US2012159626A1PendingUtilityA1

Geographical intrusion response prioritization mapping system

Assignee: MCCONNELL JAMES TRENTPriority: Aug 12, 2004Filed: Jan 2, 2012Published: Jun 21, 2012
Est. expiryAug 12, 2024(expired)· nominal 20-yr term from priority
H04L 67/52H04L 41/22H04L 41/0677H04L 63/1408
46
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Systems and methods for geographically mapping an intrusion into a network having one or more network points include receiving intrusion information identifying a intrusion into a point of the network, correlating the intrusion information with location information for the identified network point, and network identification information for the identified network point, and generating a map displaying a geographical location of the intrusion.

Claims

exact text as granted — not AI-modified
1 - 68 . (canceled) 
     
     
         69 . A method for displaying information reflecting an intrusion into a computer network, the method comprising:
 receiving network intrusion information indicating a potential intrusion into at least one computing device connected to the network;   responsive to receiving the network intrusion information, identifying a network address associated with the at least one intruded computing device;   determining, using the network address, a geographical location of the at least one intruded computing device;   providing a geographical map of an area including at least the geographical location of the at least one potentially intruded computing device; and   providing a network intrusion symbol on the map to designate the geographical location of the at least one potentially intruded computing device.   
     
     
         70 . The method of  claim 69 , wherein the network address includes an Internet Protocol (IP) address. 
     
     
         71 . The method of  claim 69 , wherein identifying a network address includes retrieving, from an Address Routing Protocol (ARP) database using the network address, a router address of a router associated with the at least one potentially intruded computing device. 
     
     
         72 . The method of  claim 71 , wherein determining a geographical location includes:
 retrieving, from a router location information database using the retrieved router address, geographical location information corresponding to the at least one potentially intruded computing device; and   determining the geographical location of the at least one potentially intruded computing device point based on the retrieved geographical location information.   
     
     
         73 . The method of  claim 69 , wherein the network intrusion symbol represents a quantity of potentially intruded computing devices. 
     
     
         74 . The method of  claim 69 , further comprising determining a status of a response to mitigate the potential intrusion into the at least one computing device. 
     
     
         75 . The method of  claim 74 , further comprising distinguishing the network intrusion symbol on the map in order to indicate the status of the response to mitigate the potential intrusion. 
     
     
         76 . The method of  claim 75 , wherein distinguishing the network intrusion symbol includes coloring the network intrusion symbol to indicate the status of the response to mitigate the potential intrusion. 
     
     
         77 . The method of  claim 75 , further comprising:
 determining an updated status of the response to mitigate the potential intrusion; and   distinguishing the network intrusion symbol on the map in order to indicate the updated status of the response to mitigate the potential intrusion.   
     
     
         78 . A non-transitory computer-readable storage medium storing instructions that, when executed, perform a method for displaying information reflecting intrusion into a computer network, the method comprising:
 receiving network intrusion information indicating a potential intrusion into at least one computing device connected to the network;   responsive to receiving the network intrusion information, identifying a network address associated with the at least one potentially intruded computing device;   determining, using the network address, a geographical location of the at least one potentially intruded computing device;   providing a geographical map of an area including at least the geographical location of the at least one potentially intruded computing device;   providing a network intrusion symbol on the map to designate the geographical location of the at least one potentially intruded computing device.   
     
     
         78 . The non-transitory computer-readable storage medium of  claim 78 , wherein the network address includes an Internet Protocol (IP) address. 
     
     
         79 . The non-transitory computer-readable storage medium of  claim 78 , wherein identifying a network address includes retrieving, from an Address Routing Protocol (ARP) database using the network address, a router address of a router associated with the at least one potentially intruded computing device. 
     
     
         80 . The non-transitory computer-readable storage medium of  claim 79 , wherein determining a geographical location includes:
 retrieving, from a router location information database using the retrieved router address, geographical location information corresponding to the at least one potentially intruded computing device; and   determining the geographical location of the at least one potentially intruded computing device point based on the retrieved geographical location information.   
     
     
         81 . The non-transitory computer-readable storage medium of  claim 78 , wherein the network intrusion symbol represents a quantity of potentially intruded computing devices. 
     
     
         82 . The non-transitory computer-readable storage medium of  claim 78 , the method further comprising determining a status of a response to mitigate the intrusion into the at least one computing device. 
     
     
         83 . The non-transitory computer-readable storage medium of  claim 82 , the method further comprising distinguishing the network intrusion symbol on the map in order to indicate the status of the response to mitigate the potential intrusion. 
     
     
         84 . The non-transitory computer-readable storage medium of  claim 83 , wherein distinguishing the network intrusion symbol includes coloring the network intrusion symbol to indicate the status of the response to mitigate the potential intrusion. 
     
     
         85 . The non-transitory computer-readable storage medium of  claim 83 , further comprising:
 determining an updated status of the response to mitigate the potential intrusion; and   distinguishing the network intrusion symbol on the map in order to indicate the updated status of the response to mitigate the potential intrusion.   
     
     
         86 . A system for geographically mapping an intrusion into a computer network, the system comprising:
 a network address database storing network address information for a plurality of computing devices connected to the network;   a location database storing geographical location information associated with the plurality of computing devices;   a computer in electronic communication with the map database and being configured to:
 receive network intrusion information indicating a potential intrusion into at least one computing device connected to the network; 
 responsive to receiving the network intrusion information, identify a network address associated with the at least one potentially intruded computing device using the network address database; 
 determine, based on the network address, a geographical location of the at least one potentially intruded computing device using the location database; 
 provide a geographical map of an area including at least the geographical location of the at least one potentially intruded computing device; and 
 provide a network intrusion symbol on the map to designate the geographical location of the at least one potentially intruded computing device. 
   
     
     
         87 . The system of  claim 86 , wherein the computer is further configured to determine a status of a response to mitigate the potential intrusion into the at least one computing device. 
     
     
         88 . The system of  claim 87 , wherein the computer is further configured to distinguish the network intrusion symbol on the map in order to indicate the status of the response to mitigate the potential intrusion.

Join the waitlist — get patent alerts

Track US2012159626A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.