会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 1. 发明授权
    • System and method for preventing computer malware from exfiltrating data from a user computer in a network via the internet
    • 用于防止计算机恶意软件通过因特网从网络中的用户计算机中渗出数据的系统和方法
    • US08631244B1
    • 2014-01-14
    • US13207651
    • 2011-08-11
    • James N. PottsSung J. KimJulianne R. CrosmerKarl F. Hoech
    • James N. PottsSung J. KimJulianne R. CrosmerKarl F. Hoech
    • H04L29/06
    • H04L67/02H04L63/101H04L63/123H04L63/1441
    • A system for preventing computer malware from exfiltrating data from a user computer in a network via the internet. A host-based network process monitor intercepts network traffic information from the user computer and transmits a network request including user and application information including the network traffic information. An authorization server cooperates with the host-based network process monitor for i) verifying whether the user and process in the network request should have network access, and ii) cryptographically signing the intercepted network traffic information with an authorization server key, to authorize network access for the intercepted network traffic information. A firewall system is operably connected to the user computer and the authorization server configured to inspect the network traffic information from the user computer and reject any traffic information not signed with the authorization server key.
    • 一种用于防止计算机恶意软件经由因特网从网络中的用户计算机中渗出数据的系统。 基于主机的网络进程监视器拦截来自用户计算机的网络流量信息,并发送包括用户的网络请求和包括网络流量信息的应用信息。 授权服务器与基于主机的网络进程监视器协作,i)验证网络请求中的用户和进程是否应具有网络访问,以及ii)使用授权服务器密钥加密地对被拦截的网络流量信息进行签名,以授权网络访问 用于拦截网络流量信息。 防火墙系统可操作地连接到用户计算机,授权服务器被配置为检查来自用户计算机的网络业务信息,并且拒绝没有用授权服务器密钥签名的任何业务信息。
    • 4. 发明授权
    • System for extending Multiple Independent Levels of Security (MILS) partitioning to input/output (I/O) devices
    • 用于将多个独立级别的安全(MILS)分区扩展到输入/输出(I / O)设备的系统
    • US07676608B1
    • 2010-03-09
    • US11637489
    • 2006-12-12
    • Julianne R. CrosmerJohn G. BendicksonScott R. Gerhold
    • Julianne R. CrosmerJohn G. BendicksonScott R. Gerhold
    • G06F3/00
    • G06F21/554G06F21/85G06F2221/2113
    • The present invention is a system for providing Multiple Independent Levels of Security (MILS) partitioning. The system includes a memory, a bus controller communicatively coupled to the memory via a memory bus, and a MILS controller communicatively coupled to the bus controller via a host-side bus, the MILS controller configured for monitoring and controlling system transactions. The system further includes a plurality of input/output (I/O) devices communicatively coupled to the MILS controller via a plurality of corresponding device-side buses. The system further includes a MILS separation kernel configured for mapping regions of the memory to a plurality of user partitions. Each I/O device included in the plurality of I/O devices is allocated to a partition included in the plurality of partitions and is isolated from MILS separation kernel space. The MILS separation kernel is configured for guaranteeing isolation of the partitions of the memory. The system further includes a processor connected to the bus controller via a processor front-side bus. The MILS controller is configured for extending MILS partitioning to the plurality of I/O devices.
    • 本发明是一种用于提供多重独立安全级别(MILS)分区的系统。 该系统包括存储器,总线控制器,其通过存储器总线通信地耦合到存储器,以及MILS控制器,MILS控制器经由主机侧总线通信地耦合到总线控制器,MILS控制器被配置用于监视和控制系统事务。 该系统还包括多个输入/输出(I / O)设备,其经由多个对应的设备侧总线通信地耦合到MILS控制器。 该系统还包括配置用于将存储器的区域映射到多个用户分区的MILS分离内核。 包括在多个I / O设备中的每个I / O设备被分配给包括在多个分区中的分区,并且与MILS分离内核空间隔离。 MILS分离内核配置为保证内存分区的隔离。 该系统还包括经由处理器前端总线连接到总线控制器的处理器。 MILS控制器被配置为将MILS分区扩展到多个I / O设备。
    • 6. 发明授权
    • Mechanism to enhance and enforce multiple independent levels of security in a microprocessor memory and I/O bus controller
    • 在微处理器存储器和I / O总线控制器中增强和实施多个独立级别的安全性的机制
    • US07779254B1
    • 2010-08-17
    • US11314981
    • 2005-12-21
    • Julianne R. CrosmerJohn G. Bendickson
    • Julianne R. CrosmerJohn G. Bendickson
    • H04L29/06
    • G06F21/85G06F21/74
    • The present invention is a system and a method for extending multiple independent levels of security to a plurality of input/output buses and components connected to the buses. In an exemplary embodiment, the system may include a processing unit suitable for operation in a plurality of security level. A bus controller including security control logic may be coupled to the processing unit for restricting access and flow of information between the physical memory and the plurality of buses. The bus controller may employ base address registers to allocate and map the physical memory to control which partitions of the physical memory are accessible to each of the plurality of buses and thus, a device connected to at least one of the plurality of buses.
    • 本发明是一种用于将多个独立级别的安全性扩展到连接到总线的多个输入/输出总线和组件的系统和方法。 在示例性实施例中,系统可以包括适于在多个安全级别中操作的处理单元。 包括安全控制逻辑的总线控制器可以耦合到处理单元,用于限制物理存储器和多个总线之间的信息的访问和流动。 总线控制器可以采用基地址寄存器来分配和映射物理存储器,以控制物理存储器的哪些分区可被多个总线中的每一个访问,并且因此连接到多个总线中的至少一个总线的设备。
    • 8. 发明授权
    • Embedded MILS network
    • 嵌入式MILS网络
    • US07509434B1
    • 2009-03-24
    • US11340096
    • 2006-01-26
    • Julianne R. CrosmerSteven E. KoenckAllen P. Mass
    • Julianne R. CrosmerSteven E. KoenckAllen P. Mass
    • G06F15/173
    • H04L63/105
    • A method for transmitting information having different classification levels within an interconnection network includes transmitting a data word having encoded information that indicates a classification level to a processing environment having a classification level. The encoded information is examined to ascertain the indicated classification level. The classification level of the processing environment is verified by comparing it with the indicated classification level, and the data word is delivered to the processing environment upon verification. An interconnection network for transmitting the data words includes a switched fabric topology with serializer/deserializer devices interconnected by router blocks. A node for connecting to the interconnection network includes a network interface module linking the interconnection network and the processing environment. The network interface module examines data words to ascertain their classification level and verifies the classification level of the processing environment. The network interface module delivers the data words to the processing environment upon verification.
    • 一种用于在互连网络内发送具有不同分类级别的信息的方法包括:向具有分类级别的处理环境发送具有指示分类级别的编码信息的数据字。 检查编码信息以确定指示的分类水平。 处理环境的分类级别通过与指定的分类级别进行比较来验证,并且在验证时将数据字传送到处理环境。 用于发送数据字的互连网络包括具有通过路由器块互连的串行器/解串器设备的交换结构拓扑。 用于连接到互连网络的节点包括链接互连网络和处理环境的网络接口模块。 网络接口模块检查数据字以确定其分类级别,并验证处理环境的分类级别。 验证后,网络接口模块将数据字传送到处理环境。