US2018146002A1PendingUtilityA1

Cyber Security System and Method Using Intelligent Agents

Assignee: CANFIELD RAYMONDPriority: Jul 16, 2015Filed: Jul 18, 2016Published: May 24, 2018
Est. expiryJul 16, 2035(~9 yrs left)· nominal 20-yr term from priority
H04L 63/1433H04L 63/1491H04L 63/20H04L 63/145H04L 41/22G06F 40/10G06N 5/02G06F 17/21
31
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A cyber security method using intelligent agents (IAs) includes: watching, by the intelligent agent (IA), over a network, a software program running on a system; receiving, by the IA, results generated by the software; presenting, by the IA, the results; categorizing the results, by the IA, for efficient storage and efficient future retrieval; saving, by the IA, the categorized results; using the categorized results, by the IA, inferring new knowledge; categorizing the new knowledge, by the IA, for efficient storage and efficient future retrieval; saving, by the IA, the categorized new knowledge; and using one or more of the saved categorized results and the saved categorized new knowledge, by the IA, configuring the software.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A cyber security method using intelligent agents (IAs), comprising:
 a) setting up, by the IA, a first network scan of a system over a network;   b) running, by the IA, using a first network scan parameter, the first network scan, generating first network scan results;   c) storing, by the IA, the first network scan results;   d) running, by the IA, using a second network scan parameter, a second network scan of the system over the network, generating second network scan results;   e) storing, by the IA, the second network scan results;   f) running a port scan of the system, by the IA, generating port scan results;   g) storing, by the IA, the port scan results;   h) using one or more of the first network scan results and the second network scan results, by the IA, optimizing the first network scan parameter;   i) using one or more of the first network scan parameter, the second network scan parameter, and the port scan configuring, by the IA, a vulnerability scan of the system over the network;   j) using one or more of the first network scan parameter, the second network scan parameter, and the port scan results, running the vulnerability scan of the system, generating vulnerability scan results;   k) storing, by the IA, the vulnerability scan results;   l) collecting, by the IA, at least one of service information and availability knowledge regarding at least one of an available target and an available service;   m) using the at least one of service information and availability knowledge, by the IA, identifying a needed setting; and   n) storing, by the IA, the needed setting.   
     
     
         2 . The method of  claim 1 , wherein the step of setting up comprises setting the first network scan parameter. 
     
     
         3 . The method of  claim 1 , wherein the network comprises one or more of the Internet, the World-Wide Web (WWW), Secure Shell (SSH), Simple Network Management Protocol (SNMP), command-line interface (CLI), and another network protocol configured to facilitate access to the system. 
     
     
         4 . The method of  claim 1 , wherein the first network scan parameter comprises one or more of a scan frequency, a scan wait time, a blast rate, and another network scan parameter. 
     
     
         5 . The method of  claim 1 , wherein the step of running the first network scan comprises one or more of analyzing criticality of a target, scoring the criticality of the target, and exploring a security weather pattern. 
     
     
         6 . The method of  claim 5 , wherein the security weather pattern comprises one or more of a new device, a new service on an existing device, a changed service on an existing device, a change in traffic to a target, and a change in traffic from a target. 
     
     
         7 . The method of  claim 5 , wherein the target comprises one or more of a target device, a target sub-system, a target port, and another target. 
     
     
         8 . The method of  claim 5 , wherein the analyzing sub-step comprises
 collecting target information; and   using the target information to perform the analysis.   
     
     
         9 . The method of  claim 8 , wherein the target information comprises one or more of a frequency of changes, a vulnerability history, a target type, a target location, services used by the target, service usages by the target, and other target information. 
     
     
         10 . The method of  claim 9 , wherein the target location comprises a proximity to a network. 
     
     
         11 . The method of  claim 5 , wherein the scoring sub-step comprises collecting target information; and
 using the target information to perform the scoring.   
     
     
         12 . The method of  claim 1 , wherein the step of running the first network scan comprises continually running the first network scan. 
     
     
         13 . The method of  claim 1 , wherein the first network scan generates first pings. 
     
     
         14 . The method of  claim 13 , wherein the first pings comprise frequent, multiple, low accuracy first pings. 
     
     
         15 . The method of  claim 14 , wherein the first pings have an accuracy between approximately eighty percent and approximately 95 percent. 
     
     
         16 . The method of  claim 14 , wherein the first pings have return times of approximately thirty seconds to approximately sixty seconds for a system comprising 256 sub-systems. 
     
     
         17 . The method of  claim 1 , wherein the second network scan parameter comprises one or more of a number of target checks, a size of data being sent, and another second network scan parameter. 
     
     
         18 . The method of  claim 1 , wherein the step of running the first network scan comprises running the first network scan using one or more of an active scan of the network, a ping networking utility, a network mapping (NMAP) security scanner, and another first network scan. 
     
     
         19 . The method of  claim 18 , wherein the step of running the first network scan comprises a sub-step of:
 actively scanning the network, by the IA.   
     
     
         20 . The method of  claim 19 , wherein the generating sub-step comprises using the first network scan results to accomplish one or more of maximizing a success rate, minimizing a scan time, minimizing a scan frequency, improving efficiency of scanning, and increasing scan frequency. 
     
     
         21 . The method of  claim 1 , wherein the step of running the second network scan comprises running the second network scan using one or more of an active scan of the network, a ping networking utility, a network mapping (NMAP) security scanner, and another second network scan. 
     
     
         22 . The method of  claim 21 , wherein the step of running the first network scan comprises a sub-step of:
 actively scanning the network, by the IA.   
     
     
         23 . The method of  claim 1 , wherein the second network scan generates second pings. 
     
     
         24 . The method of  claim 23 , wherein the second pings comprise infrequent, high accuracy second pings. 
     
     
         25 . The method of  claim 24 , wherein the second pings have an accuracy of at least approximately ninety-five percent. 
     
     
         26 . The method of  claim 24 , wherein the second pings have return times of approximately seventeen minutes to approximately twenty-two minutes for a system comprising 256 sub-systems. 
     
     
         27 . The method of  claim 1 , wherein the step of running the second network scan comprises accessing the second network scan on an operating system of the system. 
     
     
         28 . The method of  claim 1 , wherein the second network scan results have an accuracy of at least approximately ninety-five percent. 
     
     
         29 . The method of  claim 1 , comprising additional steps, performed after the optimizing step h), of:
 o) determining that a new second network scan is needed; and   p) returning to the step of d) running a second network scan.   
     
     
         30 . The method of  claim 1 , comprising an additional step, performed after the optimizing step h), of:
 o) using the optimized first network scan parameter, by the IA, in one or more of a first network scan, a second network scans, a port scans, and a vulnerability scan.   
     
     
         31 . The method of  claim 30 , wherein the determining step comprises one or more of determine performance of the system, determining success of the first network scan, determining a second network scan start time, and determining a second network scan frequency. 
     
     
         32 . The method of  claim 1 , wherein the step of running a port scan comprises scanning the network to identify one or more of a target, a scan time, and a scan frequency. 
     
     
         33 . The method of  claim 1 , wherein the step of running a port scan comprises running a port scan using one or more of data stored in storage and environment information. 
     
     
         34 . The method of  claim 33 , wherein the environment information comprises one or more of network utilization information, resource usage, and other environment information. 
     
     
         35 . The method of  claim 1 , wherein the step of running the vulnerability scan comprises identifying an at-risk target. 
     
     
         36 . The method of  claim 35 , wherein identifying the at-risk target comprises identifying the at-risk target using one or more of pre-set risk determination parameters and risk determination parameters that are calculated on the fly. 
     
     
         37 . The method of  claim 1 , further comprising a step of providing a device configured to perform one or more of tracking traffic and collecting information regarding traffic. 
     
     
         38 . A cyber security method using intelligent agents (IAs), comprising:
 watching, by the IA, over a network, a software program running on a system;   receiving, by the IA, results generated by the software;   presenting, by the IA, the results;   categorizing the results, by the IA, for efficient storage and efficient future retrieval;   saving, by the IA, the categorized results;   using the categorized results, by the IA, inferring new knowledge;   categorizing the new knowledge, by the IA, for efficient storage and efficient future retrieval;   saving, by the IA, the categorized new knowledge; and   using one or more of the saved categorized results and the saved categorized new knowledge, by the IA, configuring the software.   
     
     
         39 . The method of  claim 38 , wherein the step of watching comprises identifying in the software one or more of an inefficiency, a deficiency, an incomplete aspect and an error. 
     
     
         40 . The method of  claim 38 , wherein the step of presenting comprises presenting the results for usage by a human user. 
     
     
         41 . The method of  claim 40 , wherein the step of presenting comprises presenting the results for usage by a human user in one or more of an alert, a web page update, a graph, a database entry, and a report. 
     
     
         42 . A cyber security method using intelligent agents (IAs), comprising:
 seeking, by the IA, required configuration information from storage;   determining, by the IA, that the required configuration information cannot be retrieved from storage;   identifying, by the IA, a software program;   running, by the IA, the software program;   verifying, by the IA, that the required configuration information has been obtained;   re-running the software program, by the IA, using the required configuration information, generating a result;   reviewing the result, by the IA;   determining, by the IA, that the result is acceptable; and   using the result, by the IA, generating a result response.   
     
     
         43 . The method of  claim 42 , wherein the configuration information comprises one or more of an Internet Protocol (IP) address, login information, a device type, network access information, and other configuration information. 
     
     
         44 . The method of  claim 42 , wherein the result response comprises one or more of an alert, a web page update, a graph, a database entry, a report, recommended corrective action on a target, and another result response. 
     
     
         45 . A cyber security method using intelligent agents (IAs), comprising:
 after initial setup, directing, by the IA, a knowledge base program to scan data comprised in a target;   collecting, by the IA, configuration information required to run the target;   using the configuration information, by the IA, attempting a connection to the target;   passing, by the IA, to a human user interface target information regarding the target;   using the human user interface, by the IA, accumulating pertinent knowledge regarding one or more of a connection method and target information;   using the human user interface, by the IA, communicating with the target using the pertinent knowledge;   using the human user interface, receiving, by the IA, a response to the command from the target;   processing the response, by the IA, thereby generating a result;   transmitting, by the IA, the result to the knowledge base program;   using the knowledge base program, by the IA, processing the result;   receiving the processed result, by the IA, from the knowledge base program; and   transmitting, by the IA, the processed result to storage.   
     
     
         46 . The method of  claim 45 , wherein the step of attempting a connection comprises attempting a connection to the target in descending order of estimated likelihood of success for the connection method, until a connection succeeds. 
     
     
         47 . The method of  claim 45 , wherein the human user interface comprises one or more of a Graphical User Interface (GUI), a Command Line Interface (CLI), and another human user interface. 
     
     
         48 . The method of  claim 45 , wherein the processing step comprises one or more of interpreting the response, categorizing the response, placing the response into storage, and processing the response in another way. 
     
     
         49 . The method of  claim 45 , wherein the processing response comprises processing the result using a processing block comprised in the knowledge base program. 
     
     
         50 . A cyber security method using intelligent agents (IAs), comprising:
 after initial setup, directing, by the IA, a knowledge base program to scan data comprised in a target;   collecting, by the IA, configuration information required to run the target;   using the configuration information, by the IA, attempting a connection to the target;   using one or more of a connection method and target information regarding the target,   sending, by the IA, a command to the target;   receiving, by the IA, a response to the command from the target;   processing the response, by the IA, thereby generating a result;   transmitting, by the IA, the result to the knowledge base program;   using the knowledge base program, by the IA, processing the result;   receiving the processed result, by the IA, from the knowledge base program; and   transmitting, by the IA, the processed result to storage.   
     
     
         51 . A cyber security method using intelligent agents (IAs), comprising:
 observing, by the IA, traffic through a master system;   identifying, by the IA, a vulnerability;   diverting, by the IA, the vulnerability onto a temporary target;   constructing, by the IA, a decoy system configured to replicate one or more of the appearance and the operation of the master system; and   launching, by the IA, the decoy system.   
     
     
         52 . The method of  claim 51 , wherein the vulnerability comprises one or more of a a new vulnerability, a pattern indicating a vulnerability, a series of communication events indicating a vulnerability, a new attack method, malware, a computer virus, a document comprising a secret, and another vulnerability. 
     
     
         53 . The system of  claim 51 , wherein the decoy system is configured to mislead an attacker into thinking he has entered into the master system. 
     
     
         54 . The system of  claim 51 , wherein for the decoy system, one or more of an operating system, an application, a software version, a patch, and another decoy system parameter is substantially the same as in the master system. 
     
     
         55 . The method of  claim 51 , further comprising an additional step, performed after the launching step, of:
 reviewing, by the IA, effectiveness of the decoy system in promoting safety of the master system.   
     
     
         56 . A cyber security method using intelligent agents (IAs), comprising:
 observing, by the IA, traffic through a master system;   identifying, by the IA, a vulnerability;   diverting, by the IA, the vulnerability onto a temporary target;   tracking the vulnerability as it moves through the master system;   investigating the vulnerability, generating investigation results;   reporting the investigation results to the master system;   storing the investigation results;   constructing, by the IA, a decoy system configured to replicate one or more of the appearance and the operation of the master system;   launching, by the IA, the decoy system; and   reviewing, by the IA, effectiveness of the decoy system in promoting safety of the master system.   
     
     
         57 . The method of  claim 56 , wherein the step of investigating comprises one or more of virus scanning, binary analysis, text analysis, steganalysis, and other investigating.

Join the waitlist — get patent alerts

Track US2018146002A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.