US2008005784A1PendingUtilityA1
Proactive network security systems to protect against hackers
Est. expiryJul 25, 2023(expired)· nominal 20-yr term from priority
Inventors:Gary S. Miliefsky
H04L 63/0272H04L 63/1433
49
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
A proactive network security system to protect against hackers for the proactive automated defense against hackers by automatically finding, reporting, communicating with countermeasures about and removing the common vulnerabilities and exposures (CVEs) that they exploit.
Claims
exact text as granted — not AI-modified1 - 11 . (canceled)
12 . A method comprising:
scanning a network system to locate one or more assets; creating an asset list that includes a location of each of the one or more assets; monitoring the network system and updating the asset list; periodically updating a schedule of common vulnerabilities and exposures auditing at least one of the one or more assets for common vulnerabilities and exposures according to the schedule to provide audit data; providing the audit data to an information security system and responsively deploying one or more countermeasures.
13 . The method of claim 12 wherein the assets include one or more of LAN connected equipment and WAN connected equipment.
14 . The method of claim 12 wherein the asset list includes an IP address of each of the one or more assets.
15 . The method of claim 12 wherein the asset list identifies open ports for each of the one or more assets.
16 . The method of claim 12 wherein for each of the one or more assets, the list identifies one or more of a Media Access Control address, application information, session information, transport information, socket information, and a connection type.
17 . The method of claim 12 providing at least two information security systems, wherein each of the at least two information security systems is adapted to assume functions of other ones of the at least two information security systems in the event of a malfunction.
18 . A system for network security, comprising:
a dynamic mapping engine that monitors assets on a network and detects when an asset is added to or removed from the network, the dynamic mapping engine providing asset identification data; a gateway between one or more of the assets and the network; an interface to administer a policy relating to use of the network via the gateway; and a countermeasures communication engine administered through the interface, the countermeasures communication engine responsive to the policy to control one or more countermeasures with reference to a plurality of vulnerabilities.
19 . The system of claim 18 wherein the gateway is a software gateway.
20 . The system of claim 18 wherein the plurality of vulnerabilities include Common Vulnerabilities and Exposures.
21 . The system of claim 18 wherein the dynamic mapping engine uses asset-identification data including one or more of a MAC address, an IP address and a port.
22 . The system of claim 18 wherein the policy and the countermeasures communication engine cooperate to limit access to the network through the gateway according to at least one of MAC addresses, IP addresses, and ports.
23 . The system of claim 18 wherein the countermeasures communication engine updates a firewall to block traffic related to at least one of the plurality of vulnerabilities.
24 . A user interface, the user interface providing one or more controls to administer a policy relating to use of a network through a software gateway that resides between users and the network, wherein the policy is applied with reference to a list of vulnerabilities.
25 . The user interface of claim 24 wherein the list of vulnerabilities includes Common Vulnerabilities and Exposures.
26 . The user interface of claim 24 wherein the user interface includes a dashboard.
27 . The user interface of claim 24 wherein the user interface integrates management of an intrusion prevention system, network behavior analysis, and vulnerability assessment.
28 . The user interface of claim 24 wherein the user interface receives user input controlling an intrusion detection system that provides alerts as to traffic anomalies.
29 . The user interface of claim 24 wherein the user interface receives user input controlling an intrusion protection system that blocks an intruder.
30 . A method comprising:
operating a virtual private network that provides access to one or more network assets according to an access list; detecting a new asset on the virtual private network that contains a vulnerability requiring remediation; and in response to detecting the new asset, altering the access list to block traffic with the new asset.
31 . The method of claim 30 wherein the vulnerability includes a Common Vulnerability and Exposure.Join the waitlist — get patent alerts
Track US2008005784A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.