Network asset information management
Abstract
A network asset information management system ( 101 ) may include an asset determination and event prioritization module ( 105 ) to generate real-time asset information based on network activity involving an asset ( 102 ). A rules module ( 109 ) may include a set of rules for monitoring the network activity involving the asset. An information analysis module ( 110 ) may evaluate the real-time asset information and the rules to generate a notification ( 111 ) related to the asset. The rules may include rules for determining vulnerabilities and risks associated with the asset based on comparison of a level of traffic identified to or from an IP address related to the asset to a predetermined threshold. The notification may include a level of risk associated with the asset.
Claims
exact text as granted — not AI-modified1 . A network asset information management system ( 101 ) comprising:
an asset determination and event prioritization module ( 105 ) to generate real-time asset information based on network activity involving an asset ( 102 ); a rules module ( 109 ) to include a set of rules for monitoring the network activity involving the asset; and an information analysis module ( 110 ), executed by a processor, to i) maintain an age of the asset based on last scan time and use the age to calculate a) asset model information confidence for activity occurring on the asset, and b) priority of the activity occurring on the asset, and ii) evaluate the real-time asset information and the rules to generate a notification ( 111 ) related to the asset.
2 . The system of claim 1 , further comprising an asset model module ( 106 ) to generate an asset model based on static information about the asset, wherein the information analysis module is to evaluate the asset model, the real-time asset information, and the rules to generate the notification related to the asset.
3 . The system of claim 2 , wherein the static information about the asset is obtained from a scanner ( 107 ).
4 . The system of claim 2 , wherein the static information about the asset is obtained from an external asset database ( 108 ).
5 . The system of claim 1 , wherein the network activity involving the asset includes event data involving the asset, and wherein the event data includes asset logs, application logs or network data.
6 . The system of claim 1 , wherein the network activity involving the asset is obtained by a connector ( 104 ).
7 . The system of claim 1 , wherein the rules for monitoring the network activity involving the asset include rules for creation of an asset if the traffic identified to or from an IP address related to the asset exceeds a predetermined threshold amount of data or duration, and wherein the notification includes an indication for creation of the asset.
8 . The system of claim 1 , wherein the rules for monitoring the network activity involving the asset include rules for deletion of an asset if the traffic has not been observed from the asset for a predetermined time-period, and wherein the notification includes an indication for deletion of the asset.
9 . The system of claim 1 , wherein the rules for monitoring the network activity involving the asset include rules for updating of an asset if an event identifying an OS patch or application patch has been applied to the asset, and wherein the notification includes an indication for updating of the asset.
10 . (canceled)
11 . The system of claim 1 , wherein the notification related to the asset includes services, applications, resource utilization, traffic assessment, attacks, viruses, worms, security compromises, rogue processes, rogue servers, operating system (OS) versions, patch levels, web clients, or risk associated with the asset.
12 . The system of claim 1 , wherein the notification related to the asset is used to generate statistics associated with the asset.
13 . A method for network asset information management ( 300 ), the method comprising:
generating ( 302 ) real-time asset information based on network activity involving an asset ( 102 ); performing ( 303 ) rule-based monitoring of the network activity involving the asset; maintaining, by a processor, an age of the asset based on last scan time; calculating, by the processor, a) asset model information confidence for activity occurring on the asset, and b) priority of the activity occurring on the asset; and evaluating ( 304 ), by the processor, the real-time asset information and the monitored network activity to generate a notification ( 111 ) related to the asset.
14 . The method of claim 13 , further comprising generating ( 301 ) an asset model based on static information about the asset, wherein evaluating further comprising evaluating the asset model, the real-time asset information, and the monitored network activity to generate the notification related to the asset.
15 . A non-transitory computer readable medium storing machine readable instructions, that when executed by a computer system ( 400 ), perform a method for network asset information management ( 300 ), the method comprising:
generating ( 302 ) real-time asset information based on network activity involving an asset ( 102 ); performing ( 303 ) rule-based monitoring of the network activity involving the asset; maintaining, by a processor, an age of the asset based on last scan time calculating, by the processor, a) asset model information confidence for activity occurring on the asset, and b) priority of the activity occurring on the asset; and evaluating ( 304 ), by the processor, the real-time asset information and the monitored network activity to generate a notification ( 111 ) related to the asset.
16 . The system of claim 1 , wherein the notification includes a level of risk associated with the asset.
17 . The method of claim 13 , wherein rules for monitoring the network activity involving the asset include rules for creation of an asset if the traffic identified to or from an IP address related to the asset exceeds a predetermined threshold amount of data or duration, and wherein the notification includes an indication for creation of the asset.
18 . The method of claim 13 , wherein rules for monitoring the network activity involving the asset include rules for deletion of an asset if the traffic has not been observed from the asset for a predetermined time-period, and wherein the notification includes an indication for deletion of the asset.
19 . The computer readable medium of claim 15 , wherein the method further comprises generating an asset model based on static information about the asset, wherein the processor evaluates the asset model, the real-time asset information, and the rules to generate the notification related to the asset.
20 . The computer readable medium of claim 15 , wherein rules for monitoring the network activity involving the asset include rules for creation of an asset if the traffic identified to or from an IP address related to the asset exceeds a predetermined threshold amount of data or duration, and wherein the notification includes an indication for creation of the asset.
21 . The computer readable medium of claim 15 , wherein rules for monitoring the network activity involving the asset include rules for deletion of an asset if the traffic has not been observed from the asset for a predetermined time-period, and wherein the notification includes an indication for deletion of the asset.Join the waitlist — get patent alerts
Track US2016191352A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.