US2008047019A1PendingUtilityA1

Method and apparatus for computer network security

Assignee: IBMPriority: Aug 16, 2006Filed: Aug 16, 2006Published: Feb 21, 2008
Est. expiryAug 16, 2026(~0 yrs left)· nominal 20-yr term from priority
H04L 63/1425H04L 63/0815H04L 63/0876
49
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Techniques are provided for computer network security. The techniques include obtaining operational data for at least a first networked application; obtaining enterprise data for at least a second networked application; correlating the operational data with the enterprise data to obtain correlated data; and using the correlated data to improve security of the computer network.

Claims

exact text as granted — not AI-modified
1 . A method for improving security in a computer network, comprising the steps of:
 obtaining operational data for at least a first networked application;   obtaining enterprise data for at least a second networked application;   correlating said operational data with said enterprise data to obtain correlated data; and   using said correlated data to improve security of said computer network.   
   
   
       2 . The method according to  claim 1 , wherein said first and second networked applications are the same application. 
   
   
       3 . The method according to  claim 1 , wherein said first and second networked applications are different applications. 
   
   
       4 . The method according to  claim 1 , further comprising the additional step of converting said operational data into an operational data canonical form. 
   
   
       5 . The method according to  claim 1 , further comprising the additional step of converting said enterprise data into an enterprise data canonical form. 
   
   
       6 . The method according to  claim 1 , wherein:
 said operational data comprises a record of a unique address allocation to a user device attempting to access said computer network;   said enterprise data comprises credentials associated with local authentication at said user device;   the step of correlating said operational data with said enterprise data to obtain correlated data comprises associating said unique address and said credentials with authentication information stored in a single-sign-on server; and   the step of using said correlated data to improve security of said computer network comprises providing a user of said user device with single sign-on ability responsive to an indication of an appropriate match between said unique address and said credentials and said authentication information.   
   
   
       7 . The method according to  claim 6 , wherein said unique address comprises an IP address. 
   
   
       8 . The method according to  claim 6 , wherein said credentials comprise biometric credentials. 
   
   
       9 . The method according to  claim 6 , further comprising an additional step of eliminating said single sign-on ability of said user when said user disconnects from said computer network. 
   
   
       10 . The method according to  claim 1 , wherein said step of using the correlated data to improve network security further comprises the steps of:
 obtaining indication of a violation within said computer network;   terminating access to said computer network for a device associated with said violation; and   notifying a user of said device that access to said computer network has been terminated, using said correlated data.   
   
   
       11 . The method according to  claim 10 , wherein said violation comprises a virus. 
   
   
       12 . The method according to  claim 10 , wherein said violation comprises a security violation. 
   
   
       13 . The method according to  claim 10 , wherein said violation comprises improper software. 
   
   
       14 . The method according to  claim 1 , wherein:
 said operational data comprises:
 an IP address of a remote party of a connection with said computer network; 
 and a domain name associated with said IP address; 
   said enterprise data comprises user registration information maintained by a provider of network connectivity to said remote party of said connection;   the step of correlating said operational data with said enterprise data to obtain correlated data comprises checking that said domain name displayed to a local party of said connection matches said user registration information; and   the step of using said correlated data to improve security of said computer network comprises displaying an alert to said local party of said connection based on an outcome of said correlating step.   
   
   
       15 . The method according to  claim 14  wherein said connection comprises an HTTP protocol Internet connection. 
   
   
       16 . An apparatus for improving security in a computer network, comprising:
 a memory; and   at least one processor coupled to said memory and operative to:   obtain operational data for at least one networked application;   obtain enterprise data for at least one networked application;   correlate said operational data with said enterprise data to obtain correlated data; and   use said correlated data to improve security of said computer network.   
   
   
       17 . The apparatus of  claim 16 , wherein:
 said operational data comprises a record of a unique address allocation to a user device attempting to access said computer network;   said enterprise data comprises credentials associated with local authentication at said user device; and said at least one processor is further operative to:   correlate said operational data with said enterprise data to obtain correlated data by associating said unique address and said credentials with authentication information stored in a single-sign-on server; and   use said correlated data to improve security of the computer network by providing a user of said user device with single sign-on ability responsive to an indication of an appropriate match between said unique address and said credentials and said authentication information.   
   
   
       18 . The apparatus of  claim 16 , wherein:
 said operational data comprises an IP address of a remote party of a connection with said computer network, and a domain name associated with said IP address;   said enterprise data comprises user registration information maintained by a provider of network connectivity to a remote use of an Internet connection; and said at least one processor is further operative to:   correlate said operational data with said enterprise data to obtain correlated data by checking that said domain name displayed to a local party of said connection matches said user registration information; and   use said correlated data to improve security of said computer network by displaying an alert to said local party of said connection based on an outcome of said correlating step.   
   
   
       19 . A computer program product comprising a computer useable medium having computer useable program code for improving security in a computer network, said computer program product including:
 computer useable program code for obtaining operational data for at least one networked application;   computer useable program code for obtaining enterprise data for at least one networked application;   computer useable program code for correlating said operational data with said enterprise data to obtain correlated data; and   computer useable program code for using said correlated data to improve security of said computer network.   
   
   
       20 . The computer program product of  claim 19 , wherein:
 said operational data comprises a record of a unique address allocation to a user device attempting to access said computer network;   said enterprise data comprises credentials associated with local authentication at said user device; and said computer program product further includes:   computer useable program code for correlating said operational data with said enterprise data to obtain correlated data by associating said unique address and said credentials with authentication information stored in a single-sign-on server; and   computer useable program code for using said correlated data to improve security of said computer network by providing a user of said user device with single sign-on ability responsive to an indication of an appropriate match between said unique address and said credentials and said authentication information.   
   
   
       21 . The computer program product of  claim 19 , wherein:
 said operational data comprises:
 an IP address of a remote party of a connection with said computer network; 
 and a domain name associated with said IP address; 
   said enterprise data comprises user registration information maintained by a provider of network connectivity to a remote use of an Internet connection; and said computer program product further includes:   computer useable program code for correlating said operational data with said enterprise data to obtain correlated data by checking that said domain name displayed to a local party of said connection matches said user registration information; and   computer useable program code for using said correlated data to improve security of said computer network by displaying an alert to said local party of said connection based on an outcome of said correlating step.   
   
   
       22 . The computer program product of  claim 19 , wherein:
 said operational data comprises:
 an IP address of a remote party of a connection with said computer network; 
 and a domain name associated with said IP address; 
   said enterprise data comprises user registration information maintained by a provider of network connectivity to said remote party of said connection; and said computer program product further includes:   computer useable program code for correlating said operational data with said enterprise data to obtain correlated data by checking that said domain name displayed to a local party of said connection matches said user registration information; and   computer useable program code for using said correlated data to improve security of said computer network by displaying an alert to said local party of said connection based on an outcome of said correlating step.

Join the waitlist — get patent alerts

Track US2008047019A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.