Method and arrangement for monitoring computer manipulations
First Claim
Patent Images
1. A method of monitoring manipulations on user computers which are connected via a network comprising the steps of:
- making a plurality of inquires at different respective time intervals, during operation of the user computers, and comparing attributes of databases of the user computers with protectedly stored reference values of the attributes and, in the event of non-correspondence, triggering an alarm; and
carrying out the plurality of inquires, the comparison and the alarm triggering by a monitoring device, which is physically not accessible to intruders and which is isolated from the network to the extent that an intruder on the network cannot access the monitoring device from a user computer, the monitoring device being connected to the user computers, the databases of the user computer being not interrogatable other than by the monitoring device.
2 Assignments
0 Petitions
Accused Products
Abstract
Method and arrangement for monitoring manipulations on computers (3) which are connected via a network (2), in the method attributes being inquired automatically from databases of the computers (3) and compared with protectedly stored reference values of the attributes, and an alarm being triggered in the event of non-correspondence. The inquiry, the comparison and the alarm triggering are carried out by a monitoring device (1) which is physically not accessible to intruders, is connected to the computers (3) and the databases of which, containing the reference values, cannot be interrogated.
216 Citations
18 Claims
-
1. A method of monitoring manipulations on user computers which are connected via a network comprising the steps of:
- making a plurality of inquires at different respective time intervals, during operation of the user computers, and comparing attributes of databases of the user computers with protectedly stored reference values of the attributes and, in the event of non-correspondence, triggering an alarm; and
carrying out the plurality of inquires, the comparison and the alarm triggering by a monitoring device, which is physically not accessible to intruders and which is isolated from the network to the extent that an intruder on the network cannot access the monitoring device from a user computer, the monitoring device being connected to the user computers, the databases of the user computer being not interrogatable other than by the monitoring device. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13)
- making a plurality of inquires at different respective time intervals, during operation of the user computers, and comparing attributes of databases of the user computers with protectedly stored reference values of the attributes and, in the event of non-correspondence, triggering an alarm; and
-
14. An arrangement for monitoring manipulations on user computers which are connected via a network, comprising:
- an interrogation means for automatic interrogation of the databases of the user computers at different respective time intervals, during operation of the user computers, a means for comparing attributes of the databases of the user computers to rated values stored in protected fashion, and an alarm triggering means that triggers an alarm given non-coincidence of the attributes of the databases and the rated values, said alarm triggering means being responsive to said means for comparing that utilizes the attributes of the databases that are determined by the interrogation means;
a central monitoring device, which is physically not accessible to intruders and which is isolated from the network to the extent that an intruder on the network cannot access the monitoring device from a user computer, connected to the user computers, means for providing that the monitoring device can access the user computers without the user computers being able to access the monitoring device, the monitoring device connected to the user computers via the network and containing the interrogation means, the means for comparing and the alarm triggering means. - View Dependent Claims (15)
- an interrogation means for automatic interrogation of the databases of the user computers at different respective time intervals, during operation of the user computers, a means for comparing attributes of the databases of the user computers to rated values stored in protected fashion, and an alarm triggering means that triggers an alarm given non-coincidence of the attributes of the databases and the rated values, said alarm triggering means being responsive to said means for comparing that utilizes the attributes of the databases that are determined by the interrogation means;
-
16. A method of monitoring manipulations on a plurality of user computers which are connected via a network in a client-server architecture, comprising the steps of:
-
providing a monitoring device having a plurality of reference values stored therein and being configured such that no service programs in the client-server architecture are active or are activatable on the monitoring device; connecting the monitoring device to a respective user computer of said plurality of user computers such that the monitoring device initiates communication at different points in time with said respective user computer, and receives only answers from said respective user computer, a connection being established between the monitoring device and the respective user computer such that an intruder on the network cannot access the monitoring device from the respective user computer; sending a request from the monitoring device to the respective user computer, the respective user computer calculating an attribute of a database stored therein and sending said attribute to the monitoring device; comparing, in the monitoring device, the calculated attribute to at least one of the reference values in the monitoring device; and, in the event of non-correspondence between the calculated attribute and the at least one of the reference values, triggering an alarm. - View Dependent Claims (17, 18)
-
Specification