Computer system vulnerability lockdown mode

US11620388B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11620388-B2
Application numberUS-201916686482-A
CountryUS
Kind codeB2
Filing dateNov 18, 2019
Priority dateNov 18, 2019
Publication dateApr 4, 2023
Grant dateApr 4, 2023

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Targeted lockdown of a computer system for an identified vulnerability is provided. The targeted lockdown includes configuring a vulnerability lockdown module implemented on a computer system to perform targeted actions to change a configuration of the computer system. The computer system may be scanned by a vulnerability scanner configured to identify vulnerabilities. In response to identifying a vulnerability, the vulnerability may be communicated to the vulnerability lockdown module and the vulnerability lockdown module may implement a vulnerability lockdown mode by causing the computer system to perform the targeted actions to change the configuration of the computer system by restricting functionality of portions of the computer system affected by the identified vulnerability.

First claim

Opening claim text (preview).

What is claimed is: 1. A computer-implemented method, comprising: configuring a vulnerability lockdown module implemented on a computer system to perform targeted actions to change a configuration of the computer system, wherein the computer system is a computer or network device connected to a network, and wherein the vulnerability lockdown module is part of an operating system (OS) of the computer system or an application executing on the OS of the computer system; identifying a vulnerability on the computer system by scanning with a vulnerability scanner; configuring one or more targeted actions to be performed by the computer system in response to identification of a specific vulnerability or type of vulnerability, wherein the targeted actions are configured based at least in part on a type of data stored on the computer system and a potential severity of an impact on the computer system if the vulnerability is exploited; communicating the vulnerability to the vulnerability lockdown module; and implementing, by the vulnerability lockdown module, a vulnerability lockdown mode by causing the computer system to perform the targeted actions to change the configuration of the computer system by restricting functionality of portions of the computer system affected by the identified vulnerability, wherein the targeted actions performed by the computer system comprise increased logging of activities of the computer system. 2. The computer-implemented method of claim 1 , wherein the vulnerability lockdown mode is operable to change the configuration of the computer system by limiting functionality of the computer system with respect to operations of the computer system that are affected by the identified vulnerability while permitting operations of the computer system unaffected by the identified vulnerability. 3. The computer-implemented method of claim 1 , further comprising: providing a notification requesting configuration information via a user interface device when the targeted actions have not been configured for an identified vulnerability. 4. The computer-implemented method of claim 1 , wherein the vulnerability lockdown module comprises a part of an operating system of the computer system. 5. The computer-implemented method of claim 1 , wherein the vulnerability lockdown module comprises an application executing on the computer system. 6. The computer-implemented method of claim 1 , further comprising: disabling the vulnerability lockdown mode when the identified vulnerability is no longer detected by a subsequent vulnerability scan. 7. A non-transitory computer readable medium having stored therein instructions that are executable by one or more processors to perform operations for providing a vulnerability lockdown mode, the operations including: configuring a vulnerability lockdown module to perform one or more targeted actions to change a configuration of a computer system, wherein the computer system is a computer or network device connected to a network, and wherein the vulnerability lockdown module is part of an operating system (OS) of the computer system or an application executing on the OS of the computer system; identifying vulnerabilities on the computer system; configuring one or more targeted actions to be performed by the computer system in response to identification of a specific vulnerability or type of vulnerability, wherein the targeted actions are configured based at least in part on a type of data stored on the computer system and a potential severity of an impact on the computer system if the vulnerability is exploited; communicating the vulnerability to the vulnerability lockdown module; and implementing a vulnerability lockdown mode by the vulnerability lockdown module by causing the computer system to perform the targeted actions, wherein the targeted actions include increased logging of activities of the computer system, to change the configuration of the computer system by restricting functionality of portions of the computer system affected by the identified vulnerability. 8. The non-transitory computer readable medium of claim 7 , further comprising instruction for performing operations to implement the vulnerability lockdown mode, the operations including: changing the configuration of the computer system by limiting functionality of the computer system with respect to operations of the computer system that are affected by the identified vulnerability while permitting operations of the computer system unaffected by the identified vulnerability. 9. The non-transitory computer readable medium of claim 7 , further comprising instruction for performing operations including: providing a notification requesting configuration information via a user interface device when the targeted actions have not been configured for an identified vulnerability. 10. The non-transitory computer readable medium of claim 7 , further comprising instruction for performing operations including: disabling the vulnerability lockdown mode when the identified vulnerability is no longer detected. 11. A computer system, comprising: a non-transitory memory configured to store processor readable instructions; and a processor coupled to the memory and operable to execute the processor readable instructions for performing operations including: configuring a vulnerability lockdown module to perform one or more targeted actions to change a configuration of the computer system, wherein the computer system is a computer or network device connected to a network, and wherein the vulnerability lockdown module is part of an operating system (OS) of the computer system or an application executing on the OS of the computer system; identifying vulnerabilities on the computer system; configuring one or more targeted actions to be performed by the computer system in response to identification of a specific vulnerability or type of vulnerability, wherein the targeted actions are configured based at least in part on a type of data stored on the computer system and a potential severity of an impact on the computer system if the vulnerability is exploited; communicating the vulnerability to the vulnerability lockdown module; and implementing a vulnerability lockdown mode by the vulnerability lockdown module by causing the computer system to perform the targeted actions, wherein the targeted actions include increased logging of activities of the computer system, to change the configuration of the computer system by restricting functionality of portions of the computer system affected by the identified vulnerability. 12. The computer system of claim 11 , wherein the processor is further operable to execute the processor readable instructions for performing operations including: changing the configuration of the computer system by limiting functionality of the computer system only with respect to operations of the computer system that are affected by the identified vulnerability while permitting operations of the computer system unaffected by the identified vulnerability. 13. The computer system of claim 11 , wherein the processor is further operable to execute the processor readable instructions for performing operations including: providing a notification requesting configuration information via a user interface device when the targeted actions have not been configured for an identified vulnerability. 14. The computer system of claim 11 , wherein the processor is further operable to execute the processor readable instructions for performing operations including: disabling the vulnerability lockdown mode when the identified vuln

Assignees

Inventors

Classifications

  • involving event detection and direct action · CPC title

  • G06F21/577Primary

    Assessing vulnerabilities and evaluating computer system security · CPC title

  • Test or assess a computer or a system · CPC title

  • G06F21/57Primary

    Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities · CPC title

  • Vulnerability analysis · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11620388B2 cover?
Targeted lockdown of a computer system for an identified vulnerability is provided. The targeted lockdown includes configuring a vulnerability lockdown module implemented on a computer system to perform targeted actions to change a configuration of the computer system. The computer system may be scanned by a vulnerability scanner configured to identify vulnerabilities. In response to identifyin…
Who is the assignee on this patent?
Branch Banking &Trust Co, Truist Bank
What technology area does this patent fall under?
Primary CPC classification G06F21/577. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Apr 04 2023 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 1 related publication on this page (citations in our corpus or others sharing the same primary CPC).