IP Library Granted Patent US 8,256,002
Granted Patent B2
US 8,256,002 · App. 10/348,742 · Granted Aug 28, 2012

Tool, method and apparatus for assessing network security

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,256,002
App. No.
10/348,742
Granted
Aug 28, 2012
Kind
B2
Abstract

Tools and methods in which user interaction via a common user interface enables the assessing of network security prior to implementation of the network, as well as assessing the security of existing networks, portions of existing networks, or modifications to existing networks. A network security model useful in realizing the tools and methods is also disclosed.

Claims (55)

1. An apparatus comprising a processor and a memory, wherein the memory stores a software tool for assessing network security of at least a portion of a network, the software tool comprising:

a first module, for receiving, from a customer, information adapted for assessing network security, at least a portion of said information comprising customer responses to questions;

a second module, for executing network testing procedures on the network to generate therefrom test results adapted for assessing network security, wherein at least a portion of said network testing procedures are automatically selected for execution on the network based on at least a portion of said customer responses to said questions;

a third module, for determining, using said information and said test results, if said network has associated with it a network security vulnerability; and

a fourth module, for generating security recommendations based upon any determined network security vulnerabilities.

2. The apparatus of claim 1 , said software tool further comprising:

a fifth module, for generating a customer qualification form using qualification questions stored within a first database, said customer responses to said questions including customer responses to said qualification questions.

3. The apparatus of claim 2 , wherein:

said fifth module, in response to said customer responses to said qualification questions, generating a customized questionnaire using at least some of a plurality of survey questions stored within a second database;

said customer responses to said questions including customer responses to said survey questions.

4. The apparatus of claim 1 , wherein:

said second module executing said selected network testing procedures in response to customer question responses indicative of a vulnerability.

5. The apparatus of claim 1 , wherein:

said third module analyzing a network and its elements to determine additional vulnerabilities, mapping a network architecture, and providing an inventory of network elements;

said fourth module generating additional security recommendations based upon any additional vulnerabilities.

6. The apparatus of claim 1 , wherein:

said fourth module compares said information adapted for assessing network security to information within a vulnerability database to identify network security vulnerabilities.

7. The apparatus of claim 6 , wherein:

said vulnerability database specifies network security vulnerabilities according to a common vulnerabilities and exposure (CVE) dictionary.

8. The apparatus of claim 6 , wherein:

said vulnerability database comprises at least one of a publicly available vulnerability database and a local database.

9. The apparatus of claim 8 , wherein:

said publicly available vulnerability database comprises at least one of the ICAT Metabase and the Computer Emergency Response Team (CERT) database.

10. The apparatus of claim 7 , wherein:

said vulnerability database associates each specified network security vulnerability with at least one corresponding security recommendation;

said fifth module retrieving from said vulnerability database said security recommendations corresponding to identified network security vulnerabilities.

11. The apparatus of claim 1 , wherein:

said fourth module generates a security rating.

12. The apparatus of claim 1 , wherein:

said fourth module generates a security analysis table for correlating security threats, security mechanisms, security planes, and security layers.

13. The apparatus of claim 1 , wherein:

a network security model is used to adapt the operation of at least the third and fourth modules.

14. The apparatus of claim 13 , wherein:

said network security model classifies the functions of each of a plurality of network elements, protocols and services according to respective ones of a plurality of security layers, each of said security layers responsive to at least one of a plurality of security mechanisms adapted to mitigate network security threats;

said network model associates each classified function with at least one of a plurality of security planes, each of said plurality of security planes included within each of said plurality of security layers;

said network model enables identifying of the vulnerability of each function for each security layer and security plane associated with said function.

15. The apparatus of claim 1 , wherein:

said fourth module generates a report listing said network security vulnerabilities.

16. The apparatus of claim 15 , wherein:

said report includes security recommendations derived from a vulnerability database that specifies network security vulnerabilities according to a common vulnerabilities and exposure (CVE) dictionary.

17. The apparatus of claim 4 , wherein:

said selected network testing procedures are configured in response to at least one of said customer responses to said qualification questions and said customer responses to said survey questions.

18. The apparatus of claim 1 , wherein:

said fourth module generates a security assessment indicative of a percentage compliance with group of best practices.

19. The apparatus of claim 1 , wherein:

said customer interacts with said tool and receives said security recommendations via a common interface.

20. The apparatus of claim 14 , wherein:

said plurality of security planes comprises an end user security plane, a control security plane, and a management security plane;

said plurality of security layers comprises an infrastructure security layer, a services security layer, and an applications security layer; and

said plurality of security mechanisms comprises an access management mechanism, an authentication mechanism, a non-repudiation mechanism, a data confidentiality mechanism, a communication security mechanism, an integrity mechanism, an availability mechanism, and a privacy mechanism.

21. A computer readable storage medium storing instructions which, when executed by a processor, perform a method for assessing network security, the method comprising:

receiving, from a customer, information adapted for assessing network security, at least a portion of said information comprising customer responses to questions;

executing network testing procedures on the network to generate therefrom test results adapted for assessing network security, wherein at least a portion of said network testing procedures are automatically selected for execution on the network based on at least a portion of said customer responses to said questions;

determining, using said information and said test results, if a network has associated with it a network security vulnerability; and

generating security recommendations based upon any determined network security vulnerabilities.

Assignments (11)
NOTICE OF GRANT OF SECURITY INTEREST IN PATENTS Recorded Jan 22, 2025
From: CACI LGS INNOVATIONS LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 069987/0444 →
CHANGE OF NAME Recorded Nov 4, 2024
From: LGS INNOVATIONS LLC
To: CACI LGS INNOVATIONS LLC
Reel/Frame 069292/0770 →
NOTICE OF GRANT OF SECURITY INTEREST IN PATENTS Recorded May 29, 2019
From: LGS INNOVATIONS LLC
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 049312/0843 →
RELEASE OF SECURITY INTEREST Recorded May 21, 2019
From: BANK OF AMERICA, N.A.
To: LGS INNOVATIONS LLC
Reel/Frame 049247/0557 →
RELEASE OF SECURITY INTEREST Recorded May 2, 2019
From: BANK OF AMERICA, N.A.
To: LGS INNOVATIONS LLC
Reel/Frame 049074/0094 →
NOTICE OF GRANT OF SECURITY INTEREST IN PATENTS Recorded Jul 19, 2017
From: LGS INNOVATIONS LLC
To: BANK OF AMERICA, N.A.
Reel/Frame 043254/0393 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 23, 2014
From: ALCATEL LUCENT
To: LGS INNOVATIONS LLC
Reel/Frame 032743/0584 →
SECURITY INTEREST Recorded Apr 1, 2014
From: LGS INNOVATIONS LLC
To: BANK OF AMERICA NA
Reel/Frame 032579/0066 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 15, 2012
From: ALCATEL-LUCENT USA INC.
To: ALCATEL LUCENT
Reel/Frame 028381/0386 →
MERGER Recorded Jun 11, 2012
From: LUCENT TECHNOLOGIES INC.
To: ALCATEL-LUCENT USA INC.
Reel/Frame 028352/0218 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 21, 2003
From: CHANDRASHEKHAR, UMA; KIM, EUNYOUNG; KOLLER, DANIEL P.; MCGEE, ANDREW ROY; PICKLESIMER, DAVID D.; POLITOWICZ, TIMOTHY J.; RICHMAN, STEVEN H.; TILLER, JAMES S.; XIE, CHEN
To: LUCENT TECHNOLOGIES, INC.
Reel/Frame 013694/0928 →