Universal patching machine
Abstract
A universal patching machine is used to provide security for a computer system. A conversion function is generated for the patching machine that modifies input data to the computer system so that the computer system has an output and state that match the output and state that would be produced by a vendor-patched version of the computer system. The universal patching machine detects security vulnerabilities in intercepted data traffic. If a vulnerability violation is detected, the universal patching machine modifies the data traffic to remove the violation. Fixing the data traffic in this way ensures that the vulnerability cannot be exploited in an attack against the data network. The universal patching machine is formed from patch processors and a packet controller. The patch processors are formed from network patches. In operation, the patch processors detect vulnerabilities and issue modification commands that direct the packet controller to fix the data traffic.
Claims
exact text as granted — not AI-modified1 - 18 . (canceled)
19 . A system comprising:
a network; a computing device; a universal patching machine coupled between the network and the computing device, the universal patching machine comprising a processor programmed to:
receive data traffic from the network;
determine one or more vulnerability violations in the received data traffic;
modify the received data traffic by removing the one or more vulnerability violations; and
forward the modified data traffic to the computing device.
20 . The system of claim 19 , wherein the processor is further programmed to receive data identifying which operating systems and applications of the computing device are to be protected by the universal patching machine from vulnerability violations.
21 . The system of claim 20 , wherein the processor is further programmed to:
determine which patches are not utilized by the computing device; and update the universal patching machine to include the patches not utilized by the computing device.
22 . The system of claim 21 , wherein the processor is further programmed to remove patches within the universal patching machine that are utilized by the computing device.
23 . The system of claim 19 , wherein the universal patching machine further comprises a packet controller, the packet controller including data that informs the packet controller whether: 1) the packet controller should output the data traffic received by the universal patching machine without processing the received data traffic; 2) the packet controller should process the received data traffic; or 3) the packet controller should send the received data traffic to the processor for processing.
24 . The system of claim 23 , wherein the packet controller is configured to process the received data traffic at network layers 5, 4, 3, or 2.
25 . The system of claim 24 , wherein the patch processor is programmed to process the data traffic at network layers 6 or 7.
26 . A method for monitoring vulnerability violations in data traffic between a communications network and a computing device, the method comprising:
receiving, by a universal patching machine, data traffic from the communications network; determining one or more vulnerability violations in the received data traffic; modifying the received data traffic by removing the one or more vulnerability violations from the received data traffic; and sending the modified data traffic from the universal patching machine to the computing device.
27 . The method of claim 26 , further comprising identifying which portions of the computing device are to be protected from vulnerability violations in the data traffic.
28 . The method of claim 27 , further comprising:
monitoring vulnerability violations in the received data traffic associated with the identified protected portions of the computing device; and forwarding the received data traffic associated with identified non-protected portions of the computing device to the computing device vice without monitoring vulnerability violations in the received data traffic.
29 . The method of claim 27 , wherein the modified data traffic does not include any vulnerability violations associated with the identified protected portions of the computing device.
30 . The method of claim 26 , further comprising:
determining whether the received data traffic should be processed at network layers 5, 4, 3, or 2; and if it is determined that the received data traffic should not be processed at network layers 5, 4, 3, or 2, processing the received data traffic at network layers 6 or 7.
31 . A universal patching machine for monitoring vulnerability violations in data traffic flowing between a communications network and a computer network, the universal patching machine comprising:
a packet controller; and one or more processors programmed to:
receive data traffic from the communications network;
determine one or more vulnerability violations in the received data traffic;
send a modification command to the packet controller that instructs the packet controller to remove the one or more vulnerability violations; and
forward the modified data traffic to a computing device in the computer network.
32 . The universal patching machine of claim 31 , wherein the one or more processors are further programmed to receive data identifying which operating systems and applications of the computing device are to be protected by the universal patching machine from vulnerability violations.
33 . The universal patching machine of claim 32 , wherein the one or more processors are further programmed to:
determine which patches are not utilized by the computing device; and update the universal patching machine to include the patches not utilized by the computing device.
34 . The universal patching machine of claim 33 , wherein the one or more processors are further programmed to remove patches within the universal patching machine that are utilized by the computing device.
35 . The universal patching machine of claim 31 , wherein the packet controller includes data that informs the packet controller whether: 1) the packet controller should output the data traffic received by the universal patching machine without processing the received data traffic; 2) the packet controller should process the received data traffic; or 3) the packet controller should send the received data traffic to the one or more processors for processing.
36 . The universal patching machine of claim 35 , wherein the packet controller is configured to process the received data traffic at network layers 5, 4, 3, or 2.
37 . The universal patching machine of claim 36 , wherein the patch processor is programmed to process the data traffic at network layers 6 or 7.
38 . The universal patching machine of claim 31 , wherein the processor is further programmed to:
determine whether the received data traffic should be processed at network layers 5, 4, 3, or 2; and if it is determined that the received data traffic should not be processed at network layers 5, 4, 3, or 2, process the received data traffic at network layers 6 or 7.Join the waitlist — get patent alerts
Track US2013014265A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.