IP Library Granted Patent US 8,091,117
Granted Patent B2
US 8,091,117 · App. 10/778,779 · Granted Jan 3, 2012

System and method for interfacing with heterogeneous network data gathering tools

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,091,117
App. No.
10/778,779
Granted
Jan 3, 2012
Kind
B2
Abstract

A prevention-based network auditing system includes a plurality of heterogeneous information sources gathering information about the network. An audit server invokes the heterogeneous information sources via a uniform communications interface to gather information about the network, and converts the information gathered by the information sources into a normalized data format such as, for example, into XML (Extensible Markup Language). The converted information is then stored in an audit repository for security and regulatory policy assessment, network vulnerability analysis, report generation, and security improvement recommendations.

Claims (58)

1. A method comprising:

communicating with a plurality of heterogeneous information sources;

converting received network information into a normalized data format written in a mark-up language;

comparing at least a portion of the converted network information with a network policy;

determining, based on the comparison, compliance with the network policy; and

recommending rules for improving the network policy;

wherein the received network information is normalized for structure utilizing a conversion table that maps known fields of the received network information into fields used in the normalized data format;

wherein the rules are recommended via an ordered list, the ordered list ordering the rules based on a number of times each of the rules was previously applied, a severity meter set for each of the rules, or assets affected by each of the rules, wherein the network information includes a list of wireless access point devices and associated parameters used for accessing one or more wireless networks, and wherein a location for each of the wireless access points is determined.

2. The method of claim 1 , wherein the comparing further comprises:

identifying whether a first converted network information associated with a first information source is semantically equivalent to a second converted network information associated with a second information source.

3. The method of claim 1 further comprising:

tracking an identity of a network device; and

correlating the gathered network information based on the tracked identity of the network device.

4. The method of claim 1 further comprising:

scheduling a network audit for gathering the network information; and

dynamically configuring a packet filter for opening communication with a network device in response to a start of the scheduled network audit, and closing communication with the network device in response to an end of the scheduled network audit.

5. The method of claim 1 , further comprising:

making an association with a particular wireless access point.

6. The method of claim 5 , wherein the determining of the location of the particular wireless access point comprises:

identifying one or more routers associated with the particular wireless access point; and

associating the identified routers with the particular wireless access point parameters.

7. The method of claim 6 , wherein the identifying of the one or more routers comprises tracing a route of a packet transmitted via the routers.

8. A system, comprising:

a first server coupled to a plurality of heterogeneous information sources, the first server including:

means for facilitating communication with the plurality of heterogeneous information sources; and

means for converting the information gathered by the heterogeneous information sources into a normalized data format written in a mark-up language;

and

a recommendation engine for recommending rules for improving the network policy;

wherein the information is normalized for structure utilizing a conversion table that maps known fields of the information into fields used in the normalized data format;

wherein the rules are recommended via an ordered list, the ordered list ordering the rules based on a number of times each of the rules was previously applied, a severity meter set for each of the rules, or assets affected by each of the rules, wherein the network information includes a list of wireless access point devices and associated parameters used for accessing one or more wireless networks, and wherein a location for each of the wireless access points is determined.

9. The system of claim 8 further comprising:

means for comparing at least a portion of the converted information with a network policy.

10. The system of claim 8 further comprising:

means for identifying whether a first converted network information associated with a first information source is semantically equivalent to a second converted network information associated with a second information source.

11. The system of claim 8 further comprising:

means for tracking an identity of a network device; and

means for correlating the gathered network information based on the tracked identity of the network device.

12. The system of claim 8 further comprising:

means for scheduling a network audit for gathering the network information; and

means for dynamically configuring a packet filter for opening communication with a network device in response to a start of the scheduled network audit, and closing communication with the network device in response to an end of the scheduled network audit.

13. The system of claim 8 , the system further comprising:

means for making an association with a particular wireless access point.

14. The system of claim 13 , wherein the means for determining the location of the particular wireless access point comprises:

means for identifying one or more routers associated with the particular wireless access point; and

means for associating the identified routers with the particular wireless access point parameters.

15. A computer program product embodied on a tangible non-transitory computer readable medium, comprising:

computer code for receiving network information gathered by a heterogeneous information sources via the uniform communications interface;

computer code for converting the received network information into a normalized data format taking the form of a mark-up language;

computer code for comparing at least a portion of the converted network information with a network policy;

computer code for determining, based on the comparison, compliance with the network policy; and

computer code for recommending rules for improving the network policy;

wherein the received network information is normalized for structure utilizing a conversion table that maps known fields of the received network information into fields used in the normalized data format;

wherein the rules are recommended via an ordered list, the ordered list ordering the rules based on a number of times each of the rules was previously applied, a severity meter set for each of the rules, or assets affected by each of the rules, wherein the network information includes a list of wireless access point devices and associated parameters used for accessing one or more wireless networks, and wherein a location for each of the wireless access points is determined.

16. The method of claim 1 , wherein the mark-up language includes an extensible mark-up language (XML).

17. The method of claim 5 , wherein the associated parameters include at least one of an identifier, a radio frequency, a channel, and an encryption status associated with the particular wireless access point device.

18. The method of claim 1 , wherein at least one of the assets includes a particular wireless access point, and the rules are recommended in response to a determination that the network policy excludes rules for the particular wireless access point.

19. The method of claim 1 , wherein the rules are written for specific device types, specific application configurations, and specific subnets and further include rules that seek to find violations of network policies, rules that seek to gather the information about the network, rules that seek to identify compromised hosts, and rules that seek to identify vulnerabilities in the network.

20. The method of claim 1 , wherein the reference map includes a reference field and at least one data source field, the reference field including a list of references mapped to corresponding test IDs and keywords produced by data source products identified in the at least one data source field, and each test ID and keyword associated with a particular data source product is deemed semantically equivalent to at least one other test ID and keyword associated with another data source product when the test ID and keyword and the at least one other test ID and keyword are associated with the same reference.

Assignments (19)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 057453, FRAME 0053 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0413 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 056990, FRAME 0960 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0430 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 29, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 061007/0124 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 057315 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 11, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 060878/0126 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 056990/0960 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057453/0053 →
RELEASE OF SECURITY INTEREST Recorded Jul 26, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: MCAFEE, LLC; SKYHIGH NETWORKS, LLC
Reel/Frame 057620/0102 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →