TW200529002A

System and method for protecting a computing device from computer exploits delivered over a networked environment in a secured communication

Abstract

A network security module for protecting computing devices connected to a communication network from identified security threats communicated in a secured communication is presented. The network security module is interposed, either logically or physically, between the protected computer and the communication network. Upon detecting a secured communication, the network security module obtains a decryption key from the computing device to decrypt the secured communication. The network security module then processes the decrypted communication according to whether the decrypted communication violates protective security measures implemented by the network security module.

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

19 claims: 19 independent, 0 dependent

  1. 1
    A network security module is located between a computing device and a network, so that all network activities between the computing device and the network will pass through the network security module to protect the computing The device is protected from security threats detected on the network. The network security module includes at least:a computing device connection, which is used to connect the network security module to the computing device;a network Connection, which is used to connect the network security module to the network;a decoder module, which uses a obtained decryption key to temporarily decrypt a secure communication;and a security execution module, It controls the network activities between the computing device and the network by implementing the obtained security measures in order to protect the computing device from security threats detected on the network. 一種網路安全模組,其係介於一計算裝置與一網路之間,使該計算裝置與該網路之間的所有網路活動均會通過該網路安全模組,藉以保護該計算裝置免於受到該網路上所偵測到的安全威脅,該網路安全模組至少包含:一計算裝置連線,其係用於將該網路安全模組連接到該計算裝置;一網路連線,其係用於將該網路安全模組連接到該網路;一解碼器模組,其係利用一取得的解密金鑰,暫時將一安全通訊解密;以及一安全執行模組,其係藉由執行取得的安全措施來控制該計算裝置與該網路之間的網路活動,以便保護該計算裝置免於受到該網路上所偵測到的安全威脅。 200529002 拾、申請專利範圍: 1 . 一種網路安全模組,其係介於一計算裝置與一網 間,使該計算裝置與該網路之間的所有網路活動均會 該網路安全模組,藉以保護該計算裝置免於受到該網 所偵測到的安全威脅,該網路安全模組至少包含: 一計算裝置連線,其係用於將該網路安全模組連接 計算裝置; 一網路連線,其係用於將該網路安全模組連接到 路; 一解碼器模組,其係利用一取得的解密金鑰,暫時 安全通訊解密;以及 一安全執行模組,其係藉由執行取得的安全措施來 該計算裝置與該網路之間的網路活動,以便保護該計 置免於受到該網路上所偵測到的安全威脅。 2.如申請專利範圍第1項所述之網路安全模組,其中 之安全執行模組係藉由取得該暫時解密的安全通訊, 據該取得的安全措施來評估該暫時解密的安全通訊, 制該計算裝置與該網路之間的網路活動。 3 .如申請專利範圍第1項所述之網路安全模組,其中 之解碼器模組取得該解密金鑰,並將來自於該計算裝 的解碼模組的安全通訊暫時解密。 路之 通過 路上 到該 該網 將一 控制 算裝 上述 並根 以控 上述 置上 46 200529002 4 ·如申請專利範圍第3項所述之網路安全 含一輔助通訊連線,其係用於將該網路安 計算裝置,且其中該解碼器模組透過該輔 得該解密金鑰,並將來自於該計算裝置上 全通訊暫時解密。 5 ·如申請專利範圍第1項所述之網路安全 之安全通訊係依據安全套接字層(Secure SSL)協定以加密之。 6.如申請專利範圍第1項所述之網路安全 之安全通訊係依據傳輸層安全(Transp()i t 協定以加密之。 '•一槿保護一計算裝置免於受到網路 脅的方法,該方法係由介於該計算裝 路安全模組所執行,使該計算裝置與 路活動均會通過該網路安全模組,該 取柃保4安全措施,用於保護該計 到所偵測到之安全威脅; 偵測送往該計算裝置的安全通訊; 將該安全通訊暫時解密;以及 模組,其中更包 全模組連接到該 助通訊連線而取 的解碼模組的安 模組,其中上述 Sockets Layer, 模組,其中上述 Layer Security) 偵測到之安全威 該網路之間的網 路之間的所有網 至少包含: .置,使其免於受 47 200529002 針對該暫時被解密的安全通訊進行該保護安全措施 8.如申請專利範圍第7項所述之方法,其中更包含從 算裝置取得用於將該安全通訊解密的解密金鑰。 9 ·如申請專利範圍第8項所述之方法,其中上述之解 鑰係經由該網路安全模組與該計算裝置之間的一輔助 連接而從該計算裝置取得。 1 0 ·如申請專利範圍第9項所述之方法,其中上述之解 鑰係從該計算裝置上的解碼模組取得。 11.如申請專利範圍第9項所述之方法,其中上述之安 訊係根據安全套接字層協定以加密之。 1 2.如申請專利範圍第9項所述之方法,其中上述之安 訊係根據傳輸層安全協定以加密之。 13.如申請專利範圍第7項所述之方法,其中更包含從 算裝置取得關於該計算裝置的組態資訊,且其中取得 安全措施,其用於保護該計算裝置,使其免於受到所 到之安全威脅的步驟包含取得保護安全措施,並根據 該計算裝置的組態資訊來保護該計算裝置。 該計 密金 通訊 密金 全通 全通 該計 保護 偵測 關於 48 200529002 1 4. 一種網路安全模組,其係介於網路裝置與網路之間,使 該網路裝置與該網路之間的所有網路活動均會通過該網路 安全模組,藉以保護該網路裝置免於受到該網路上所偵測 到的安全威脅,該網路安全模組至少包含: 一網路裝置連線,其係用於將該網路安全模組連接到該 網路裝置; 一網路連線,其係用於將該網路安全模組連接到該網 路; 一解碼器裝置,其係利用取得的解密金鑰,暫時將一安 全通訊解密;以及 一安全執行裝置,其係藉由執行取得的安全措施來控制 該網路裝置與該網路之間的網路活動,以便保護該網路裝 置免於受到該網路上所偵測到的安全威脅。 1 5 .如申請專利範圍第1 4項所述之網路安全模組,其中上 述之安全執行裝置係從該解碼器裝置取得該暫時解密的安 全通訊,並根據該取得的安全措施來評估該暫時解密的安 全通訊,以控制該網路裝置與該網路之間的網路活動。 1 6 .如申請專利範圍第1 4項所述之網路安全模組,其中上 述之解碼器裝置取得該解密金鑰,並將來自於該網路裝置 上的解碼模組的安全通訊暫時解密。 49 200529002 1 7.如申請專利範圍第1 6項所述之網路安全模組,其 包含一輔助通訊連線,其係用於將該網路安全模組連 該網路裝置,且其中該解碼器裝置透過該辅助通訊連 取得該解密金鑰,並將來自於該網路裝置上的解碼模 安全通訊暫時解密。 1 8 .如申請專利範圍第1 4項所述之網路安全模組,其 述之安全通訊係根據安全套接字層協定以加密之。 19.如申請專利範圍第14項所述之網路安全模組,其 述之安全通訊係根據傳輸層安全協定以加密之。 中更 接到 線而 組的 中上 中上 50
  2. 2
    The network security module according to item 1 of the scope of patent application, wherein the security execution module mentioned above obtains the temporarily decrypted secure communication and evaluates the temporarily decrypted secure communication according to the obtained security measures To control network activity between the computing device and the network. 如申請專利範圍第1項所述之網路安全模組,其中上述之安全執行模組係藉由取得該暫時解密的安全通訊,並根據該取得的安全措施來評估該暫時解密的安全通訊,以控制該計算裝置與該網路之間的網路活動。
  3. 3
    The network security module according to item 1 of the scope of patent application, wherein the above-mentioned decoder module obtains the decryption key and temporarily decrypts the secure communication from the decoding module on the computing device. 如申請專利範圍第1項所述之網路安全模組,其中上述之解碼器模組取得該解密金鑰,並將來自於該計算裝置上的解碼模組的安全通訊暫時解密。
  4. 4
    The network security module described in item 3 of the patent application scope further includes an auxiliary communication connection, which is used to connect the network security module to the computing device, and wherein the decoder module passes through The auxiliary communication connects to obtain the decryption key, and temporarily decrypts the secure communication from the decoding module on the computing device. 如申請專利範圍第3項所述之網路安全模組,其中更包含一輔助通訊連線,其係用於將該網路安全模組連接到該計算裝置,且其中該解碼器模組透過該輔助通訊連線而取得該解密金鑰,並將來自於該計算裝置上的解碼模組的安全通訊暫時解密。
  5. 5
    The network security module described in item 1 of the scope of patent application, wherein the above-mentioned secure communication is encrypted according to the Secure Sockets Layer (SSL) protocol. 如申請專利範圍第1項所述之網路安全模組,其中上述之安全通訊係依據安全套接字層(Secure Sockets Layer,SSL)協定以加密之。
  6. 6
    The network security module described in item 1 of the scope of patent application, wherein the above-mentioned secure communication is encrypted according to the Transport Layer Security protocol. 如申請專利範圍第1項所述之網路安全模組,其中上述之安全通訊係依據傳輸層安全(Transport Layer Security)協定以加密之。
  7. 7
    A method for protecting a computing device from a security threat detected on a network, the method is executed by a network security module between the computing device and the network, so that the computing device and the network All network activities between roads pass through the network security module. The method at least includes:obtaining protective security measures to protect the computing device from the detected security threats;detection Secure communications sent to the computing device;temporarily decrypting the secure communications;and implementing the protection security measures for the temporarily decrypted secure communications. 一種保護一計算裝置免於受到網路上所偵測到之安全威脅的方法,該方法係由介於該計算裝置與該網路之間的網路安全模組所執行,使該計算裝置與該網路之間的所有網路活動均會通過該網路安全模組,該方法至少包含:取得保護安全措施,用於保護該計算裝置,使其免於受到所偵測到之安全威脅;偵測送往該計算裝置的安全通訊;將該安全通訊暫時解密;以及針對該暫時被解密的安全通訊進行該保護安全措施。
  8. 8
    The method according to item 7 of the scope of patent application, further comprising obtaining a decryption key from the computing device for decrypting the secure communication. 如申請專利範圍第7項所述之方法,其中更包含從該計算裝置取得用於將該安全通訊解密的解密金鑰。
  9. 9
    The method according to item 8 of the scope of patent application, wherein the decryption key is obtained from the computing device via an auxiliary communication connection between the network security module and the computing device. 如申請專利範圍第8項所述之方法,其中上述之解密金鑰係經由該網路安全模組與該計算裝置之間的一輔助通訊連接而從該計算裝置取得。
  10. 10
    The method according to item 9 of the scope of patent application, wherein the decryption key is obtained from a decoding module on the computing device. 如申請專利範圍第9項所述之方法,其中上述之解密金鑰係從該計算裝置上的解碼模組取得。
  11. 11
    The method according to item 9 of the scope of patent application, wherein the above-mentioned secure communication is encrypted according to a secure socket layer protocol. 如申請專利範圍第9項所述之方法,其中上述之安全通訊係根據安全套接字層協定以加密之。
  12. 12
    The method according to item 9 of the scope of patent application, wherein the above-mentioned secure communication is encrypted according to a transport layer security protocol. 如申請專利範圍第9項所述之方法,其中上述之安全通訊係根據傳輸層安全協定以加密之。
  13. 13
    The method described in item 7 of the scope of patent application, which further includes obtaining configuration information about the computing device from the computing device, and obtaining protective security measures for protecting the computing device from being subject to The steps of detecting a security threat include obtaining protective security measures and protecting the computing device based on configuration information about the computing device. 如申請專利範圍第7項所述之方法,其中更包含從該計算裝置取得關於該計算裝置的組態資訊,且其中取得保護安全措施,其用於保護該計算裝置,使其免於受到所偵測到之安全威脅的步驟包含取得保護安全措施,並根據關於該計算裝置的組態資訊來保護該計算裝置。
  14. 14
    A network security module is located between a network device and a network, so that all network activities between the network device and the network will pass through the network security module, thereby protecting the network The road device is protected from security threats detected on the network. The network security module includes at least:a network device connection, which is used to connect the network security module to the network device;A network connection for connecting the network security module to the network;a decoder device for temporarily decrypting a secure communication using the obtained decryption key;and a security execution device, It controls the network activity between the network device and the network by implementing the obtained security measures in order to protect the network device from security threats detected on the network. 一種網路安全模組,其係介於網路裝置與網路之間,使該網路裝置與該網路之間的所有網路活動均會通過該網路安全模組,藉以保護該網路裝置免於受到該網路上所偵測到的安全威脅,該網路安全模組至少包含:一網路裝置連線,其係用於將該網路安全模組連接到該網路裝置;一網路連線,其係用於將該網路安全模組連接到該網路;一解碼器裝置,其係利用取得的解密金鑰,暫時將一安全通訊解密;以及一安全執行裝置,其係藉由執行取得的安全措施來控制該網路裝置與該網路之間的網路活動,以便保護該網路裝置免於受到該網路上所偵測到的安全威脅。
  15. 15
    The network security module according to item 14 of the scope of patent application, wherein the security execution device obtains the temporarily decrypted secure communication from the decoder device, and evaluates the temporarily decrypted security according to the obtained security measures. Communication to control network activity between the network device and the network. 如申請專利範圍第14項所述之網路安全模組,其中上述之安全執行裝置係從該解碼器裝置取得該暫時解密的安全通訊,並根據該取得的安全措施來評估該暫時解密的安全通訊,以控制該網路裝置與該網路之間的網路活動。
  16. 16
    The network security module according to item 14 of the scope of patent application, wherein the above-mentioned decoder device obtains the decryption key and temporarily decrypts the secure communication from the decoding module on the network device. 如申請專利範圍第14項所述之網路安全模組,其中上述之解碼器裝置取得該解密金鑰,並將來自於該網路裝置上的解碼模組的安全通訊暫時解密。
  17. 17
    The network security module according to item 16 of the scope of patent application, which further includes an auxiliary communication connection, which is used to connect the network security module to the network device, and wherein the decoder device passes through The auxiliary communication connection obtains the decryption key, and temporarily decrypts the secure communication from the decoding module on the network device. 如申請專利範圍第16項所述之網路安全模組,其中更包含一輔助通訊連線,其係用於將該網路安全模組連接到該網路裝置,且其中該解碼器裝置透過該輔助通訊連線而取得該解密金鑰,並將來自於該網路裝置上的解碼模組的安全通訊暫時解密。
  18. 18
    The network security module according to item 14 of the scope of patent application, wherein the above-mentioned secure communication is encrypted according to the secure socket layer protocol. 如申請專利範圍第14項所述之網路安全模組,其中上述之安全通訊係根據安全套接字層協定以加密之。
  19. 19
    The network security module according to item 14 of the scope of patent application, wherein the above-mentioned secure communication is encrypted according to the transport layer security protocol. 如申請專利範圍第14項所述之網路安全模組,其中上述之安全通訊係根據傳輸層安全協定以加密之。
Independent claims19