Systems and methods for analyzing vulnerabilities of networked systems

US11533328B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11533328-B2
Application numberUS-201916433688-A
CountryUS
Kind codeB2
Filing dateJun 6, 2019
Priority dateJun 6, 2019
Publication dateDec 20, 2022
Grant dateDec 20, 2022

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Methods and systems for assessing and evaluating vulnerabilities of a networked system are presented. A list of known vulnerabilities that have been disclosed in the public may be obtained. The networked system may be scanned from an external perspective to obtain network information of the networked system. A subset of the known vulnerabilities may be determined to be relevant to the networked system based on correlations between the vulnerabilities and the network information. The networked system may also be analyzed from an internal perspective to determine impacts of the relevant known vulnerabilities to the networked system. The impact of a vulnerability may be determined based on the type of data and/or the type of services that may be accessible in an attack that exploits the vulnerability. The vulnerabilities may then be ranked and addressed based on the impacts.

First claim

Opening claim text (preview).

What is claimed is: 1. A system for assessing vulnerabilities of a networked system, comprising: a non-transitory memory; and one or more hardware processors coupled with the non-transitory memory and configured to read instructions from the non-transitory memory to cause the system to perform operations comprising: monitoring, via a first device and based on a first perspective external to the networked system, a plurality of open access points usable for gaining access to the networked system; determining, based on the monitoring, that a subset of the plurality of open access points corresponds to a first vulnerability among a plurality of known network vulnerabilities; analyzing the networked system via a second device and based on a second perspective internal to the networked system, wherein the analyzing the networked system comprises (i) identifying, based on a network topology associated with the networked system, a portion of the networked system accessible through the subset of the plurality of open access points and (ii) determining a particular type of data stored within the portion of the networked system and accessible through the subset of the plurality of open access points; determining a sensitivity level of the particular type of data; determining an impact of the first vulnerability to the networked system based at least in part on the analyzing and the sensitivity level of the particular type of data, wherein the impact represents a potential exposure of the particular type of data due to an attack associated with the first vulnerability; and determining a severity of the first vulnerability for the networked system based on the impact. 2. The system of claim 1 , wherein the first vulnerability is associated with a particular network communication protocol. 3. The system of claim 1 , wherein the first vulnerability is associated with a service provided by the networked system. 4. The system of claim 1 , wherein the operations further comprise determining a likelihood that the attack associated with the first vulnerability will occur based on at least one of a plurality of factors comprising: a number of available computer tools configured to exploit the first vulnerability, an amount of communication associated with the first vulnerability, a duration of time that the first vulnerability has been disclosed, or a number of previous attacks based on the first vulnerability, and wherein the severity of the first vulnerability is further based on the likelihood of the attack. 5. The system of claim 4 , wherein the determining the severity comprises using a machine learning model to estimate the severity of the first vulnerability based on at least one of the plurality of factors and the determined impact of the first vulnerability to the networked system. 6. The system of claim 1 , wherein the analyzing the networked system further comprises identifying a set of services provided by the networked system through the subset of the plurality of open access points. 7. The system of claim 1 , wherein the determining the impact comprises determining a type of service that can be interrupted based on the attack on the networked system. 8. A method for assessing vulnerabilities of a networked system, comprising: obtaining information regarding a plurality of network vulnerabilities; scanning, based on a first perspective external to the networked system, a plurality of open access points usable to gain access to the networked system; determining that a first network vulnerability from the plurality of network vulnerabilities is relevant to the networked system based on the scanning and a correlation between the first network vulnerability and a first open access point from the plurality of open access points; analyzing the networked system based on a second perspective internal to the networked system, wherein the analyzing the networked system comprises (i) identifying, based on a network topology associated with the networked system, a portion of the networked system accessible through the first open access point and (ii) determining a particular type of data stored within the portion of the networked system and accessible through the first open access point; determining a sensitivity level of the particular type of data; and determining an impact of the first network vulnerability to the networked system based on the analyzing and the sensitivity level of the particular type of data, wherein the impact represents a potential exposure of the particular type of data due to an attack associated with the first network vulnerability. 9. The method of claim 8 , wherein the networked system is configured to provide a set of services via the first open access point, and wherein the impact determined for the first network vulnerability represents an amount of time that the set of services will be interrupted based on the attack. 10. The method of claim 8 , further comprising: determining the correlation between the first network vulnerability and the first open access point, wherein the correlation indicates that the first open access point is usable to exploit the first network vulnerability within the networked system. 11. The method of claim 8 , further comprising: ranking the plurality of network vulnerabilities based on determined impacts of the plurality of network vulnerabilities on the networked system; and presenting, on a device within the networked system, the ranking of the plurality of network vulnerabilities. 12. The method of claim 8 , further comprising re-configuring the networked system based on the impact determined for the first network vulnerability. 13. The method of claim 12 , wherein the re-configuring the networked system comprises modifying a security policy associated with at least one of the plurality of open access points. 14. The method of claim 12 , wherein the re-configuring the networked system comprises closing at least one of the plurality of open access points. 15. A non-transitory machine-readable medium having stored thereon machine-readable instructions executable to cause a machine to perform operations comprising: monitoring, via a first device and based on a first perspective external to a networked system, a plurality of open access points usable for gaining access to the networked system; determining, based on the monitoring, that a subset of the plurality of open access points corresponds to a first vulnerability among a plurality of vulnerabilities; analyzing the networked system via a second device and based on a second perspective internal to the networked system, wherein the analyzing the networked system comprises (i) identifying, based on a network topology associated with the networked system, a portion of the networked system accessible through the subset of the plurality of open access points and (ii) determining a particular type of data stored within the portion of the networked system and accessible through the subset of the plurality of open access points; determining a sensitivity level of the particular type of data; determining an impact of the first vulnerability to the networked system based at least in part on the analyzing and the sensitivity of the particular type of data, wherein the impact represents a potential exposure of the particular type of data due to an attack associated with the first vulnerability; and determining a severity of the first vulnerability for the networked system based on the impact. 16. The non-transitory machine-readable medium of claim 15 , wherein the first vulnerability is associa

Assignees

Inventors

Classifications

  • by monitoring network traffic (monitoring network traffic per se H04L43/00) · CPC title

  • Learning methods · CPC title

  • Vulnerability analysis · CPC title

  • based on web technology, e.g. hypertext transfer protocol [HTTP] · CPC title

  • Machine learning · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11533328B2 cover?
Methods and systems for assessing and evaluating vulnerabilities of a networked system are presented. A list of known vulnerabilities that have been disclosed in the public may be obtained. The networked system may be scanned from an external perspective to obtain network information of the networked system. A subset of the known vulnerabilities may be determined to be relevant to the networked…
Who is the assignee on this patent?
Paypal Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/1408. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Dec 20 2022 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 3 related publications on this page (citations in our corpus or others sharing the same primary CPC).