US2008005784A1PendingUtilityA1

Proactive network security systems to protect against hackers

Assignee: MILIEFSKY GARYPriority: Jul 25, 2003Filed: Jun 28, 2007Published: Jan 3, 2008
Est. expiryJul 25, 2023(expired)· nominal 20-yr term from priority
H04L 63/0272H04L 63/1433
49
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A proactive network security system to protect against hackers for the proactive automated defense against hackers by automatically finding, reporting, communicating with countermeasures about and removing the common vulnerabilities and exposures (CVEs) that they exploit.

Claims

exact text as granted — not AI-modified
1 - 11 . (canceled)  
     
     
         12 . A method comprising: 
 scanning a network system to locate one or more assets;    creating an asset list that includes a location of each of the one or more assets;    monitoring the network system and updating the asset list;    periodically updating a schedule of common vulnerabilities and exposures    auditing at least one of the one or more assets for common vulnerabilities and exposures according to the schedule to provide audit data;    providing the audit data to an information security system and responsively deploying one or more countermeasures.    
     
     
         13 . The method of  claim 12  wherein the assets include one or more of LAN connected equipment and WAN connected equipment.  
     
     
         14 . The method of  claim 12  wherein the asset list includes an IP address of each of the one or more assets.  
     
     
         15 . The method of  claim 12  wherein the asset list identifies open ports for each of the one or more assets.  
     
     
         16 . The method of  claim 12  wherein for each of the one or more assets, the list identifies one or more of a Media Access Control address, application information, session information, transport information, socket information, and a connection type.  
     
     
         17 . The method of  claim 12  providing at least two information security systems, wherein each of the at least two information security systems is adapted to assume functions of other ones of the at least two information security systems in the event of a malfunction.  
     
     
         18 . A system for network security, comprising: 
 a dynamic mapping engine that monitors assets on a network and detects when an asset is added to or removed from the network, the dynamic mapping engine providing asset identification data;    a gateway between one or more of the assets and the network;    an interface to administer a policy relating to use of the network via the gateway; and    a countermeasures communication engine administered through the interface, the countermeasures communication engine responsive to the policy to control one or more countermeasures with reference to a plurality of vulnerabilities.    
     
     
         19 . The system of  claim 18  wherein the gateway is a software gateway.  
     
     
         20 . The system of  claim 18  wherein the plurality of vulnerabilities include Common Vulnerabilities and Exposures.  
     
     
         21 . The system of  claim 18  wherein the dynamic mapping engine uses asset-identification data including one or more of a MAC address, an IP address and a port.  
     
     
         22 . The system of  claim 18  wherein the policy and the countermeasures communication engine cooperate to limit access to the network through the gateway according to at least one of MAC addresses, IP addresses, and ports.  
     
     
         23 . The system of  claim 18  wherein the countermeasures communication engine updates a firewall to block traffic related to at least one of the plurality of vulnerabilities.  
     
     
         24 . A user interface, the user interface providing one or more controls to administer a policy relating to use of a network through a software gateway that resides between users and the network, wherein the policy is applied with reference to a list of vulnerabilities.  
     
     
         25 . The user interface of  claim 24  wherein the list of vulnerabilities includes Common Vulnerabilities and Exposures.  
     
     
         26 . The user interface of  claim 24  wherein the user interface includes a dashboard.  
     
     
         27 . The user interface of  claim 24  wherein the user interface integrates management of an intrusion prevention system, network behavior analysis, and vulnerability assessment.  
     
     
         28 . The user interface of  claim 24  wherein the user interface receives user input controlling an intrusion detection system that provides alerts as to traffic anomalies.  
     
     
         29 . The user interface of  claim 24  wherein the user interface receives user input controlling an intrusion protection system that blocks an intruder.  
     
     
         30 . A method comprising: 
 operating a virtual private network that provides access to one or more network assets according to an access list;    detecting a new asset on the virtual private network that contains a vulnerability requiring remediation; and    in response to detecting the new asset, altering the access list to block traffic with the new asset.    
     
     
         31 . The method of  claim 30  wherein the vulnerability includes a Common Vulnerability and Exposure.

Join the waitlist — get patent alerts

Track US2008005784A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.