Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

17 results about "Endpoint security" patented technology

Endpoint security or endpoint protection is an approach to the protection of computer networks that are remotely bridged to client devices. The connection of laptops, tablets, mobile phones and other wireless devices to corporate networks creates attack paths for security threats. Endpoint security attempts to ensure that such devices follow a definite level of compliance to standards.

System and method for preventing data leakage by realtime native fingerprinting inside a cloud storage

PendingUS20260073067A1Digital data protectionEndpoint securityCloud storage
The present disclosure provides a system and a method for performing real-time cloud-native fingerprinting and managing sensitive content within a cloud storage platform to prevent data leakage. The system comprises a cloud storage platform comprising a data leakage prevention (DLP) server. The DLP server configured for receiving and storing a sensitive document, receiving a sensitivity level of the sensitive document, fingerprinting the sensitive document based on the sensitivity level, indexing and storing the fingerprint, sharing the fingerprint to an endpoint security agent, receiving leak indication, performing leak analysis and notifying the leak to a document owner. The system and method further perform monitoring of the sensitive data that has been fingerprinted and stored under a security folder, for a predefined time and automatically moving the sensitive data from the security folder after the predefined time.
Owner:SHRIVASTAVA VIKALP

System and method for pre-emptive detection of email impersonation and man-in-the-middle attacks using ai-driven telemetry and data leak prevention remediation

Disclosed is a system and method for pre-emptive detection, attribution, and reversal of outbound data leaks and impersonation-based attacks occurring beyond traditional enterprise endpoint security boundaries. An outbound instrumentation gateway may insert telemetry identifiers into outbound electronic communications, enabling persistent tracking of message interactions within external or third-party domains. A RAPTORAI analytics engine may process metadata collected from these interactions using a multi-stage artificial-intelligence pipeline that combines predictive anomaly modeling and large-language-model (LLM) attribution. When anomalous or malicious behavior is detected, a Double DLP remediation engine may be activated, which is capable of pausing, auto-locking, or revoking message access after transmission but before compromise. A PRE-Crime telemetry layer provides visibility into early-stage reconnaissance activities by threat actors operating beyond the endpoint, thereby reducing mean time to detect (MTTD) and mean time to respond (MTTR) to effectively zero. Administrative dashboards present live analytics of third-party risks, reconnaissance indicators, and auto-remediation events.
Owner:KHAN ZAFAR

Cloud dynamic endpoint group

PendingUS20260181022A1Securing communicationEndpoint securitySecurity policy
The present application discloses a method, system, and computer system for managing endpoint security and protecting a network based on a security posture. The method includes: (a) receiving a set of risk signals for each of a plurality of endpoints, wherein the set of risk signals is received from one or more trusted sources, (b) dynamically creating an endpoint group based at least in part on a risk criteria and the set of risk signals, and (c) applying security policy controls to the endpoint group consistently across access through a cloud security service and gateway firewalls.
Owner:PALO ALTO NETWORKS INC

AI-based cybersecurity system trained with multimodal large models

ActiveCN120281550BImprove fault prediction accuracyImprove attack detection accuracyKey distribution for secure communicationUser identity/authority verificationAttackMultidimensional data
This invention relates to the field of intelligent security operation and maintenance technology, specifically to an artificial intelligence network security system based on multimodal large model training. The system includes a server fault diagnosis module, a network attack detection module, an endpoint security monitoring module, a key management optimization module, and a threat analysis feedback module. In this invention, multidimensional data analysis improves the accuracy of fault prediction, reducing business interruptions caused by sudden hardware failures. Based on server anomaly assessment, network access frequency, source, and command characteristics are evaluated to improve attack detection accuracy and reduce the risk of false positives. Endpoint device execution behavior, resource calls, and behavior sequences are extracted to achieve fine-grained security monitoring, enhancing attack tracing capabilities. Key policies are dynamically adjusted to improve security adaptability and reduce policy lag risks. Multi-level data is integrated to calculate the fit between threat behavior and attack, enhancing the precision and response speed of threat assessment and improving overall security situation awareness.
Owner:SHENZHEN JINCHAO CLOUD CONTROL TECH CO LTD

Systems and methods of information security monitoring with third-party indicators of compromise

ActiveUS12647460B2Securing communicationThird partyEndpoint security
An information security monitoring system can import indicators of compromise (IOC) definitions in disparate formats from third-party source systems, convert them into editable security definitions in an internal system format, and provide a user interface for composing or editing these security definitions with enhancements, including complex security definitions such as those having a nested Boolean structure and / or those that reference one or more security definitions, a behavioral rule, and / or a vulnerability description. One or more whitelists can be added to handle exceptions. Each composed or modified security definition is then compiled into an executable rule. The executable rule, when evaluated, produces a result indicative of an endpoint security action needed in view of an endpoint event that meets the composed or modified security definition.
Owner:OPEN TEXT CORPORATION

Global application catalog generation system

A system and method for generating a software product component catalog for endpoint security is presented. The method includes receiving data on endpoint usage of software product components, wherein the data on endpoint usage includes information on states of software product components; invoking at least one AI agent and external data sources based on the data on endpoint usage, wherein the external data sources are invokable by the at least one AI agent to extract particular types of attributes of the software product components; extracting, by the at least one AI agent using external data sources, attributes of the software product components, wherein attributes are dynamic qualities of a software product component; verifying the extracted attributes of the software product components using at least a language model, heuristics, and a combination thereof; and generating an endpoint security policy based, in part, on the verified attributes.
Owner:GLOW TECHNOLOGY LTD

Realtime synchronization of endpoint and cloud service protection

PendingUS20260189610A1Synchronization networksInternet traffic
Systems, methods, and computer readable medium are disclosed for synchronizing network and endpoint security protocols. synchronizing network and endpoint security protocols includes receiving a device posture from an application running on an edge device; receiving from a server in communication with the edge device, network traffic information associated with the edge device; correlating the device posture and the network traffic information; and implementing a network security policy based on the correlation such that both the device posture from the edge device and the network traffic information from the server are used to enforce the network security policy.
Owner:CATO NETWORKS LTD

Attestation and enforcement of cryptographic requirements across multiple hops

The disclosure provides an approach for multi-endpoint cryptographic orchestration. Embodiments include establishing, by a first endpoint of a plurality of endpoints related to a multi-endpoint secure communication session, a metadata channel with one or more other endpoints of the plurality of endpoints. Embodiments include sending, by the first endpoint, to a second endpoint of the one or more other endpoints, via the metadata channel, an indication of a cryptographic requirement related to the multi-endpoint secure communication session. Embodiments include performing, by the second endpoint, one or more cryptographic operations related to the multi-endpoint secure communication session based on the indication of the cryptographic requirement. Embodiments include attesting, by the second endpoint, via the metadata channel, that the one or more cryptographic operations comply with the cryptographic requirement.
Owner:VMWARE INC

Shared secret key based on system components

Systems and methods for establishing a shared secret (or pre-shared key (PSK)) between a Chipset and a trusted platform module (TPM) of a computing device that can be used to encrypt all communication between those two components. The PSK may include two (or more) factors that must both be available to the Chipset in order to communicate with the TPM. The first factor may originate from an Endpoint Security Controller (EpSC) and the second factor may originate from within the Chipset. The PSK may only be regenerated by combining multiple segments of a key, referred to as “factors,” that may be separately assigned to different components of a computing device. If all factors are not provided to a TPM upon boot-up, communication between the Chipset and the TPM may be disabled.
Owner:HEWLETT PACKARD DEVELOPMENT COMPANY LP

Zero-trust network access (ZTNA) secure traffic forwarding

ActiveUS12621271B2Securing communicationMan-in-the-middle attackEndpoint security
Systems and methods for performing zero-trust network access (ZTNA) secure traffic forwarding are provided. In one example, as part of setting up a transmission control protocol (TCP) forward access proxy (TFAP) tunnel, between a target service and an endpoint security agent of an endpoint device through which an application running on the endpoint device can interact with the target service, a secure connection is established between the endpoint security agent and a ZTNA access proxy (AP). Based on an encryption status of traffic transmitted from the application to the target service: (i) protection against eavesdropping by a man-in-the-middle attacker is provided by using the secure connection to encrypt one or more critical messages of the traffic between the endpoint security agent and the ZTNA AP; and (ii) the endpoint security agent abstains from switching to bypassing mode through the TFAP tunnel until after the one or more critical messages of the traffic have been exchanged.
Owner:FORTINET INC

Power distribution network security domain evaluation method and system considering double-end tie-in backup

The application belongs to the technical field of safe operation analysis of power distribution system, and particularly discloses a power distribution network safety domain evaluation method and system considering double-end tie-in backup, which comprises the following steps: constructing a power distribution network model containing distributed power supply and energy storage system under double-end tie-in, performing linear extrapolation on the safety boundary distance searched by the first two rays to predict the safety boundary distance of the current ray; constructing an adaptive reduced search interval; if the safety check is passed, performing standard dichotomy search in the adaptive reduced search interval to finally locate the safety domain boundary point in the direction of the current ray; calculating the discrete curvature of each safety domain boundary point and the chord-length-curvature error between two adjacent boundary points to determine whether local encryption is triggered; and performing safety domain boundary search on the encrypted curve again to obtain the final power distribution network safety domain. The application can maintain search robustness when boundary prediction fails through endpoint safety check and full-interval back-off mechanism.
Owner:SHANDONG UNIV

Operation and maintenance method, system and equipment, computer program product and storage medium

PendingCN122069158ASecuring communicationPrivate networkEndpoint security
The embodiment of the invention provides an operation and maintenance method, system and device, a computer program product and a storage medium. A bastion host created for a user is in communication connection with a server in an endpoint security service used by the user, so that the bastion host can break through the isolation limitation of a virtual private network by virtue of the cross-virtual private network traffic forwarding capability of the endpoint security service, and the security of the user is improved. The operation and maintenance instruction can be transmitted to any cloud asset in any virtual private network of a user in a barrier-free manner so as to carry out resource operation and maintenance. Therefore, in the embodiment of the invention, under the condition that asset operation and maintenance need to be carried out on the plurality of virtual private networks of the user, the operation and maintenance instruction for any cloud asset in any virtual private network of the target user can be processed in a centralized manner through one bastion host, and the bastion host does not need to be independently deployed in each virtual private network, so that the operation and maintenance of the cloud assets in the virtual private networks of the target user are facilitated. And the use cost of the bastion host can be effectively saved.
Owner:ALIBABA CLOUD COMPUTING CO LTD

A firewall data processing method based on terminal security protection

PendingCN122316683ARate limitingPathPing
This invention relates to a firewall data processing method based on endpoint security protection. It establishes an endpoint connection management mechanism, maintains an active connection table and a state hook mapping table, and associates outbound connections with process identifiers, user identities, data payload summaries, and creation times to form state hooks. Hook verification is triggered when the endpoint state changes. If sensitive privilege escalation or behavior deviating from the initial digest is detected, the connection priority is dynamically adjusted, and rate limiting, blocking, or transition to observation mode is implemented. Access path consistency verification is performed on outbound connections, comparing DNS requests, process calls, and actual packet paths. If unexplained path offsets exist, the source is traced and the path is reconstructed. Connection behavior is periodically split according to operating system event granularity, and concurrent or abrupt behavior is logically redefined into multiple sub-sessions with corresponding policies applied. Transmission delays are applied to reversible connection operations, and action chain tracing is activated to determine whether to restore or terminate the connection.
Owner:LEADCHUANG ANDA (BEIJING) TECHNOLOGY CO LTD

Exposed asset security assessment method and device

PendingCN121309122ASecuring communicationEndpoint securitySecurity policy
The invention provides an exposed asset security assessment method and device. The method comprises the following steps: collecting vulnerability scanning data, security policy data, business importance data and endpoint security data of exposed assets; based on the vulnerability scanning data, the security policy data, the service importance data, the endpoint security data and a preset scoring rule, determining a vulnerability scanning score, a security policy score, a service importance score and an endpoint security score; the vulnerability scanning score, the security policy score, the service importance score and the endpoint security score are quantitative and comparable numerical values; taking the weighted sum of the vulnerability scanning score, the security policy score, the service importance score and the endpoint security score as a comprehensive security score of the exposed assets; and generating an asset security assessment report based on the comprehensive security score. According to the method, the comprehensiveness and the accuracy of exposed asset safety assessment are improved.
Owner:BEIJING ANBOTONG TECH CO LTD

Endpoint security groups in private multi-access edge compute networks

ActiveUS12676891B2Device typeEndpoint security
Endpoint security groups include computing device endpoints that are classified according to commonly shared device features and capabilities including device type, function, role, or location. Endpoint security groups are used as an alternative identity mechanism for endpoints for purposes of security and data traffic policy enforcement rather than using conventional IP (Internet Protocol) addressing. Grouping endpoints reduces the scope of network management to enable dynamic policy enforcement for endpoints as they join, leave, and then rejoin computing networks, which is a common behavior, particularly for IoT (Internet-of-Things) devices in manufacturing environments. In an illustrative example, a private multi-access edge compute (MEC) platform supports a scalable policy definition and enforcement framework that provides consistent endpoint handling independent of network access methodology. Endpoint security groups facilitate improvements in security of network access and utilization and segmentation of data traffic on a fine-grained basis.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

A substation dispatching data network security communication method based on quantum tunnel encryption

The application discloses a substation dispatching data network security communication method based on quantum tunnel encryption, relates to the technical field of large-scale power grid security guarantee, and aims to solve the problems of security loss of a dispatching data network endpoint, boundary solidification, weak anti-quantum threat capability and inflexible deployment. The method is characterized in that quantum security communication terminals are arranged at a dispatching master station and a substation, quantum key distribution and post-quantum cryptographic operation modules are integrated, a secure session is established, data is encapsulated and encrypted, and is restored. The method also encrypts and signs remote protocol data at an application layer, constructs a double-layer encryption tunnel, and supports transmission of various physical network media. Through the scheme, the application realizes end-to-end protection, effectively resists quantum attacks, provides double encryption, and improves networking flexibility and smooth evolution.
Owner:INNER MONGOLIA HUIQIANG TECH CO LTD