US2021165886A1PendingUtilityA1

Security risk management system, server, control method, and non-transitory computer-readable medium

Assignee: NEC CORPPriority: Mar 25, 2016Filed: Nov 20, 2020Published: Jun 3, 2021
Est. expiryMar 25, 2036(~9.6 yrs left)· nominal 20-yr term from priority
G06F 21/577G06F 2221/034G06F 21/552G06Q 10/0635
49
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A security risk management system ( 305 ) of the present disclosure includes a server ( 310 ) and an agent unit ( 320 ) included in a terminal. The server ( 310 ) transmits vulnerability information to the agent unit ( 320 ) before the release date and time of the vulnerability information. The agent unit ( 320 ) investigates the presence or absence of vulnerabilities in the terminal based on information regarding a method for vulnerability investigation contained in the vulnerability information, and transmits vulnerability investigation results containing the investigation results to the server ( 310 ) before the release date and time of the vulnerability information. The server ( 310 ) presents the vulnerability information and the vulnerability investigation results on or after the release date and time of the vulnerability information.

Claims

exact text as granted — not AI-modified
1 - 15 . (canceled) 
     
     
         16 . A method performed by a terminal, the method comprising:
 receiving, from a server, vulnerability information concerning vulnerability, including a release date and time, and a method for investigation, before the release date and time, wherein the vulnerability information is received by the server from a vulnerability information distribution system; and   investigating the terminal using the method for investigation.   
     
     
         17 . The method according to  claim 16 , wherein
 the investigating is performed before the release date and time.   
     
     
         18 . The method according to  claim 16 , further comprising:
 sending a result of the investigating to the server.   
     
     
         19 . The method according to  claim 16 , wherein the vulnerability information is encrypted, and the method further comprising:
 decrypting the encrypted vulnerability information before the investigating is performed.   
     
     
         20 . A method comprising:
 receiving, from a vulnerability information distribution system, vulnerability information concerning vulnerability, including a release date and time, and a method for investigation;   transmitting the vulnerability information to a terminal before the release date and time; and   receiving, from the terminal, a result of investigation performed in the terminal using the method for investigation.   
     
     
         21 . The method according to  claim 20 , further comprising:
 displaying the result before the release date and time.   
     
     
         22 . A method for a system including a server and a terminal comprising:
 receiving, by the server from a vulnerability information distribution system, vulnerability information concerning vulnerability, including a release date and time, and a method for investigation;   transmitting, by the server, the vulnerability information to the terminal before the release date and time;   investigating the terminal using the method for investigation; and   receiving, from the terminal, a result of the investigating.   
     
     
         23 . A terminal comprising:
 one or more processors; and   one or more memories storing executable instructions that, when executed by the one or more processors, causes the one or more processors to perform:   receiving, from a server, vulnerability information concerning vulnerability, including a release date and time, and a method for investigation, before the release date and time, wherein the vulnerability information is received by the server from a vulnerability information distribution system; and   investigating the terminal using the method for investigation.   
     
     
         24 . The terminal according to  claim 23 , wherein
 the investigating is performed before the release date and time.   
     
     
         25 . The terminal according to  claim 23 , wherein the one or more processors further perform sending a result of the investigating to the server. 
     
     
         26 . The terminal according to  claim 23 , wherein the vulnerability information is encrypted, and
 the one or more processors further perform decrypting the encrypted vulnerability information before the investigating is performed.   
     
     
         27 . A server comprising:
 one or more processors; and   one or more memories storing executable instructions that, when executed by the one or more processors, causes the one or more processors to perform:   receiving, from a vulnerability information distribution system, vulnerability information concerning vulnerability, including a release date and time, and a method for investigation;   transmitting the vulnerability information to a terminal before the release date and time; and   receiving, from the terminal, a result of investigation performed in the terminal using the method for investigation.   
     
     
         28 . The server according to  claim 20 , wherein the one or more processors further perform:
 displaying the result before the release date and time.   
     
     
         29 . A system comprising:
 a terminal;   a server;   one or more processors; and   one or more memories storing executable instructions that, when executed by the one or more processors, causes the one or more processors to perform:   receiving, by the server from a vulnerability information distribution system, vulnerability information concerning vulnerability, including a release date and time, and a method for investigation;   transmitting, by the server, the vulnerability information to a terminal before the release date and time;   investigating the terminal using the method for investigation; and   receiving, from the terminal, a result of the investigating.   
     
     
         30 . A non-transitory computer readable information recording medium storing a program, that when executed by a processor, causes the processor to execute:
 receiving, from a server, vulnerability information concerning vulnerability, including a release date and time, and a method for investigation, before the release date and time, wherein the vulnerability information is received by the server from a vulnerability information distribution system; and   investigating the terminal using the method for investigation.   
     
     
         31 . A non-transitory computer readable information recording medium storing a program, that when executed by a processor, causes the processor to execute:
 receiving, from a vulnerability information distribution system, vulnerability information concerning vulnerability, including a release date and time, and a method for investigation;   transmitting the vulnerability information to a terminal before the release date and time; and   receiving, from the terminal, a result of investigation performed in the terminal using the method for investigation.

Join the waitlist — get patent alerts

Track US2021165886A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.