Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

24 results about "Endpoint security" patented technology

Endpoint security or endpoint protection is an approach to the protection of computer networks that are remotely bridged to client devices. The connection of laptops, tablets, mobile phones and other wireless devices to corporate networks creates attack paths for security threats. Endpoint security attempts to ensure that such devices follow a definite level of compliance to standards.

Substation dispatching data network security communication method based on quantum tunnel encryption

The invention discloses a substation dispatching data network security communication method based on quantum tunnel encryption, relates to the technical field of large-scale power grid security assurance, and aims to solve the problems of endpoint security loss, boundary solidification, weak quantum threat resistance and inflexible deployment of a dispatching data network. According to the method, the establishment of a secure session and the encapsulation, encryption and restoration of data are realized by integrating quantum key distribution and a post quantum cryptographic operation module through quantum secure communication terminals deployed in a dispatching master station and a transformer substation. According to the method, application layer encryption and signature are carried out on telecontrol protocol data, a double-layer encryption tunnel is constructed, and transmission of various physical network media is supported. By means of the scheme, end-to-end protection is achieved, quantum attacks are effectively resisted, double encryption is provided, and networking flexibility and smooth evolution are improved.
Owner:INNER MONGOLIA HUIQIANG TECH CO LTD

System and method for preventing data leakage by realtime native fingerprinting inside a cloud storage

PendingUS20260073067A1Digital data protectionEndpoint securityCloud storage
The present disclosure provides a system and a method for performing real-time cloud-native fingerprinting and managing sensitive content within a cloud storage platform to prevent data leakage. The system comprises a cloud storage platform comprising a data leakage prevention (DLP) server. The DLP server configured for receiving and storing a sensitive document, receiving a sensitivity level of the sensitive document, fingerprinting the sensitive document based on the sensitivity level, indexing and storing the fingerprint, sharing the fingerprint to an endpoint security agent, receiving leak indication, performing leak analysis and notifying the leak to a document owner. The system and method further perform monitoring of the sensitive data that has been fingerprinted and stored under a security folder, for a predefined time and automatically moving the sensitive data from the security folder after the predefined time.
Owner:SHRIVASTAVA VIKALP

System and method for pre-emptive detection of email impersonation and man-in-the-middle attacks using ai-driven telemetry and data leak prevention remediation

Disclosed is a system and method for pre-emptive detection, attribution, and reversal of outbound data leaks and impersonation-based attacks occurring beyond traditional enterprise endpoint security boundaries. An outbound instrumentation gateway may insert telemetry identifiers into outbound electronic communications, enabling persistent tracking of message interactions within external or third-party domains. A RAPTORAI analytics engine may process metadata collected from these interactions using a multi-stage artificial-intelligence pipeline that combines predictive anomaly modeling and large-language-model (LLM) attribution. When anomalous or malicious behavior is detected, a Double DLP remediation engine may be activated, which is capable of pausing, auto-locking, or revoking message access after transmission but before compromise. A PRE-Crime telemetry layer provides visibility into early-stage reconnaissance activities by threat actors operating beyond the endpoint, thereby reducing mean time to detect (MTTD) and mean time to respond (MTTR) to effectively zero. Administrative dashboards present live analytics of third-party risks, reconnaissance indicators, and auto-remediation events.
Owner:KHAN ZAFAR

Cloud dynamic endpoint group

PendingUS20260181022A1Securing communicationEndpoint securitySecurity policy
The present application discloses a method, system, and computer system for managing endpoint security and protecting a network based on a security posture. The method includes: (a) receiving a set of risk signals for each of a plurality of endpoints, wherein the set of risk signals is received from one or more trusted sources, (b) dynamically creating an endpoint group based at least in part on a risk criteria and the set of risk signals, and (c) applying security policy controls to the endpoint group consistently across access through a cloud security service and gateway firewalls.
Owner:PALO ALTO NETWORKS INC

AI-based cybersecurity system trained with multimodal large models

ActiveCN120281550BImprove fault prediction accuracyImprove attack detection accuracyKey distribution for secure communicationUser identity/authority verificationAttackMultidimensional data
This invention relates to the field of intelligent security operation and maintenance technology, specifically to an artificial intelligence network security system based on multimodal large model training. The system includes a server fault diagnosis module, a network attack detection module, an endpoint security monitoring module, a key management optimization module, and a threat analysis feedback module. In this invention, multidimensional data analysis improves the accuracy of fault prediction, reducing business interruptions caused by sudden hardware failures. Based on server anomaly assessment, network access frequency, source, and command characteristics are evaluated to improve attack detection accuracy and reduce the risk of false positives. Endpoint device execution behavior, resource calls, and behavior sequences are extracted to achieve fine-grained security monitoring, enhancing attack tracing capabilities. Key policies are dynamically adjusted to improve security adaptability and reduce policy lag risks. Multi-level data is integrated to calculate the fit between threat behavior and attack, enhancing the precision and response speed of threat assessment and improving overall security situation awareness.
Owner:SHENZHEN JINCHAO CLOUD CONTROL TECH CO LTD

Systems and methods of information security monitoring with third-party indicators of compromise

ActiveUS12647460B2Securing communicationThird partyEndpoint security
An information security monitoring system can import indicators of compromise (IOC) definitions in disparate formats from third-party source systems, convert them into editable security definitions in an internal system format, and provide a user interface for composing or editing these security definitions with enhancements, including complex security definitions such as those having a nested Boolean structure and / or those that reference one or more security definitions, a behavioral rule, and / or a vulnerability description. One or more whitelists can be added to handle exceptions. Each composed or modified security definition is then compiled into an executable rule. The executable rule, when evaluated, produces a result indicative of an endpoint security action needed in view of an endpoint event that meets the composed or modified security definition.
Owner:OPEN TEXT CORPORATION

Global application catalog generation system

A system and method for generating a software product component catalog for endpoint security is presented. The method includes receiving data on endpoint usage of software product components, wherein the data on endpoint usage includes information on states of software product components; invoking at least one AI agent and external data sources based on the data on endpoint usage, wherein the external data sources are invokable by the at least one AI agent to extract particular types of attributes of the software product components; extracting, by the at least one AI agent using external data sources, attributes of the software product components, wherein attributes are dynamic qualities of a software product component; verifying the extracted attributes of the software product components using at least a language model, heuristics, and a combination thereof; and generating an endpoint security policy based, in part, on the verified attributes.
Owner:GLOW TECHNOLOGY LTD

Realtime synchronization of endpoint and cloud service protection

Systems, methods, and computer readable medium are disclosed for synchronizing network and endpoint security protocols. synchronizing network and endpoint security protocols includes receiving a device posture from an application running on an edge device; receiving from a server in communication with the edge device, network traffic information associated with the edge device; correlating the device posture and the network traffic information; and implementing a network security policy based on the correlation such that both the device posture from the edge device and the network traffic information from the server are used to enforce the network security policy.
Owner:CATO NETWORKS LTD

Fuzzing based security assessment

A computer implemented method for assessing endpoint security includes identifying a size of exposed PCIe space corresponding to a system of interest comprising one or more endpoints, determining an observable state of correct functionality for the system, generating random transaction layer packets corresponding to the endpoint, injecting the generated transaction layer packets, monitoring the system following the injection of the generated transaction layer packets for erroneous patterns exhibited by the system, and reporting the erroneous patterns exhibited by the system. A corresponding computer program product and computer system are also disclosed.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Endpoint security synchronization

PendingUS20250348605A1Digital data protectionAttackEndpoint security
A computing system is configured to manage and synchronize indicators-of-attack (IOA) rules across multiple tenants of an Endpoint Detection and Response (EDR) tool. The computing system is configured to compare rules between an indicated source tenant and a destination tenant. The computing system may then generate output indicating common rules, updated rules, and missing rules between the source and destination tenants. A user, or the system itself, may update the rules at the destination tenant based on the rules at the source tenant. Such an endpoint security synchronization system avoids problems that may occur with manually transferring IOA rules across multiple tenants of an EDR tool which may result in errors that result in false or misleading security alerts.
Owner:WELLS FARGO BANK NA

Attestation and enforcement of cryptographic requirements across multiple hops

The disclosure provides an approach for multi-endpoint cryptographic orchestration. Embodiments include establishing, by a first endpoint of a plurality of endpoints related to a multi-endpoint secure communication session, a metadata channel with one or more other endpoints of the plurality of endpoints. Embodiments include sending, by the first endpoint, to a second endpoint of the one or more other endpoints, via the metadata channel, an indication of a cryptographic requirement related to the multi-endpoint secure communication session. Embodiments include performing, by the second endpoint, one or more cryptographic operations related to the multi-endpoint secure communication session based on the indication of the cryptographic requirement. Embodiments include attesting, by the second endpoint, via the metadata channel, that the one or more cryptographic operations comply with the cryptographic requirement.
Owner:VMWARE INC

Shared secret key based on system components

Systems and methods for establishing a shared secret (or pre-shared key (PSK)) between a Chipset and a trusted platform module (TPM) of a computing device that can be used to encrypt all communication between those two components. The PSK may include two (or more) factors that must both be available to the Chipset in order to communicate with the TPM. The first factor may originate from an Endpoint Security Controller (EpSC) and the second factor may originate from within the Chipset. The PSK may only be regenerated by combining multiple segments of a key, referred to as “factors,” that may be separately assigned to different components of a computing device. If all factors are not provided to a TPM upon boot-up, communication between the Chipset and the TPM may be disabled.
Owner:HEWLETT PACKARD DEVELOPMENT COMPANY LP

Zero-trust network access (ZTNA) secure traffic forwarding

ActiveUS12621271B2Securing communicationMan-in-the-middle attackEndpoint security
Systems and methods for performing zero-trust network access (ZTNA) secure traffic forwarding are provided. In one example, as part of setting up a transmission control protocol (TCP) forward access proxy (TFAP) tunnel, between a target service and an endpoint security agent of an endpoint device through which an application running on the endpoint device can interact with the target service, a secure connection is established between the endpoint security agent and a ZTNA access proxy (AP). Based on an encryption status of traffic transmitted from the application to the target service: (i) protection against eavesdropping by a man-in-the-middle attacker is provided by using the secure connection to encrypt one or more critical messages of the traffic between the endpoint security agent and the ZTNA AP; and (ii) the endpoint security agent abstains from switching to bypassing mode through the TFAP tunnel until after the one or more critical messages of the traffic have been exchanged.
Owner:FORTINET INC

Power distribution network security domain evaluation method and system considering double-end tie-in backup

The application belongs to the technical field of safe operation analysis of power distribution system, and particularly discloses a power distribution network safety domain evaluation method and system considering double-end tie-in backup, which comprises the following steps: constructing a power distribution network model containing distributed power supply and energy storage system under double-end tie-in, performing linear extrapolation on the safety boundary distance searched by the first two rays to predict the safety boundary distance of the current ray; constructing an adaptive reduced search interval; if the safety check is passed, performing standard dichotomy search in the adaptive reduced search interval to finally locate the safety domain boundary point in the direction of the current ray; calculating the discrete curvature of each safety domain boundary point and the chord-length-curvature error between two adjacent boundary points to determine whether local encryption is triggered; and performing safety domain boundary search on the encrypted curve again to obtain the final power distribution network safety domain. The application can maintain search robustness when boundary prediction fails through endpoint safety check and full-interval back-off mechanism.
Owner:SHANDONG UNIV

Endpoint safety guarantee method and device in electric vehicle charging and discharging infrastructure management protocol

The invention discloses an endpoint safety method and device suitable for an electric vehicle charging and discharging infrastructure management protocol. The endpoint security method comprises the steps of: signing at least one key-value pair among elements in a message body to be transmitted to a second node of the communication architecture; and sending a message comprising the at least one signed key-value pair to the second node.
Owner:HYUNDAI MOTOR CO LTD +2

Adjusting behavior of an endpoint security agent based on network location

ActiveUS12463979B2Securing communicationEndpoint securityEngineering
Systems and methods for adjusting the behavior of an endpoint security agent based on a network location are provided. According to an embodiment, an agent of an endpoint device identifies whether a security service of a cloud-based security service is not reachable or is unresponsive. The security service is associated with a particular security function implemented by the agent. When the security service is not reachable or is unresponsive, the agent further determines whether the endpoint device is within a trusted network of multiple trusted networks that have been previously registered with the cloud-based security service by querying a trusted network determination service associated with the cloud-based security service. When the determination is affirmative, the particular security feature is configured for operating inside a trusted network. When the determination is negative, the particular security feature is configured for operating outside a trusted network.
Owner:FORTINET INC

Systems and methods for asset based event prioritization for remote endpoint security

Systems and methods for event threat prioritization are provided. In some embodiments, an event priority engine receives event data detected by event agents executing on devices. The events are prioritized and ranked according to threat scores for events generated according to threat indicators which are fed event data and threat data. In some embodiments, security systems may take the approach of prioritizing events based on the endpoints from which they originate using attributes associated with those endpoints. In this way, events can be prioritized at least in part based on the damage to the enterprise that may occur if those events were to compromise security, not just the likelihood of those events actually resulting in a security breach.
Owner:OPEN TEXT CORPORATION

Operation and maintenance method, system and equipment, computer program product and storage medium

PendingCN122069158ASecuring communicationPrivate networkEndpoint security
The embodiment of the invention provides an operation and maintenance method, system and device, a computer program product and a storage medium. A bastion host created for a user is in communication connection with a server in an endpoint security service used by the user, so that the bastion host can break through the isolation limitation of a virtual private network by virtue of the cross-virtual private network traffic forwarding capability of the endpoint security service, and the security of the user is improved. The operation and maintenance instruction can be transmitted to any cloud asset in any virtual private network of a user in a barrier-free manner so as to carry out resource operation and maintenance. Therefore, in the embodiment of the invention, under the condition that asset operation and maintenance need to be carried out on the plurality of virtual private networks of the user, the operation and maintenance instruction for any cloud asset in any virtual private network of the target user can be processed in a centralized manner through one bastion host, and the bastion host does not need to be independently deployed in each virtual private network, so that the operation and maintenance of the cloud assets in the virtual private networks of the target user are facilitated. And the use cost of the bastion host can be effectively saved.
Owner:ALIBABA CLOUD COMPUTING CO LTD

A firewall data processing method based on terminal security protection

PendingCN122316683ARate limitingPathPing
This invention relates to a firewall data processing method based on endpoint security protection. It establishes an endpoint connection management mechanism, maintains an active connection table and a state hook mapping table, and associates outbound connections with process identifiers, user identities, data payload summaries, and creation times to form state hooks. Hook verification is triggered when the endpoint state changes. If sensitive privilege escalation or behavior deviating from the initial digest is detected, the connection priority is dynamically adjusted, and rate limiting, blocking, or transition to observation mode is implemented. Access path consistency verification is performed on outbound connections, comparing DNS requests, process calls, and actual packet paths. If unexplained path offsets exist, the source is traced and the path is reconstructed. Connection behavior is periodically split according to operating system event granularity, and concurrent or abrupt behavior is logically redefined into multiple sub-sessions with corresponding policies applied. Transmission delays are applied to reversible connection operations, and action chain tracing is activated to determine whether to restore or terminate the connection.
Owner:LEADCHUANG ANDA (BEIJING) TECHNOLOGY CO LTD

Exposed asset security assessment method and device

PendingCN121309122ASecuring communicationEndpoint securitySecurity policy
The invention provides an exposed asset security assessment method and device. The method comprises the following steps: collecting vulnerability scanning data, security policy data, business importance data and endpoint security data of exposed assets; based on the vulnerability scanning data, the security policy data, the service importance data, the endpoint security data and a preset scoring rule, determining a vulnerability scanning score, a security policy score, a service importance score and an endpoint security score; the vulnerability scanning score, the security policy score, the service importance score and the endpoint security score are quantitative and comparable numerical values; taking the weighted sum of the vulnerability scanning score, the security policy score, the service importance score and the endpoint security score as a comprehensive security score of the exposed assets; and generating an asset security assessment report based on the comprehensive security score. According to the method, the comprehensiveness and the accuracy of exposed asset safety assessment are improved.
Owner:BEIJING ANBOTONG TECH CO LTD

Endpoint security groups in private multi-access edge compute networks

ActiveUS12676891B2Device typeEndpoint security
Endpoint security groups include computing device endpoints that are classified according to commonly shared device features and capabilities including device type, function, role, or location. Endpoint security groups are used as an alternative identity mechanism for endpoints for purposes of security and data traffic policy enforcement rather than using conventional IP (Internet Protocol) addressing. Grouping endpoints reduces the scope of network management to enable dynamic policy enforcement for endpoints as they join, leave, and then rejoin computing networks, which is a common behavior, particularly for IoT (Internet-of-Things) devices in manufacturing environments. In an illustrative example, a private multi-access edge compute (MEC) platform supports a scalable policy definition and enforcement framework that provides consistent endpoint handling independent of network access methodology. Endpoint security groups facilitate improvements in security of network access and utilization and segmentation of data traffic on a fine-grained basis.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

A substation dispatching data network security communication method based on quantum tunnel encryption

The application discloses a substation dispatching data network security communication method based on quantum tunnel encryption, relates to the technical field of large-scale power grid security guarantee, and aims to solve the problems of security loss of a dispatching data network endpoint, boundary solidification, weak anti-quantum threat capability and inflexible deployment. The method is characterized in that quantum security communication terminals are arranged at a dispatching master station and a substation, quantum key distribution and post-quantum cryptographic operation modules are integrated, a secure session is established, data is encapsulated and encrypted, and is restored. The method also encrypts and signs remote protocol data at an application layer, constructs a double-layer encryption tunnel, and supports transmission of various physical network media. Through the scheme, the application realizes end-to-end protection, effectively resists quantum attacks, provides double encryption, and improves networking flexibility and smooth evolution.
Owner:INNER MONGOLIA HUIQIANG TECH CO LTD