Systems and methods for tracking and managing event records associated with network incidents
US-9049105-B1 · Jun 2, 2015 · US
US9246935B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-9246935-B2 |
| Application number | US-201314052971-A |
| Country | US |
| Kind code | B2 |
| Filing date | Oct 14, 2013 |
| Priority date | Oct 14, 2013 |
| Publication date | Jan 26, 2016 |
| Grant date | Jan 26, 2016 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
One or more relevant scanners used to identify asset vulnerabilities are identified, obtained, and logically arranged for deployment on an asset in accordance with a vulnerability management policy and a scanner deployment policy such that the relevant scanners are deployed at, or before, a determined ideal time to minimize the resources necessary to correct the vulnerabilities, if found. The relevant scanners are then automatically deployed in accordance with the scanner deployment policy and, if a vulnerability is identified, one or more associated remedies or remedy procedures are applied to the asset. At least one of the one or more relevant scanners are then re-deployed on the asset to determine if the identified vulnerability has been corrected and, if the vulnerability is not corrected at, or before, a defined time, protective measures are automatically taken.
Opening claim text (preview).
What is claimed is: 1. A system for dynamic and comprehensive vulnerability management comprising: at least one processor; and at least one memory unit coupled to the at least one processor, the at least one memory unit having stored therein instructions which when executed by any set of the one or more processors, perform a process for dynamic and comprehensive vulnerability management, the process for dynamic and comprehensive vulnerability management including: obtaining vulnerability management data; obtaining scanner data representing one or more scanner tests configured to discover one or more vulnerabilities in an asset; obtaining remedy data representing two or more remedies associated with vulnerabilities scanned for by the one or more scanner tests, the two or more remedies including a first remedy of automatic re-sizing of buffers and buffer pools and a second remedy of automatic re-setting or changing a response time; correlating the remedy data with vulnerabilities discoverable by the scanner tests; obtaining asset data associated with an asset; analyzing the vulnerability management data and the asset data to automatically identify a relevant scanner test in the scanner data to be applied to the asset; determining an ideal time to deploy the relevant scanner test on the asset; automatically deploying the relevant scanner test on the asset at, or before, the ideal time; if a vulnerability is identified by the relevant scanner test, identifying the remedy in the remedy data associated with the identified vulnerability; automatically applying the identified remedy to the asset; automatically re-deploying the relevant scanner on the asset to determine if the identified vulnerability has been corrected; and if the identified vulnerability is present after the remedy associated with the identified vulnerability has been applied taking protective action to mitigate the vulnerability. 2. The system for dynamic and comprehensive vulnerability management of claim 1 wherein the vulnerability management data is open-ended to allow for the addition, deletion, and modification of vulnerabilities and vulnerability characteristics represented by the vulnerability management data. 3. The system for dynamic and comprehensive vulnerability management of claim 1 wherein the scanner data is open-ended to allow for the addition, deletion, and modification of scanner tests represented by the scanner data. 4. The system for dynamic and comprehensive vulnerability management of claim 1 wherein the remedy data is open-ended to allow for the addition, deletion, and modification of remedies represented by the remedy data. 5. The system for dynamic and comprehensive vulnerability management of claim 1 wherein at least one of the vulnerabilities discoverable by the one or more scanner tests are vulnerabilities included in the group of vulnerabilities consisting of: the existence of a known weakness pattern in the asset; an incorrect buffer length; the inability of the asset to patch correctly; a lack of security requirements, or insufficient security requirements associated with the asset; the existence of a known vulnerable version of software or code; code written in a language, or version of a language, known to be vulnerable to attack; lack of encryption, or the proper level of encryption; no checks of buffer lengths; no checks of the integrity of arguments; and any combination thereof. 6. The system for dynamic and comprehensive vulnerability management of claim 1 wherein at least one of the remedies associated with vulnerabilities discoverable by the scanner tests is selected from the group of remedies consisting of: automatic application of a software patch; automatic installation of a software version update; automatic deletion of an asset component; automatic replacement of an asset component; automatic notification of a contact entity associated with the asset of the vulnerability and the need to correct the vulnerability; an automatic change to a configuration; and any combination thereof. 7. The system for dynamic and comprehensive vulnerability management of claim 1 wherein at least one of the one or more assets is selected from the group of assets consisting of: a file; an application development process; an application; a virtual machine; an instance in a cloud infrastructure; storage capability allocated to an instance in a cloud infrastructure; processing capability allocated to an instance in a cloud infrastructure; hardware allocated to an instance in a cloud infrastructure; software allocated to an instance in a cloud infrastructure; a cloud infrastructure access system; and any combination thereof. 8. The system for dynamic and comprehensive vulnerability management of claim 1 wherein the ideal time to deploy the relevant scanner test on the asset is determined based on deploying the relevant scanner test at a time where minimum resources are required to correct the vulnerability being scanned for. 9. The system for dynamic and comprehensive vulnerability management of claim 1 wherein the protective action taken is selected from the group of protective actions consisting of: closing one or more accounts associated with the asset; closing down a service that is the asset or is associated with the asset; closing down an instance that is the asset or is associated with the asset; destroying a data store that is the asset or is associated with the asset; blocking Internet access to the asset; closing down any communication channels that are the asset or are associated with the asset; upgrading the asset; replacing the asset; and any combination thereof. 10. A system for dynamic and comprehensive vulnerability management comprising: at least one processor; and at least one memory unit coupled to the at least one processor, the at least one memory unit having stored therein instructions which when executed by any set of the one or more processors, perform a process for dynamic and comprehensive vulnerability management, the process for dynamic and comprehensive vulnerability management including: obtaining vulnerability management data; obtaining scanner data representing one or more scanner tests configured to discover one or more vulnerabilities in an asset; obtaining remedy data representing one or more remedy procedures associated with vulnerabilities discoverable by the one or more scanner tests, the one or more remedy procedures indicating an associated vulnerability correction time period within which the vulnerability must be corrected, the remedy data further including two remedies including a first remedy of automatic re-sizing of buffers and buffer pools and a second remedy of automatic re-setting or changing a response time; correlating the remedy data with vulnerabilities discoverable by the scanner tests; obtaining asset data associated with an asset; analyzing the vulnerability management data and the asset data to automatically identify a relevant scanner in the scanner data to be applied to the asset; determining an ideal time to deploy the relevant scanner test on the asset; automatically deploying the relevant scanner test on the asset at, or before, the determined ideal time; if a vulnerability is identified by the relevant scanner test, identifying the remedy procedure in the remedy data associated with the identified vulnerability; automatically implementing the identified remedy procedure; automatically re-deploying the relevant scanner test on the asset to determine if the identified vulnerability has been corrected; and if the identified vulnerability is present after the defined vulnerab
involving the movement of software or configuration parameters (network booting or remote initial program loading [RIPL] G06F9/4416) · CPC title
by source code analysis · CPC title
Vulnerability analysis · CPC title
for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title
Countermeasures against malicious traffic (countermeasures against attacks on cryptographic mechanisms H04L9/002) · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.