类号: G06F21/56 G06F21/577

    摘要: A system and method for a secure supervisory control and data acquisition (SCADA) system. Secure SCADA elements (SSEs) have individual system security monitoring and enforcement of policies throughout the SCADA system. And isolation core ensures that a system security monitor monitors and takes appropriate action with respect to untrusted applications that may impact an SSE. The system security server provides policy enforcement on all of the SSEs that exist on the system. New security policies are created that are populated to individual SSEs in the system. Biomorphing algorithms allow for system uniqueness to be derived over time further enhancing security of SSEs

    摘要翻译: 一种用于安全监控和数据采集(SCADA)系统的系统和方法。 安全的SCADA元素(SSEs)在整个SCADA系统中都有单独的系统安全监控和策略执行。 并且隔离核心可确保系统安全监视器对可能影响SSE的不受信任的应用程序进行监控并采取适当的措施。 系统安全服务器为系统上存在的所有SSE提供策略强制。 创建新的安全策略,将其填充到系统中的各个SSE。 生物识别算法允许随着时间推移系统唯一性进一步增强SSEs的安全性