IP Library Granted Patent US 6,988,208
Granted Patent B2
US 6,988,208 · App. 10/196,472 · Granted Jan 17, 2006

Method and apparatus for verifying the integrity and security of computer networks and implementing counter measures

Assignee: Solutionary, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 6,988,208
App. No.
10/196,472
Granted
Jan 17, 2006
Kind
B2
Abstract

A method and apparatus for verifying the integrity of devices on a target network. The apparatus has security subsystems and a master security system hierarchically connected to the security subsystems via a secure link. The target network includes various intrusion detection devices, which may be part of the security subsystem. Each intrusion detection device generates a plurality of event messages when an attack on the network is detected. The security subsystem collects these event messages, correlates, and analyzes them, and performs network scanning processes. If certain events warrant additional scrutiny, they are uploaded to the master security system for review.

Claims (52)

1. A security system for a computer connected to a computer network comprising:

at least one detection means associated with said computer, said detection means configured to generate event messages when said computer is under an attack;

a master security system located outside said computer network;

a second master security system located outside said computer network; and

a secure link between said detection means and said master security system enabling data communication therebetween;

wherein said at least one detection means further comprises means for collecting said event messages and means for analyzing said event messages, wherein said second master security system further comprises means for monitoring attacks on said master security system, and wherein said detection means uploads certain event messages to said master security system through said secure link.

2. The security system of claim 1 , wherein said at least one detection means further comprises means for countering said attack.

3. The security system of claim 1 , wherein said means for analyzing said event messages further comprises means for consolidating said event messages.

4. The security system of claim 1 , wherein said means for analyzing said event messages further comprises means for classifying said event messages.

5. The security system of claim 1 , wherein said means for analyzing said event messages further comprises means for correlating said event messages.

6. The security system of claim 1 , wherein said means for analyzing said event messages further comprises multiple views, each of said views analyzing a different subset of event information.

7. The security system of claim 1 , wherein said detection means is one or more selected from the group consisting of an intrusion detection system, a firewall and a security subsystem.

8. The security system of claim 1 , wherein said master security system is hierarchically independent from said detection means.

9. The security system of claim 1 further comprising a pseudo attack generator associated with said master security system for generating attacks on said computer detectable by said detection means wherein said master security system monitors said detection means by comparing said pseudo-attacks to said attacks detected by said detection means.

10. The security system of claim 1 , further comprising a vulnerability scanning means determining vulnerability of various components of said computer network to a particular attack.

11. The security system of claim 10 , wherein said means for analyzing said event messages are configured to compare said determined vulnerability of said various components to said attack on said computer network.

12. A network security system for a target network of computers comprising:

at least one detection means associated with said target network, said detection means configured to generate event messages when said computer is under an attack;

a master security system located outside said network;

a second master security system located outside said computer network, and

a secure link between said detection means and said master security system enabling data communication therebetween;

wherein said at least one detection means further comprises means for collecting said event messages and means for analyzing said event messages, wherein said second master security system monitors attacks on said master security system, and wherein said detection means uploads certain event messages to said master security system through said secure link.

13. The network security system of claim 12 , wherein said at least one detection means further comprises means for countering said attack.

14. The network security system of claim 12 , wherein said means for analyzing said event messages further comprises means for consolidating said event messages.

15. The network security system of claim 12 , wherein said means for analyzing said event messages further comprises means for classifying said event messages.

16. The network security system of claim 12 , wherein said means for analyzing said event messages further comprises means for correlating said event messages.

17. The security system of claim 12 , wherein said means for analyzing said event messages further comprises multiple views, each of said views analyzing a different subset of event information.

18. The network security system of claim 12 , wherein said detection means is one or more selected from the group consisting of an intrusion detection system, a firewall and a security subsystem.

19. The network security system of claim 12 , wherein said master security system is hierarchically independent from said detection means.

20. The network security system of claim 12 , further comprising a pseudo attack generator associated with said master security system for generating attacks on said target network detectable by said detection means wherein said master security system monitors said detection means by comparing said pseudo-attacks to said attacks detected by said detection means.

21. The security system of claim 12 , further comprising a vulnerability scanning means determining vulnerability of various components of said computer network to a particular attack.

22. The security system of claim 21 , wherein said means for analyzing said event messages are configured to compare said determined vulnerability of said various components to said attack on said computer network.

23. A method for monitoring the integrity of a computer associated with a detection means, said computer being connected to a computer network and said detection means configured to detect an attack on said computer, said method comprising the steps of:

establishing a secure link for the transfer of data between said detection means and a master security system hierarchically independent from said detection means

collecting data related to said attack;

analyzing said collected data related to said attack;

uploading certain analyzed data to said master security system over said secure link;

monitoring attacks on said master security system using a second master security system; and

countering said attack.

24. The method for monitoring the integrity of a computer of claim 23 , wherein said step of analyzing data further comprises the step of consolidating said data.

25. The method for monitoring the integrity of a computer of claim 23 , wherein said step of analyzing data further comprises the step of classifying said data.

26. The method for monitoring the integrity of a computer of claim 25 , wherein said step of analyzing data further comprises the step of correlating said data.

27. A method for monitoring the integrity of a target computer network associated with a detection means, said detection means configured to detect an attack on said target computer network, said method comprising the steps of:

establishing a secure link for the transfer of data between said detection means and a master system hierarchically independent from said detection means

collecting data related to said attack;

analyzing data related to said attack;

uploading certain analyzed data to said master security system over said secure link;

monitoring attacks on said master security system using a second master security system; and

countering said attack.

28. The method for monitoring the integrity of a target computer network of claim 27 , wherein said step of analyzing data further comprises the step of consolidating said data.

29. The method for monitoring the integrity of a target computer network of claim 27 , wherein said step of analyzing data further comprises the step of classifying said data.

30. The method for monitoring the integrity of a target computer network of claim 27 , wherein said step of analyzing data further comprises the step of correlating said data.

Assignments (5)
MERGER AND CHANGE OF NAME Recorded Sep 22, 2016
From: SOLUTIONARY, INC; NTT SECURITY (US) INC.
To: NTT SECURITY (US) INC.
Reel/Frame 039835/0477 →
RELEASE OF SECURITY INTEREST Recorded Dec 23, 2009
From: HERCULES TECHNOLOGY II, L.P.
To: SOLUTIONARY, INC.
Reel/Frame 023691/0982 →
CORRECTIVE ASSIGNMENT TO CORRECT THE NATURE OF CONVEYANCE FROM AN ASSIGNMENT TO A SECURITY INTEREST PREVIOUSLY RECORDED ON REEL 019215 FRAME 0218. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Apr 27, 2007
From: SOLUTIONARY, INC.
To: HERCULES TECHNOLOGY II, L.P.
Reel/Frame 019215/0963 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 26, 2007
From: SOLUTIONARY, INC.
To: HERCULES TECHNOLOGY II, L.P.
Reel/Frame 019215/0218 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 16, 2002
From: HRABIK, MICHAEL; GUILFOYLE, JEFFREY; BEAVER, EDWARD MAC
To: SOLUTIONARY, INC.
Reel/Frame 013113/0834 →
Continuity (2)
Continuation In Part 0977052500 · Jan 25, 2001
Related Publication 20020178383A1 · Nov 28, 2002