CN115427957A - 一种移动存储设备的控制方法、装置和计算机可读介质 - Google Patents

一种移动存储设备的控制方法、装置和计算机可读介质 Download PDF

Info

Publication number
CN115427957A
CN115427957A CN202080099452.3A CN202080099452A CN115427957A CN 115427957 A CN115427957 A CN 115427957A CN 202080099452 A CN202080099452 A CN 202080099452A CN 115427957 A CN115427957 A CN 115427957A
Authority
CN
China
Prior art keywords
storage device
mobile storage
specific operation
file system
scanning
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN202080099452.3A
Other languages
English (en)
Inventor
王哲
高永吉
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Siemens AG
Original Assignee
Siemens AG
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Siemens AG filed Critical Siemens AG
Publication of CN115427957A publication Critical patent/CN115427957A/zh
Pending legal-status Critical Current

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/70Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer
    • G06F21/82Protecting input, output or interconnection devices
    • G06F21/85Protecting input, output or interconnection devices interconnection devices, e.g. bus-connected or in-line devices
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/55Detecting local intrusion or implementing counter-measures
    • G06F21/56Computer malware detection or handling, e.g. anti-virus arrangements
    • G06F21/562Static detection
    • G06F21/565Static detection by checking file integrity
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/55Detecting local intrusion or implementing counter-measures
    • G06F21/56Computer malware detection or handling, e.g. anti-virus arrangements
    • G06F21/562Static detection
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/62Protecting access to data via a platform, e.g. using keys or access control rules
    • G06F21/6218Protecting access to data via a platform, e.g. using keys or access control rules to a system of files or objects, e.g. local or distributed file system or database
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/70Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer
    • G06F21/78Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure storage of data
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/55Detecting local intrusion or implementing counter-measures
    • G06F21/56Computer malware detection or handling, e.g. anti-virus arrangements
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F2221/00Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F2221/03Indexing scheme relating to G06F21/50, monitoring users, programs or devices to maintain the integrity of platforms
    • G06F2221/034Test or assess a computer or a system

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Theoretical Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • Software Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • General Physics & Mathematics (AREA)
  • Physics & Mathematics (AREA)
  • Health & Medical Sciences (AREA)
  • General Health & Medical Sciences (AREA)
  • Virology (AREA)
  • Databases & Information Systems (AREA)
  • Bioethics (AREA)
  • Storage Device Security (AREA)
  • Debugging And Monitoring (AREA)

Abstract

涉及信息安全技术领域,尤其涉及一种移动存储设备的控制方法、装置和计算机可读介质。移动存储设备控制系统(200),包括:独立运行的扫描装置(201),被配置为扫描所述移动存储设备(20)并对其执行一个特定操作,以使其文件系统日志中记录所述特定操作;控制装置(202),被配置为:检查所述移动存储设备(20)中的文件系统日志中最后一条记录是否为所述特定操作的记录;若是,则允许用户访问所述移动存储设备(20);否则,禁止用户访问。由于文件系统日志难以被操作,因此该控制方案可靠性较高。并且,由于仅检查文件系统日志中的最后一条,执行速度快,且占用的计算资源少。

Description

PCT国内申请,说明书已公开。

Claims (12)

  1. PCT国内申请,权利要求书已公开。
CN202080099452.3A 2020-04-30 2020-04-30 一种移动存储设备的控制方法、装置和计算机可读介质 Pending CN115427957A (zh)

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CN2020/088487 WO2021217652A1 (zh) 2020-04-30 2020-04-30 一种移动存储设备的控制方法、装置和计算机可读介质

Publications (1)

Publication Number Publication Date
CN115427957A true CN115427957A (zh) 2022-12-02

Family

ID=78331673

Family Applications (1)

Application Number Title Priority Date Filing Date
CN202080099452.3A Pending CN115427957A (zh) 2020-04-30 2020-04-30 一种移动存储设备的控制方法、装置和计算机可读介质

Country Status (4)

Country Link
US (1) US11880459B2 (zh)
EP (1) EP4131044A4 (zh)
CN (1) CN115427957A (zh)
WO (1) WO2021217652A1 (zh)

Families Citing this family (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20230229764A1 (en) * 2022-01-20 2023-07-20 Pure Storage, Inc. Storage System Based Threat Detection and Remediation for Containers

Family Cites Families (12)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US8473941B2 (en) 2008-07-08 2013-06-25 Sandisk Il Ltd. Dynamic file system restriction for portable storage devices
CN101329709B (zh) * 2008-08-01 2011-11-16 北京航空航天大学 一种用于数据安全迁移的系统及方法
CN103093145B (zh) * 2013-01-18 2016-01-13 北京奇虎科技有限公司 一种扫描移动存储设备的方法、装置和系统
US10628263B1 (en) * 2013-08-02 2020-04-21 David Cowen Logfile-related technologies and techniques
CN105069382A (zh) * 2015-07-27 2015-11-18 浪潮软件集团有限公司 一种适用于普通u盘的安全应用系统
US10643007B2 (en) * 2016-06-03 2020-05-05 Honeywell International Inc. System and method for auditing file access to secure media by nodes of a protected system
US10205726B2 (en) * 2016-06-03 2019-02-12 Honeywell International Inc. Apparatus and method for preventing file access by nodes of a protected system
US10853488B2 (en) * 2017-07-10 2020-12-01 Dell Products, Lp System and method for a security filewall system for protection of an information handling system
US10990671B2 (en) * 2018-01-12 2021-04-27 Honeywell International Inc. System and method for implementing secure media exchange on a single board computer
DE102018213616A1 (de) 2018-06-20 2019-12-24 Robert Bosch Gmbh Kryptografiemodul und Betriebsverfahren hierfür
CN109033313B (zh) * 2018-07-17 2020-09-25 北京明朝万达科技股份有限公司 一种应用usn实现全盘扫描功能的方法和终端设备
CN110598428B (zh) * 2019-08-22 2021-08-06 中国电子科技集团公司第二十八研究所 一种基于Linux用户空间的USB设备管控系统

Also Published As

Publication number Publication date
EP4131044A4 (en) 2023-12-20
US11880459B2 (en) 2024-01-23
US20230131910A1 (en) 2023-04-27
EP4131044A1 (en) 2023-02-08
WO2021217652A1 (zh) 2021-11-04

Similar Documents

Publication Publication Date Title
US8990923B1 (en) Protection against unauthorized access to automated system for control of technological processes
RU2680736C1 (ru) Сервер и способ для определения вредоносных файлов в сетевом трафике
CN109196511B (zh) 用于锁定和解锁可移除介质以供在受保护系统内部和外部使用的装置和方法
CN110826067B (zh) 一种病毒检测方法、装置、电子设备及存储介质
CN109196509B (zh) 用于防止由受保护系统的节点进行的文件访问的装置和方法
CN107347057B (zh) 入侵检测方法、检测规则生成方法、装置及系统
CN114760103B (zh) 一种工业控制系统异常检测系统、方法、设备及存储介质
CN109074448B (zh) 计算装置的安全状态与额定安全状态的偏差的检测
CN102867146A (zh) 一种防止计算机病毒反复感染系统的方法及系统
Serhane et al. Programmable logic controllers based systems (PLC-BS): Vulnerabilities and threats
US20190109824A1 (en) Rule enforcement in a network
US11399036B2 (en) Systems and methods for correlating events to detect an information security incident
EP3767913A1 (en) Systems and methods for correlating events to detect an information security incident
JP2008083751A (ja) 不正アクセス対応ネットワークシステム
US11683336B2 (en) System and method for using weighting factor values of inventory rules to efficiently identify devices of a computer network
EP3964990A1 (en) Method and system for deciding on the need for an automated response to an incident
CN111756683B (zh) 逐步增加技术系统的元件的it安全性的系统和方法
CN115427957A (zh) 一种移动存储设备的控制方法、装置和计算机可读介质
US20210099479A1 (en) System and method for using inventory rules to identify devices of a computer network
JP6911723B2 (ja) ネットワーク監視装置、ネットワーク監視方法及びネットワーク監視プログラム
CN106411816B (zh) 一种工业控制系统、安全互联系统及其处理方法
JP2019022099A (ja) セキュリティポリシー情報管理システム、セキュリティポリシー情報管理方法、及びプログラム
KR20220073103A (ko) 사이버물리시스템의 고가용성 보장을 위한 악성코드 대응 방법
CN107342967B (zh) 僵尸网络检测系统及其方法
WO2017099062A1 (ja) 診断装置、診断方法、及び、診断プログラムが記録された記録媒体

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination