IP Library Granted Patent US 7,680,880
Granted Patent B2
US 7,680,880 · App. 11/410,730 · Granted Mar 16, 2010

System and method for protecting a computer network

Assignee: McAfee, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,680,880
App. No.
11/410,730
Granted
Mar 16, 2010
Kind
B2
Abstract

A system for protecting a computer network from vulnerabilities can be provided that generally includes a remedy and patch server located at a client site and adapted to receive a global remedy package and a global patch package. The global remedy package may include at least one remedy and the global patch package may include at least one patch. At least one remedy and optionally at least one patch can repair a vulnerability in the computer network. The system can further include at least one local remedy server adapted to communicate with the remedy and patch server for receiving at least one remedy. At least one local patch server may be adapted to communicate with the remedy and patch server to receive at least one patch. The system also generally includes a local computer system adapted to communicate, independently, with the at least one local remedy server and at least one local patch server for receiving, respectively, at least one remedy and optionally at least one patch.

Claims (42)

1. A system, comprising:

a remedy and patch hardware server located at a client site and adapted to receive a global remedy package from a primary provider comprising at least one remedy and a global patch package from a secondary provider comprising at least one patch, wherein at least one remedy and optionally at least one patch can repair a vulnerability in a computer network;

at least one local remedy hardware server separate from the remedy and patch hardware server, the at least one local remedy hardware server adapted to communicate with the remedy and patch hardware server for receiving at least one remedy, wherein the at least one local remedy hardware server is provided by the primary provider of the global remedy package;

at least one local patch hardware server separate from the remedy and patch hardware server and the at least one local remedy hardware server, the at least one local patch hardware server adapted to communicate with the remedy and patch hardware server to receive at least one patch;

a local computer hardware system adapted to communicate, independently, with the at least one local remedy hardware server and at least one local patch hardware server for receiving, respectively, at least one remedy and optionally at least one patch;

a globally connected system comprising the remedy and patch hardware server, the at least one local remedy hardware server, the at least one local patch hardware server, and the local computer system;

a disconnected system at the client site comprising a second remedy and patch server, at least one second local remedy server and at least one second local patch server, wherein each of the at least one second local remedy server and at least one second local patch server communicates, independently, with a second local computer system; and

the remedy and patch hardware server in the globally connected system being adapted to transfer at least one of the global remedy package and the global patch package on a data transfer media, and the at least one disconnected local remedy server and at least one disconnected local patch server being adapted to receive at least a portion of data from the data transfer media.

2. The system according to claim 1 , wherein the system further comprises a second-tier remedy and patch server, which is adaptable to be in a mirrored configuration with the remedy and patch hardware server.

3. The system according to claim 1 , wherein one of the local patch hardware servers in the globally connected system is a master local patch server.

4. The system according to claim 1 , wherein one of the local patch servers in the disconnected system is a master local patch server.

5. The system according to claim 1 , wherein the globally connected system further comprises a second-tier remedy and patch server, which is adaptable to be in a mirrored configuration with the remedy and patch hardware server in the globally connected system.

6. The system according to claim 5 , wherein the globally connected system further comprises a third-tier remedy and patch server, which is adaptable to be in a mirrored configuration with the second-tier remedy and patch server.

7. The system according to claim 5 , wherein the tiered configuration of the remedy and patch servers can be altered.

8. The system according to claim 5 , wherein the mirrored configuration of the tiered remedy and patch servers are initiated on a predetermined schedule.

9. The system according to claim 5 , wherein the mirrored configuration of the tiered remedy and patch servers are initiated on demand.

10. The system according to claim 1 , wherein the disconnected system further comprises a second-tier remedy and patch server, at least one second-tier local remedy server, and at least one second-tier local patch server, wherein the second-tier remedy and patch server is adaptable to be in a mirrored configuration with the second remedy and patch server in the disconnected system.

11. A system, comprising:

a first server comprising a storage unit at a client site and in communication with a local computer system, wherein the storage unit comprises:

a remedy repository for receiving data from a global remedy package, in turn, comprising at least one remedy to repair a vulnerability in a computer network and obtained via the Internet from a primary provider;

a patch repository for receiving data from a global patch package, in turn, comprising at least one patch to repair a vulnerability in the computer network and obtained via the Internet from at least one secondary provider, wherein the packages are requested at the client site for transfer of at least one remedy and optionally at least one patch to the local computer system to repair a vulnerability;

a custom repository comprising prioritization data and testing approval data originating from within the client site;

wherein the client site is operable to receive the at least one remedy from the first server via a local remedy server separate from the first server and is further operable to optionally receive the at least one patch from the first server via a local patch server separate from the first server and the local remedy server;

wherein the local remedy server is provided by the primary provider of the global remedy package;

wherein a globally connected system comprises the first server, the at least one local remedy server, the at least one local patch server, and the local computer system;

wherein a disconnected system at the client site comprises a second server, at least one second local remedy server and at least one second local patch server, wherein each of the at least one second local remedy server and at least one second local patch server communicates, independently, with a second local computer system;

wherein the first server in the globally connected system is adapted to transfer at least one of the global remedy package and the global patch package on a data transfer media, and the at least one disconnected local remedy server and at least one disconnected local patch server being adapted to receive at least a portion of the global remedy package and the global patch package from the data transfer media.

12. A system according to claim 11 , further comprising a secured server disconnected from the computer network, the first server being adapted to replicate the global remedy package and the global patch package to the data transfer media, and the secured server being adapted to receive the global remedy package and the global patch package from the data transfer media.

13. A system according to claim 11 , wherein the global remedy package comprises remedy data, patch validation data, and association data comprising a correlation of a remedy to at least one vulnerability, and optionally to one or more patches.

14. A method, comprising:

generating remedies at a primary provider to repair vulnerabilities in a computer network and combining the remedies into a global remedy package;

generating patches at a secondary provider to repair vulnerabilities in the computer network and combining the patches into a global patch package;

sending the global remedy package and the global patch package upon request by a client to a remedy and patch server wherein the global remedy package comprises remedy data, patch validation data, and association data of a remedy to at least one vulnerability;

disseminating the remedy package directly or indirectly to a local remedy server and the global patch package to a local patch sever after downloading to the remedy and patch server; and

disseminating the remedy package from the local remedy server to a local computer system and applying the remedy on the local computer system;

wherein the remedy and patch server, the local remedy server and the local patch server include separate servers;

wherein the local remedy server is provided by the primary provider of the global remedy package;

disseminating the remedy package directly or indirectly to the local remedy server on a system disconnected from the remedy and patch server and the global patch package to the local patch sever on the disconnected system after downloading to the remedy and patch server; and

disseminating the remedy package from the local remedy server to a local computer system on the disconnected system.

15. A method according to claim 14 , further comprising archiving the patch data in the global patch package to the remedy and patch server after downloading.

16. A method according to claim 14 , further comprising validating at least one patch against the patch validation data.

17. A method according to claim 14 , wherein the association data further comprises data associating one or more patches to a vulnerability.

Assignments (12)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 23, 2007
From: MCAFEE SECURITY, LLC, A DELAWARE LIMITED LIABILITY COMPANY
To: MCAFEE, INC., A DELAWARE CORPORATION
Reel/Frame 018923/0152 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 22, 2006
From: CITADEL SECURITY SOFTWARE, INC.
To: MCAFEE SECURITY LLC
Reel/Frame 018668/0179 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 25, 2006
From: LANDFIELD, KENT B.
To: CITADEL SECURITY SOFTWARE, INC.
Reel/Frame 017828/0174 →
Continuity (1)
Related Publication 20070250595A1 · Oct 25, 2007