Identity attack detection and blocking
US-2021288981-A1 · Sep 16, 2021 · US
US11595386B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-11595386-B2 |
| Application number | US-202117159715-A |
| Country | US |
| Kind code | B2 |
| Filing date | Jan 27, 2021 |
| Priority date | Sep 16, 2020 |
| Publication date | Feb 28, 2023 |
| Grant date | Feb 28, 2023 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Techniques for storage management involve: receiving, at a storage server, an access request for target data from a client, wherein the access request occurs in a session between the storage server and the client; determining, based on attribute information of the client, security information of the session, wherein the security information indicates whether the session is subjected to antivirus protection; and executing, based on the security information, an access operation specified by the access request on the target data. Therefore, the performance of the storage server can be improved while the security of the storage server is ensured.
Opening claim text (preview).
The invention claimed is: 1. A method for storage management, comprising: receiving, at a storage server, an access request for target data from a client, wherein the access request occurs in a session between the storage server and the client; determining, based on attribute information of the client, security information of the session, wherein the security information indicates whether the session is subjected to antivirus protection; and executing, based on the security information, an access operation specified by the access request on the target data; determining a first user ID of the user initiating the access request from the attribute information; and determining that the first user ID does not match a second user ID of a trusted user stored in the storage server; sending a request for performing virus detection on the target data to a virus detector in response to determining that the first user ID does not match the second user ID; and wherein executing the access operation is in response to receiving, from the virus detector, a response indicating that the target data is not threatened by a virus. 2. The method according to claim 1 , further comprising: determining that the security information has not been predetermined; and acquiring the attribute information in response to determining that the security information has not been predetermined. 3. The method according to claim 1 , wherein the attribute information comprises at least one of: an Internet protocol (IP) address of the client, a multi-access control (MAC) address of the client, an identifier of the client, and a user identifier (ID) of a user initiating the access request. 4. The method according to claim 1 , wherein the determining the security information comprises: sending the attribute information to a security manager associated with the client; receiving, from the security manager, information of antivirus software installed on the client corresponding to the attribute information; and determining, based on the information of the antivirus software, the security information. 5. The method according to claim 4 , wherein the information of the antivirus software comprises at least one of: an identifier of the antivirus software, update time of the antivirus software, and a function enabled in the antivirus software. 6. The method according to claim 5 , wherein the determining the security information comprises determining at least one of: whether the identifier of the antivirus software matches an identifier of specified antivirus software, whether the update time exceeds a threshold time, and whether the enabled function is a specified function. 7. The method according to claim 1 , further comprising: determining credibility of a second user in response to security information of a second session indicating that the second session is subjected to the antivirus protection; and executing, based on the credibility, a second access operation on the target data. 8. The method according to claim 7 , wherein the determining the credibility comprises: determining a first user ID of the second user initiating a second access request from the attribute information; and determining that the first user ID matches a second user ID of a trusted user stored in the storage server; and wherein executing the second access operation is in response to determining that the first user ID matches the second user ID. 9. An electronic device, comprising: at least one processing unit; and at least one memory, wherein the at least one memory is coupled to the at least one processing unit and stores instructions configured to be executed by the at least one processing unit, and the instructions, when executed by the at least one processing unit, cause the device to perform actions comprising: receiving, at a storage server, an access request for target data from a client, wherein the access request occurs in a session between the storage server and the client; determining, based on attribute information of the client, security information of the session, wherein the security information indicates whether the session is subjected to antivirus protection; and executing, based on the security information, an access operation specified by the access request on the target data; determining a first user ID of the user initiating the access request from the attribute information; and determining that the first user ID does not match a second user ID of a trusted user stored in the storage server; sending a request for performing virus detection on the target data to a virus detector in response to determining that the first user ID does not match the second user ID; and wherein executing the access operation is in response to receiving, from the virus detector, a response indicating that the target data is not threatened by a virus. 10. The device according to claim 9 , wherein the actions further comprise: determining that the security information has not been predetermined; and acquiring the attribute information in response to determining that the security information has not been predetermined. 11. The device according to claim 9 , wherein the attribute information comprises at least one of: an IP address of the client, an MAC address of the client, an identifier of the client, and a user ID of a user initiating the access request. 12. The device according to claim 9 , wherein the determining the security information comprises: sending the attribute information to a security manager associated with the client; receiving, from the security manager, information of antivirus software installed on the client corresponding to the attribute information; and determining, based on the information of the antivirus software, the security information. 13. The device according to claim 12 , wherein the information of the antivirus software comprises at least one of: an identifier of the antivirus software, update time of the antivirus software, and a function enabled in the antivirus software. 14. The device according to claim 13 , wherein the determining the security information comprises determining at least one of: whether the identifier of the antivirus software matches an identifier of specified antivirus software, whether the update time exceeds a threshold time, and whether the enabled function is a specified function. 15. The device according to claim 9 , further comprising: determining credibility of a second user in response to security information of a second session indicating that the second session is subjected to the antivirus protection; and executing, based on the credibility, a second access operation on the target data. 16. The device according to claim 15 , wherein the determining the credibility comprises: determining a first user ID of the second user initiating a second access request from the attribute information; and determining that the first user ID matches a second user ID of a trusted user stored in the storage server; and wherein executing the second access operation is in response to determining that the first user ID matches the second user ID. 17. A computer program product having a non-transitory computer readable medium which stores a set of instructions to perform storage management; the set of instructions, when carried out by computerized circuitry, causing the computerized circuitry to perform a method of: receiving, at a storage server, an access request for target data from a client, wherein the acces
for distributed storage of data in networks, e.g. transport arrangements for network file system [NFS], storage area networks [SAN] or network attached storage [NAS] · CPC title
based on the identity of the terminal or configuration, e.g. MAC address, hardware or software configuration or device fingerprint · CPC title
Entity profiles · CPC title
the attack involving the propagation of malware through the network, e.g. viruses, trojans or worms · CPC title
for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.