US2014317752A1PendingUtilityA1

Computer network security platform

Assignee: NOBLIS INCPriority: Nov 16, 2009Filed: Jun 27, 2014Published: Oct 23, 2014
Est. expiryNov 16, 2029(~3.2 yrs left)· nominal 20-yr term from priority
Inventors:John Maguire
H04L 63/1433G06F 21/552H04L 9/32
48
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A computer system for managing security information for an organization includes a scanner execution module configured to automatically execute at least two scanners in a predetermined interval to analyze potential vulnerabilities of a computer environment. A vulnerability is acquired from the at least two scanners and stored in a data store. A user associated with the analyzed computer environment is determined based on the vulnerability stored in the data store, the user is notified of the vulnerability.

Claims

exact text as granted — not AI-modified
1 .- 20 . (canceled) 
     
     
         21 . A computer system for managing security information for an organization, comprising:
 one or more memories storing instructions; and   one or more processors configured to execute the instructions to:
 receive scan data from at least two scanners; 
 correlate the scan data to determine one or more vulnerabilities; 
 receive an input indicating that a vulnerability from the one or more vulnerabilities is an excluded vulnerability, the excluded vulnerability being excluded from a report based on a risk rating of the vulnerability; and 
 generate a report that includes the one or more vulnerabilities but not the excluded vulnerability. 
   
     
     
         22 . The computer system of  claim 21 , wherein the one or more processors are further configured to execute the instructions to:
 generate a user interface that displays vulnerability data.   
     
     
         23 . The computer system of  claim 22 , wherein the one or more processors are further configured to execute the instructions to:
 receive an input through the user interface from a user, the input specifying one or more preferences of the user that are remembered between sessions.   
     
     
         24 . The computer system of  claim 22 , wherein the one or more processors are further configured to execute the instructions to:
 enable a user to exclude, override, or accept a risk associated with one of the one or more vulnerabilities through the user interface.   
     
     
         25 . The computer system of  claim 22 , wherein the one or more processors are further configured to execute the instructions to:
 enable a user to exclude, through the user interface, one of the one or more vulnerabilities from display or inclusion in the report permanently.   
     
     
         26 . The computer system of  claim 22 , wherein the one or more processors are further configured to execute the instructions to:
 enable a user to exclude, through the user interface, one of the one or more vulnerabilities from display or inclusion in the report for a time period.   
     
     
         27 . The computer system of  claim 22 , wherein the one or more processors are further configured to execute the instructions to:
 enable a user to adjust the risk rating of one of the one or more vulnerabilities through the user interface.   
     
     
         28 . A computer-implemented method for managing computer security, the method comprising the following operations performed by at least one processor:
 receiving scan data from at least two scanners;   correlating the scan data to determine one or more vulnerabilities;   receiving an input indicating that a vulnerability from the one or more vulnerabilities is an excluded vulnerability, the excluded vulnerability being excluded from a report based on a risk rating of the vulnerability; and   generating a report that includes the one or more vulnerabilities but not the excluded vulnerability.   
     
     
         29 . The computer-implemented method of  claim 28 , further comprising:
 generating a user interface that displays vulnerability data.   
     
     
         30 . The computer-implemented method of  claim 29 , further comprising:
 receive an input through the user interface from a user, the input specifying one or more preferences of the user that are remembered between sessions.   
     
     
         31 . The computer-implemented method of  claim 29 , further comprising:
 enabling a user to exclude, override, or accept a risk associated with one of the one or more vulnerabilities through the user interface.   
     
     
         32 . The computer-implemented method of  claim 29 , further comprising:
 enabling a user to exclude, through the user interface, one of the one or more vulnerabilities from display or inclusion in the report permanently.   
     
     
         33 . The computer-implemented method of  claim 29 , further comprising:
 enabling a user to exclude, through the user interface, one of the one or more vulnerabilities from display or inclusion in the report for a time period.   
     
     
         34 . The computer-implemented method of  claim 29 , further comprising:
 enabling a user to adjust the risk rating of one of the one or more vulnerabilities through the user interface.   
     
     
         35 . A nontransitory computer readable medium encoded with instructions that, when executed by at least one processor, cause the at least one processor to perform a method for managing security information for an organization, the method comprising:
 receiving scan data from at least two scanners;   correlating the scan data to determine one or more vulnerabilities;   receiving an input indicating that a vulnerability from the one or more vulnerabilities is an excluded vulnerability, the excluded vulnerability being excluded from a report based on a risk rating of the vulnerability; and   generating a report that includes the one or more vulnerabilities but not the excluded vulnerability.   
     
     
         36 . The nontransitory computer readable medium of  claim 35 , the method further comprising:
 generating a user interface that displays vulnerability data.   
     
     
         37 . The nontransitory computer readable medium of  claim 36 , the method further comprising:
 receive an input through the user interface from a user, the input specifying one or more preferences of the user that are remembered between sessions.   
     
     
         38 . The nontransitory computer readable medium of  claim 36 , the method further comprising:
 enabling a user to exclude, override, or accept a risk associated with one of the one or more vulnerabilities through the user interface.   
     
     
         39 . The nontransitory computer readable medium of  claim 36 , the method further comprising:
 enabling a user to exclude, through the user interface, one of the one or more vulnerabilities from display or inclusion in the report permanently.   
     
     
         40 . The nontransitory computer readable medium of  claim 36 , further comprising:
 enabling a user to exclude, through the user interface, one of the one or more vulnerabilities from display or inclusion in the report for a time period.

Join the waitlist — get patent alerts

Track US2014317752A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.