Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

84results about "Data taking prevention" patented technology

In-vehicle device, program, and information processing method

This vehicle-mounted device is connected to a vehicle-mounted network mounted on a vehicle, and is provided with a processing unit that performs a process relating to a determination of whether or not data flowing through the vehicle-mounted network is normal, receives periodic data periodically transmitted through the vehicle-mounted network, and transmits the periodic data to the vehicle-mounted network. When event data of the same type as the periodic data is received between the reception time points of two pieces of continuously received periodic data, a determination is made as to whether or not the event data is normal on the basis of the value of the payload of the event data and the value of the payload of at least one of the two pieces of periodic data.
Owner:AUTONETWORKS TECH LTD +2

Communication control system, communication method and program

To provide a communication control system for easily setting a RADIUS client and provide a method.SOLUTION: A communication control system 1 contains: an access point 10 that includes a function as a RADIUS server for determining whether or not a network communication of a terminal is identified or a first RADIUS client corresponded to the RADIUS server, and stores identification information and a secret key for identifying the RADIUS server; and a layer 2(L2) switch 20 directly connected in a network segment similar to the access point. The access point 10 contains a transmission part that transmits the stored identification information and the secret key to the L2 switch in a first time period. The layer L2 switch contains: a reception part that receives the identification information and the secret key transmitted from the access point; and a setting part that performs a setting so that the L2 switch is operated as a second RADIUS client corresponded to the RADIUS server on the basis of the received identification information and the secret key.SELECTED DRAWING: Figure 1
Owner:YAMAHA CORP

Communication analysis system, analysis method, and program

A communication analysis system includes: an information obtainer (2501) that obtains past communication information indicating communication performed by a monitoring target (10); a prediction target link extractor (2502) that extracts, based on the past communication information obtained, an unestablished communication link of communication that has not been established in the past communication information, the unestablished communication link being at least one communication link that is a prediction target; a link confidence level calculator (2504) that calculates a confidence level indicating the likelihood that the unestablished communication link extracted will be established as a normal communication link in the future; and a NW graph creator (2506) that creates a NW graph, in which the unestablished communication link and information regarding the unestablished communication link are mapped, as graph information for determining whether to add the communication link to a whitelist (22), using the unestablished communication link extracted, the confidence level calculated, and the past communication information obtained.
Owner:PANASONIC INTELLECTUAL PROPERTY CORP OF AMERICA

Communication analysis system, analysis method, and recording medium

A communication analysis system includes: an information obtainer that obtains past communication information indicating communication performed by a monitoring target; a prediction target link extractor that extracts, based on the past communication information obtained, an unestablished communication link of communication that has not been established in the past communication information, the unestablished communication link being at least one communication link that is a prediction target; a link confidence level calculator that calculates a confidence level indicating the likelihood that the unestablished communication link extracted will be established as a normal communication link in the future; and a NW graph creator that creates a NW graph, in which the unestablished communication link and information regarding the unestablished communication link are mapped, as graph information for determining whether to add the communication link to a whitelist, using the unestablished communication link extracted, the confidence level calculated, and the past communication information obtained.
Owner:PANASONIC INTELLECTUAL PROPERTY CORP OF AMERICA

Vehicle communication system and vehicle communication methods

Vehicle communication system, comprehensive: an on-board device (130); and one or more vehicle controllers (120) connected to a vehicle network (NW1, NW2) wherein the on-board device (130) is configured to perform the following steps: Transmitting an encrypted message (MS), encrypted outside of a vehicle, to one or more vehicle controllers (120) connected to the vehicle network (NW1, NW2); and if the encrypted message (MS) is an individual message to one of the vehicle controllers (120), transmission of the encrypted message (MS) to one of the vehicle controllers (120) via the vehicle network (NW1, NW2); and if the encrypted message (MS) is a common message to the one or more vehicle controllers (120), decrypt the encrypted message (MS) using an encryption key (K2, K5) belonging to the on-board device (130), and then transmit the decrypted message to the one or more vehicle controllers (120) via the vehicle network (NW1, NW2).
Owner:TOYOTA JIDOSHA KK

Communication device, communication method, and program

To prevent normal data frames from being discarded when a communication device establishes a connection via multiple frequency channels.SOLUTION: In a state in which a communication device 102 and a communication device 103 have established a connection via a first frequency channel on a first link 104, it is determined whether the communication device 103 has established a connection via a second frequency channel on a second link 105, and if it is determined that the communication device 103 has established a connection via the second frequency channel, a cryptographic key common to communication via the first frequency channel and communication via the second frequency channel is set.SELECTED DRAWING: Figure 1
Owner:CANON KK

Communication device

To provide a communication device capable of determining that an unauthorized device is connected by the communication device as a single unit.SOLUTION: A communication device includes a transceiver 10 and a controller 20. The controller outputs a transmission signal including identification information as a communication signal to be transmitted through a communication wire, and receives a reception signal including the identification information as a communication signal received through the communication wire. The transceiver is connected to the communication wire, transmits the transmission signal inputted from the controller from the communication wire, and outputs the reception signal received from the communication wire to the controller. The transceiver includes a storage part 132 for storing the identification information included in the transmission signal, and a processing part 131 for determining that an unauthorized device is connected to the communication wire in the case that the same identification information as the identification information included in the reception signal is stored in the storage part.SELECTED DRAWING: Figure 2
Owner:DENSO CORP

Security policy analysis

A security policy analysis is disclosed. Configuration information containing at least one policy is received. A model is built using the received configuration information, which includes normalizing the policy. A policy analysis is performed using the policy, which includes performing a pre-change analysis associated with the proposed policy change. The results of the policy analysis are provided as output.
Owner:PALO ALTO NETWORKS INC

Information management system having firewall with transparency setting function

The information management system includes a firewall connected to a network camera (i.e., a device) having an image capturing function and a sound collecting function and a management server performing an authentication process for authenticating a user using the user terminal between the management server and the user terminal and allowing the user terminal to connect to the network camera via the firewall. The information management system is configured to acquire, via the firewall, media data including an image captured by the network camera and an audio collected by the network camera from the network camera to which the user terminal is allowed to connect based on a connection permission condition defined in the management server.
Owner:PZP CO

Unauthorized signal detection device, vehicle, and unauthorized signal detection method

To provide a fraudulent signal detection device and a fraudulent signal detection method for detecting that a fraudulent signal is input to a communication network where signals are expected to be input at a predetermined period.SOLUTION: In a vehicle, a fraudulent signal detection device (ECU 110) includes a measurement unit that measures a time interval between a plurality of consecutive signals input to a communication network in chronological order, and a determination unit that determines that a conflict has occurred when a second signal is transmitted, and determines that the second signal is a mediated normal signal if a time interval between a first signal and the second signal that should be transmitted at the time interval is longer than the time interval, and a signal interval between the second signal and a signal input immediately before is equal to or less than a predetermined interval.SELECTED DRAWING: Figure 2
Owner:HONDA MOTOR CO LTD

Information processing device, information processing method, and information processing program

The information processing apparatus (100) includes: an acquirer (121) configured to acquire a security log including information regarding unauthorized communication stored in the upper NW device being a device constituting an overlay network, an authentication log stored in the cloud server, and a communication log stored in the lower NW device being a device constituting an underlay network; a specifier (123) configured to specify information such that, when the authentication log includes a connection source IP address that does not exist in the communication log acquired by the acquirer (121) and the security log includes information regarding an access not permitted to be used from the connection source IP address, the specifier (123) specifies the information regarding the access as unauthorized communication; and a blocking instructor (124) configured to give an instruction for blocking of the unauthorized communication specified by the specifier (123).
Owner:NTT DOCOMO BUSINESS INC

Information processing device, information processing program, and information processing method

This makes it easy to analyze the settings of firewall policies. [Solution] The information processing device according to the present invention comprises: a configuration file that describes a firewall policy that controls packet transmission based on a pre-configured policy; a policy format that shows a policy description pattern; an extraction unit that identifies an authorization record from the configuration file that corresponds to a policy containing authorization information that allows the firewall to transmit packets; and extracts source information and destination information from the authorization record; and a generation unit that generates first communication pattern information relating to a communication pattern permitted between the source and the destination based on the source information and destination information.
Owner:SOFTBANK CORPORATION

Information processing system, information processing method, and information processing program

The information processing system (1) is an information processing system including: an upper NW device (100) being a device constituting an overlay network; and a lower NW device (200) being a device constituting an underlay network. In this system, the upper NW device (100) detects unauthorized communication, specifies at least one of a communication destination and a communication source of the unauthorized communication using information regarding the unauthorized communication detected, notifies the lower NW device (200) of at least one of the communication destination and the communication source of the specified unauthorized communication. The lower NW device (200) acquires information related to communication of a terminal connected to the lower NW device (200), and blocks unauthorized communication based on the information regarding the unauthorized communication notification of which is provided.
Owner:NTT DOCOMO BUSINESS INC

Automated web traffic anomaly detection

An anomaly detection system that includes a database and a server. The server is connected to the database. The server is configured to identify anomalous web traffic for a certain time period based on one or more client keys from the certain time period. The client key(s) includes at least two characteristics related to web traffic data. The server includes a processing unit and a memory. The server is configured to receive the web traffic data from the database, calculate a z-score metric for the client key, calculate a change rate metric for the client key, calculate a failure metric for the client key, determine an anomaly score based on the z-score metric, the change rate metric, and the failure metric, and determine that the certain time period is an anomalous time period based on the anomaly score.
Owner:MASTERCARD TECHNOLOGIES CANADA ULC

Method for managing a terminal connection

Terminal Connection Management Procedure The process for managing a connection from a terminal (T1) to a communication service, via at least one network (R), is implemented by a management device (DG) and comprises: - a step of receiving, from said terminal (T1), a first identifier contained in a signal of said connection, - in the absence of a match between the first identifier and a second identifier contained in at least one media stream of the communication service supported by the connection, a step of rejecting the connection of said terminal. Figure for the abbreviation: Figure 1
Owner:ORANGE SA

Vehicle-mounted relay device, vehicle-mounted relay method, and vehicle-mounted relay program

To improve security while suppressing communication delay in an on-vehicle network.SOLUTION: An on-vehicle relay device comprises: a reception section which receives a frame from an on-vehicle unit; a first IC (Integrated Circuit) which performs relay processing of the frame received by the reception section; and a second IC which is connected between the reception section and the first IC, outputs the frame received from the reception section to the first IC and outputs the frame received from the first IC to the outside of the on-vehicle relay device. The second IC monitors the frame and, in a case where it is determined that the frame is an unauthorized frame, stops outputting the frame.SELECTED DRAWING: Figure 3
Owner:AUTONETWORKS TECH LTD +2

In-vehicle network

To provide an ECU layout determination method with which it is possible to suppress the adverse effect of illegal access to an onboard network.SOLUTION: The layout of each ECU is determined on the basis of the cost attributable to the number of wire and the diameter of wire used in an onboard network (step ST4). The form of wire division for realizing the layout of each ECU is determined, and accordingly the position of a connector located at the divided position and the number of connectors are determined (step ST5). Determination is made as to whether or not there exists an ECU whose access difficulty is low (step ST7), and when a bus to which an ECU having security risk is connected is the one that has an ECU connected thereto whose security level is not high, the ECU having security risk is connected to anther bus by layout change and an onboard network to be established is determined (step ST10).SELECTED DRAWING: Figure 2
Owner:TOYOTA JIDOSHA KK

Networking and security split architecture

Technologies for providing networking and security split architectures are disclosed. [Solution] In some embodiments, a system, process, and / or computer program product for providing a networking and security split architecture includes the steps of: receiving flows in a security service; processing flows in the network layer of the security service to perform one or more networking functions; and offloading flows to the security layer of the security service to perform security enforcement based on policies.
Owner:PALO ALTO NETWORKS INC

Systems, methods, and storage media that compute a frequency of network risk loss within a computing system

Systems, methods, and storage media for determining the probability of network risk-related losses within a computing system comprised of one or more computing elements are disclosed. Exemplary implementations may: assess vulnerability by determining an exposure window of the computing element based on the number of discrete times within a given time frame in which the computing element is vulnerable; determine the frequency of contact between the computing element and threat actors; normalize the exposure window and the contact frequency; calculate the frequency of loss events by dividing the normalized exposure window by the normalized contact frequency; and repeat these steps for multiple elements. When combined with liability data implied by the magnitude of losses describing these events, organizations can prioritize elements based on loss exposure and take action to prevent loss exposure.
Owner:RISKLENS INC