首页> 外国专利> SYSTEM FOR IMPLEMENTING A SECURITY POLICY

SYSTEM FOR IMPLEMENTING A SECURITY POLICY

机译:实施安全政策的系统

摘要

Detection policies must be viewed as delicate and valuable assets in a system. Given the knowledge of the detection policy, an intruder would potentially know how to penetrate the target systems and how to circumvent a Security Policy Enforcement System to avoid detection of his actions. The policies need to be protected from reverse engineering in order to be useful in the context of secure policies (i.e. to prevent disclosure of the detection policy). This invention address the problem of protecting the detection policy in a Security Policy Enforcement System against disclosure to unauthorized persons. The invention protects a detection policy by utilising an irreversible transform function, such as an one-way function or a public/secret encryption scheme, to transform the states of a Security Policy Enforcement System finite-state machine. The Security Policy Enforcement System executes/operates these transformed states and state transitions, which means that it is impossible to study its function by use of so called reverse engineering. The input data to the Security Policy Enforcement System will control the execution path of state transitions to an end-state/access-state. In the end-state, the Security Policy Enforcement System will generate a response, if the detection policy have been violated or not. The invention relates to a security device, to a method for creating a Security Policy Enforcement System performing classification of input events in accordance with a predefined rule-base of detection policy elements, to a method for intrusion detection in a computer and information system having a Security Policy Enforcement System and to computer program products for implementing said methods. IMAGE
机译:检测策略必须被视为系统中的微妙和有价值的资产。有了检测策略的知识,入侵者就可能知道如何渗透目标系统以及如何规避安全策略执行系统以避免检测到他的行为。为了在安全策略的上下文中有用(例如,防止泄露检测策略),需要保护策略免受逆向工程。本发明解决了保护安全策略执行系统中的检测策略以防止泄露给未授权人员的问题。本发明通过利用诸如单向功能或公共/秘密加密方案之类的不可逆变换功能来变换安全策略执行系统有限状态机的状态来保护检测策略。安全策略执行系统执行/操作这些转换后的状态和状态转换,这意味着不可能通过所谓的逆向工程来研究其功能。安全策略执行系统的输入数据将控制状态转换到结束状态/访问状态的执行路径。在最终状态下,无论是否违反了检测策略,安全策略执行系统都会生成响应。技术领域本发明涉及一种安全设备,一种用于创建根据检测策略元素的预定义规则库对输入事件进行分类的安全策略执行系统的方法,涉及一种在计算机和信息系统中进行入侵检测的方法。安全策略执行系统以及用于实现所述方法的计算机程序产品。 <图像>

著录项

  • 公开/公告号AT386291T

    专利类型

  • 公开/公告日2008-03-15

    原文格式PDF

  • 申请/专利权人 TELIASONERA AB;

    申请/专利号AT20030445083T

  • 发明设计人 KVARNSTROEM HAKAN;HEDBOM HANS;

    申请日2003-06-30

  • 分类号G06F1;G06F21/55;

  • 国家 AT

  • 入库时间 2022-08-21 20:05:08

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号