IP Library Granted Patent US 7,386,883
Granted Patent B2
US 7,386,883 · App. 10/624,158 · Granted Jun 10, 2008

Systems, methods and computer program products for administration of computer security threat countermeasures to a computer system

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,386,883
App. No.
10/624,158
Granted
Jun 10, 2008
Kind
B2
Abstract

A countermeasure for a computer security threat to a computer system is administered by establishing a baseline identification of an operating or application system type and an operating or application system release level for the computer system that is compatible with a Threat Management Vector (TMV). A TMV is then received, including therein a first field that provides identification of at least one operating system type that is affected by a computer security threat, a second field that provides identification of an operating system release level for the operating system type, and a third field that provides identification of a set of possible countermeasures for an operating system type and an operating system release level. Countermeasures that are identified in the TMV are processed if the TMV identifies the operating system type and operating system release level for the computer system as being affected by the computer security threat. The received TMV may be mutated to a format for processing of the countermeasure.

Claims (27)

1. A method of administering a countermeasure for a computer security threat to a computer system, comprising:

establishing a baseline identification of an operating system type and an operating system release level for the computer system that is compatible with a Threat Management Vector (TMV);

receiving a TMV including therein a first field that provides identification of at least one operating system type that is affected by a computer security threat, a second field that provides identification of an operating system release level for the operating system type and a third field that provides identification of a set of possible countermeasures for an operating system type and an operating system release level; and

processing countermeasures that are identified in the TMV if the TMV identifies the operating system type and operating system release level for the computer system as being affected by the computer security threat;

wherein the processing comprises:

determining whether the TMV identifies the operating system type and operating system release level for the computer system as being affected by the computer security threat;

adding at least one instance identifier to the TMV to account for multiple instances of the operating system running on the computer system, if the TMV identifies the operating system type and operating system release level for the computer system as being affected by the computer security threat; and

processing countermeasures that are identified in the TMV for the instance of the operating system type and operating system release level when the instance of the operating system type and operating system release level is instantiated in the computer system.

2. A method according to claim 1 wherein the processing comprises installing and running the countermeasure.

3. A method of administering a countermeasure for a computer security threat to a computer system, comprising:

establishing a baseline identification of an operating system type and an operating system release level for the computer system that is compatible with a Threat Management Vector (TMV);

receiving a TMV including therein a first field that provides identification of at least one operating system type that is affected by a computer security threat, a second field that provides identification of an operating system release level for the operating system type and a third field that provides identification of a set of possible countermeasures for an operating system type and an operating system release level; and

processing countermeasures that are identified in the TMV if the TMV identifies the operating system type and operating system release level for the computer system as being affected by the computer security threat;

wherein the receiving comprises receiving a TMV including therein the first field that provides identification of at least one operating system type that is affected by a computer security threat, the second field that provides identification of an operating system release level for the operating system type, a fourth field that provides identification of at least one application program type that is affected by the computer security threat and a fifth field that provides identification of a release level for the application program type, the third field providing identification of a set of possible countermeasures for the application program type and the application program release level; and

wherein the processing comprises processing countermeasures that are identified in the TMV if the TMV identifies the application program type and application program release level for the computer system as being affected by the computer security threat.

4. A method according to claim 3 wherein the processing further comprises:

determining whether the TMV identifies the application program type and application programming release level for the computer system as being affected by the computer security threat;

adding at least one instance identifier to the TMV to account for multiple instances of the application program running on the computer system if the TMV identifies the application program type and application program release level for the computer system as being affected by the computer security threat; and

processing countermeasures that are identified in the TMV for the instance of the application program type and application program release level when the instance of the application program type and application program release level is instantiated in the computer system.

5. A computer program product is configured to administer a countermeasure for a computer security threat to a computer system, the computer program product comprising a computer usable storage medium having computer-readable program code embodied in the medium, the computer-readable program code comprising:

computer-readable program code that is configured to establish a baseline identification of an operating system type and an operating system release level for the computer system that is compatible with a Threat Management Vector (TMV);

computer-readable program code that is configured to receive a TMV including therein a first field that provides identification of at least one operating system type that is affected by a computer security threat, a second field that provides identification of an operating system release level for the operating system type and a third field that provides identification of a set of possible countermeasures for an operating system type and an operating system release level; and

computer-readable program code that is configured to process countermeasures that are identified in the TMV if the TMV identifies the operating system type and operating system release level for the computer system as being affected by the computer security threat;

wherein the computer-readable program code that is configured to process comprises:

computer-readable program code that is configured to determine whether the TMV identifies the operating system type and operating system release level for the computer system as being affected by the computer security threat;

computer-readable program code that is configured to add at least one instance identifier to the TMV to account for multiple instances of the operating system running on the computer system if the TMV identifies the operating system type and operating system release level for the computer system as being affected by the computer security threat; and

computer-readable program code that is configured to process countermeasures that are identified in the TMV for the instance of the operating system type and operating system release level when the instance of the operating system type and operating system release level is instantiated in the computer system.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 27, 2010
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: TREND MICRO INCORPORATED
Reel/Frame 024286/0924 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2003
From: BARDSLEY, JEFFREY S.; BROCK, ASHLEY A.; DAVIS, CHARLES K., III; KIM, NATHANIEL W.; MCKENNA, JOHN J.; VILLEGAS, CAROLS F.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 014329/0558 →