首页> 外国专利> DETECTION OF COMPROMISED UNMANAGED CLIENT END STATIONS USING SYNCHRONIZED TOKENS FROM ENTERPRISE-MANAGED CLIENT END STATIONS

DETECTION OF COMPROMISED UNMANAGED CLIENT END STATIONS USING SYNCHRONIZED TOKENS FROM ENTERPRISE-MANAGED CLIENT END STATIONS

机译:使用企业管理的客户端终端站中的同步令牌检测受损的未管理客户端终端站

摘要

Techniques related to detecting compromised unmanaged client end stations using synchronized tokens placed on enterprise-managed client end stations are described. A token distribution module causes token(s) to be placed with user data of a managed client end station in specific locations. The placement locations are selected due to the token(s) likely being synchronized, the token(s) being unlikely to be discovered or used by an authorized user, but likely discovered by an attacker. During a synchronization process, the token(s) are sent to an unmanaged client end station. The token(s) can be detected and/or acquired from the unmanaged client end station by an attacker, and thereafter used in an attempt to access an apparent enterprise resource. A token detection module can detect this use of the token(s) to thereby detect the compromise of the unmanaged client end station, without needing direct access to the unmanaged client end station.
机译:描述了与使用放置在企业管理的客户端站上的同步令牌来检测受损的非管理客户端站有关的技术。令牌分发模块使令牌与托管客户端终端站的用户数据一起放置在特定位置。选择放置位置的原因是令牌可能已同步,令牌不太可能被授权用户发现或使用,但很可能被攻击者发现。在同步过程中,令牌将发送到非托管客户端终端站。攻击者可以从非托管客户端终端检测和/或获取令牌,然后将其用于尝试访问明显的企业资源。令牌检测模块可以检测对令牌的使用,从而检测非托管客户端站的危害,而无需直接访问非托管客户端站。

著录项

  • 公开/公告号US2016381023A1

    专利类型

  • 公开/公告日2016-12-29

    原文格式PDF

  • 申请/专利权人 IMPERVA INC.;

    申请/专利号US201514750539

  • 发明设计人 AMICHAI SHULMAN;SAGIE DULCE;

    申请日2015-06-25

  • 分类号H04L29/06;

  • 国家 US

  • 入库时间 2022-08-21 13:46:23

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号