IP Library Granted Patent US 7,162,742
Granted Patent B1
US 7,162,742 · App. 10/987,988 · Granted Jan 9, 2007

Interoperability of vulnerability and intrusion detection systems

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,162,742
App. No.
10/987,988
Granted
Jan 9, 2007
Kind
B1
Abstract

A system in accordance with an embodiment of the invention includes a vulnerability detection system (VDS) and an intrusion detection system (IDS). The intrusion detection system leverages off of information gathered about a network, such as vulnerabilities, so that it only examines and alerts the user to potential intrusions that could actually affect the particular network. In addition both the VDS and IDS use rules in performing their respective analyses that are query-based and that are easy to construct. In particular these rules are based on a set of templates, which represent various entities or processes on the network.

Claims (34)

1. A computer-based system for protecting a network, comprising:

means for gathering information about the network to determine vulnerabilities of a host from a plurality of hosts on the network; and

cooperative with the means for gathering information, means for examining network traffic responsive to the determined vulnerabilities of the host from the plurality of hosts, the means for examining configured to detect network traffic indicative of malicious activity.

2. The system of claim 1 , wherein the means for gathering information further comprises:

means for sending data to plurality of hosts on the network; and

means for receiving responsive data from the plurality of hosts.

3. The system of claim 1 , wherein the means for gathering information comprises means for receiving data automatically provided by the plurality of hosts on the network.

4. The system of claim 1 , further comprising:

means for storing rules to describe vulnerabilities of the plurality of hosts,

wherein the means for gathering is configured to determine vulnerabilities by analyzing the gathered information with the rules in the means for storing.

5. The system of claim 4 , wherein the means for gathering information is further configured to determine vulnerabilities by analyzing the gathered information with the rules stored in the means for storing to identify operating systems on the plurality of hosts.

6. The system of claim 4 , wherein the means for gathering information is further configured to determine vulnerabilities by analyzing gathered information with the rules stored in the means for storing to identify open ports on the plurality of hosts.

7. The system of claim 4 , wherein the means for gathering information is further configured to determine vulnerabilities by comparing gathered information against the rules to identify applications on the plurality of hosts.

8. The system of claim 1 , further comprising:

means for storing rules describing malicious activity,

wherein the means for examining is further configured to detect network traffic indicative of malicious activity by analyzing the network traffic with the rules in the means for storing to detect traffic indicative of exploitations of determined vulnerabilities.

9. The system of claim 1 , wherein the means for examining network traffic is further configured to detect traffic indicative of exploitations of only the determined vulnerabilities.

10. The system of claim 1 , further comprising:

means for updating the determined vulnerabilities,

wherein the means for examining is further configured to detect traffic indicative of malicious activity in response to an update from the means for updating.

11. The system of claim 10 , wherein the means for updating is configured to update the determined vulnerabilities in response to a change in the network.

12. The system of claim 1 , wherein the means for examining automatically cooperate with the means for gathering information without further manual intervention.

13. The system of claim 1 , wherein the means for examining forward to the host network traffic indicative of malicious activity that does not correspond to the determined vulnerabilities of the host.

14. The system of claim 1 , wherein the means for examining forward network traffic indicative of malicious activity that corresponds to the determined vulnerabilities of the host, but is not directed to the host.

15. The system of claim 1 , wherein, responsive to a new host joining the plurality of hosts on the network, the means for gathering information gather information about the new host to determine vulnerabilities of the new host and the means for examining examine network traffic directed to the new host responsive to the determined vulnerabilities of the new host to detect network traffic indicative of malicious activity.

16. A computer-implemented method for protecting a network, comprising:

gathering information about the network to determine vulnerabilities of a host from a plurality of hosts on the network;

cooperative with the step of gathering information, examining network traffic responsive to the determined vulnerabilities of the host from the plurality of hosts to detect network traffic indicative of malicious activity; and

forwarding to the host network traffic indicative of malicious activity that does not correspond to the determined vulnerabilities of the host.

17. A computer-implemented method for protecting a network, comprising:

gathering information about the network to determine vulnerabilities of a host from a plurality of hosts on the network;

cooperative with the step of gathering information, examining network traffic responsive to the determined vulnerabilities of the host from the plurality of hosts to detect network traffic indicative of malicious activity;

responsive to a new host joining the plurality of hosts on the network, gathering information about the new host to determine vulnerabilities of the new host; and

examining network traffic directed to the new host responsive to the determined vulnerabilities of the new host to detect network traffic indicative of malicious activity.

Assignments (15)
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 60306/0365 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: TRIPWIRE, INC.
Reel/Frame 074023/0235 →
TERMINATION AND RELEASE OF FIRST LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 60306/0555 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: TRIPWIRE, INC.
Reel/Frame 074023/0320 →
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 60306/0649 Recorded Nov 21, 2025
From: ACQUIOM AGENCY SERVICES LLC
To: TRIPWIRE, INC.
Reel/Frame 073663/0698 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 14, 2025
From: GOLUB CAPITAL MARKETS LLC (AS EXISTING AGENT)
To: ACQUIOM AGENCY SERVICES LLC (AS SUCCESSOR COLLATERAL AGENT)
Reel/Frame 072471/0665 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jun 7, 2022
From: TRIPWIRE, INC.
To: GOLUB CAPITAL MARKETS LLC, AS COLLATERAL AGENT
Reel/Frame 060306/0649 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jun 7, 2022
From: TRIPWIRE, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 060306/0365 →
RELEASE OF SECURITY INTEREST Recorded Feb 2, 2015
From: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
To: TRIPWIRE, INC.; NCIRCLE NETWORK SECURITY INC.
Reel/Frame 034874/0150 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 24, 2014
From: NCIRCLE NETWORK SECURITY, INC.
To: TRIPWIRE, INC.
Reel/Frame 032124/0592 →
RELEASE OF SECURITY INTEREST Recorded Apr 3, 2013
From: COMERICA BANK
To: NCIRCLE NETWORK SECURITY, INC.
Reel/Frame 030145/0916 →
RELEASE OF SECURITY INTEREST Recorded Apr 3, 2013
From: COMERICA BANK
To: NCIRCLE NETWORK SECURITY, INC.
Reel/Frame 030146/0080 →
SECURITY AGREEMENT Recorded Apr 2, 2013
From: TRIPWIRE, INC.; NCIRCLE NETWORK SECURITY, INC.
To: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 030132/0101 →
SECURITY AGREEMENT Recorded Jul 7, 2011
From: NCIRCLE NETWORK SECURITY, INC.
To: COMERICA BANK
Reel/Frame 026558/0699 →
RELEASE OF SECURITY INTEREST Recorded Jun 30, 2010
From: VELOCITY VENTURE FUNDING, LLC
To: NCIRCLE NETWORK SECURITY, INC.
Reel/Frame 024611/0368 →
SECURITY AGREEMENT Recorded Apr 28, 2010
From: NCIRCLE NETWORK SECURITY, INC.
To: COMERICA BANK
Reel/Frame 024305/0076 →
SECURITY AGREEMENT Recorded May 7, 2008
From: NCIRCLE NETWORK SECURITY, INC.
To: VELOCITY FINANCIAL GROUP, INC.
Reel/Frame 020909/0383 →