H04L2463/146

System for resource-centric threat modeling and identifying controls for securing technology resources

Systems, computer program products, and methods are described herein for identifying threat vectors and implementing controls for securing resources within a network. The present invention is configured to determine one or more threat vectors associated with the resource; determine one or more controls associated with each of the one or more threat vectors associated with the resource; determine whether the one or more controls associated with the at least one of the one or more threat vectors is capable of detecting the access by an external computing device via at least one of the one or more types of access; and dynamically generate a graphical representation of the resource and the one or more threat vectors based on at least the received analysis request.

TRAITOR TRACING FOR OBFUSCATED CREDENTIALS

A method, computer program product, and system for providing verification processes associated with a commitment-based authentication protocol are described. A request by a user for access to one or more resources is received, and a presentation policy is transmitted to the user indicating required credentials. A commitment to a revocation handle is received, including an indication of an associated Sigma protocol executed by the user. A challenge value selected from a challenge value set associated with the associated Sigma protocol is transmitted to the user. Based on the selected challenge value, a presentation token and a value parameter that is distinct from the presentation token are received from the user. Based on a determination as to whether the presentation token and value parameter are valid in accordance with the associated Sigma protocol, access for the user to the one or more resources is granted to the user or prevented.

COMMUNICATION APPARATUS, SERVER APPARATUS, COMMUNICATION SYSTEM, COMPUTER PROGRAM PRODUCT, AND COMMUNICATION METHOD
20180083914 · 2018-03-22 · ·

According to an embodiment, a communication apparatus includes a communication unit and an output unit. The communication unit is configured to receive an unauthorized communication message. The output unit is configured to output a notification message based on the unauthorized communication message. The notification message includes unauthorized communication identification information for identifying the unauthorized communication message and reception position information indicating a position of the communication apparatus when the unauthorized communication message is received. The unauthorized communication identification information includes entire frame information about the unauthorized communication message.

METHOD AND SYSTEM FOR DETECTING SUSPICIOUS ADMINISTRATIVE ACTIVITY

Disclosed is an improved approach for identifying suspicious administrative host activity within a network. Network traffic is examined to learn the behavior of hosts within a network. This provides an effective way of determining whether or not a host is performing suspicious activity over an administrative protocol.

NON-TRANSITORY RECORDING MEDIUM RECORDING CYBER-ATTACK ANALYSIS SUPPORTING PROGRAM, CYBER-ATTACK ANALYSIS SUPPORTING METHOD, AND CYBER-ATTACK ANALYSIS SUPPORTING APPARATUS

A non-transitory recording medium recording a cyber-attack analysis supporting program that causes a computer to execute a process, the process includes: accepting registration of information of one or more items regarding a cyber-attack event in response to detection of malware in an information processing system of a monitoring target; and displaying the information registered regarding the cyber-attack event in a state in which each of the one or more items is coupled as a subordinate node to a representative node of the cyber-attack event.

ISOLATING A SOURCE OF AN ATTACK THAT ORIGINATES FROM A SHARED COMPUTING ENVIRONMENT

A method and associated systems for isolating a source of an attack that originates from a shared computing environment. A computer-security system tags outgoing packets originating from within the shared computing environment in a tamper-proof manner in order to identify which tenant of the shared environment is the true source of each packet. If one of those tenants transmits malicious packets to an external recipient, either because the tenant has malicious intent or becomes infected with malware, the transmitted malicious packets' tags allow the recipient to determine which tenant is the source of the unwanted transmissions. The recipient may then block further communications from the problematic tenant without blocking communications from other tenants of the shared environment.

AUTOMATIC FIREWALL CONFIGURATION BASED ON AGGREGATED CLOUD MANAGED INFORMATION
20180063085 · 2018-03-01 ·

Disclosed are systems, methods, and computer-readable storage media for automatic firewall configuration based on aggregated cloud managed information. A cloud management device can determine, based on security event data received from a first set of client computing environments, that a security attack detected on at least one client computing environment from the first set of client computing environments is likely to occur on other client computing environments. In response to determining that the security attack detected on at least one client computing environment from the first set of client computing environments is likely to occur on other client computing environments, the cloud management device can identify a second set of client computing environments to protect from the security attack. For each client computing environment from the second set of client computing environments, the cloud management device can configure firewall settings to protect from the security attack.

ALLOWING ACCESS TO FALSE DATA

In one aspect, a device includes a processor and storage accessible to the processor. The storage bears instructions executable by the processor to determine that an attempt has occurred of unauthorized access to a computer system having a computer interface for presentation to an authorized user. The instructions are also executable to, responsive to determining that an attempt has occurred of unauthorized access to the computer system, return from the computer system a proxy interface instead of the computer interface, the proxy interface permitting access to at least partially falsified data.

Method, apparatus, and computer program product for managing unwanted traffic in a wireless network
09894082 · 2018-02-13 · ·

Various methods for unwanted traffic control in a wireless network are provided. One example method may include detecting an occurrence of unwanted content as indicated by receipt of a complaint about a content item provided by a source device, wherein the complaint may be received from a remote mobile device or generated locally based on a local detection. The example method may further include determining a trust value for the source device based at least on the complaint, determining that the source device is a distrusted device based at least on a comparison between the trust value and a trust threshold value, and causing traffic from the source device to be controlled as unwanted traffic. Similar and related example methods, example apparatuses, and example computer program products are also provided.

MANAGING DYNAMIC DECEPTIVE ENVIRONMENTS

A deception management system to detect attackers within a dynamically changing network of computer resources, including a deployment governor dynamically designating deception policies, each deception policy including names of non-existing web servers, and levels of diversity for planting the names of non-existing web servers in browser histories of web browsers within resources of the network, the levels of diversity specifying how densely the name of each non-existing web server is planted within resources of the network, a deception deployer dynamically planting the names of non-existing web servers in the browser histories of the web browsers in resources in the network, in accordance with the levels of diversity of the current deception policy, and a notification processor transmitting an alert to an administrator of the network in response to an attempt to access one of the non-existing web servers.