US2006075472A1PendingUtilityA1

System and method for enhanced network client security

Individually held — no corporate assignee on recordPriority: Jun 28, 2004Filed: Jun 27, 2005Published: Apr 6, 2006
Est. expiryJun 28, 2024(expired)· nominal 20-yr term from priority
H04L 63/145H04L 63/08H04W 48/18H04L 67/04G06F 21/6227H04L 63/166H04L 63/0272H04L 41/509H04L 67/14H04L 41/5067H04L 63/0263H04L 41/0213H04L 41/5009H04L 41/5016H04L 9/3273H04L 43/045H04L 2209/805H04L 47/24H04L 2209/60G06F 21/316H04L 47/22H04L 41/0681H04L 2209/56H04L 67/30H04L 69/329H04L 47/11H04L 63/102H04L 63/162H04L 63/0823H04L 9/321H04L 63/0869H04L 63/0227H04L 63/20H04L 63/1408H04L 43/0817H04L 67/02H04L 67/61H04W 12/088
39
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Systems are methods for enhanced network client security are described. One aspect of one embodiment of the present invention includes receiving a security-related policy associated with a user, determining a security model associated with the security-related policy, and applying the security model to a network connection on a client device. One aspect of another embodiment of the present invention includes receiving a first measure associated with a usage characteristic, the usage characteristic associated with a user, receiving a second measure associated with the usage characteristic, comparing the first measure and second measure, and determining the likelihood that an unauthorized access has occurred based at least in part on the comparison.

Claims

exact text as granted — not AI-modified
1 . A method comprising: 
 receiving a security-related policy associated with a user;    determining a security model associated with the security-related policy; and    applying the security model to a network connection on a client device.    
   
   
       2 . The method of  claim 1 , wherein the security model comprises at least one rule.  
   
   
       3 . The method of  claim 2 , wherein the rule comprises a rule selected from the group consisting of a firewall rule, an antivirus rule, and a virtual private network rule.  
   
   
       4 . The method of  claim 1 , wherein the security policy is associated with a connection type.  
   
   
       5 . The method of  claim 4 , wherein the connection type comprises a connection type selected from the group consisting of Wifi, local area network, wide area network, wireless wide area network, personal handy network, dial-up, and satellite.  
   
   
       6 . The method of  claim 1 , wherein the security policy comprises a secure zone and a non-secure zone.  
   
   
       7 . The method of  claim 1 , wherein the user is associated with a user group.  
   
   
       8 . The method of  claim 1 , wherein receiving the security policy comprises receiving the security policy from a policy server.  
   
   
       9 . The method of  claim 8 , further comprising: 
 creating a security policy; and    associating the security policy with the user.    
   
   
       10 . A method comprising: 
 receiving a first measure associated with a usage characteristic, the usage characteristic associated with a user;    receiving a second measure associated with the usage characteristic;    comparing the first measure and second measure; and    determining the likelihood that an unauthorized access has occurred based at least in part on the comparison.    
   
   
       11 . The method of  claim 10 , wherein the usage characteristic comprises at least one usage characteristic selected from the group consisting of a uniform resource locator visited, an application launched, an number of systems calls per specified duration, a keystroke sequence, a system call, a processor utilization measure, and a memory utilization measure.  
   
   
       12 . The method of  claim 10 , wherein the usage characteristic comprises at least one usage characteristic selected from the group consisting of a traffic level associated with a connection, a protocol used, and a port hit.  
   
   
       13 . The method of  claim 10 , wherein comparing the first measure and second measure comprises performing a statistical linear regression.  
   
   
       14 . A computer-readable medium on which is encoded program code, the program code comprising: 
 program code for receiving a security-related policy associated with a user;    program code for determining a security model associated with the security-related policy; and    program code for applying the security model to a network connection on a client device.    
   
   
       15 . A computer-readable medium on which is encoded program code, the program code comprising: 
 program code for receiving a first measure associated with a usage characteristic, the usage characteristic associated with a user;    program code for receiving a second measure associated with the usage characteristic;    program code for comparing the first measure and second measure; and    program code for determining the likelihood that an unauthorized access has occurred based at least in part on the comparison.    
   
   
       16 . A system comprising: 
 a policy reader operable to determine a policy associated with a user; and    a client security module operable to: 
 receive a security-related policy associated with a user;  
 determine a security model associated with the security-related policy; and  
 apply the security model to a network connection on a client device.  
   
   
   
       17 . A system comprising: 
 a policy reader operable to determine a policy associated with a user; and    a unauthorized access detector operable to: 
 receive a first measure associated with a usage characteristic, the usage characteristic associated with a user;  
 receive a second measure associated with the usage characteristic;  
 compare the first measure and second measure; and  
 determine the likelihood that an unauthorized access has occurred based at least in part on the comparison.

Join the waitlist — get patent alerts

Track US2006075472A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.