Methods and systems for integrated risk management in enterprise environments
US-2018068241-A1 · Mar 8, 2018 · US
US11070583B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-11070583-B2 |
| Application number | US-201916559791-A |
| Country | US |
| Kind code | B2 |
| Filing date | Sep 4, 2019 |
| Priority date | Mar 7, 2017 |
| Publication date | Jul 20, 2021 |
| Grant date | Jul 20, 2021 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
A method for automatically improving security of a network system includes: collecting security relevant information from network devices of the network system, the security relevant information including security settings and operational information of the network devices; analyzing the security relevant information for determining weak security settings of a network device, the weak security settings being not necessary for a regular operation of the network system; determining hardened security settings for the network devices based on the weak security settings, the hardened security settings restricting a possible operation of the network device but allow a regular operation of the network system; and applying the hardened security settings to the network device.
Opening claim text (preview).
The invention claimed is: 1. A method for automatically improving security of a network system, the method comprising: collecting security relevant information from network devices of the network system, the security relevant information including security settings and operational information of the network devices, wherein collecting the security relevant information is performed by one or more monitoring processes; determining a regular behavior of the network system from previously stored security relevant information; when security relevant information has been collected, instructing a coordinator process to analyze the security relevant information by the one or more monitoring processes; analyzing the security relevant information for determining weak security settings from collected security settings of a network device and from the regular behavior, the weak security settings being not necessary for a regular operation of the network system in accordance with the operational information, wherein analyzing the security relevant information is performed by analysis processes that are coordinated by the coordinator process, wherein information encoding regular behavior and corresponding security settings are grouped into groups, which are analyzed by different analysis processes; determining hardened security settings for the network device based on the weak security settings, the hardened security settings restricting a possible operation of the network device but allow a regular operation of the network system in accordance with the operational information, wherein the hardened security settings are determined by restricting weak security settings; applying the hardened security settings to the network device. 2. The method of claim 1 , further comprising: permanently storing the security relevant information in at least one storage device for generating a history of security relevant information of the network system. 3. The method of claim 2 , further comprising: determining irregular behavior of the network system by comparing actual collected security information with at least one of a regular behavior of the network system and previously stored security relevant information; stopping irregular behavior of a network system by applying changed security settings to network devices associated with the irregular behavior. 4. The method of claim 1 , wherein the security settings comprise at least one of: roles assigned to a user and/or a network device, rights of a role, firewall rules, opened/closed ports of a network device, installed and/or running processes on a network device. 5. The method of claim 1 , wherein the operational information comprises at least one of: a running process on a network device, a running time of a process on a network device, network traffic between network devices. 6. The method of claim 1 , wherein hardened security settings comprise at least one of: a removal of a role to a user and/or a network device, a removal of rights from a role, a modification of firewall rules, a closing of a port of a network device, a termination of a process on a network device, a removal of a process from a network device, a restricted running time of a process of a network device. 7. The method of claim 1 , wherein the security relevant information is collected by a monitoring device interconnected with the network system, which retrieves the security relevant information from the network device. 8. The method of claim 1 , wherein the security relevant information of a network device is collected by a monitoring process installed in the network device, which sends the security relevant information to a monitoring device. 9. The method of claim 1 , wherein the security relevant information is analysed by an analysis device and changed security settings are applied by a network hardening device connected to the network system. 10. The method of claim 4 , wherein the operational information comprises at least one of: a running process on a network device, a running time of a process on a network device, network traffic between network devices. 11. The method of claim 10 , wherein hardened security settings comprise at least one of: a removal of a role to a user and/or a network device, a removal of rights from a role, a modification of firewall rules, a closing of a port of a network device, a termination of a process on a network device, a removal of a process from a network device, a restricted running time of a process of a network device. 12. The method of claim 11 , wherein the security relevant information is collected by a monitoring device interconnected with the network system, which retrieves the security relevant information from at least one of said network devices of the network system. 13. The method of claim 12 , wherein the security relevant information is collected by a monitoring process installed in the at least one of said network devices of the network system, which sends the security relevant information to the monitoring device. 14. The method of claim 1 , wherein the regular behavior of the network system is determined based at least in part on network traffic information. 15. The method of claim 1 , wherein the regular behavior of the network system is determined based on a statistical determination of how the network system operates during a majority of a time period. 16. A non-transitory computer-readable medium for automatically improving security of a network system comprising: a set of instructions configured to be executed by at least one processor effective to: receive security relevant information from network devices of the network system, the security relevant information including security settings and operational information of the network devices, wherein the security relevant information is collected by one or more monitoring processes; determine a regular behavior of the network system from previously stored security relevant information; when security relevant information has been collected, instruct a coordinator process to analyze the security relevant information by the one or more monitoring processes; analyze the security relevant information for determining weak security settings from collected security settings of a network device and from the regular behavior, the weak security settings being not necessary for a regular operation of the network system in accordance with the operational information, wherein analyzing the security relevant information is performed by analysis processes that are coordinated by the coordinator process, wherein information encoding regular behavior and corresponding security settings are grouped into groups, which are analyzed by different analysis processes; determine hardened security settings for the network device based on the weak security settings, the hardened security settings restricting a possible operation of the network device but allow a regular operation of the network system in accordance with the operational information, wherein the hardened security settings are determined by restricting weak security settings; apply the hardened security settings to the network device. 17. A network monitoring and hardened system, comprising: at least one monitoring device including a first non-transitory computer-readable medium having a first set of instructions that, when executed by a first processor, is effective to collect security relevant information from network devices of a network system, the security relevant informat
Rule management · CPC title
Vulnerability analysis · CPC title
Countermeasures against malicious traffic (countermeasures against attacks on cryptographic mechanisms H04L9/002) · CPC title
Assessing vulnerabilities and evaluating computer system security · CPC title
for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.