US2005171737A1PendingUtilityA1

Method and apparatus for assessing the security of a computer system

Priority: Jun 15, 1998Filed: Apr 7, 2005Published: Aug 4, 2005
Est. expiryJun 15, 2018(expired)· nominal 20-yr term from priority
G06Q 30/06H04L 63/1433
46
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method and apparatus performs a security analysis on a computer system to identify, notify, and possibly correct, vulnerabilities and discrepancies. The security system includes a number of security tools and utilities in order to perform these functions. The security system includes the capability to identify the system configuration and once this is done performs different processes to analyze the computer system directories, locate vulnerabilities in the files or directories, check the network access, do analysis of the users or groups which have access to the computer system and check the permissions which these parties have been granted, and analyze passwords of the users. The utilities include the functionality to permanently remove files from the computer system, mark particular files to be analyzed, as well as schedule the security tests to be performed at predetermined times.

Claims

exact text as granted — not AI-modified
1 . A computer security system, comprising: 
 a configuration/set-up module that operates under direction of a processor of a computer system and that identifies security critical files of the computer system;    a directory checking module that operates under direction of the processor and that identifies unauthorized changes to the security critical files; and    a user manager module that operates under direction of the processor and that identifies unauthorized access to the security critical files.    
   
   
       2 . The computer security system of  claim 1 , further comprising an integrity checking module that operates under direction of the processor and that identifies one or more files stored in memory that correspond to one or more files in a database of known security threats.  
   
   
       3 . The computer security system of  claim 2 , further comprising a file removal module that operates under direction of the processor and that removes the files from the memory when corresponding to the files in the database.  
   
   
       4 . The computer security system of  claim 1 , the computer system comprising a data network.  
   
   
       5 . The computer security system of  claim 4 , further comprising a network checking module that operates under direction of the processor and that detects excessive system service use on at least one access port of the network.  
   
   
       6 . The computer security system of  claim 1 , further comprising a password checking module that operates under direction of the processor and that (a) tests the integrity of user passwords and (b) identifies weak user passwords.  
   
   
       7 . The computer security system of  claim 1 , further comprising a reporting module that operates under direction of the processor and that provides status information pertaining to the computer security system to a system administrator.  
   
   
       8 . The computer security system of  claim 1 , further comprising at least one graphical user interface through which a user may command the processor.  
   
   
       9 . The computer security system of  claim 1 , further comprising a file marking module that operates under direction of the processor and that facilitates selection or deselection of the security critical files.  
   
   
       10 . The computer security system of  claim 1 , further comprising a scheduling module that operates under direction of the processor and that facilitates execution scheduling of one or more of the modules.  
   
   
       11 . The computer security system of  claim 1 , the computer system comprising a UNIX server.  
   
   
       12 . A software product comprising instructions, stored on computer-readable media, wherein the instructions, when executed by a computer, perform steps for identifying and removing unwanted users from computer resources, comprising: 
 instructions for identifying security critical files;    instructions for identifying unauthorized changes or unauthorized access to the security critical files;    instructions for detecting excessive system service use;    instructions for testing the integrity of user passwords or for identifying weak user passwords; and    instructions for reporting the unauthorized changes, unauthorized access, excessive system service use or weak user passwords to a system administrator.    
   
   
       13 . The software product of  claim 12 , further comprising instructions for identifying corrective measures.  
   
   
       14 . The software product of  claim 13 , further comprising instructions for initiating the corrective measures.  
   
   
       15 . The software product of  claim 12 , further comprising instructions for blocking the unauthorized changes, unauthorized access, excessive system service use or weak user passwords.  
   
   
       16 . The software product of  claim 12 , wherein the instructions for reporting further comprise instructions for displaying a result on a graphical user interface.  
   
   
       17 . A method of analyzing and protecting the security of a local area network (LAN), comprising: 
 directing a computer processor to execute a password checking module that carries out the steps of:    retrieving user passwords from a database;    comparing the user passwords to a word list;    comparing the user passwords to pseudo words generated by a word filtering program; and    identifying the user passwords that match the word list or the pseudo words as potential security threats.    
   
   
       18 . The method of  claim 17 , further comprising the step of notifying users who have selected the user passwords that are potential security threats.  
   
   
       19 . The method of  claim 17 , further comprising the step of removing access privileges from the users who have selected the user passwords that are potential security threats.  
   
   
       20 . The method of  claim 17 , further comprising the step of displaying a result.

Join the waitlist — get patent alerts

Track US2005171737A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.