System and method for protecting a computing device from computer exploits delivered over a networked environment in a secured communication
Abstract
A network security module for protecting computing devices connected to a communication network from identified security threats communicated in a secured communication is presented. The network security module is interposed, either logically or physically, between the protected computer and the communication network. Upon detecting a secured communication, the network security module obtains a decryption key from the computing device to decrypt the secured communication. The network security module then processes the decrypted communication according to whether the decrypted communication violates protective security measures implemented by the network security module.
Term
No projected expiry on record.
- Priority
- Filed
- Published
- Today
19 claims: 19 independent, 0 dependent
- 1A network security module is located between a computing device and a network, so that all network activities between the computing device and the network will pass through the network security module to protect the computing The device is protected from security threats detected on the network. The network security module includes at least:a computing device connection, which is used to connect the network security module to the computing device;a network Connection, which is used to connect the network security module to the network;a decoder module, which uses a obtained decryption key to temporarily decrypt a secure communication;and a security execution module, It controls the network activities between the computing device and the network by implementing the obtained security measures in order to protect the computing device from security threats detected on the network. 一種網路安全模組,其係介於一計算裝置與一網路之間,使該計算裝置與該網路之間的所有網路活動均會通過該網路安全模組,藉以保護該計算裝置免於受到該網路上所偵測到的安全威脅,該網路安全模組至少包含:一計算裝置連線,其係用於將該網路安全模組連接到該計算裝置;一網路連線,其係用於將該網路安全模組連接到該網路;一解碼器模組,其係利用一取得的解密金鑰,暫時將一安全通訊解密;以及一安全執行模組,其係藉由執行取得的安全措施來控制該計算裝置與該網路之間的網路活動,以便保護該計算裝置免於受到該網路上所偵測到的安全威脅。 200529002 拾、申請專利範圍: 1 . 一種網路安全模組,其係介於一計算裝置與一網 間,使該計算裝置與該網路之間的所有網路活動均會 該網路安全模組,藉以保護該計算裝置免於受到該網 所偵測到的安全威脅,該網路安全模組至少包含: 一計算裝置連線,其係用於將該網路安全模組連接 計算裝置; 一網路連線,其係用於將該網路安全模組連接到 路; 一解碼器模組,其係利用一取得的解密金鑰,暫時 安全通訊解密;以及 一安全執行模組,其係藉由執行取得的安全措施來 該計算裝置與該網路之間的網路活動,以便保護該計 置免於受到該網路上所偵測到的安全威脅。 2.如申請專利範圍第1項所述之網路安全模組,其中 之安全執行模組係藉由取得該暫時解密的安全通訊, 據該取得的安全措施來評估該暫時解密的安全通訊, 制該計算裝置與該網路之間的網路活動。 3 .如申請專利範圍第1項所述之網路安全模組,其中 之解碼器模組取得該解密金鑰,並將來自於該計算裝 的解碼模組的安全通訊暫時解密。 路之 通過 路上 到該 該網 將一 控制 算裝 上述 並根 以控 上述 置上 46 200529002 4 ·如申請專利範圍第3項所述之網路安全 含一輔助通訊連線,其係用於將該網路安 計算裝置,且其中該解碼器模組透過該輔 得該解密金鑰,並將來自於該計算裝置上 全通訊暫時解密。 5 ·如申請專利範圍第1項所述之網路安全 之安全通訊係依據安全套接字層(Secure SSL)協定以加密之。 6.如申請專利範圍第1項所述之網路安全 之安全通訊係依據傳輸層安全(Transp()i t 協定以加密之。 '•一槿保護一計算裝置免於受到網路 脅的方法,該方法係由介於該計算裝 路安全模組所執行,使該計算裝置與 路活動均會通過該網路安全模組,該 取柃保4安全措施,用於保護該計 到所偵測到之安全威脅; 偵測送往該計算裝置的安全通訊; 將該安全通訊暫時解密;以及 模組,其中更包 全模組連接到該 助通訊連線而取 的解碼模組的安 模組,其中上述 Sockets Layer, 模組,其中上述 Layer Security) 偵測到之安全威 該網路之間的網 路之間的所有網 至少包含: .置,使其免於受 47 200529002 針對該暫時被解密的安全通訊進行該保護安全措施 8.如申請專利範圍第7項所述之方法,其中更包含從 算裝置取得用於將該安全通訊解密的解密金鑰。 9 ·如申請專利範圍第8項所述之方法,其中上述之解 鑰係經由該網路安全模組與該計算裝置之間的一輔助 連接而從該計算裝置取得。 1 0 ·如申請專利範圍第9項所述之方法,其中上述之解 鑰係從該計算裝置上的解碼模組取得。 11.如申請專利範圍第9項所述之方法,其中上述之安 訊係根據安全套接字層協定以加密之。 1 2.如申請專利範圍第9項所述之方法,其中上述之安 訊係根據傳輸層安全協定以加密之。 13.如申請專利範圍第7項所述之方法,其中更包含從 算裝置取得關於該計算裝置的組態資訊,且其中取得 安全措施,其用於保護該計算裝置,使其免於受到所 到之安全威脅的步驟包含取得保護安全措施,並根據 該計算裝置的組態資訊來保護該計算裝置。 該計 密金 通訊 密金 全通 全通 該計 保護 偵測 關於 48 200529002 1 4. 一種網路安全模組,其係介於網路裝置與網路之間,使 該網路裝置與該網路之間的所有網路活動均會通過該網路 安全模組,藉以保護該網路裝置免於受到該網路上所偵測 到的安全威脅,該網路安全模組至少包含: 一網路裝置連線,其係用於將該網路安全模組連接到該 網路裝置; 一網路連線,其係用於將該網路安全模組連接到該網 路; 一解碼器裝置,其係利用取得的解密金鑰,暫時將一安 全通訊解密;以及 一安全執行裝置,其係藉由執行取得的安全措施來控制 該網路裝置與該網路之間的網路活動,以便保護該網路裝 置免於受到該網路上所偵測到的安全威脅。 1 5 .如申請專利範圍第1 4項所述之網路安全模組,其中上 述之安全執行裝置係從該解碼器裝置取得該暫時解密的安 全通訊,並根據該取得的安全措施來評估該暫時解密的安 全通訊,以控制該網路裝置與該網路之間的網路活動。 1 6 .如申請專利範圍第1 4項所述之網路安全模組,其中上 述之解碼器裝置取得該解密金鑰,並將來自於該網路裝置 上的解碼模組的安全通訊暫時解密。 49 200529002 1 7.如申請專利範圍第1 6項所述之網路安全模組,其 包含一輔助通訊連線,其係用於將該網路安全模組連 該網路裝置,且其中該解碼器裝置透過該辅助通訊連 取得該解密金鑰,並將來自於該網路裝置上的解碼模 安全通訊暫時解密。 1 8 .如申請專利範圍第1 4項所述之網路安全模組,其 述之安全通訊係根據安全套接字層協定以加密之。 19.如申請專利範圍第14項所述之網路安全模組,其 述之安全通訊係根據傳輸層安全協定以加密之。 中更 接到 線而 組的 中上 中上 50
- 2The network security module according to item 1 of the scope of patent application, wherein the security execution module mentioned above obtains the temporarily decrypted secure communication and evaluates the temporarily decrypted secure communication according to the obtained security measures To control network activity between the computing device and the network. 如申請專利範圍第1項所述之網路安全模組,其中上述之安全執行模組係藉由取得該暫時解密的安全通訊,並根據該取得的安全措施來評估該暫時解密的安全通訊,以控制該計算裝置與該網路之間的網路活動。
- 3The network security module according to item 1 of the scope of patent application, wherein the above-mentioned decoder module obtains the decryption key and temporarily decrypts the secure communication from the decoding module on the computing device. 如申請專利範圍第1項所述之網路安全模組,其中上述之解碼器模組取得該解密金鑰,並將來自於該計算裝置上的解碼模組的安全通訊暫時解密。
- 4The network security module described in item 3 of the patent application scope further includes an auxiliary communication connection, which is used to connect the network security module to the computing device, and wherein the decoder module passes through The auxiliary communication connects to obtain the decryption key, and temporarily decrypts the secure communication from the decoding module on the computing device. 如申請專利範圍第3項所述之網路安全模組,其中更包含一輔助通訊連線,其係用於將該網路安全模組連接到該計算裝置,且其中該解碼器模組透過該輔助通訊連線而取得該解密金鑰,並將來自於該計算裝置上的解碼模組的安全通訊暫時解密。
- 5The network security module described in item 1 of the scope of patent application, wherein the above-mentioned secure communication is encrypted according to the Secure Sockets Layer (SSL) protocol. 如申請專利範圍第1項所述之網路安全模組,其中上述之安全通訊係依據安全套接字層(Secure Sockets Layer,SSL)協定以加密之。
- 6The network security module described in item 1 of the scope of patent application, wherein the above-mentioned secure communication is encrypted according to the Transport Layer Security protocol. 如申請專利範圍第1項所述之網路安全模組,其中上述之安全通訊係依據傳輸層安全(Transport Layer Security)協定以加密之。
- 7A method for protecting a computing device from a security threat detected on a network, the method is executed by a network security module between the computing device and the network, so that the computing device and the network All network activities between roads pass through the network security module. The method at least includes:obtaining protective security measures to protect the computing device from the detected security threats;detection Secure communications sent to the computing device;temporarily decrypting the secure communications;and implementing the protection security measures for the temporarily decrypted secure communications. 一種保護一計算裝置免於受到網路上所偵測到之安全威脅的方法,該方法係由介於該計算裝置與該網路之間的網路安全模組所執行,使該計算裝置與該網路之間的所有網路活動均會通過該網路安全模組,該方法至少包含:取得保護安全措施,用於保護該計算裝置,使其免於受到所偵測到之安全威脅;偵測送往該計算裝置的安全通訊;將該安全通訊暫時解密;以及針對該暫時被解密的安全通訊進行該保護安全措施。
- 8The method according to item 7 of the scope of patent application, further comprising obtaining a decryption key from the computing device for decrypting the secure communication. 如申請專利範圍第7項所述之方法,其中更包含從該計算裝置取得用於將該安全通訊解密的解密金鑰。
- 9The method according to item 8 of the scope of patent application, wherein the decryption key is obtained from the computing device via an auxiliary communication connection between the network security module and the computing device. 如申請專利範圍第8項所述之方法,其中上述之解密金鑰係經由該網路安全模組與該計算裝置之間的一輔助通訊連接而從該計算裝置取得。
- 10The method according to item 9 of the scope of patent application, wherein the decryption key is obtained from a decoding module on the computing device. 如申請專利範圍第9項所述之方法,其中上述之解密金鑰係從該計算裝置上的解碼模組取得。
- 11The method according to item 9 of the scope of patent application, wherein the above-mentioned secure communication is encrypted according to a secure socket layer protocol. 如申請專利範圍第9項所述之方法,其中上述之安全通訊係根據安全套接字層協定以加密之。
- 12The method according to item 9 of the scope of patent application, wherein the above-mentioned secure communication is encrypted according to a transport layer security protocol. 如申請專利範圍第9項所述之方法,其中上述之安全通訊係根據傳輸層安全協定以加密之。
- 13The method described in item 7 of the scope of patent application, which further includes obtaining configuration information about the computing device from the computing device, and obtaining protective security measures for protecting the computing device from being subject to The steps of detecting a security threat include obtaining protective security measures and protecting the computing device based on configuration information about the computing device. 如申請專利範圍第7項所述之方法,其中更包含從該計算裝置取得關於該計算裝置的組態資訊,且其中取得保護安全措施,其用於保護該計算裝置,使其免於受到所偵測到之安全威脅的步驟包含取得保護安全措施,並根據關於該計算裝置的組態資訊來保護該計算裝置。
- 14A network security module is located between a network device and a network, so that all network activities between the network device and the network will pass through the network security module, thereby protecting the network The road device is protected from security threats detected on the network. The network security module includes at least:a network device connection, which is used to connect the network security module to the network device;A network connection for connecting the network security module to the network;a decoder device for temporarily decrypting a secure communication using the obtained decryption key;and a security execution device, It controls the network activity between the network device and the network by implementing the obtained security measures in order to protect the network device from security threats detected on the network. 一種網路安全模組,其係介於網路裝置與網路之間,使該網路裝置與該網路之間的所有網路活動均會通過該網路安全模組,藉以保護該網路裝置免於受到該網路上所偵測到的安全威脅,該網路安全模組至少包含:一網路裝置連線,其係用於將該網路安全模組連接到該網路裝置;一網路連線,其係用於將該網路安全模組連接到該網路;一解碼器裝置,其係利用取得的解密金鑰,暫時將一安全通訊解密;以及一安全執行裝置,其係藉由執行取得的安全措施來控制該網路裝置與該網路之間的網路活動,以便保護該網路裝置免於受到該網路上所偵測到的安全威脅。
- 15The network security module according to item 14 of the scope of patent application, wherein the security execution device obtains the temporarily decrypted secure communication from the decoder device, and evaluates the temporarily decrypted security according to the obtained security measures. Communication to control network activity between the network device and the network. 如申請專利範圍第14項所述之網路安全模組,其中上述之安全執行裝置係從該解碼器裝置取得該暫時解密的安全通訊,並根據該取得的安全措施來評估該暫時解密的安全通訊,以控制該網路裝置與該網路之間的網路活動。
- 16The network security module according to item 14 of the scope of patent application, wherein the above-mentioned decoder device obtains the decryption key and temporarily decrypts the secure communication from the decoding module on the network device. 如申請專利範圍第14項所述之網路安全模組,其中上述之解碼器裝置取得該解密金鑰,並將來自於該網路裝置上的解碼模組的安全通訊暫時解密。
- 17The network security module according to item 16 of the scope of patent application, which further includes an auxiliary communication connection, which is used to connect the network security module to the network device, and wherein the decoder device passes through The auxiliary communication connection obtains the decryption key, and temporarily decrypts the secure communication from the decoding module on the network device. 如申請專利範圍第16項所述之網路安全模組,其中更包含一輔助通訊連線,其係用於將該網路安全模組連接到該網路裝置,且其中該解碼器裝置透過該輔助通訊連線而取得該解密金鑰,並將來自於該網路裝置上的解碼模組的安全通訊暫時解密。
- 18The network security module according to item 14 of the scope of patent application, wherein the above-mentioned secure communication is encrypted according to the secure socket layer protocol. 如申請專利範圍第14項所述之網路安全模組,其中上述之安全通訊係根據安全套接字層協定以加密之。
- 19The network security module according to item 14 of the scope of patent application, wherein the above-mentioned secure communication is encrypted according to the transport layer security protocol. 如申請專利範圍第14項所述之網路安全模組,其中上述之安全通訊係根據傳輸層安全協定以加密之。
Independent claims19
120 paragraphs, as filed
System and method for preventing computer equipment from generating computer loopholes in network environment by secure communication
The present invention relates to a system and method for protecting a computing device from a computer exploit transmitted via a network with secure communication.
As more and more computers and other computing devices are interconnected through various networks, such as the Internet, computer security has become increasingly important, especially for intrusions or transmissions through the network or through information streams. attack. As those skilled in the art know, this type of attack can take many forms, including computer viruses, computer worms, system component replacements, denial of service attacks, and even misuse / abuse of proper computer system characteristics, but not as such All of the above attacks are against one or more security vulnerabilities in computer systems for improper purposes. Although those skilled in the art can understand that various computer attacks are technically different, in order to facilitate the explanation of the principles of the present invention, the above-mentioned various attacks are collectively referred to as computer attack programs or simply referred to as exploits.
When a computer is attacked or "infected" by a computer attacker, it can cause a variety of negative effects, including invalidating system devices; deleting or tampering with firmware, applications, or file data; Send confidential data to another location on the network; shut down the computer system; or cause the computer system to crash. Although not all, the harm of most computer attack programs is that infected computer systems can be used to infect other computers.
FIG. 1 is a schematic diagram of a network environment 100 through which computer attack programs usually spread. As shown in FIG. 1, a typical network environment 100 includes a plurality of computers 102-108 interconnected via a communication network 110. The communication network 110 may be an internal network or a large-scale communication network. Domain TCP / IP network. For some reason, a malicious person on a computer (eg, computer 102) connected to the network 110 developed a computer attack program 112 and distributed it on the network. As shown by arrow 114, the distributed computer attack program 112 is received by one or more computers (such as computer 104) and infected. As is typical of many computer attack programs, once infected, as shown by arrow 116, computer 104 will infect other computers (such as computer 106), and then as shown by arrow 118, it will infect other computers (such as computer 108). . Obviously, due to the speed and scope of the modern computer network, the computer attack program 112 can "grow" exponentially, and quickly become a global computer panic from a local epidemic.
Anti-virus software system is a typical defense against computer attack programs, especially computer viruses and sabotage programs. In general, antivirus software scans incoming data sent over the network and searches for recognizable patterns related to known computer attack programs. When a pattern associated with a known computer attack program is detected, the antivirus software's response may be to remove the computer virus from the infected data, quarantine the data, or delete the "infected" incoming data. Unfortunately, antivirus software is usually only effective against "known" identifiable computer attacks. This task is often accomplished by matching the patterns in the data to a "signature" called an attacker. One of the major drawbacks of this attack detection mode is that until the computer's antivirus software is updated to find and respond to new computer attack programs, unknown computer attack programs may In case of transmission on the network.
As antivirus software has become more sophisticated and can more efficiently identify thousands of known computer attack programs, computer attack programs have become more complex and difficult to understand. For example, there are many computer attack programs that have multiple types (polymorphic); in other words, they do not have an identifiable pattern or "identifying feature" recognized by current antivirus software. Because such multi-type computer attack programs modify themselves before being transmitted to another computer system, antivirus software often fails to recognize them.
A hardware or software network firewall is another common measure currently used to protect against computer attacks. Those skilled in the art should understand that a firewall is a security system that can protect the internal network by controlling the flow of information between the internal network and the external network to prevent the external network from being used without authorization. Intranet. All communications from outside the firewall are first sent to a proxy server for inspection, and it is determined whether the communications are secure or allowed to be forwarded to their intended destination. Unfortunately, it is a highly sophisticated and complex task to properly configure a firewall so that allowed network activities are not restricted, and to reject unallowed network activities. In addition to technical complexity, firewall settings are also difficult to manage. When the firewall is not properly set, allowed network traffic may be inadvertently closed, and inadmissible network traffic may be allowed to pass, thus endangering the security of the firewall. Therefore, changes to the firewall are rarely made, and only those skilled in network design can perform this task.
Another limitation of firewalls is that while the firewall is protecting the internal network, it will not protect specific computers. In other words, a firewall does not adapt itself to the needs of a particular computer. Even if a firewall is used to protect a single computer, it will still protect the computer according to the setting structure of the firewall, instead of protecting according to the setting configuration of the single computer.
Another issue with firewalls is that they do not provide protection from computer attacks that originate from within the boundaries they establish. In other words, once the attacker can pass through the network protected by the firewall, the firewall cannot stop the attacker. This often happens when an employee takes a portable computer home (that is, not protected by a company firewall) and uses the computer in a less secure environment. The portable computer was subsequently infected without the employee's knowledge. When the portable computer reconnects to the company's network protected by a firewall, attackers often infect other computers at will without being checked by the firewall.
As mentioned earlier, current computer attack programs can also take advantage of suitable computer system characteristics in an attack. Many groups, other than firewall and antivirus software providers, must now join the defense against computer attacks by computer attacks. For example, operating system providers must now continuously analyze the functions of their operating systems for economic or contractual reasons in order to identify weaknesses or security vulnerabilities that could be exploited by computer attackers. For the purposes of this discussion, the channels that computer attackers may use to attack computer systems are commonly referred to as computer system security vulnerabilities, or simply security vulnerabilities.
When a security vulnerability is found in the operating system or other computer system components, drivers, or applications, providers often release software updates to patch the security vulnerability. This type of update, often called a patch, should be installed on your computer system to protect your computer system from security vulnerabilities. However, such updates are code in nature and can change operating system components, device drivers, or software applications. In this regard, the release of such updates cannot be as fast and extensive as the antivirus software providers. Because such updates are code changes, software updates must undergo extensive internal testing by the provider before they can be released to the public domain. Unfortunately, even if a software update is first tested internally by the company, it may still cause damage to one or more other computer system features or malfunction. Therefore, software updates can create a dilemma for those who rely on computer systems. Exactly, should the parties risk computer system damage to update their computer systems from the threat of security breaches? Or shouldn't they update their computer systems at the risk of becoming infected?
In the current system, there is a period called the vulnerability window, which exists when new computer attack programs are spread on the network 110 and the computer system is updated to protect it from the computer. Attackers wait between two points in time. As its name implies, computer systems have security vulnerabilities or face the threat of new computer attack programs during the empty window period of this security vulnerability. Figures 2A and 2B are block diagrams of timeline examples, which illustrate empty window periods for security vulnerabilities. In the following description of the timeline, important times or events will be considered and referred to as timeline-related events.
Figure 2A shows the window time of a computer system regarding one of the latest types of advanced computer attack programs that are widely distributed in public area networks. This new type of computer attack program will use the proactive security measures of the system provider to find out the security vulnerabilities of the computer system, and then create and distribute the computer attack program. In this regard, the following will provide further Instructions.
Please refer to Figure 2A; at event 202, the operating system provider found a security vulnerability in the operating system issued. For example, in one scenario, when an operating system provider performs its own internal analysis of a released operating system, it finds a previously unknown security vulnerability that can be used to attack computer systems. In another scenario, a third person, including an organization that conducts system security analysis of computer systems, found a previously unknown security vulnerability and relayed information about the security vulnerability to the operating system provider.
Once the operating system provider is aware of a security vulnerability, the operating system provider resolves the security vulnerability at event 204 and directs the creation and release of patches to protect the computer system running the operating system. Operating system providers usually issue a notice that a system patch is available and recommends that all users of the operating system install the patch. Such patches are usually stored in a known location on the network 110 for download and installation on affected computer systems.
Unfortunately, at Incident 206, often after an operating system provider releases a patch, malicious people will download the patch and use some kind of reverse engineering and any published by the operating system or other systems Information to find technical details of "patched" security holes in the operating system. Malicious individuals can use this information to create computer attack programs that can attack potential security holes. At Incident 208, a malicious person spread computer attacks on the network 110. Although the purpose of publishing software patches-also known as "patches" -is to fix potential security vulnerabilities, unfortunately: "patches" themselves are often complex pieces of software code that may form or Contains new security vulnerabilities, which in turn may be attacked by computer attack programs created by malicious people. Therefore, in addition to assessing what exactly the Patch fixes, you also need to evaluate the Patch against potential security vulnerabilities.
Although "patches" are available, for a variety of reasons including the above, malicious people can understand that not every computer system will be immediately upgraded. Therefore, at Incident 208, the malicious person distributed computer attack programs 112 on the network 110. As mentioned above, the distribution of the computer attack program 112 will open the security vulnerability window period 212; among them, the computer system with the security vulnerability will be threatened by the attack program. At Incident 210, the security window gap period 212 of the computer system can only be ended when the patch is finally installed on the computer system.
Although many computer attack programs currently distributed are based on known security vulnerabilities-such as the situation illustrated in Figure 2A-computer attack programs spread on the network 110 sometimes utilize previously unknown security vulnerabilities. FIG. 2B illustrates the VUL empty window period 230 relative to the timeline 220 in this case. Therefore, as shown by timeline 220, at event 222, the malicious person distributed a new computer attack program. Because this is a new computer attack program, neither operating system patches nor anti-virus updates are available to protect computer systems that are under threat from security. For this reason, the VUL empty window period 230 is in an open state.
As shown in event 224, at a certain point in time after the new computer attack program is transmitted on the network 110, the operating system provider and / or the antivirus software provider will detect the new computer attack program. Those skilled in the art will understand that operating system providers and antivirus software providers usually detect the emergence of new computer attack programs within a few hours.
Once a computer attack program is detected, the antivirus software provider can begin the process of identifying a pattern or "identification feature"; the antivirus software can use this program to identify the computer attack program. Similarly, the operating system provider will begin the process of analyzing computer attack programs to determine whether the operating system must be patched to prevent attacks from computer attack programs. At event 226, after similar efforts as described above, the operating system provider and / or anti-virus software provider will issue updates to the computer attack program, that is, operating system software patches or anti-virus code updates. Then, at event 228, the update will be installed on the user's computer system to protect the computer system and end the VUL empty window period 230.
From the above example, it can be seen that it is only an example of all possible situations in which a computer attack program poses a security threat to a computer system. The VUL window period exists when the computer attack program 112 is distributed on the network 110 and the corresponding update is installed in On the user's computer system, the VUL empty window period ends between two points in time. Unfortunately, regardless of the length of the VUL window, the possible "detoxification" and repair of infected computers will cost a lot of money to computer owners. For a large company or organization with thousands or hundreds of thousands of devices connected to the network 110, this cost can be significant. This cost will be even greater if computer attack programs have altered or destroyed customer data and it is extremely difficult or impossible to track down and remedy it. We need a system and method to protect computer systems in a responsive manner and according to the needs of individual computer systems, so that they can be protected from computer threats before they obtain protection updates and / or install on computer systems. The invention can solve the above problems and other problems encountered in the conventional technology.
The technical aspect of the present invention provides a network security module between a computing device and a network, which is used to protect the computing device from the security threats found on the network. This network security module is set up so that all network activities between the computer and the network will pass through the network security module. This network security module includes a connection to a computing device. This computing device connection connects the aforementioned network security module to the computing device. The network security module also includes a network connection that enables the network security module to connect to the network. Network activity is through a network security module via a computing device connection and a network connection. The above network security module also includes a decoder module; the decoder module can use the obtained decryption key to temporarily decrypt the security communication. The above network security module further includes a security execution module; the security execution module can control network activities between the computing device and the network. The security enforcement module is able to implement the acquired security measures to protect the computing device from security threats found on the network.
Another technical aspect of the present invention provides a method performed by a network security module between a computing device and a network. The method enables network activities between the computing device and the network to pass through The network security module to protect the computing device from security threats. In this way, proactive security measures can be obtained. When protective security measures are implemented, they can protect computing devices from identified security threats. Security communications sent to the computing device will be detected. In this way, protected secure communications can be temporarily decrypted. Protective measures are then implemented on secure communications that are temporarily decrypted.
FIG. 3A is a schematic diagram of a network environment 300 suitable for implementing the technical aspects of the present invention. The exemplary network environment 300 includes a computer 302 connected to a network 110. It should be noted that although the present invention is described in general with related operations of a personal computer such as computer 302, the purpose is only for illustration and should not be interpreted as a limitation of the invention. Those skilled in the art should understand that almost all networked computing devices may be attacked by computer attack programs. Therefore, the implementation of the present invention will be beneficial to the protection of various computers, computing devices or computer systems, including but not limited to: personal computers, tablet computers, notebook computers, personal digital assistants (PDAs), Mini and mainframe computers, wireless phone / PDA combinations, and similar devices. Implementing the present invention is also beneficial for protecting hardware devices, peripheral devices, software applications, device drivers, operating systems, and similar devices or programs.
Those skilled in the art need to understand that the network 110 includes an unlimited number of actual communication networks. Such actual communication networks include, but are not limited to, the Internet, wide area and local area networks, intranets, mobile networks, IEEE 802.11 and Bluetooth wireless networks, and similar networks. Therefore, although the present invention is described from the perspective of a computer network, its purpose is only for illustration, and should not be interpreted as a limitation of the invention.
The exemplary network environment 300 also includes a network security module 304 and a security service 306. The network security module 304 is between a computer, such as computer 302, and the network 110. The network security module 304 may be physically or logically configured between the computer 302 and the network 110. The communication between the computer 302 and the network 110 passes through the network security module 304. According to the present invention, the network security module 304 can selectively control the network activities between the computer 302 and the network 110 according to the security information corresponding to the specific configuration of the computer; the specific configuration of the computer includes, but is not limited to Specific operating system revisions installed on computer 302, anti-virus information including anti-virus software and corresponding identification profile data files, installed applications, device drivers, and similar configurations, all of which may be computers A potential target of an attack program is a computer system vulnerability.
According to an embodiment of the present invention, in order to regularly obtain security information from the security service 306, the network security module 304 periodically requests the security service 306 for security information corresponding to the security information of the specific configuration of the computer 302. After being set, the network security module 304 can periodically obtain security information from the security service 306. For example, I can set the network security module 304 to get security information from the security service 306 every minute. Alternatively, we can set the network security module 304 to obtain security information from the security service 306 according to the time specified by the user.
Since many users have to delay updating their computer systems for various reasons, it is important to obtain security information that corresponds to a particular configuration of a computer. For example, the delay in updating your operating system or antivirus software may be because your computer has not been used for a while. Therefore, although the latest revised operating system and / or anti-virus software can provide sufficient protection against newly discovered computer attack programs, the computer may still not be in the "latest state" and therefore vulnerable to computer attack programs. Security measures must be taken that match the specific configuration of the computer. In light of this, security information requirements may include, but are not limited to, identifying information about computer operating system revisions including installed patches; specific antivirus software and its modifications used by the computer, and updates to software and data files; And web-enabled application information such as email or browser identifiers, fixes, firmware providers and versions, and other security settings.
According to the technical aspect of the present invention, when updating computer system components, one of the actions is to obtain the specific configuration information of the computer by the network security module 304. For example, when a user installs a patch of an operating system on the computer 302, one of the installation actions is to inform the network security module 304 of the currently revised operating system version. Similarly, other computer system features such as network-enabled applications or anti-virus software will inform the network security module 304 when it is installed, so that the network security module can obtain the most reliable and sufficient security information. To protect the computer 302 according to the computer's current specific configuration.
According to the computer-specific configuration information in the security information request, the security service 306 can find relevant security information to protect the computer from known or perceived computer system security vulnerabilities. Below is a more detailed explanation of finding relevant security information. The security information includes protection measures implemented by the network security module 304, which can enable the network security module to isolate the computer 302 from computer attack programs with known security vulnerabilities. Protective security measures include any number of network activity controls or combinations thereof, including, but not limited to, blocking all network activity between computer 302 and network 110, but excluding certain known secure network locations (such as Install patches or updated security services 306 or anti-virus software services 308); block access on specific ports and addresses; block certain network-related applications-such as email or web browsing applications- Communications; and deny access to specific hardware or software components on computer 302. In this way, the network security module implements security measures after receiving a security response.
As mentioned above, the network security module 304 is between the computer 302 and the network 110; in this regard, all network activities between the computer and the network must pass through the network security module. When the network transmission passes the network security module 304, the network security module monitors the network transmission and implements the protection measures received from the security service 306, such as blocking all network access activities, but Does not include communications between certain known safe locations, or similar security measures.
According to another aspect of the present invention, a security response may also include specified security levels, such as red, yellow, and green levels. For the user of the computer 302, the security level represents the level of protection measures performed by the network security module 304. For example, a red security level may indicate that the network security module 304 is currently blocking all network activities between the computer 302 and the network 110, but this block does not include access activities that are known to be secure locations. Alternatively, the yellow security level may indicate that the network security module 304 is currently performing certain protection security measures, and the computer 302 can still contact the network 110. In addition, the green security level may indicate that the network security module 304 has not implemented any kind of protection security measures, and the communication between the computer 302 and the network 110 is not restricted. According to the above security levels, for convenience of explanation, the red security level can also be referred to as a full block, the yellow security level can also be referred to as a partial block, and the green security level can be referred to as free network access. Although the three security levels and the representations of red, yellow, and green are mentioned above, they are only examples and should not be interpreted as limitations of the present invention. Those skilled in the art will understand that we can implement any number of security levels and provide users with other representations.
Because the network security module 304 operates in an automated manner, that is, does not require user intervention, the purpose of the above-mentioned security level and any corresponding security level representation is to provide user information only, and to The user indicates the level of restriction performed by the network security module 304. This graphical representation is particularly useful when users are trying to determine if the network connection is malfunctioning, or if they are limiting network activity due to current network security considerations.
According to the technical aspect of the present invention, a security measure is added. When the power of the network security module 304 is turned on, it enters a preset state. This default state is equivalent to the highest security level, that is, a completely blocked state, but allows network activities between the computer 302 and a trusted network location. Whether during the power-on process or during regular contact with the security service 306, the network security module 304 will obtain the latest security information, and can adopt less stringent according to this security information Security measures. The execution of the default state on the network security module 304 is obviously very beneficial to the computer 302, because during the time when the network security module is powered off, a security vulnerability may occur, or an attack program has been spread on the network 110.
According to an embodiment of the present invention, the network security module 304 does not request or access information from the computer 302. Instead, the network security module 304 operates on information transmitted from the computer 302 on certain events. Therefore, when the network security module 304 first protects the computer, for example, when the network security module is first configured between the computer 302 and the network 110, the network security module 304 will not have any correspondence to the computer system. Specific configuration information for. As mentioned above, when the network security module 304 does not have the relevant configuration information of the computer 302, or when the power of the network security module 304 is turned on, the network security module will enter its default state, that is, Completely blocked. However, as described above, a complete blockade will still allow computer 302 to contact a known secure location. For example, such known safe locations include one or more storage locations for operating system updates. Therefore, even if the computer 302 is equipped with the latest operating system, anti-virus software, applications and available device drivers, users can still execute the update process to generate a configuration that will be transmitted to the network security module 304. Information. In another embodiment, the special program can inform the network security module 304 of the current configuration of the computer system.
In order to ensure that the communication between the network security module 304 and the security service 306 is true and reliable and has not been tampered with, in one embodiment of the present invention, the communication between the network security module and the security service-for example, security requirements And security information-will be transmitted in encrypted secure communications, such as using the Secure Sockets Layer (SSL) protocol. Similarly, the communication between the network security module 304 and the computer 302 is protected in a similar manner.
According to the non-essential technical aspect of the present invention, even when the computer is turned off, the network security module 304 will continue to operate, that is, obtain security information corresponding to the computer 302. For example, when the network security module 304 is turned on, it can continuously obtain the security information for the computer 302 according to the latest operating system and / or anti-virus software revision data provided to the computer. According to an embodiment, the network security module 304 is connected to a computer's auxiliary power rail; as known to those skilled in the art, the auxiliary power rail can provide power to peripheral devices when the computer 302 is in an off state. In addition, if the network security module 304 only operates during the operation of the computer 302, when the network security module is re-operated, the network security module will perform a complete block and obtain the latest security corresponding to the current configuration of the computer Sexual information.
According to another embodiment of the present invention, the user may choose to disable the network security module 304. This is useful because sometimes the need to be able to fully use the network is more important than the risk of a computer attack. For example, when trying to debug a network troubleshooting problem, the network security module 304 may have to be disabled. Alternatively, certain emergency situations, such as using E911 Voice over Internet Protocol (VoIP) services, may require the network security module 304 to be disabled.
According to the technical aspect of the present invention, when the network security module 304 is disabled, it will continuously obtain the security information from the security service 306, but it will not perform protection security measures. Because the network security module will have the latest security information when it is re-enabled, it is very beneficial for users to continuously update the security information; especially when the network security module 304 is temporarily disabled Case. In another case, if the network security module 304 is disabled and not continuously updated, the network security module will revert to its default setting after a preset period of time without any communication with the security service 306 Status-Total blockade of network activity.
The security service 306 may be implemented as a single server / source of all security information, or a server / source hierarchy structure dispersed on the network 110. In a hierarchical system, the network security module 304 will accept the initialization settings that the root server / service in the security service must perform. However, perhaps during the first communication between the network security module 304 and the security service, the security service will provide information about the hierarchical structure of the security service as part of the security information returned by the security service. This information can be a range of one or more network addresses, which are nodes of the security service hierarchy structure, and can provide appropriate security information to the network security module 304. Thereafter, the network security module 304 does not need to query the original node to obtain information. Obviously, the advantage of implementing security services in a hierarchical manner is that we can easily enlarge or reduce the size of security services to match the number of network security modules that request information, so that the original nodes of the security service layer will not be derived from The security information requirements of all network security modules on the network are destroyed. Under the hierarchical structure dispersed in the network 110, the effect of load balancing can be obtained, and the backup structure can be built into the system, so that when a node in the hierarchical structure fails, other nodes can still take over to provide Security information.
According to the technical aspect of the present invention, using the conventional port mimicking technology, the computer 302 and the network 110 cannot detect the existence of the network security module 304. In a nutshell, using the communication port mimicry technology, the network security module 304 looks like the network 110 to the computer 302, and the network security module 304 looks like a computer to the devices on the network. Therefore, unless the network security module determines that the communication is directed to a network security module (such as notification of an operating system update or security information response), or that the network security module must block network activities in accordance with security measures, the computer The network activity between the 302 and the network 110 through the network security module can be freely circulated.
As described above, after querying, the network security module 304 can obtain security information from the security service 306. Those skilled in the art will understand that this is a poll system, that is, the security service 306 is polled for security information. However, in another embodiment, the security service 306 can broadcast important security information to the network security module in the network 110 in a more advantageous manner. For example, if a particularly destructive computer attack program begins to circulate on the network 110, the security service will depend on the time period during which the network security module in the network environment 300 obtains security information from the security service 306. Security information is broadcast to the network security module without waiting for the network security module to request important security information. This security information-hereafter referred to as a security notice-usually includes all configurations that are vulnerable to computer attack programs, the protection measures to be taken, and the corresponding security levels. According to an embodiment of the present invention, the security notice is an XML file planned according to a predetermined design profile.
The system for broadcasting information to listeners is called a push system, that is, the security service 306 pushes important security information to a network security module. According to the technical aspect of the present invention, the security notice is a method for broadcasting on the network 110 by using the "guaranteed transmission" service. Among the guaranteed transmission services, the security notice is considered as a high priority item, and will be transmitted prior to other network circulations that would otherwise be transmitted first with the consent of the network service provider.
In addition to sending security notices on the same network 110 to which the computer 302 is connected, many times it is very helpful to communicate out-of-band, that is, by separating from the network 110 To the secondary communication link. FIG. 3B is a schematic diagram of another network environment 310. The environment shown is suitable for implementing various technical aspects of the present invention, including an auxiliary communication link 314, which can be used to transmit security information to a network connected to the network 110. Road Safety Module.
As shown in FIG. 3B, another networked environment 310 includes similar components as shown in the networked environment 300, including a computer 302, a security service 306, and a network security module 304. However, the security service 306 is additionally configured to transmit security information, including security information and / or security notices, to the network security module 304; in addition, the network security module is specifically configured with a secondary communication link 314 to receive information receiving device 312. According to the technical aspect of the present invention, the auxiliary communication link 314 may be a satellite communication link, a radio frequency broadcast, or other auxiliary communication provided between the security service 306 and the network security module 304. Those skilled in the art will understand that any number of communication channels can be used here.
According to other technical aspects of the present invention, the auxiliary communication link 314 may be a one-way communication from the security service 306 and the network security module 304, or a two-way communication link between the security service and the network security module. In addition, via the auxiliary communication link 314, software updates or patches as described above can be downloaded from the security service 306.
Although the network security module 304 is between the computer 302 and the Internet 110, the actual setting method of the network security module may be changed. Either way, the network security module 304 will be regarded by the computer 302 as a trusted unit. According to an embodiment, the network security module 304 is a hardware device (sometimes referred to as a "dongle") located outside the computer 302 and connected to the network 110 and the computer 302. In another embodiment, the network security module 304 can be integrated with the computer 302 to form a hardware unit, or as a sub-unit within the computer network interface. When the computer 302 is connected to the network 110 via a wireless connection, it is particularly useful to integrate the network security module 304 in the computer 302 or as a sub-unit of the computer network interface.
According to another embodiment of the present invention, the network security module can be regarded as a logic circuit in a certain unit of the computer 302, such as microcoding or firmware, including but not limited to a processor, a graphics processing Unit, North Bridge or South Bridge. In another embodiment, the network security module may be a software module that cooperates with the operating system or becomes a part of the operating system, or as an independent application installed on the computer 302. The network security module 304 implemented in software can be operated on a second processor in the computer 302. Therefore, the network security module 304 should not be limited to a specific embodiment.
It should be particularly noted here that the advantages obtained by the present invention are that the system will reduce the impact of many computer attack programs. For example, those skilled in the art should understand that a denial of service (DOS) attack attempts to destroy a computer with a network request until the computer runs out of resources and crashes; or By mistake, it is more vulnerable to external attacks / attacks. However, by using the network security module 304 to respond to the security service 306 by implementing protection security measures, the above-mentioned attack programs including the potentially damaging network request will not be able to access the computer 302.
In order to better understand how the above units operate to provide enhanced security for the computer 302, the following description will be made with reference to a scenario example drawn on a timeline corresponding to an event. 4A and 4B are block diagrams illustrating exemplary timelines for explaining the operations of the units of the present invention. Specifically, FIG. 4A shows a block diagram of an example timeline 400, which illustrates how the present invention can reduce the security vulnerability 406 of the computer 302 relative to new computer attack programs distributed on the network 110. It should be noted that the following description only takes a computer attack program that attacks the operating system as an example, which should not be interpreted as a limitation of the present invention. The invention can be used to protect code modules and services on computer systems, and even protect hardware devices.
As shown in timeline 400, at event 402, a malicious person spread a new computer attack program on the network 110. This dissemination operation will open the security window 406 of the security vulnerability of the computer that belongs to the target of the new computer attack program and has been connected to the network 110. At event 404, a new computer attack was detected by the operating system provider or antivirus software provider in the manner described above.
At event 408, after detecting the existence of a new computer attack program, even if the characteristics or attack mode of the attack program have not been determined, the operating system provider will issue security information via the security service 306. Under typical circumstances, when a computer attack program is found and its characteristics, scope of influence, or attack mode is unknown, the security service will set the security level of all computer systems that appear to be affected to the red level-that is, completely blocked. At block 410, the network security module 304 obtains security information through periodic requests or security notices, and implements corresponding security measures-in this example, completely blocked. After the security measures from the security service 306 are executed, the security vulnerability window 406 of the computer belonging to the attack target will be effectively closed.
Compared with the security vulnerability empty window period 230 shown in FIG. 2B, the security vulnerability empty window period 406 is shorter, so the exposure time of the computer system belonging to the target of the new computer attack program can be shortened. Obviously, the actual length of time that a security vulnerability (eg, security vulnerability empty window period 406) is open depends on a few factors. The length of time before a computer attack is detected is one of the factors. As mentioned above, new computer attack programs are generally detected within 15 minutes to hours after distribution. The second factor is the length of time it takes for the network security module 304 to obtain security information from the security service 306; the degree of change of this factor is greater than the degree of change of the first factor. If the network security module 304 can continuously obtain security information, it only takes a few seconds to obtain the security information and implement corresponding security measures. However, if the network security module 304 cannot continuously contact the security service 306, or the time period for regularly obtaining security information is too long, it will take a long time to implement the protection security measures. According to the technical aspect of the present invention, if the network security module 304 does not contact the security service 306 for a period of time, the network security module will return to the preset completely blocked state and wait for future contact with the security service. .
After the initial security information is released, operating system providers or anti-virus software providers often continuously analyze computer attack programs to better understand how they work and / or the characteristics of the computer systems they attack. From this analysis, a second set of perhaps less stringent protection measures can be found; computer systems with security vulnerabilities must take this protection measure to avoid being infected by computer attack programs. Therefore, at Incident 412, the updated security information is published at the yellow security level, and the protection measures that are used to block at-risk network activities-that is, partial blockades-are determined. For example, as mentioned above, protection can be simply blocking a specific range of ports-including source and / or destination ports, or disabling email communication ports installed on a protected computer system, Web browsing or other network activities that lead to operating systems, application device drivers, or similar programs, while allowing other network activities to circulate freely. What needs to be understood here is that "at-risk" network activities include network activities where computer systems are threatened by attack programs, regardless of whether the computer attack programs are security vulnerabilities that attack computer systems or abuse the characteristics of eligible computer systems. In addition, "at-risk" cyber activity includes unilateral cyber activity initiated by another device against a computer system. In other words, "at-risk" network activity includes network activity launched by attackers against computer systems that are simply connected to the network.
At event 414, the network security module 304 obtains the updated security information and executes corresponding protection security measures. At event 416, when the operating system provider and / or anti-virus software provider creates a usable software update, another updated security information is released. If a software update-for example, an update from an operating system provider, an antivirus software provider, or an application provider-is installed on computer 302, this updated security information may identify the security level Is a green level. Subsequently, another updated security information is obtained at event 418, the software update is installed on computer 302, and the network security module 304 enables free (ie, unlimited) network access.
FIG. 4B illustrates a block diagram of another exemplary timeline 420, which illustrates how the present invention can eliminate the window of security vulnerabilities with respect to computer attack programs distributed on the network 110; in particular, a method utilizing previously found Security vulnerabilities rather than new attacks. As mentioned above, attacks that exploit previously known security vulnerabilities are more common than brand new attacks. At event 422, the operating system provider found a security vulnerability in a currently released operating system. At event 424, the operating system provider releases security information that can mitigate the threat, sets the security level, and confirms the corresponding protection security measures to deal with the threat caused by the found security vulnerability. In the example shown in Figure 4B, if a security breach poses a great danger to a computer connected to the network 110, the operating system provider will publish the security information and set the security level to the red level while taking the full Blocked security measures. At event 426, the network security module 304 obtains the latest security information and implements a complete blocking measure. It should be noted that before the patch or "fix" is available, the security measures to protect the security vulnerability of computer 302 have been implemented. Since most computer attack programs are more or less derived from information obtained by analyzing security vulnerabilities fixed by patches, malicious people will pre-empt the opportunity to create an attack program to attack security vulnerabilities, and therefore will not Open a window of security vulnerabilities. This result is obviously very beneficial to computer users, especially when the network security module does not implement security measures; please refer to the corresponding timeline 200 shown in Figure 2A.
After further analysis of computer attack programs, the operating system can often determine a less stringent set of protection measures to protect computers connected to the network from computer attack programs. Therefore, as shown in Figure 4B, an updated security bulletin will be issued at event 428, the security level will be set to yellow, and the corresponding protection security measures that specifically target the threatened security vulnerability-that is, part Block and start all other network activities at the same time. In this way, the updated security information is obtained at event 430, and the network security module 304 performs a partial block.
Once an operating system patch or anti-virus software update is available, if such a program is installed on computer 302, it can protect computer 302 so that the computer's security vulnerability will not be the target of computer attack programs; in event 432 , The operating system provider publishes information and states that once installed, the network security module allows free network access, that is, after installing the patch, the network security module sets the security level to Green level. Similarly, at event 434, after a patch or anti-virus update is installed on the computer 302, the network security module 304 enables free access.
FIG. 5 is a flowchart illustrating a subroutine example 500 for dynamically controlling a computer's network access according to the released security information. Figure 5 contains two originating endpoints. The originating endpoint 502 is equivalent to the origin of the network security module 304, and the originating endpoint 520 is equivalent to receiving an update notification from the computer system 302. First, starting from the starting endpoint 502 and proceeding to block 504, the network security module 304 will execute the related security measures of complete blockade. As mentioned above, when completely blocked, the computer will be restricted from communicating with known trusted network locations, including security service 306, in order to obtain the latest security status information and any available update information.
At block 506, the network security module 304 obtains security information from the security service 306 corresponding to the current configuration of the computer. According to the technical aspect of the present invention, the network security module 304 can obtain the latest security information from the security service by issuing a request for security information to the security service. In another embodiment, the network security module 304 can obtain the latest security information from the broadcast of the security service 306 via an auxiliary communication link or broadcast on the network.
At decision block 508, the network security module 304 determines whether the currently implemented security measure and the corresponding security level are as new as the acquired security information based on the latest security information obtained from the security service 306. According to a technical aspect of the present invention, the judgment is made by simply comparing the computer system revision information currently stored by the network security module with the latest revision information released by the security service.
At block 510, if the currently implemented security measures are not up-to-date, the network security module obtains the security measures of the computer system according to the information about the computer system it has stored. In another embodiment (not shown in the figure), security measures may be included in the obtained security information. At block 512, once the network security module 304 obtains a security measure, it will execute the security measure and set a corresponding security level, that is, a security level such as red, yellow, or green.
At block 514, after the security measures of the computer system are implemented, or if the security measures currently implemented for the computer system are up to date, the network security module 304 enters a delayed state. This delay state corresponds to a time period during which the network security module 304 periodically queries the security service 306 to obtain the latest security information. After a predetermined time delay, the process returns to block 506; here, the process of obtaining the latest security information from the security service 306 is repeatedly executed to determine whether the security measures currently implemented for the computer system are up to date , While implementing any new security measures.
As shown in FIG. 5, since the exemplary subroutine 500 is designed in such a way that it can continue to operate to protect the computer 302 from computer program attacks, the subroutine 500 does not have an end point. However, those skilled in the art should understand that if the power of the network security module 304 is turned off without being connected to the exemplary network environment 300, or disabled by the user as described above, the subroutine 500 will terminate. .
Referring to another starting endpoint 520, this entry point represents the situation when the network security module 304 receives the update notification from the computer system. As described above, the application program suitable for utilizing the present invention notifies the network security module 304 of the current revision information, and is used as one of the steps for updating the computer system. For example, when updating the anti-virus software, one of the steps is to send a notification to the network security module 304 to inform the network security module 304 about the current revision information. Therefore, at block 522, the network security module 304 receives the update notification.
At block 524, the network security module 304 stores the update notification information for later use in determining whether the currently implemented security measures are up-to-date. Operating system updates and other code module updates are suitable to provide notification to the network security module 304, so that the security system can make judgments about the appropriate security measures needed to protect any computer system with sufficient information.
After storing the information, the subroutine 500 proceeds to block 506, where the steps of obtaining the latest security information from the security service 306 are started, and the above method is used to determine whether the security measures currently implemented for the computer system are up to date While implementing any new security measures. In another embodiment (not shown in the figure), after receiving the updated computer system information at block 524, the network security module waits to obtain the security status information before the current delay status ends.
FIG. 6 is a flowchart of an exemplary subroutine 600 for broadcasting security information required by a network security module, such as the network security module 304 in the exemplary network environment 300. Beginning at block 602, the security service 306 obtains security-related information from various sources. For example, the security service 306 typically obtains information from operating system providers and antivirus software providers about the latest fixes, patches, and available updates, as well as various attackers and / or computer attacks to be addressed by various patches and updates. Security breach. Security-related information can also be obtained by polling other sources, including various government agencies, security experts, or similar sources.
At block 604, the security service 306 obtains information about security vulnerabilities of the computer system connected to the network 110. This information may come from operating system providers, antivirus software providers, or others who have detected security holes. At block 606, the security service 306 determines the level of security--such as the red, yellow, and green levels--and the protection performed by a network security module--such as the network security module 304--based on the threat caused by the security breach. Measures to prevent affected computers from being compromised by computer attack programs.
At block 606, the security service 306 broadcasts the security notice including the security level and corresponding protection security measures to the network security module connected to the network 110 in the manner described above. As mentioned above, the security service 306 can send a network-wide broadcast to all network security modules for broadcast of security announcements. I can choose to use the above-mentioned guaranteed transmission for network-wide broadcast via network 110, or network-wide device connected to auxiliary communication link 314 in network environment 300 for network-wide broadcast. Subsequent to the submission of the security notice, subroutine 600 terminates.
FIG. 7 is a flowchart illustrating an example 700 of a subroutine implemented by the security service 306. The subroutine can receive and respond to requests for security information from the network security module 304. Beginning at block 702, the security service receives a request for security information from the network security device 304. As mentioned above, the security information request may contain information corresponding to the current configuration of the computer.
At block 704, according to the specific computer configuration information in the security information request provided by the network security module, the security service 306 finds the security related to the current configuration information of the computer corresponding to the security information request Information.
According to an embodiment, the security service 306 finds the relevant security information by determining the protection security measures needed to protect the computer 302 according to the computer configuration information. According to another embodiment, the security service 306 determines which protection security measures should be performed by returning all security information corresponding to a specific computer configuration for further processing by the network security module. In another embodiment, the security service 306 returns all security information corresponding to a specific computer configuration, and then forwards it from the network security device to the computer 302, so that the computer can inform the network security module that it should What protection measures are implemented. We can also use other combinations or other systems of the above embodiments. Therefore, the present invention should not be interpreted and limited to any one specific embodiment.
At block 706, the security service 306 returns the relevant security information to the requesting network security module 304. Subsequently, the subroutine 700 is terminated.
FIG. 8 is a flowchart of a method 800 implemented by the network security module 304, which can control the network flow between the computer 302 and the network according to the security measures taken from the security service 306. Beginning at block 802, the network security module 304 receives network circulation, including network circulation sent to the computer 302, and network circulation sent from the computer.
At decision block 804, it is determined whether the network circulation is sent from a trusted network location or to a trusted network location-such as a security service, an antivirus software provider, an operating system provider, or a similar source. If the network flow is from or sent to a trusted location, the subroutine proceeds to block 810; here the network communication is allowed to pass through the network security module 304, and then the subroutine 800 terminates. However, if the network circulation is not from or sent to a trusted network location, the subroutine proceeds to decision block 806.
A decision is made at decision block 806 as to whether the network flow is restricted by the security measures currently implemented. If the network circulation is not restricted by the currently implemented security measures, the subroutine proceeds to block 810; here the network circulation is allowed to pass through the network security module 304, and then the subroutine 800 terminates. However, if the network circulation has been restricted according to the currently implemented security measures, the subroutine proceeds to block 808; here, the network circulation is not allowed to pass through the network security module 304. Subroutine 800 then terminates.
Although the network security module 304 is located between the computer 302 and the Internet 110, the embodiment of the network security module may be changed. According to an embodiment, the network security module 304 may be a hardware device external to the computer 302 and connected to the Internet 110 and the computer 302. FIG. 9 is a schematic diagram showing an example of a network security module 304 implemented by an external hardware device of the computer 302.
As shown in FIG. 9, the network security module 304 as an external device has a connection 902 connected to the network 110 and a corresponding connection 904 connected to the computer 302. All network activities between the computer 302 and the network 110 are performed on a connection 904 connected to the computer. The network security module 304 shown in the figure also has an auxiliary computer connection 918, which is responsible for transmitting information between the computer 302 and the network security module. The network security device 304 shown in the figure further includes an enable / disable switch 906, status indicators 910-916, and a backup connection 908 to an external power source.
As mentioned above, sometimes it is necessary to stop the network security module from implementing its current security measures. According to the embodiment shown in FIG. 9, the enable / disable switch 906 is a two-state switch: when the current security measures need to be ignored, the enable / disable switch 906 can disable the network security module 304; enable / disable The switch 906 can also enable the network security module 304 to enable it to implement the current security measures it has obtained from the security service 306.
The status indicators 910-916 contain a visual indication of the current status of the network security module. As mentioned above, the status indicator is only for the purpose of providing information, and it provides computer users with tips about the protection and security measures implemented by the network security module 304. Each indicator corresponds to a specific security state. For example, the status indicator 910 may correspond to a red security level, which means that the network activity is completely blocked, and the status indicator will emit a red light when the network security module 304 is performing a complete blocking. The status indicator 912 may correspond to a yellow security level, which means that the network activity is partially blocked, and the status indicator will emit a yellow light when the network security module 304 is performing a partial blocking. Similarly, the status indicator 914 may correspond to a green security level, ie, free use of the network, and the status indicator emits a green light when the network security module 304 allows use of an unrestricted network. The status indicator 916 may correspond to the enabled / disabled status of the network security module 304, and when the network security module 304 is disabled, it emits a red flash.
Although the embodiment of the present invention can be as shown in FIG. 9, it is only an example; the embodiment shown in FIG. 9 has various modifications and replacements without departing from the scope of the present invention. Therefore, the present invention should not be interpreted as being limited to any one embodiment.
In another embodiment (not shown), the network security module 304 may be a component integrated in the computer 302 or a sub-component in a computer network interface. These two embodiments are particularly useful when the computer 302 is connected to the Internet 110 via a wireless connection. In another embodiment, the network security module 304 may be a software module integrated in the operating system or a separate module installed on the computer 302. Therefore, the network security module 304 should not be interpreted as being limited to a specific physical or logical implementation.
FIG. 10 is a block diagram of a logic unit of the network security module 304 constructed according to the present invention. Network security module 304 includes memory 1002, security status indicator module 1004, comparison module 1006, security execution module 1008, update request module 1010, network connection 1012, computer connection 1014, and backup Computer connection 1018, and encoder / decoder module 1020.
The memory 1002-including volatile and non-volatile memory areas-is used to store current security measures implemented by the network security module 304. The memory 1002 may also store configuration information provided to the network security module 304, including current revision information of the operating system, antivirus software and signatures, applications, and the like. Other information may also be stored in the memory 1002, including addresses of trusted locations, update sources, and similar information. Information such as addresses of trusted locations is more likely to be stored in non-volatile memory.
The security status indicator module 1004 indicates the current security status of the network security module 304 to the computer user. For example, when the network security module 304 is a physical device type as shown in FIG. 9, the security status indicator module 1004 controls the status indicator 910 according to the current security status of the network security module. 916.
The comparison module 1006 compares the security information stored in the memory 1002 with the security information obtained from the security service 306 to determine whether the security information stored in the memory 1002 is related to the current configuration of the computer. For the latest. The secure execution module 1008 is a component that protects the computer 302 from known threats by implementing security measures. Therefore, the security execution module 1008 controls the network activity flow between the computer 302 and the network 110 according to the security measures stored in the memory 1002.
The update request module 1010 is used for a polling system, which periodically requests the security service 306 for the latest security information. In a push system, the update request module 1010 can be used as a receiver that receives security information from the security service, and cooperates with the comparison module 1006 to find information based on the information received from the security service 306. To fully protect the computer 302's protective security measures. In another embodiment, the update request module may contact the computer 302 to establish / find protection security measures to fully protect the computer 302 based on the information received from the security service 306. All components of the network security module 304 are interconnected via a common system bus 1016.
The encoder / decoder module 1020 is used to encode and decode the secure communication between the network security module 304 and the security service 306 and the secure communication between the computer 302 and the network security module. The information decoded by the encoder / decoder module 1020 is provided to the security execution module 1008 to execute the current security information.
According to an embodiment, the secure communication between the computer 302 and the network security module 304 is transmitted via the auxiliary computer connection 1018. However, the invention should not be interpreted as necessarily including an auxiliary computer connection 1018. In another embodiment, the network security module 304 uses only the main computer connection 1014 to contact the computer 302.
Although the individual components of the network security module 304 have been described above, it should be understood that the above-mentioned components are only logic components, and during implementation, they may be combined together or combined with other components not described here. Therefore, the above-mentioned elements are merely examples, and should not be interpreted as limiting conditions of the present invention.
Although the above network security modules can protect the computer from being damaged by many computer attack programs / attacks, either alone or in conjunction with anti-virus software, in some cases, some attack programs may be able to Bypass network security modules and / or anti-virus software. In certain cases, one of the techniques used by malicious people to attack computing devices is to use secure communications between the origin of the infected computer / attack program and the computing device targeted by the attack to isolate the attack program from detection . Figure 11 is a block diagram illustrating how a computer attack program can be transmitted to a computing device using secure communications.
Referring to FIG. 11, in an example of how to use a secure communication to transmit a computer attack program to a computing device, it is assumed that a malicious person on the computer 102 has an attack program. In order to infect another computer, such as computer 1104, the malicious person may send the attack program 112 to others with appropriate resources / content, but transmit it through secure communication. As is known to those skilled in the art, secure communications are usually encrypted by public or private cryptographic keys so that the owner of the decryption key (private key) can decrypt and view the content of the secure communications. Examples of secure communication protocols include the SSL protocol and the Transport Layer Security (TLS) protocol.
Continuing the description of this example: an unaware user will be deceived via the computing device 1104 to believe that the attack program 112 is indeed qualified content, and request the attack program from the computer 102. The computer 102 and the computing device 1104 negotiate and exchange cryptographic keys used to encrypt and decrypt the attack program 112. Subsequently, as shown by arrow 1108, the transmission encoder 1106 encodes the attack program for transmission, and securely transmits the encrypted attack program to the computing device 1104 via the network 110. Since the attack program 122 is transmitted in an encrypted state, it is likely to pass the network security module 304 (not shown in the figure) and any anti-virus software. After reaching the computing device 1104, the transmission decoder module 1110 decodes / decrypts the secure communication and provides it to the browser display module 1112. Those skilled in the art will understand that the transmission decoder module 1110 is often a part of the browser display module 1112 as a whole. After displaying the attack program, the browser display module 1112 will enable the attack program 112 to infect the computing device 1104.
According to the technical aspect of the present invention, the network security module 304 can be used to protect a computing device from being damaged by a computer attack program transmitted through secure communication. Referring again to FIG. 10, the network security module 304 will connect to the 1018 via the auxiliary computer to obtain the cryptographic key required for decrypting the secure communication from the computing device. Once the cryptographic key is obtained, the encoder / decoder module 1020 temporarily decodes the secure communication for processing. If the secure communication is found to violate the security measures performed by the network security module 304, or if the secure communication is found to be an attack program, the secure communication is not allowed to reach the computing device 1104. However, if the secure communication does not violate the implemented security measures and is not an attack program, the secure communication will be allowed to be sent to the computing device 1104. Regarding the above technical characteristics, the following will be explained in further detail.
According to the technical aspect of the present invention, the auxiliary computer connection 1018 (FIG. 10) may be one of various communication channels leading to the computing device 1104. For example, the auxiliary computer connection 1018 may be a Universal Serial Bus (USB) connection, an IEEE 1394 connection, or a standardized serial or parallel data connection. As mentioned above, one of the purposes of the auxiliary computer connection 1018 is to provide a communication channel through which the network security module 304 can obtain a decryption key from the transmission decoder 1110 in order to temporarily decrypt the secure communication. Therefore, in another embodiment, the auxiliary computer connection 1018 may also be a computer connection 1014 through which a network device performs network activities between the computing device and the network 110. According to this embodiment, the difference between the computer connection 1014 and the auxiliary computer connection 1018 is a logical difference, not a physical difference.
FIG. 12 is a block diagram of an exemplary environment 1200, which illustrates how the network security module 304 can protect a computing device 1104 from a computer attack program 112 transmitted to the computing device via secure communication according to the technical aspect of the present invention. Attack. As shown by arrow 1108, as in the embodiment shown in FIG. 11, the malicious person on the computer 102 attempts to transmit the computer attack program to the computing device via secure communication. However, the network security module 304 between the network 110 and the computing device 1104 first obtains secure communication. The network security module 304 checks the incoming network activity to determine whether any communication is secure and as part of implementing security measures regarding the current security level, or simply an ongoing security alert.
As shown by arrow 1202, after detecting the secure communication, the network security module 304 will connect to the 1018 through the auxiliary computer and request the transmission decoder module 1110 on the computing device 1102 to obtain a decryption key. The network security module 304 uses this decryption key to temporarily decrypt the secure communication, and processes the decrypted communication data according to any security measures performed by the network security module. According to other technical aspects of the present invention, the network security module 304 can also cooperate with the operation of the antivirus software to transmit the temporarily decrypted communication data to the antivirus software for its evaluation of attack programs / viruses.
As shown by arrow 1204, when security communication is detected as a network activity prohibited by the implemented security measures, or after antivirus software detects that the security communication is an attack program, the network security module 304 will prohibit the security The communication / attack program reached the computing device 1104. In this manner, the computing device 1104 can be protected even if communication is transmitted through a secure communication channel. In another way, if the secure communication does not violate any of the implemented security measures and is not an attack program, the secure communication is forwarded to the computing device 1104.
In the above description of Figs. 11 and 12, although the transmission decoder 1110 is a separate module from the browser display module 1112, it is only an example. Those skilled in the art will understand that the transmission decoder 1110 is often an integrated component of the browser display module 1112 on the computing device.
13A and 13B show block diagrams of a subroutine example 1300, which is based on the technical aspect of the present invention to detect and process secure communications. It should be noted here that although the exemplary subroutine 1300 can be executed on the network security module 304, it can also be executed separately and executed by a software module that cooperates with the browser display module 1112 to protect The computing device 1104 is protected from damage by the attack program 112.
Beginning at block 1302 (FIG. 13A), an exemplary subroutine 1300 monitors network activity-especially incoming network activity. When incoming network activity is detected, a decision block 1304 determines whether the network activity is a secure communication to a protected computing device. If the network activity is not a secure communication to a protected computing device, then at block 1306, the network activity is forwarded to the protected computing device. The process then returns to block 1302 for other network activity monitoring. Although not shown in the figure, other processes may still occur in unsafe network activities. For example, if the exemplary subroutine 1300 is executed on a network security module, such as the network security module 304, there may be other processes, such as determining whether the network activity violates the execution of the network security module Any kind of security measures. This is how we deal with unsafe network activity.
If the network activity is a secure communication, at block 1308, the decryption key needed to decrypt the secure communication is obtained. At block 1310, the obtained decryption key is used to temporarily decrypt the secure communication. Next, at decision block 1312 (FIG. 13B), it is determined whether the decrypted communication is prohibited by the security measures implemented by the network security module 304. If the communication representative is forbidden network activity, then at block 1314, the secure communication is blocked, that is, it is not forwarded to the computing device. Subroutine 1300 then returns to block 1302 (Figure 13A) and continues to monitor network activity.
If the decrypted communication is not prohibited by the implemented security measures, then at decision block 1316, it is additionally determined whether the decrypted communication is an attack program. As described above, the network security module 304 can cooperate with external anti-virus software. In this environment, the network security module 304 sends the temporarily decrypted communication to the anti-virus software for checking whether it is an attack program or has been infected by the attack program. If the decrypted communication is judged to be an attack program, at block 14314, the secure communication is blocked, and the subroutine 1300 returns to block 14302 (Figure 13A) and continues to monitor network activity. In another method, if the decrypted communication is determined not to be an attack program, then at block 1318, the secure communication is forwarded to the computing device. Subroutine 1300 then returns to block 1302 (Figure 13A) and continues to monitor network activity.
Although various embodiments including the preferred embodiment of the present invention have been explained in detail and exemplified above, it should be understood that there are various changes without departing from the principle and scope of the present invention.
<p>100. . .Network environment</p><p>102-108. . .computer</p><p>110. . .Communication network</p><p>112. . .Computer attack program</p><p>200. . .timeline</p><p>220. . .timeline</p><p>300. . .Network environment</p><p>302. . .computer</p><p>304. . .Network Security Module</p><p>306. . .Security services</p><p>308. . .Anti-virus software service</p><p>310. . .Network environment</p><p>312. . .Receiving device</p><p>314. . .Auxiliary communication link</p><p>400. . .timeline</p><p>420. . .timeline</p><p>902. . .Connect</p><p>904. . .Connect</p><p>908. . .Backup connection</p><p>910-916. . .Status indicator</p><p>1002. . .Memory</p><p>1004. . .Safety status indicator module</p><p>1006. . .Match module</p><p>1008. . .Safe execution module</p><p>1010. . .Update Request Module</p><p>1012. . .Internet connection</p><p>1014. . .Computer connection</p><p>1016. . .System bus</p><p>1018. . .Backup computer connection</p><p>1020. . .Encoder / decoder module</p><p>1104. . .Computing device</p><p>1106. . .Transmission encoder</p><p>1110. . .Transmission decoder module</p><p>1112. . .Browser display module</p><p>1200. . .surroundings</p>
Figure 1 is a schematic diagram of a known network environment, in which computer attack programs are usually distributed on the network shown.
Figures 2A and 2B are block diagrams of the timeline, which respectively show different VUL window periods of the computer system relative to computer attack programs scattered on the network.
3A and 3B are schematic diagrams of a networked environment, and the environment shown is suitable for implementing various technical aspects of the present invention.
FIG. 4A and FIG. 4B are schematic diagrams of a timeline, which illustrate how the present invention reduces the VUL empty window period related to a computer attack program.
FIG. 5 is a flowchart of an example of a subroutine according to the present invention. The subroutine controls network access of a computer system according to released security information.
FIG. 6 is a flowchart illustrating an example of a subroutine implemented by a security service according to the present invention. The subroutine can publish security information required by a network security module in an exemplary networked environment.
Figure 7 is a flowchart showing an example of a subroutine implemented by a security service. The subroutine can receive and respond to requests for security information from a network security module.
FIG. 8 is a flowchart of a method implemented by the network security module, which can control the network communication between the computer and the network according to the security measures taken from the security service.
Figure 9 is a schematic diagram showing an example of a network security module implemented with a computer external hardware device.
FIG. 10 is a block diagram of a logic unit of a network security module constructed according to the present invention.
Figure 11 is a block diagram illustrating how a computer attack program can be transmitted to a computing device using secure communications.
FIG. 12 is a block diagram illustrating how a network security module can protect a computing device from being attacked by a computer attack program transmitted to the computing device using secure communication.
13A and 13B show block diagrams of examples of subroutines that detect and process secure communications according to the technical aspects of the present invention.
36 members in 9 offices
Priority claims8
| Document | Office | Kind | Date |
|---|---|---|---|
| 54477204 | United States of America | P | |
| 60544772 | United States of America | – | |
| 10879837 | United States of America | – | |
| 87983704 | United States of America | A | |
| 20040544772P | – | – | – |
| 20040879837 | – | – | – |
| US20040544772P | – | – | – |
| US20040879837 | – | – | – |
Members36
| Document | Office | Kind | |
|---|---|---|---|
| EP1564623A1 | European Patent Office (EPO) | A1 | |
| EP1564963A1 | European Patent Office (EPO) | A1 | |
| EP1564964A2 | European Patent Office (EPO) | A2 | |
| US2005182949A1 | United States of America | A1 | |
| US2005182967A1 | United States of America | A1 | |
| US2005183138A1 | United States of America | A1 | |
| CN1658577A | China | A | |
| JP2005229626A | Japan | A | |
| CN1661970A | China | A | |
| TW200529002AThis record | Taiwan Province of China | A | |
| TW200529622A | Taiwan Province of China | A | |
| CN1665201A | China | A | |
| JP2005251189A | Japan | A | |
| JP2005285097A | Japan | A | |
| TW200536327A | Taiwan Province of China | A | |
| US2006064754A1 | United States of America | A1 | |
| KR20060041865A | Republic of Korea | A | |
| KR20060041880A | Republic of Korea | A | |
| WO2007032967A1 | World Intellectual Property Organization (WIPO) | A1 | |
| KR20070070287A | Republic of Korea | A | |
| EP1564963B1 | European Patent Office (EPO) | B1 | |
| AT374494T | Austria | T | |
| DE602005002572D1 | Germany | D1 | |
| DE602005002572T2 | Germany | T2 | |
| CN100484020C | China | C | |
| US7603716B2 | United States of America | B2 | |
| US7716726B2 | United States of America | B2 | |
| US7814543B2 | United States of America | B2 | |
| CN1661970B | China | B | |
| JP4741255B2 | Japan | B2 | |
| CN102158489A | China | A | |
| KR101130385B1 | Republic of Korea | B1 | |
| KR101130394B1 | Republic of Korea | B1 | |
| TWI369116B | Taiwan Province of China | B | |
| CN102158489B | China | B | |
| TWI402691B | Taiwan Province of China | B |
1 legal event, as the office reported them to INPADOC
Events
| Event | Code | |
|---|---|---|
| Annulment or lapse of patent due to non-payment of feesLapsedMM4A | MM4A |
Numbers
- Publication
- 200529002
- Publication, DOCDB
- 200529002
- Publication, EPODOC
- TW200529002
- Application
- 94102532
- Application, DOCDB
- 94102532
- Application, EPODOC
- TW200594102532
Titles2
- Chinese
- ???????????????????????????????
- English
- SYSTEM AND METHOD FOR PROTECTING A COMPUTING DEVICE FROM COMPUTER EXPLOITS DELIVERED OVER A NETWORKED ENVIRONMENT IN A SECURED COMMUNICATION
Classification
- CPC, 6
- H04L63/0263
- H04L63/0428
- H04L63/1408
- H04L63/166
- H05B41/26
- Y02B20/40
- IPC, 4
- H04L9 10
- H04L12 66
- H04L29 06
- G06F15 163