JP5607469B2 - 個別化メッセージ・セキュリティ・ポリシーのための方法、コンピューティング装置およびコンピュータ・プログラム - Google Patents
個別化メッセージ・セキュリティ・ポリシーのための方法、コンピューティング装置およびコンピュータ・プログラム Download PDFInfo
- Publication number
- JP5607469B2 JP5607469B2 JP2010199813A JP2010199813A JP5607469B2 JP 5607469 B2 JP5607469 B2 JP 5607469B2 JP 2010199813 A JP2010199813 A JP 2010199813A JP 2010199813 A JP2010199813 A JP 2010199813A JP 5607469 B2 JP5607469 B2 JP 5607469B2
- Authority
- JP
- Japan
- Prior art keywords
- user
- security
- organization
- activity
- security risk
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Active
Links
- 238000000034 method Methods 0.000 title claims description 32
- 238000004590 computer program Methods 0.000 title claims description 17
- 230000008520 organization Effects 0.000 claims description 34
- 230000000694 effects Effects 0.000 claims description 32
- 230000008859 change Effects 0.000 claims description 13
- 230000003993 interaction Effects 0.000 claims description 13
- 230000008569 process Effects 0.000 description 15
- 238000010586 diagram Methods 0.000 description 10
- 230000006870 function Effects 0.000 description 9
- 230000009471 action Effects 0.000 description 6
- 238000012545 processing Methods 0.000 description 5
- 230000006399 behavior Effects 0.000 description 4
- 238000004891 communication Methods 0.000 description 4
- 230000003287 optical effect Effects 0.000 description 3
- 241000700605 Viruses Species 0.000 description 2
- 230000000644 propagated effect Effects 0.000 description 2
- 230000004622 sleep time Effects 0.000 description 2
- 230000006978 adaptation Effects 0.000 description 1
- 230000008901 benefit Effects 0.000 description 1
- 230000002860 competitive effect Effects 0.000 description 1
- 230000007613 environmental effect Effects 0.000 description 1
- 239000000835 fiber Substances 0.000 description 1
- 238000012423 maintenance Methods 0.000 description 1
- 238000004519 manufacturing process Methods 0.000 description 1
- 239000013307 optical fiber Substances 0.000 description 1
- 230000001737 promoting effect Effects 0.000 description 1
- 239000004065 semiconductor Substances 0.000 description 1
- 238000012546 transfer Methods 0.000 description 1
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/10—Network architectures or network communication protocols for network security for controlling access to devices or network resources
- H04L63/102—Entity profiles
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1408—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
- H04L63/1416—Event detection, e.g. attack signature detection
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/10—Network architectures or network communication protocols for network security for controlling access to devices or network resources
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Information Transfer Between Computers (AREA)
- Information Retrieval, Db Structures And Fs Structures Therefor (AREA)
Description
101、102 サーバー
103 メール・サーバー
104ないし109 ワークステーション
110 ネットワーク
111 ネットワーク・インターフェース
112 プロセッサ
113 メモリ
114 ネットワーク・インターフェース
115 プロセッサ
116 メモリ
117ないし119 ワイヤレス装置
120ないし122 アクセス・ポイント(AP)
Claims (19)
- 個別化メッセージ・セキュリティ・ポリシーのための、サーバー上で動作可能な方法であって、
ユーザによって送信又は受信されたメッセージを前記サーバがスキャンするステップと、
前記スキャンの結果を解析して、前記ユーザーのアクティビティに関する情報を前記サーバーが受け取るステップと、
前記ユーザの前記アクティビティに基づき前記ユーザーのためのセキュリティ・リスクを、前記サーバーが決定するステップと、
前記セキュリティ・リスクに基づき前記ユーザーのためのセキュリティ・ポリシーを、前記サーバーがセットするステップと
を含む方法。 - 前記ユーザーの前記セキュリティ・リスクの変化に基づき前記ユーザーの前記セキュリティ・ポリシーを、前記サーバーが修正するステップを更に含む、請求項1に記載の方法。
- 所定のレベルを超える前記ユーザーの前記セキュリティ・リスクに基づき前記ユーザーの前記セキュリティ・ポリシーを、前記サーバーが修正するステップを更に含む、請求項1又は2に記載の方法。
- 前記サーバーが決定するステップは、前記ユーザーの前記アクティビティに関係するセキュリティ変数を用いる統合されたスコアリング・システムに基づき、前記セキュリティ・リスクを、前記サーバーが決定する請求項1乃至3のいずれかに記載の方法。
- 前記セキュリティ変数が、組織における前記ユーザーのレベル、組織におけるユーザーの役割、前記ユーザーが通信する組織、前記ユーザーのふるまいのパターン、機密のインタラクションの数、機密のインタラクションのレベル、機密のメッセージの数、セキュリティ・リスクの高い人々との関係、前記ユーザーが受け取るメールおよびメッセージの言語学的な解析、組織の装置上で生じる前記ユーザーの個人的なアクティビティの度合い、組織の時間上で生じる前記ユーザーの個人的なアクティビティの度合い、およびランダムなファクタのうちの少なくとも一つを含む、請求項4に記載の方法。
- 前記セキュリティ変数が、前記ユーザーがハッキングのターゲットになってきた頻度、前記ユーザーの組織がハッキングのターゲットになってきた頻度、および前記ユーザーが属するグループがハッキングのターゲットになってきた頻度のうちの少なくとも一つを含む、請求項4又は5に記載の方法。
- 各セキュリティ変数に相対的な重み付けを前記サーバーにより割り当てるステップを更に含む、請求項4乃至6のいずれかに記載の方法。
- ユーザによって送信又は受信されたメッセージをスキャンして、前記ユーザーのアクティビティに関する情報を受け取るように構成された入力インターフェースと、
前記ユーザーのアクティビティに基づき前記ユーザーのためのセキュリティ・リスクを決定するよう、かつセキュリティ・リスクに基づいて前記ユーザーのためのセキュリティ・ポリシーをセットするように構成されたプロセッサと
を含む、個別化メッセージ・セキュリティ・ポリシーのためのコンピューティング装置。 - 前記プロセッサは、前記ユーザーの前記アクティビティに関係するセキュリティ変数を用いる統合されたスコアリング・システムに基づいて前記セキュリティ・リスクを決定する請求項8に記載のコンピューティング装置。
- 前記ユーザーの前記セキュリティ・ポリシーの少なくとも一つをストアし、かつ少なくとも一つの他のユーザーのセキュリティ・ポリシーをストアするストレージ装置を更に含む、請求項8又は9に記載のコンピューティング装置。
- 前記コンピューティング装置が、サーバー、クライアント装置、Eメール・システム、ウェッブ会議システムおよびメッセージング・システムのうちの一つを含む、請求項8乃至10のいずれかに記載のコンピューティング装置。
- 前記プロセッサは、更に前記ユーザーの前記セキュリティ・リスクの変化および所定のレベルを超える前記ユーザーの前記セキュリティ・レベルのうちの少なくとも一つに基づき前記ユーザーのセキュリティ・ポリシーを修正する請求項8乃至11のいずれかに記載のコンピューティング装置。
- 前記プロセッサは、更に前記ユーザーの前記アクティビティに関係するセキュリティ変数を用いる統合されたスコアリング・システムに基づくセキュリティ・リスクを決定する請求項8乃至12のいずれかに記載のコンピューティング装置。
- 前記セキュリティ変数が、組織における前記ユーザーのレベル、組織におけるユーザーの役割、前記ユーザーが通信する組織、前記ユーザーのふるまいのパターン、機密のインタラクションの数、機密のインタラクションのレベル、機密のメッセージの数、セキュリティ・リスクの高い人々との関係、前記ユーザーが受け取るメールおよびメッセージの言語学的な解析、組織の装置上で生じる前記ユーザーの個人的なアクティビティの度合い、組織の時間上で生じる前記ユーザーの個人的なアクティビティの度合い、ランダムなファクタ、前記ユーザーがハッキングのターゲットになってきた頻度、前記ユーザーの組織がハッキングのターゲットになってきた頻度、および前記ユーザーの属するグループがハッキングのターゲットになってきた頻度のうちの少なくとも一つのレベルを含む、請求項13に記載のコンピューティング装置。
- 各セキュリティ変数に相対的な重みが割り当てられる請求項13又は14に記載のコンピューティング装置。
- コンピュータにより実行されることで、当該コンピュータに
ユーザによって送信又は受信されたメッセージを前記サーバがスキャンするステップと、
前記スキャンの結果を解析して、前記ユーザーのアクティビティに関する情報を受け取るステップと、
前記ユーザーの前記アクティビティに基づき前記ユーザーのためのセキュリティ・リスクを決定するステップと、
前記セキュリティ・リスクに基づき前記ユーザーのためのセキュリティ・ポリシーをセットするステップと
を実行させることのできるコンピュータ・プログラム。 - 更に前記ユーザーの前記セキュリティ・リスクの変化および所定のレベルを超える前記ユーザーの前記セキュリティ・レベルのうちの少なくとも一つに基づき前記ユーザーのセキュリティ・ポリシーを修正するステップをコンピュータに更に実行させることのできる、請求項16に記載のコンピュータ・プログラム。
- 前記セキュリティ・リスクを決定するステップは、前記ユーザーの前記アクティビティに関係するセキュリティ変数を用いる統合されたスコアリング・システムに基づき、前記セキュリティ・リスクを決定する請求項16又は17に記載のコンピュータ・プログラム。
- 前記セキュリティ変数が、組織における前記ユーザーのレベル、組織におけるユーザーの役割、前記ユーザーが通信する組織、前記ユーザーのふるまいのパターン、機密のインタラクションの数、機密のインタラクションのレベル、機密のメッセージの数、セキュリティ・リスクの高い人々との関係、前記ユーザーが受け取るメールおよびメッセージの言語学的な解析、組織の装置上で生じる前記ユーザーの個人的なアクティビティの度合い、組織の時間上で生じる前記ユーザーの個人的なアクティビティの度合い、およびランダムなファクタのうちの少なくとも一つを含む、請求項18に記載のコンピュータ・プログラム。
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US12/555,978 US9742778B2 (en) | 2009-09-09 | 2009-09-09 | Differential security policies in email systems |
| US12/555,978 | 2009-09-09 |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| JP2011060288A JP2011060288A (ja) | 2011-03-24 |
| JP5607469B2 true JP5607469B2 (ja) | 2014-10-15 |
Family
ID=43648670
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| JP2010199813A Active JP5607469B2 (ja) | 2009-09-09 | 2010-09-07 | 個別化メッセージ・セキュリティ・ポリシーのための方法、コンピューティング装置およびコンピュータ・プログラム |
Country Status (3)
| Country | Link |
|---|---|
| US (2) | US9742778B2 (ja) |
| JP (1) | JP5607469B2 (ja) |
| TW (1) | TW201112037A (ja) |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US10812491B2 (en) | 2009-09-09 | 2020-10-20 | International Business Machines Corporation | Differential security policies in email systems |
Families Citing this family (49)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN103597445A (zh) * | 2011-06-16 | 2014-02-19 | 惠普发展公司,有限责任合伙企业 | 用于策略生成的系统和方法 |
| US9361443B2 (en) | 2011-08-15 | 2016-06-07 | Bank Of America Corporation | Method and apparatus for token-based combining of authentication methods |
| US8752143B2 (en) * | 2011-08-15 | 2014-06-10 | Bank Of America Corporation | Method and apparatus for token-based reassignment of privileges |
| US8732814B2 (en) | 2011-08-15 | 2014-05-20 | Bank Of America Corporation | Method and apparatus for token-based packet prioritization |
| US8484741B1 (en) | 2012-01-27 | 2013-07-09 | Chapman Technology Group, Inc. | Software service to facilitate organizational testing of employees to determine their potential susceptibility to phishing scams |
| KR20140142745A (ko) | 2012-07-20 | 2014-12-12 | 휴렛-팩커드 디벨롭먼트 컴퍼니, 엘.피. | 네트워크 리소스의 정책 기반 스케일링 |
| CN103577987A (zh) * | 2012-07-20 | 2014-02-12 | 阿里巴巴集团控股有限公司 | 一种风险用户的识别方法和装置 |
| US9356948B2 (en) | 2013-02-08 | 2016-05-31 | PhishMe, Inc. | Collaborative phishing attack detection |
| US9253207B2 (en) | 2013-02-08 | 2016-02-02 | PhishMe, Inc. | Collaborative phishing attack detection |
| US8966637B2 (en) | 2013-02-08 | 2015-02-24 | PhishMe, Inc. | Performance benchmarking for simulated phishing attacks |
| US9398038B2 (en) | 2013-02-08 | 2016-07-19 | PhishMe, Inc. | Collaborative phishing attack detection |
| US9053326B2 (en) | 2013-02-08 | 2015-06-09 | PhishMe, Inc. | Simulated phishing attack with sequential messages |
| US9661023B1 (en) * | 2013-07-12 | 2017-05-23 | Symantec Corporation | Systems and methods for automatic endpoint protection and policy management |
| US10694029B1 (en) | 2013-11-07 | 2020-06-23 | Rightquestion, Llc | Validating automatic number identification data |
| US9935977B1 (en) * | 2013-12-09 | 2018-04-03 | Amazon Technologies, Inc. | Content delivery employing multiple security levels |
| US9262629B2 (en) | 2014-01-21 | 2016-02-16 | PhishMe, Inc. | Methods and systems for preventing malicious use of phishing simulation records |
| US9378357B2 (en) | 2014-09-05 | 2016-06-28 | International Business Machines Corporation | Timing of password change requirements based on ambient intelligence |
| US10104097B1 (en) * | 2014-12-12 | 2018-10-16 | Symantec Corporation | Systems and methods for preventing targeted malware attacks |
| US9699207B2 (en) | 2015-02-05 | 2017-07-04 | Phishline, Llc | Social engineering simulation workflow appliance |
| US9906539B2 (en) | 2015-04-10 | 2018-02-27 | PhishMe, Inc. | Suspicious message processing and incident response |
| US10360178B2 (en) * | 2016-05-12 | 2019-07-23 | International Business Machines Corporation | Process scheduling based on file system consistency level |
| US11010717B2 (en) * | 2016-06-21 | 2021-05-18 | The Prudential Insurance Company Of America | Tool for improving network security |
| JP7073348B2 (ja) * | 2016-09-19 | 2022-05-23 | エヌ・ティ・ティ リサーチ インコーポレイテッド | 脅威スコアリングシステム及び方法 |
| US10880322B1 (en) | 2016-09-26 | 2020-12-29 | Agari Data, Inc. | Automated tracking of interaction with a resource of a message |
| US11936604B2 (en) * | 2016-09-26 | 2024-03-19 | Agari Data, Inc. | Multi-level security analysis and intermediate delivery of an electronic message |
| US10805270B2 (en) | 2016-09-26 | 2020-10-13 | Agari Data, Inc. | Mitigating communication risk by verifying a sender of a message |
| US10805314B2 (en) | 2017-05-19 | 2020-10-13 | Agari Data, Inc. | Using message context to evaluate security of requested data |
| US11044267B2 (en) | 2016-11-30 | 2021-06-22 | Agari Data, Inc. | Using a measure of influence of sender in determining a security risk associated with an electronic message |
| US11722513B2 (en) | 2016-11-30 | 2023-08-08 | Agari Data, Inc. | Using a measure of influence of sender in determining a security risk associated with an electronic message |
| US11757857B2 (en) | 2017-01-23 | 2023-09-12 | Ntt Research, Inc. | Digital credential issuing system and method |
| US20180270248A1 (en) | 2017-03-14 | 2018-09-20 | International Business Machines Corporation | Secure resource access based on psychometrics |
| US12452304B2 (en) * | 2017-03-31 | 2025-10-21 | International Business Machines Corporation | Dynamically changing access rules for context-sensitive access control |
| US11019076B1 (en) | 2017-04-26 | 2021-05-25 | Agari Data, Inc. | Message security assessment using sender identity profiles |
| US11888859B2 (en) | 2017-05-15 | 2024-01-30 | Forcepoint Llc | Associating a security risk persona with a phase of a cyber kill chain |
| US10999296B2 (en) * | 2017-05-15 | 2021-05-04 | Forcepoint, LLC | Generating adaptive trust profiles using information derived from similarly situated organizations |
| US11102244B1 (en) | 2017-06-07 | 2021-08-24 | Agari Data, Inc. | Automated intelligence gathering |
| US11757914B1 (en) | 2017-06-07 | 2023-09-12 | Agari Data, Inc. | Automated responsive message to determine a security risk of a message sender |
| US10250623B1 (en) * | 2017-12-11 | 2019-04-02 | Malwarebytes, Inc. | Generating analytical data from detection events of malicious objects |
| US10990682B2 (en) * | 2017-12-18 | 2021-04-27 | Nuvoton Technology Corporation | System and method for coping with fault injection attacks |
| US12506747B1 (en) | 2019-03-29 | 2025-12-23 | Agari Data, Inc. | Message campaign and malicious threat detection |
| JP7501023B2 (ja) * | 2020-03-23 | 2024-06-18 | 富士フイルムビジネスイノベーション株式会社 | 情報処理装置 |
| US12406185B1 (en) | 2020-07-15 | 2025-09-02 | Ntt Research, Inc. | System and method for pruning neural networks at initialization using iteratively conserving synaptic flow |
| CN112231336B (zh) * | 2020-07-17 | 2023-07-25 | 北京百度网讯科技有限公司 | 识别用户的方法、装置、存储介质及电子设备 |
| US12609045B2 (en) * | 2020-10-26 | 2026-04-21 | Proofpoint, Inc. | Dynamically injecting security awareness training prompts into enterprise user flows |
| US12519806B2 (en) * | 2021-04-29 | 2026-01-06 | KnowBe4, Inc. | Systems and methods for determination of indicators of malicious elements within messages |
| KR20220158908A (ko) | 2021-05-24 | 2022-12-02 | 삼성전자주식회사 | 프라이버시에 기반한 오디오 운용 방법 및 장치 |
| US12160447B2 (en) | 2022-01-31 | 2024-12-03 | Saudi Arabian Oil Company | Method to safeguard against email phishing attacks |
| CN116305047A (zh) * | 2023-03-01 | 2023-06-23 | 华能信息技术有限公司 | 一种安全访问虚拟密码处理方法及系统 |
| US20240414188A1 (en) * | 2023-06-07 | 2024-12-12 | Bank Of America Corporation | System and method for detecting and preventing malfeasant targeting of individual users in a network |
Family Cites Families (50)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US5987149A (en) | 1992-07-08 | 1999-11-16 | Uniscore Incorporated | Method for scoring and control of scoring open-ended assessments using scorers in diverse locations |
| US5950172A (en) | 1996-06-07 | 1999-09-07 | Klingman; Edwin E. | Secured electronic rating system |
| US5958051A (en) * | 1996-11-27 | 1999-09-28 | Sun Microsystems, Inc. | Implementing digital signatures for data streams and data archives |
| US5991758A (en) | 1997-06-06 | 1999-11-23 | Madison Information Technologies, Inc. | System and method for indexing information about entities from different information sources |
| GB9925289D0 (en) * | 1999-10-27 | 1999-12-29 | Ibm | Method and means for adjusting the timing of user-activity-dependent changes of operational state of an apparatus |
| US20030065942A1 (en) * | 2001-09-28 | 2003-04-03 | Lineman David J. | Method and apparatus for actively managing security policies for users and computers in a network |
| JP2003150748A (ja) | 2001-11-09 | 2003-05-23 | Asgent Inc | リスク評価方法 |
| US7290275B2 (en) | 2002-04-29 | 2007-10-30 | Schlumberger Omnes, Inc. | Security maturity assessment method |
| AU2003276626A1 (en) * | 2002-06-18 | 2003-12-31 | Douglas Ray Duquette | System and method for analyzing and displaying security trade transactions |
| US7406715B2 (en) * | 2003-03-19 | 2008-07-29 | Intel Corp. | Controlling and remotely monitoring accessed network data |
| US7437763B2 (en) * | 2003-06-05 | 2008-10-14 | Microsoft Corporation | In-context security advisor in a computing environment |
| EP1636672A4 (en) * | 2003-06-09 | 2008-03-12 | Greenline Systems Inc | SYSTEM AND METHODS FOR RISK DETECTION, REPORTS AND INFRASTRUCTURE |
| US20090100138A1 (en) * | 2003-07-18 | 2009-04-16 | Harris Scott C | Spam filter |
| JP4778899B2 (ja) * | 2003-09-12 | 2011-09-21 | イーエムシー コーポレイション | リスクベース認証のためのシステムおよび方法 |
| US7237267B2 (en) * | 2003-10-16 | 2007-06-26 | Cisco Technology, Inc. | Policy-based network security management |
| KR100623552B1 (ko) * | 2003-12-29 | 2006-09-18 | 한국정보보호진흥원 | 자동침입대응시스템에서의 위험수준 분석 방법 |
| US8020210B2 (en) * | 2004-06-09 | 2011-09-13 | Verizon Patent And Licensing Inc. | System and method for assessing risk to a collection of information resources |
| US7490356B2 (en) * | 2004-07-20 | 2009-02-10 | Reflectent Software, Inc. | End user risk management |
| US20060075503A1 (en) * | 2004-09-13 | 2006-04-06 | Achilles Guard, Inc. Dba Critical Watch | Method and system for applying security vulnerability management process to an organization |
| US8117659B2 (en) * | 2005-12-28 | 2012-02-14 | Microsoft Corporation | Malicious code infection cause-and-effect analysis |
| US7580982B2 (en) * | 2004-12-14 | 2009-08-25 | The Go Daddy Group, Inc. | Email filtering system and method |
| US20060179484A1 (en) * | 2005-02-09 | 2006-08-10 | Scrimsher John P | Remediating effects of an undesired application |
| US7962960B2 (en) * | 2005-02-25 | 2011-06-14 | Verizon Business Global Llc | Systems and methods for performing risk analysis |
| US20060206941A1 (en) * | 2005-03-08 | 2006-09-14 | Praesidium Technologies, Ltd. | Communications system with distributed risk management |
| US8135728B2 (en) * | 2005-03-24 | 2012-03-13 | Microsoft Corporation | Web document keyword and phrase extraction |
| US7606801B2 (en) * | 2005-06-07 | 2009-10-20 | Varonis Inc. | Automatic management of storage access control |
| GB2427048A (en) * | 2005-06-09 | 2006-12-13 | Avecho Group Ltd | Detection of unwanted code or data in electronic mail |
| US8682979B2 (en) * | 2005-07-01 | 2014-03-25 | Email2 Scp Solutions Inc. | Secure electronic mail system |
| US8503624B2 (en) * | 2005-09-28 | 2013-08-06 | Cisco Technology, Inc. | Method and apparatus to process an incoming message |
| US7627893B2 (en) * | 2005-10-20 | 2009-12-01 | International Business Machines Corporation | Method and system for dynamic adjustment of computer security based on network activity of users |
| US8370183B2 (en) * | 2005-12-12 | 2013-02-05 | United Technologies Corporation | Method, program, and system for conducting trade studies and evaluation activities |
| US20070143851A1 (en) * | 2005-12-21 | 2007-06-21 | Fiberlink | Method and systems for controlling access to computing resources based on known security vulnerabilities |
| FR2902546B1 (fr) * | 2006-06-16 | 2008-12-26 | Olfeo Sarl | Procede et systeme de traitement de donnees de securite d'un reseau informatique. |
| JP5304243B2 (ja) | 2006-07-06 | 2013-10-02 | 日本電気株式会社 | セキュリティリスク管理システム、装置、方法、およびプログラム |
| JP5125069B2 (ja) | 2006-11-16 | 2013-01-23 | 日本電気株式会社 | セキュリティリスク管理システム、セキュリティリスク管理方法およびセキュリティリスク管理用プログラム |
| US8413247B2 (en) * | 2007-03-14 | 2013-04-02 | Microsoft Corporation | Adaptive data collection for root-cause analysis and intrusion detection |
| EP2156315A4 (en) * | 2007-05-14 | 2011-04-13 | Sailpoint Technologies Inc | SYSTEM AND METHOD FOR USER RISK ASSESSMENT |
| BRPI0721733A2 (pt) * | 2007-06-14 | 2013-02-13 | Thomson Licensing | mÉtodo e aparelho para definir um limite de detecÇço dada uma probabilidade falsa desejada |
| US20090164572A1 (en) * | 2007-12-20 | 2009-06-25 | Motorola, Inc. | Apparatus and method for content item annotation |
| US9130986B2 (en) * | 2008-03-19 | 2015-09-08 | Websense, Inc. | Method and system for protection against information stealing software |
| US7996374B1 (en) * | 2008-03-28 | 2011-08-09 | Symantec Corporation | Method and apparatus for automatically correlating related incidents of policy violations |
| US8370925B2 (en) * | 2008-07-29 | 2013-02-05 | International Business Machines Corporation | User policy manageable strength-based password aging |
| US20100125911A1 (en) * | 2008-11-17 | 2010-05-20 | Prakash Bhaskaran | Risk Scoring Based On Endpoint User Activities |
| US8402546B2 (en) * | 2008-11-19 | 2013-03-19 | Microsoft Corporation | Estimating and visualizing security risk in information technology systems |
| US8522350B2 (en) * | 2008-11-19 | 2013-08-27 | Dell Products, Lp | System and method for run-time attack prevention |
| US20100287597A1 (en) * | 2009-05-07 | 2010-11-11 | Microsoft Corporation | Security policy trigger for policy enforcement |
| JP5405921B2 (ja) | 2009-06-29 | 2014-02-05 | 株式会社野村総合研究所 | タスク管理システムおよびセキュリティ管理支援システム |
| US9098856B2 (en) * | 2009-08-17 | 2015-08-04 | Yahoo! Inc. | Platform for delivery of heavy content to a user |
| US9742778B2 (en) | 2009-09-09 | 2017-08-22 | International Business Machines Corporation | Differential security policies in email systems |
| US20130097660A1 (en) * | 2011-10-17 | 2013-04-18 | Mcafee, Inc. | System and method for whitelisting applications in a mobile network environment |
-
2009
- 2009-09-09 US US12/555,978 patent/US9742778B2/en active Active
-
2010
- 2010-06-10 TW TW099118929A patent/TW201112037A/zh unknown
- 2010-09-07 JP JP2010199813A patent/JP5607469B2/ja active Active
-
2017
- 2017-07-24 US US15/657,808 patent/US10812491B2/en not_active Expired - Fee Related
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US10812491B2 (en) | 2009-09-09 | 2020-10-20 | International Business Machines Corporation | Differential security policies in email systems |
Also Published As
| Publication number | Publication date |
|---|---|
| TW201112037A (en) | 2011-04-01 |
| US20170324745A1 (en) | 2017-11-09 |
| US20110061089A1 (en) | 2011-03-10 |
| US9742778B2 (en) | 2017-08-22 |
| US20180152458A9 (en) | 2018-05-31 |
| US10812491B2 (en) | 2020-10-20 |
| JP2011060288A (ja) | 2011-03-24 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| JP2011060288A (ja) | 個別化メッセージ・セキュリティ・ポリシーのための方法、コンピューティング装置およびコンピュータ・プログラム | |
| US11736480B2 (en) | Device risk level based on device metadata comparison | |
| US11151232B2 (en) | User authentication by endpoint device using local policy engine and endpoint data | |
| Koyun et al. | Social engineering attacks | |
| US11323470B2 (en) | Analyzing and addressing least-privilege security threats on a composite basis | |
| US20200014702A1 (en) | Adaptive multi-factor authentication system with multi-user permission strategy to access sensitive information | |
| US20210194913A1 (en) | Measuring and comparing security efficiency and importance in virtualized environments | |
| US10609038B2 (en) | Discovering and evaluating privileged entities in a network environment | |
| US20230229787A1 (en) | Automated zero trust security validation | |
| Basholli et al. | Framework, tools and challenges in cyber security | |
| Jackson | A systematic review of machine learning enabled phishing | |
| Onwuegbuzie et al. | A review of authentication and authorization mechanisms in zero trust architecture: Evolution and efficiency | |
| Powell et al. | Awareness of mobile device security and data privacy tools. | |
| US10681066B2 (en) | Intelligent cyber-security help network for student community | |
| Saini | Analysis of minimum and maximum character bounds of password lengths of globally ranked websites | |
| van Vuuren et al. | Identifying gaps in IT retail Information Security policy implementation processes | |
| Mehra et al. | Graph of effort: Quantifying risk of ai usage for vulnerability assessment | |
| Caron | Zero trust in an all too trusting world | |
| Keil et al. | Evaluating the evaluation criteria for account-recovery procedures in passwordless authentication | |
| Chukwu et al. | Redefining Access Control: AI-Powered Authentication in Nigeria’s Enterprise Networks | |
| Valvi et al. | Benchmarking Malware Detection Tools: A Study on Tool Efficiency and Real-Time Feedback | |
| Boyanov et al. | Implementation of credential harvester attack method in the computer network and systems | |
| Hasan et al. | Risk Catalogue for Mobile Business Applications. | |
| Imoriafe | Accessing Weak Password Vulnerabilities through Penetration Testing | |
| Mihalache | Cloud Penetration Testing |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| A621 | Written request for application examination |
Free format text: JAPANESE INTERMEDIATE CODE: A621 Effective date: 20130607 |
|
| A977 | Report on retrieval |
Free format text: JAPANESE INTERMEDIATE CODE: A971007 Effective date: 20140221 |
|
| A131 | Notification of reasons for refusal |
Free format text: JAPANESE INTERMEDIATE CODE: A131 Effective date: 20140408 |
|
| A521 | Request for written amendment filed |
Free format text: JAPANESE INTERMEDIATE CODE: A523 Effective date: 20140708 |
|
| TRDD | Decision of grant or rejection written | ||
| A01 | Written decision to grant a patent or to grant a registration (utility model) |
Free format text: JAPANESE INTERMEDIATE CODE: A01 Effective date: 20140805 |
|
| A61 | First payment of annual fees (during grant procedure) |
Free format text: JAPANESE INTERMEDIATE CODE: A61 Effective date: 20140828 |
|
| R150 | Certificate of patent or registration of utility model |
Ref document number: 5607469 Country of ref document: JP Free format text: JAPANESE INTERMEDIATE CODE: R150 |