US2013263267A1PendingUtilityA1

Methods, computer program products and data structures for intrusion detection, intrusion response and vulnerability remediation across target computer systems

Assignee: IBMPriority: Jul 13, 2004Filed: May 24, 2013Published: Oct 3, 2013
Est. expiryJul 13, 2024(expired)· nominal 20-yr term from priority
Inventors:John J. Mckenna
G06F 21/55G06F 21/577
50
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Computer security threat management information is generated by receiving a notification of a security threat and/or a notification of a test that detects intrusion of a computer security threat. A computer-actionable TMV is generated from the notification that was received. The TMV includes a computer-readable field that provides identification of at least one system type that is effected by the computer security threat, a computer-readable field that provides identification of a release level for a system type, and a computer-readable field that provides identification of the test that detects intrusion of the computer security threat for a system type and a release level, a computer-readable field that provides identification of a method to reverse the intrusion exploit of the computer security threat for a system type and a release level, and a computer-readable field that provides identification of a method to remediate the vulnerability subject to exploit of the computer security threat for a system type and a release level. The TMV is transmitted to target systems for processing by the target systems.

Claims

exact text as granted — not AI-modified
1 . A computer program product for detecting intrusions, the computer program product comprising:
 one or more computer-readable storage devices and program instructions stored on at least one of the one or more storage devices, the program instructions comprising:   program instructions to receive, at a target system, a message identifying a first version of a program that is installed at the target system, and select from a plurality of different intrusion detection tests for a respective plurality of different versions of the program, a first one of the tests that detects intrusion of the first version of the program; and   program instructions, responsive to the message, to perform the first test at the target system.   
     
     
         2 . The computer program product of  claim 1  further comprising:
 program instructions, stored on the one or more computer-readable storage devices, to send a notification from the target system that an intrusion of the first version of the program has been detected; 
 program instructions, stored on the one or more computer-readable storage devices, to receive another message at the target system that identifies instructions for removing the detected intrusion from the target system; and 
 program instructions to perform the instructions for removing the detected intrusion at the target system in response to the other message. 
 
     
     
         3 . A method for processing computer security information, the method comprising:
 a computer transmitting, to a target system, one or more messages identifying a plurality of versions of a program that are available for installation at the target system and a respective plurality of different intrusion detection test programs to detect intrusions directed to the respective plurality of different versions of the program, wherein the plurality of different intrusion detection tests programs includes a first intrusion detection test program that detects intrusion directed to a first one of the plurality of versions of the program; and   the computer subsequently receiving a notification from the target system that intrusion of the first version of the program has been detected.   
     
     
         4 . The method of  claim 3  further comprising:
 the computer transmitting another message to the target system for processing by the target system that identifies instructions for removing the detected intrusion from the target system. 
 
     
     
         5 . The method of  claim 3 , further comprising:
 the target system selecting from the plurality of different intrusion detection test programs the first one of the test programs based on the first version of the program being installed at the target system.

Join the waitlist — get patent alerts

Track US2013263267A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.