会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 101. 发明授权
    • Method and apparatus for analyzing information systems using stored tree
database structures
    • 用于使用存储的树数据库结构分析信息系统的方法和装置
    • US5850516A
    • 1998-12-15
    • US772413
    • 1996-12-23
    • Bruce Schneier
    • Bruce Schneier
    • G06F1/00G06F21/00H04L29/06G06F11/00
    • H04L63/14G06F21/57H04L29/06G06F2211/008Y10S707/99939
    • A computer-implemented method and apparatus electronically represent and quantify the security of a system as a logical tree structure including leaf nodes representing attacks against the system and intermediate nodes representing various logical combinations of attacks necessary to mount a successful overall attack. An indication of the overall security of the system is quantified in a value of a root node of the tree. The values of the various nodes can be Boolean or continuous, representing simple binary security attributes such as feasible/infeasible or more complicated attributes such as cost, time or probability. The nodes' attributes and values can also represent defenses as well as attacks. The attack trees can be used to calculate the cost, time or probability of an attack to list the security assumptions of a system, to compare competing systems, to evaluate system modifications, to perform security subsystem analysis, to allocate a security budget, and for many other uses.
    • 计算机实现的方法和装置以电子方式表示和量化系统的安全性,作为逻辑树结构,包括表示对系统的攻击的叶节点和表示安装成功的整体攻击所必需的各种攻击逻辑组合的中间节点。 在树的根节点的值中量化系统的总体安全性的指示。 各种节点的值可以是布尔或连续的,代表简单的二进制安全属性,如可行/不可行或更复杂的属性,如成本,时间或概率。 节点的属性和值也可以表示防御以及攻击。 攻击树可用于计算攻击的成本,时间或概率,列出系统的安全假设,比较竞争系统,评估系统修改,执行安全子系统分析,分配安全预算,以及 许多其他用途。
    • 102. 发明授权
    • Method and system for dynamic network intrusion monitoring, detection and response
    • 动态网络入侵监测,检测和响应的方法和系统
    • US07895641B2
    • 2011-02-22
    • US11551606
    • 2006-10-20
    • Bruce SchneierAndrew H. GrossJonathan D. Callas
    • Bruce SchneierAndrew H. GrossJonathan D. Callas
    • G06F7/04G08B23/00
    • G06F21/552H04L63/1416H04L63/20
    • A probe attached to a customer's network collects status data and other audit information from monitored components of the network, looking for footprints or evidence of unauthorized intrusions or attacks. The probe filters and analyzes the collected data to identify potentially security-related events happening on the network. Identified events are transmitted to a human analyst for problem resolution. The analyst has access to a variety of databases (including security intelligence databases containing information about known vulnerabilities of particular network products and characteristics of various hacker tools, and problem resolution databases containing information relevant to possible approaches or solutions) to aid in problem resolution. The analyst may follow a predetermined escalation procedure in the event he or she is unable to resolve the problem without assistance from others. Various customer personnel can be alerted in a variety of ways depending on the nature of the problem and the status of its resolution. Feedback from problem resolution efforts can be used to update the knowledge base available to analysts for future attacks and to update the filtering and analysis capabilities of the probe and other systems.
    • 连接到客户网络的探头从网络的受监视组件收集状态数据和其他审核信息,寻找未经授权的入侵或攻击的脚印或证据。 探测器过滤和分析收集的数据,以识别网络上发生的潜在安全相关事件。 识别的事件被传送给人类分析人员以解决问题。 分析人员可以访问各种数据库(包括安全情报数据库,其中包含有关特定网络产品的已知漏洞和各种黑客工具的特征的信息,以及包含与可能的方法或解决方案相关的信息的问题解决数据库),以帮助解决问题。 如果分析人员无法在没有他人协助的情况下解决问题,分析师可能会遵循预定的升级程序。 可以根据问题的性质和其解决状况,以各种方式提醒各种客户人员。 解决问题的反馈可用于更新分析人员可用于未来攻击的知识库,并更新探测器和其他系统的过滤和分析功能。
    • 107. 发明申请
    • Method and apparatus for secure gaming
    • 用于安全游戏的方法和装置
    • US20050187022A1
    • 2005-08-25
    • US11105707
    • 2005-04-15
    • Jay WalkerBruce Schneier
    • Jay WalkerBruce Schneier
    • G07F17/32A63F13/00
    • G07F17/32G07F17/3223G07F17/3241G07F17/3244G07F17/3262G07F17/329
    • A remote gaming system whereby a player can gamble against a wagering establishment or state-run lottery from a remote location on a personal computer or portable computer device where it is unnecessary to establish an on-line connection with a host computer associated with the wagering establishment, the gaming computer having associated gaming software for providing at least one wagering opportunity and enabling the player to obtain gambling credit and cash-out any resulting winnings, the host computer enabling the player to purchase and redeem gambling credit at the remote location in one embodiment of the invention using cryptographic protocols such as through a series of authenticatable message exchanges between the player and the wagering establishment, the gaming computer and the host computer directly on-line, or the gaming computer having a detachable tamper-resistant or tamper-evident credit module associated therewith or for use with a personal computer being provided to the player with preinstalled or preloaded gambling credit, the gaming system also enabling participation in future events of which the outcome is uncertain such as, for example, a lottery whereby the player makes selections on a gaming computer at a remote location.
    • 远程游戏系统,其中玩家可以从个人计算机或便携式计算机设备上的远程位置赌注投注设立或者国营彩票,其中不需要与与投注机构相关联的主计算机建立在线连接 游戏计算机具有相关联的游戏软件,用于提供至少一个投注机会,并使得玩家获得赌博信用和兑现任何所得到的奖金,主计算机使玩家能够在一个实施例中在远程位置购买和兑换赌博信用 使用加密协议,例如通过玩家和投注机构之间的一系列可认证的消息交换,游戏计算机和主机直接在线,或具有可拆卸的防篡改或防篡改信用的游戏计算机 与之相关联的模块或用于与个人计算机一起使用的模块 玩家具有预先安装或预加载的赌博信用,游戏系统还能够参与未来事件的结果不确定,例如玩家在远程位置的游戏计算机上进行选择的彩票。