IP Library Granted Patent US 9,967,270
Granted Patent B2
US 9,967,270 · App. 15/419,012 · Granted May 8, 2018

Enterprise intrusion detection and remediation

Inventors: Erick Kobres (Lawrenceville, GA); Stavros Antonakakis (Lake Mary, FL)
Assignee: NCR Corporation
H04L63/1416G06F21/50G06F21/554G06F21/55
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,967,270
App. No.
15/419,012
Granted
May 8, 2018
Kind
B2
Abstract

Events are securely packaged and transmitted from peripherals of terminals and from secure input/out modules (SIOMs) of terminals. The events are collected and mined in real time for security risk patterns and dynamic remedial actions are pushed back down to the terminals, peripherals, and SIOMs.

Claims (60)

1. A method, comprising:

receiving, by a hardware server, a security intrusion event securely communicated from a peripheral of a terminal over a network, wherein receiving further includes obtaining the security intrusion event from the peripheral of the terminal, the security intrusion event pushed up to a secure input/output module (SIOM) that is acting as a secure interface for communications to and from the peripheral during a secure session between the peripheral and the SIOM, and wherein the SIOM is independent of the operating system;

accessing, by the hardware server, heuristics and identifying a pattern for the security intrusion event relevant to a security intrusion within the peripheral; and

triggering, by the hardware server, an action based on the pattern and securely pushing the action to the peripheral for dynamic and real-time processing by the peripheral in response to the security intrusion, wherein the peripheral comprises a card reader;

wherein the pattern comprises a failure of the secure session between the terminal and the card reader.

2. The method of claim 1 , wherein the pattern is configurable.

3. The method of claim 1 , wherein the pattern comprises detection of a duplicate secure peripheral identifier.

4. The method of claim 1 , wherein the pattern comprises detection of a secure peripheral identifier that is not in an inventory of peripherals on the SIOM.

5. The method of claim 1 , wherein the pattern comprises detection of duplicate SIOM identifiers.

6. The method of claim 1 , wherein the pattern comprises detection of a revoked or decommissioned peripheral or the SIOM.

7. A method, comprising:

receiving, by a hardware server, a security intrusion event securely communicated from a peripheral of a terminal over a network, wherein receiving further includes obtaining the security intrusion event from the peripheral of the terminal, the security intrusion event pushed up to a secure input/output module (SIOM) that is acting as a secure interface for communications to and from the peripheral during a secure session between the peripheral and the SIOM, and wherein the SIOM is independent of the operating system;

accessing, by the hardware server, heuristics and identifying a pattern for the security intrusion event relevant to a security intrusion within the peripheral; and

triggering, by the hardware server, an action based on the pattern and securely pushing the action to the peripheral for dynamic and real-time processing by the peripheral in response to the security intrusion;

wherein the pattern comprises receipt of an out-of-order secure session message from the peripheral by the SIOM.

8. A method, comprising:

receiving, by a hardware server, a security intrusion event securely communicated from a peripheral of a terminal over a network, wherein receiving further includes obtaining the security intrusion event from the peripheral of the terminal, the security intrusion event pushed up to a secure input/output module (SIOM) that is acting as a secure interface for communications to and from the peripheral during a secure session between the peripheral and the SIOM, and wherein the SIOM is independent of the operating system;

accessing, by the hardware server, heuristics and identifying a pattern for the security intrusion event relevant to a security intrusion within the peripheral; and

triggering, by the hardware server, an action based on the pattern and securely pushing the action to the peripheral for dynamic and real-time processing by the peripheral in response to the security intrusion;

wherein the pattern comprises receipt of an out-of-order secure session message from the SIOM by the peripheral.

9. A method, comprising:

receiving, by a hardware server, a security intrusion event securely communicated from a peripheral of a terminal over a network, wherein receiving further includes obtaining the security intrusion event from the peripheral of the terminal, the security intrusion event pushed up to a secure input/output module (SIOM) that is acting as a secure interface for communications to and from the peripheral during a secure session between the peripheral and the SIOM, and wherein the SIOM is independent of the operating system;

accessing, by the hardware server, heuristics and identifying a pattern for the security intrusion event relevant to a security intrusion within the peripheral; and

triggering, by the hardware server, an action based on the pattern and securely pushing the action to the peripheral for dynamic and real-time processing by the peripheral in response to the security intrusion;

wherein the pattern comprises a failure to pair with the peripheral by the SIOM.

10. A method, comprising:

receiving, by a hardware server, a security intrusion event securely communicated from a peripheral of a terminal over a network, wherein receiving further includes obtaining the security intrusion event from the peripheral of the terminal, the security intrusion event pushed up to a secure input/output module (SIOM) that is acting as a secure interface for communications to and from the peripheral during a secure session between the peripheral and the SIOM, and wherein the SIOM is independent of the operating system;

accessing, by the hardware server, heuristics and identifying a pattern for the security intrusion event relevant to a security intrusion within the peripheral; and

triggering, by the hardware server, an action based on the pattern and securely pushing the action to the peripheral for dynamic and real-time processing by the peripheral in response to the security intrusion;

wherein the pattern comprises receipt of the secure session message for the secure session that is no longer active by the SIOM.

11. A method, comprising:

receiving, by a hardware server, a security intrusion event securely communicated from a peripheral of a terminal over a network, wherein receiving further includes obtaining the security intrusion event from the peripheral of the terminal, the security intrusion event pushed up to a secure input/output module (SIOM) that is acting as a secure interface for communications to and from the peripheral during a secure session between the peripheral and the SIOM, and wherein the SIOM is independent of the operating system;

accessing, by the hardware server, heuristics and identifying a pattern for the security intrusion event relevant to a security intrusion within the peripheral; and

triggering, by the hardware server, an action based on the pattern and securely pushing the action to the peripheral for dynamic and real-time processing by the peripheral in response to the security intrusion;

wherein the pattern comprises a mismatch between a SIOM pairing request issued by a provisioning server and provisioning events on the SIOM.

12. A method, comprising:

receiving, by a hardware server, a security intrusion event securely communicated from a peripheral of a terminal over a network, wherein receiving further includes obtaining the security intrusion event from the peripheral of the terminal, the security intrusion event pushed up to a secure input/output module (SIOM) that is acting as a secure interface for communications to and from the peripheral during a secure session between the peripheral and the SIOM, and wherein the SIOM is independent of the operating system;

accessing, by the hardware server, heuristics and identifying a pattern for the security intrusion event relevant to a security intrusion within the peripheral; and

triggering, by the hardware server, an action based on the pattern and securely pushing the action to the peripheral for dynamic and real-time processing by the peripheral in response to the security intrusion;

wherein the pattern comprises a failure of a SIOM to be provisioned by the hardware server.

13. A method, comprising:

receiving, by a hardware server, a security intrusion event securely communicated from a peripheral of a terminal over a network, wherein receiving further includes obtaining the security intrusion event from the peripheral of the terminal, the security intrusion event pushed up to a secure input/output module (SIOM) that is acting as a secure interface for communications to and from the peripheral during a secure session between the peripheral and the SIOM, and wherein the SIOM is independent of the operating system;

accessing, by the hardware server, heuristics and identifying a pattern for the security intrusion event relevant to a security intrusion within the peripheral; and

triggering, by the hardware server, an action based on the pattern and securely pushing the action to the peripheral for dynamic and real-time processing by the peripheral in response to the security intrusion;

wherein the pattern comprises failure of the peripheral to create the secure session message after the secure session is established.

14. A method, comprising:

receiving, by a hardware server, a security intrusion event securely communicated from a peripheral of a terminal over a network, wherein receiving further includes obtaining the security intrusion event from the peripheral of the terminal, the security intrusion event pushed up to a secure input/output module (SIOM) that is acting as a secure interface for communications to and from the peripheral during a secure session between the peripheral and the SIOM, and wherein the SIOM is independent of the operating system;

accessing, by the hardware server, heuristics and identifying a pattern for the security intrusion event relevant to a security intrusion within the peripheral; and

triggering, by the hardware server, an action based on the pattern and securely pushing the action to the peripheral for dynamic and real-time processing by the peripheral in response to the security intrusion;

wherein the pattern comprises failure of the peripheral to decode and decrypt a message during the secure session.

15. A method, comprising:

receiving, by a hardware server, a security intrusion event securely communicated from a peripheral of a terminal over a network, wherein receiving further includes obtaining the security intrusion event from the peripheral of the terminal, the security intrusion event pushed up to a secure input/output module (SIOM) that is acting as a secure interface for communications to and from the peripheral during a secure session between the peripheral and the SIOM, and wherein the SIOM is independent of the operating system;

accessing, by the hardware server, heuristics and identifying a pattern for the security intrusion event relevant to a security intrusion within the peripheral; and

triggering, by the hardware server, an action based on the pattern and securely pushing the action to the peripheral for dynamic and real-time processing by the peripheral in response to the security intrusion;

wherein the pattern comprises changing a secure profile used for communication during the secure session by the peripheral.

16. A method, comprising:

receiving, by a hardware server, a security intrusion event securely communicated from a peripheral of a terminal over a network, wherein receiving further includes obtaining the security intrusion event from the peripheral of the terminal, the security intrusion event pushed up to a secure input/output module (SIOM) that is acting as a secure interface for communications to and from the peripheral during a secure session between the peripheral and the SIOM, and wherein the SIOM is independent of the operating system;

accessing, by the hardware server, heuristics and identifying a pattern for the security intrusion event relevant to a security intrusion within the peripheral; and

triggering, by the hardware server, an action based on the pattern and securely pushing the action to the peripheral for dynamic and real-time processing by the peripheral in response to the security intrusion;

wherein the pattern comprises failure of the SIOM and detection of SIOM attempts to re-pair with the peripheral.

Assignments (6)
CHANGE OF NAME Recorded Dec 7, 2023
From: NCR CORPORATION
To: NCR VOYIX CORPORATION
Reel/Frame 065820/0704 →
RELEASE OF PATENT SECURITY INTEREST Recorded Oct 25, 2023
From: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
To: NCR VOYIX CORPORATION
Reel/Frame 065346/0531 →
SECURITY INTEREST Recorded Oct 25, 2023
From: NCR VOYIX CORPORATION
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 065346/0168 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS SECTION TO REMOVE PATENT APPLICATION: 15000000 PREVIOUSLY RECORDED AT REEL: 050874 FRAME: 0063. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Apr 12, 2021
From: NCR CORPORATION
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 057047/0161 →
SECURITY INTEREST Recorded Oct 29, 2019
From: NCR CORPORATION
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 050874/0063 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 30, 2017
From: KOBRES, ERICK; ANTONAKAKIS, STAVROS
To: NCR CORPORATION
Reel/Frame 041553/0994 →
Continuity (2)
Continuation 14530133 · Oct 31, 2014
Related Publication 20170142142A1 · May 18, 2017