IP Library Granted Patent US 7,181,769
Granted Patent B1
US 7,181,769 · App. 10/456,837 · Granted Feb 20, 2007

Network security system having a device profiler communicatively coupled to a traffic monitor

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,181,769
App. No.
10/456,837
Granted
Feb 20, 2007
Kind
B1
Abstract

A system and method for providing distributed security of a network. Several device profilers are placed at different locations of a network to assess vulnerabilities from different perspectives. The device profiler identifies the hosts on the network, and characteristics such as operating system and applications running on the hosts. The device profiler traverses a vulnerability tree having nodes representative of characteristics of the hosts, each node having an associated set of potential vulnerabilities. Verification rules can verify the potential vulnerabilities. A centralized correlation server, at a centrally accessible location in the network, stores the determined vulnerabilities of the network and associates the determined vulnerabilities with attach signatures. Traffic monitors access the attack signatures and monitor network traffic for attacks against the determined vulnerabilities.

Claims (30)

1. A distributed computer network security system for detecting an attack on a host on a network having a plurality of hosts, the system comprising:

a device profiler communicatively coupled with the network, the device profiler for identifying characteristics of a host from the plurality of hosts on the network and determining vulnerabilities of the host based on the characteristics according to a tree-structured vulnerability table; and

a traffic monitor, communicatively coupled with the network and the device profiler, and cooperative with the device profiler, for monitoring the network for traffic indicative of an attack on the host, from the plurality of hosts on the network, exploiting one of the determined vulnerabilities of the host, wherein a determined vulnerability pertains to a specific location and wherein the traffic monitor monitors for exploits of the determined vulnerability directed to the location and ignores exploits of the determined vulnerability directed to locations to which the determined vulnerability does not pertain.

2. The system of claim 1 , wherein the device profiler comprises:

an identification subsystem for sending data packets to the host and determining the characteristics of the host based on the host's response to the data packets.

3. The system of claim 2 , wherein the identification subsystem comprises:

an high-level sensor for sending data packets to the host and analyzing responses of the host with respect to at least one of layer 5, layer 6 and layer 7 of the Open Systems Interconnection model to determine characteristics of the host.

4. The system of claim 3 , wherein the determined characteristics comprise an application executing on the host.

5. The system of claim 2 , further comprising:

a control module for generating a list of vulnerabilities of the host based on the characteristics determined by the identification subsystem.

6. The system of claim 5 , wherein the control module is adapted to use the characteristics determined by the identification subsystem to traverse the tree-structured vulnerability table, the vulnerability table having nodes associated with the characteristics of the host, each node having an associated set of vulnerabilities.

7. The system of claim 6 , wherein a node representing an application further comprises an operating system weight indicative of an operating system executing on the host.

8. The system of claim 6 , wherein the control module is adapted to determine a set of vulnerabilities of the host by summing the vulnerabilities associated with traversed nodes.

9. A distributed computer network security system for detecting an attack on a host on a network having a plurality of hosts, the system comprising:

a device profiler communicatively coupled with the network, the device profiler for identifying characteristics of a host from the plurality of hosts on the network and determining vulnerabilities of the host based on the characteristics according to a tree-structured vulnerability table;

a traffic monitor, communicatively coupled with the network and the device profiler, and cooperative with the device profiler, for monitoring the network for traffic indicative of an attack on the host, from the plurality of hosts on the network, exploiting one of the determined vulnerabilities of the host; and

a centralized correlation server, communicatively coupled with the network at a centrally accessible location, the device profiler and the traffic monitor, the centralized correlation server for receiving the determined vulnerabilities from the device profiler, identifying signatures of network traffic indicating attacks exploiting the determined vulnerabilities, and sending the signatures to the traffic monitor.

10. The system of claim 9 , wherein the network has a plurality of locations and each location provides a different perspective of the host, and wherein there are a plurality of device profilers coupled to the network at a network location, each device profiler determining vulnerabilities of the host from the device profiler's perspective at the network location.

11. The system of claim 10 , wherein the centralized correlation server further comprises a vulnerability verification rules database for storing rules to non-intrusively verify the identified vulnerabilities.

12. The system of claim 10 , wherein the centralized correlation server further comprises an identified vulnerabilities module for storing a plurality of determined vulnerabilities received from the plurality of device profilers, identifying signatures of network traffic indicating attacks exploiting determined vulnerabilities, and sending the attack signatures to the traffic monitor.

13. The system of claim 12 , wherein one or more traffic monitors are at selected locations on the network, and wherein the centralized correlation server sends the traffic monitor attack signatures for only vulnerabilities exploitable from the perspective of the traffic monitor.

14. The system of claim 9 , wherein the centralized correlation server comprises:

an event module for, in response to receiving a notification related to one of the determined vulnerabilities, performing a set of actions to block exposure to the vulnerability.

15. The system of claim 14 , further comprising:

a firewall adapted to selectively restrict network traffic to the host, wherein the event module is adapted to configure the firewall to restrict traffic that exploits the determined vulnerability.

16. A distributed computer network security system for detecting an attack on a host on a network having a plurality of hosts, the system comprising:

a device profiler communicatively coupled with the network, the device profiler for identifying characteristics of a host from the plurality of hosts on the network and determining vulnerabilities of the host based on the characteristics according to a tree-structured vulnerability table, the device profiler including a low-level sensor for sending anomalous data packets to the host and determining the characteristics based on the host's response to the anomalous data packets; and

a traffic monitor, communicatively coupled with the network and the device profiler, and cooperative with the device profiler, for monitoring the network for traffic indicative of an attack on the host, from the plurality of hosts on the network, exploiting one of the determined vulnerabilities of the host.

17. The system of claim 16 , wherein the low-level sensor is adapted to determine the characteristics of the host by analyzing responses of the host with respect to at least one of layer 3 and layer 4 of the Open Systems Interconnection model.

18. The system of claim 16 , wherein the determined characteristics comprise an operating system version and patch level of the host.

Assignments (16)
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 60306/0365 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: TRIPWIRE, INC.
Reel/Frame 074023/0235 →
TERMINATION AND RELEASE OF FIRST LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 60306/0555 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: TRIPWIRE, INC.
Reel/Frame 074023/0320 →
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 60306/0649 Recorded Nov 21, 2025
From: ACQUIOM AGENCY SERVICES LLC
To: TRIPWIRE, INC.
Reel/Frame 073663/0698 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 14, 2025
From: GOLUB CAPITAL MARKETS LLC (AS EXISTING AGENT)
To: ACQUIOM AGENCY SERVICES LLC (AS SUCCESSOR COLLATERAL AGENT)
Reel/Frame 072471/0665 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jun 7, 2022
From: TRIPWIRE, INC.
To: GOLUB CAPITAL MARKETS LLC, AS COLLATERAL AGENT
Reel/Frame 060306/0649 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jun 7, 2022
From: TRIPWIRE, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 060306/0365 →
RELEASE OF SECURITY INTEREST Recorded Feb 2, 2015
From: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
To: TRIPWIRE, INC.; NCIRCLE NETWORK SECURITY INC.
Reel/Frame 034874/0150 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 24, 2014
From: NCIRCLE NETWORK SECURITY, INC.
To: TRIPWIRE, INC.
Reel/Frame 032124/0592 →
RELEASE OF SECURITY INTEREST Recorded Apr 3, 2013
From: COMERICA BANK
To: NCIRCLE NETWORK SECURITY, INC.
Reel/Frame 030145/0916 →
RELEASE OF SECURITY INTEREST Recorded Apr 3, 2013
From: COMERICA BANK
To: NCIRCLE NETWORK SECURITY, INC.
Reel/Frame 030146/0080 →
SECURITY AGREEMENT Recorded Apr 2, 2013
From: TRIPWIRE, INC.; NCIRCLE NETWORK SECURITY, INC.
To: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 030132/0101 →
SECURITY AGREEMENT Recorded Jul 7, 2011
From: NCIRCLE NETWORK SECURITY, INC.
To: COMERICA BANK
Reel/Frame 026558/0699 →
RELEASE OF SECURITY INTEREST Recorded Jun 30, 2010
From: VELOCITY VENTURE FUNDING, LLC
To: NCIRCLE NETWORK SECURITY, INC.
Reel/Frame 024611/0368 →
SECURITY AGREEMENT Recorded Apr 28, 2010
From: NCIRCLE NETWORK SECURITY, INC.
To: COMERICA BANK
Reel/Frame 024305/0076 →
SECURITY AGREEMENT Recorded May 7, 2008
From: NCIRCLE NETWORK SECURITY, INC.
To: VELOCITY FINANCIAL GROUP, INC.
Reel/Frame 020909/0383 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 6, 2003
From: KEANINI, TIMOTHY D.; QUIROGA, MARTIN A.; BUCHANAN, BRIAN W.; FLOWERS, JOHN S.
To: NCIRCLE NETWORK SECURITY, INC.
Reel/Frame 014161/0123 →