IP Library Granted Patent US 7,536,456
Granted Patent B2
US 7,536,456 · App. 10/778,836 · Granted May 19, 2009

System and method for applying a machine-processable policy rule to information gathered about a network

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,536,456
App. No.
10/778,836
Granted
May 19, 2009
Kind
B2
Abstract

A prevention-based network auditing system includes a central compliance server storing both natural language policy documents and machine-processable policy rules in an audit repository. The compliance server provides a client-side user interface allowing a user to easily generate a machine-auditable policy by selecting/generating a natural language policy source document, and linking the applicable machine-processable policy rules to the applicable portions of the source document. The selected machine-processable policy rules are then applied to information gathered about the network during a scheduled network audit session for efficiently and systematically determining whether policy violations and/or vulnerabilities exist.

Claims (49)

1. A method comprising:

maintaining in a data store, a natural language policy document for a network policy and one or more machine-processable policy rules;

associating at least a portion of the natural language policy document to at least one of the machine-processable policy rules;

applying the at least one of the machine-processable policy rules to information gathered about a network; and

determining, based on the application of the at least one of the machine-processable policy rules, compliance with the network policy;

wherein the information is gathered via a plurality of audit servers using heterogeneous information sources, the heterogeneous information sources including at least one of a scanner, a camera, and manually entered data;

wherein each of the plurality of audit servers include a scan harness that interoperates with the scanner;

wherein the audit servers are configured to allow enumeration of unique network devices, to allow correlation of characteristics associated with the unique network devices, and to filter network packets.

2. The method of claim 1 , further comprising making a recommendation for modifying a network feature based on the compliance with the network policy.

3. The method of claim 2 , wherein the recommendation is associated with a change to the network policy.

4. The method of claim 3 , wherein the recommendation is adding a rule to the network policy.

5. The method of claim 1 , wherein the at least one of the machine-processable policy rules is uniformly applied to the gathered information without regard to an information source type.

6. The method of claim 1 , further comprising:

receiving a user selection of a first portion of the natural language policy document;

receiving a user selection of a first policy rule from a list of machine-processable policy rules;

receiving a user selection of a second portion of the natural language policy document;

receiving a user selection of a second policy rule from the list of machine-processable policy rules; and

associating the first portion of the natural language policy document to the first policy rule, and the second portion of the natural language policy document to the second policy rule.

7. The method of claim 1 , further comprising:

receiving a user selection of the network policy;

associating the selected network policy to a network audit; and

automatically applying the at least one of the machine-processable policy rules to the information gathered about the network during the network audit.

8. The method of claim 1 , wherein the at least one of the machine-processable policy rules is associated with a severity meter for violating the at least one of the machine-processable policy rules.

9. The method of claim 1 , wherein the information gathered about the network is historic audit information, and the method further comprises modeling an effect of applying the network policy on the network based on the historic audit information.

10. The method of claim 1 , wherein the gathered information is converted into a normalized data format and stored in an audit repository for access by a compliance server.

11. The method of claim 1 , wherein the scanner includes at least one of an open source scanner, a third party scanner, a special purpose scanner, and a customer scanner.

12. A server in a network auditing system, the server comprising:

a data store storing a natural language policy document for a network policy and one or more machine-processable policy rules;

a client-side user interface coupled to the data store, the user interface allowing a user to associate at least a portion of the natural language policy document to at least one of the machine-processable policy rules;

means for applying the at least one of the machine-processable policy rules to information gathered about a network; and

means for determining, based on the application of the at least one of the machine-processable policy rules, compliance with the network policy;

wherein the information is gathered via a plurality of audit servers using heterogeneous information sources, the heterogeneous information sources including at least one of a scanner, a camera, and manually entered data;

wherein each of the plurality of audit servers include a scan harness that interonerates with the scanner;

wherein the audit servers are configured to allow enumeration of unique network devices, to allow correlation of characteristics associated with the unique network devices, and to filter network packets.

13. The server of claim 12 , further comprising means for making a recommendation for modifying a network feature based on the compliance with the network policy.

14. The server of claim 13 , wherein the recommendation is associated with a change to the network policy.

15. The server of claim 13 , wherein the recommendation is adding a rule to the network policy.

16. The server of claim 12 , further comprising means for uniformly applying the at least one of the machine-processable policy rules to the gathered information without regard to an information source type.

17. The server of claim 12 , wherein the client-side user interface further comprises:

means for receiving a user selection of a first portion of the natural language policy document;

means for receiving a user selection of a first policy rule from a list of machine-processable policy rules;

means for receiving a user selection of a second portion of the natural language policy document;

means for receiving a user selection of a second policy rule from the list of machine-processable policy rules; and

means for associating the first portion of the natural language policy document to the first policy rule, and the second portion of the natural language policy document to the second policy rule.

18. The server of claim 12 , further comprising:

means for receiving a user selection of the network policy;

means for associating the selected network policy to a network audit; and

means for automatically applying the at least one of the machine-processable policy rules to information gathered about the network during the network audit.

19. The server of claim 12 , wherein the information gathered about the network is historic audit information, and the server comprises means for modeling an effect of applying the network policy on the network based on the historic audit information.

Assignments (22)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 057453, FRAME 0053 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0413 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 056990, FRAME 0960 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0430 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 29, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 061007/0124 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 057315 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 11, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 060878/0126 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 056990/0960 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057453/0053 →
RELEASE OF SECURITY INTEREST Recorded Jul 26, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: MCAFEE, LLC; SKYHIGH NETWORKS, LLC
Reel/Frame 057620/0102 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 16, 2014
From: PREVENTSYS, INC.
To: MCAFEE, INC.
Reel/Frame 034511/0915 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 23, 2004
From: PAYNE, JOHN; WILLIAMS, JOHN LESLIE; COSTELLO, BRIAN; RAVENEL, JOHN PATRICK; RITTER, STEPHEN J.; TADASHI, RYAN; PELLY, JOHN; RUTHERFORD, CELESTE
To: PREVENTSYS, INC.
Reel/Frame 016007/0117 →