IP Library Granted Patent US 7,624,422
Granted Patent B2
US 7,624,422 · App. 10/778,837 · Granted Nov 24, 2009

System and method for security information normalization

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,624,422
App. No.
10/778,837
Granted
Nov 24, 2009
Kind
B2
Abstract

A prevention-based network auditing system includes an audit repository storing network information gathered by a plurality of heterogeneous information sources. A semantic normalization module identifies semantic equivalencies in the gathered information, and generates a map listing for each fact gathered by an information source, an equivalent fact or set of facts gathered by each of the other information sources. A network policy is then uniformly applied to the information that is identified as being semantically equivalent.

Claims (41)

1. A network auditing method comprising:

retrieving network information gathered by a plurality of heterogeneous information sources;

identifying a network policy to be applied to the retrieved information, utilizing a policy and vulnerability engine;

identifying semantic equivalencies in the information gathered by the plurality of heterogeneous information sources, utilizing the policy and vulnerability engine;

uniformly applying the network policy to the information identified as being semantically equivalent, utilizing the policy and vulnerability engine;

determining compliance with the network policy, utilizing the policy and vulnerability engine; and

making a recommendation for modifying a network feature based on the compliance determination, utilizing the policy and vulnerability engine;

wherein the identifying semantic equivalencies comprises:

identifying a list of facts gathered by each information source;

identifying for each fact on the list one or more equivalent facts gathered by each of the other information sources; and

storing the semantic equivalences;

wherein the recommendation is a list of network policy rules to include in the network policy;

wherein the network policy rules are ranked based on a number of times that a network policy rule was applied, a severity meter set for the network policy rule, and assets that are affected;

wherein an identifier is used for generating the network policy rule independently of a source type.

2. The method of claim 1 , wherein each semantic equivalence is associated with the identifier.

3. The method of claim 2 , wherein the identifier is associated with computer code parsing the information gathered by each heterogeneous information source.

4. The method of claim 1 , wherein the recommendation is a change to the network policy.

5. The method of claim 1 , wherein the recommendation is a task associated with the network feature.

6. A server in a network auditing system, the server comprising:

a data store storing network information gathered by a plurality of heterogeneous information sources;

a semantic normalization module coupled to the data store, the module identifying semantic equivalencies in the information gathered by the plurality of heterogeneous information sources;

means for uniformly applying a network policy to the information identified as being semantically equivalent;

means for determining compliance with the network policy; and

means for making a recommendation for modifying a network feature based on the compliance determination;

wherein the identifying semantic equivalencies comprises:

identifying a list of facts gathered by each information source;

identifying for each fact on the list one or more equivalent facts gathered by each of the other information sources; and

storing the semantic equivalences;

wherein the recommendation is a list of network policy rules to include in the network policy;

wherein the network policy rules are ranked based on a number of times that a network policy rule was applied, a severity meter set for the network policy rule, and assets that are affected;

wherein an identifier is used for generating the network policy rule independently of a source type.

7. The server of claim 6 , wherein each semantic equivalence is associated with the identifier.

8. The server of claim 7 , further comprising means for generating the network policy rule independently of the source type based on the identifier.

9. The server of claim 7 , wherein the identifier is associated with computer code parsing the information gathered by each heterogeneous information source.

10. The server of claim 6 , wherein the recommendation is a change to the network policy.

11. The server of claim 6 , wherein the recommendation is a task associated with the network feature.

12. The method of claim 1 , wherein the information gathered by the plurality of heterogeneous information sources is converted into a machine-processable language format normalized for structure.

13. The method of claim 1 , wherein the plurality of heterogeneous information sources include at least one of a scanner, a camera, and manually entered data.

14. The method of claim 1 , wherein the network policy rules include at least one of the network policy rules to find violations of the network policies; the network policy rules to gather information about a network; the network policy rules to identify compromised hosts; and the network policy rules to identify vulnerabilities in the network.

15. The method of claim 1 , wherein the severity meter quantifies the network policy rule as a severity from a severity range of 1 to 100, and allows the network policy rule to be weighted relative to other network policy rules in the list of network policy rules.

16. The method of claim 1 , wherein the making of the recommendation includes generating a remediation task for the network policy, the remediation task including information indicating the remediation task is for a network policy violation, a name of the network policy or a name of the network policy rule, a severity measure for the network policy rule, an address of a host in which the network policy violation was noted, and a date in which the network policy violation was detected.

Assignments (14)
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 056990, FRAME 0960 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0430 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 057453, FRAME 0053 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0413 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 057315 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 11, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 060878/0126 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 056990/0960 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057453/0053 →
RELEASE OF SECURITY INTEREST Recorded Jul 26, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: MCAFEE, LLC; SKYHIGH NETWORKS, LLC
Reel/Frame 057620/0102 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 16, 2014
From: PREVENTSYS, INC.
To: MCAFEE, INC.
Reel/Frame 034511/0965 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 23, 2004
From: WILLIAMS, JOHN LESLIE; COSTELLO, BRIAN; RAVENEL, JOHN PATRICK; PELLY, JOHN; NAKAWATASE, RYAN TADASHI; WALPOLE, THOMAS PAUL
To: PREVENTSYS, INC.
Reel/Frame 016007/0237 →