EP1817862A2

Method to control access between network endpoints based on trust scores calculated from information system component analysis

Abstract

This record has no abstract on file.

Term

Term ended

Projected expiry passed 28 November 2025, 0.8 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

20 claims: 3 independent, 17 dependent

  1. 1
    Claims of equivalent WO 2006058313 A2 CLAIMS 1. An apparatus, comprising:a database arranged to store a first plurality of signatures for a first plurality of modules;a receiver to receive a second plurality of signatures corresponding to a second plurality of modules;a validator operative to compare at least a received one of the second plurality of signatures with the one or more of plurality of signatures in the database, to identify a first subset of the second plurality of modules for which the corresponding signatures are found in the database, and to identify a second subset of the second plurality of modules for which the corresponding signatures are not found in the database;and a trust score generator to generate a trust score based on the first subset of the second plurality of modules for which the corresponding signatures are found in the database and the second subset of the second plurality of modules for which the corresponding signatures are not found in the database.
  2. 8
    A system, comprising:a network;a resource connected to the network;a computer connected to the network, including an integrity log generator to generate an integrity log including a first plurality of signatures for a first plurality of modules;and an apparatus connected to the network, including: a database arranged to store a second plurality of signatures for a second plurality of modules;a receiver to receive from the computer the integrity log;a trust score generator to generate a trust score based on a comparison of the integrity log with the first plurality of signatures;and a policy to control access to the resource, the policy including a threshold score to receive full access to the resource;wherein access to the resource by the computer is controlled by the policy.
  3. 11
    A method, comprising:receiving a first plurality of signatures corresponding to a plurality of modules;comparing the first plurality of signatures for the plurality of modules with a second plurality of signatures in a database;identifying a first subset of the plurality of modules for which the corresponding signatures are found in the database and a second subset of the plurality of modules for which the corresponding signatures are not found in the database;and generating a trust score based on the first subset of the plurality of modules for which the corresponding signatures are found in the database and a second subset of the plurality of modules for which the corresponding signatures are not found in the database.