IP Library Granted Patent US 8,266,703
Granted Patent B1
US 8,266,703 · App. 11/854,412 · Granted Sep 11, 2012

System, method and computer program product for improving computer network intrusion detection by risk prioritization

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,266,703
App. No.
11/854,412
Granted
Sep 11, 2012
Kind
B1
Abstract

A system, method and computer program product are provided for prioritized network security. Initially, a risk assessment scan is conducted for identifying vulnerabilities on a network device. Next, network communications are identified that exploit the vulnerabilities identified by the risk assessment scan before identifying network communications that exploit other vulnerabilities. In other words, network communications are monitored for identifying any exploitation of the vulnerabilities identified by the risk assessment scan before identifying any exploitation of other vulnerabilities.

Claims (28)

1. A method for prioritized network security, comprising:

performing a risk assessment scan for identifying vulnerabilities on a network device;

prioritizing the vulnerabilities identified by the risk assessment scan and known vulnerabilities not identified by the risk assessment scan to form a prioritized order, wherein at least one identified vulnerability is prioritized higher than a non-identified vulnerability; and

inspecting network communications to attempt to identify, in priority order, network communications that exploit the at least one identified vulnerability before attempting to identify network communications that exploit other known vulnerabilities not identified by the risk assessment scan;

wherein performing the risk assessment scan includes simulating security events.

2. The method as recited in claim 1 , wherein the risk assessment scan is carried out utilizing a risk assessment scanning tool.

3. The method as recited in claim 1 , wherein the risk assessment scan is performed on a plurality of network devices.

4. The method as recited in claim 1 , further comprising executing a remedying event upon identifying network communications that exploit the vulnerabilities.

5. The method as recited in claim 1 , wherein the network communications that exploit vulnerabilities of a lower risk are dropped before network communications that exploit vulnerabilities of a higher risk.

6. The method as recited in claim 1 , wherein the network communications include packets.

7. The method as recited in claim 1 , wherein results of simulating the security events and executing the one or more vulnerability probes are compared against a list of known vulnerabilities.

8. The method as recited in claim 1 , wherein the risk assessment scan is repeated.

9. The method as recited in claim 8 , wherein the risk assessment scan is repeated periodically.

10. The method as recited in claim 1 , wherein the vulnerabilities are prioritized by comparing the vulnerabilities identified by the risk assessment scan against a plurality of groups of vulnerabilities.

11. The method as recited in claim 10 , wherein the groups of vulnerabilities include a low risk group, a medium risk group, and a high risk group.

12. The method as recited in claim 11 , wherein the vulnerabilities identified by the risk assessment scan are transmitted to an intrusion detection system capable of identifying the network communications that exploit the vulnerabilities identified by the risk assessment scan before identifying network communications that exploit other vulnerabilities.

13. The method as recited in claim 11 , wherein the act of performing the risk assessment scan and the act of identifying the network communications are carried out by a common module.

14. A computer program product for prioritized network security embodied on a non-transitory computer-readable medium comprising instructions to cause one or more processing devices to:

perform a risk assessment scan to identify vulnerabilities on a network device;

prioritize the vulnerabilities identified by the risk assessment scan and known vulnerabilities not identified by the risk assessment scan to form a prioritized order, wherein at least one identified vulnerability is prioritized higher than a non-identified vulnerability; and

inspect network communications to attempt to identify, in priority order, network communications that exploit the at least one identified vulnerability before attempting to identify network communications that exploit other known vulnerabilities not identified by the scan;

wherein the instructions to cause the one or more processors to perform the risk assessment scan further comprise instructions to cause the one or more processors to simulate security events that make up an attack and instructions to cause the one or more processors to execute one or more vulnerability probes.

15. A method for prioritized network security, comprising:

performing a risk assessment scan for identifying vulnerabilities on a plurality of network devices utilizing a risk assessment scanning tool;

prioritizing the vulnerabilities identified by the risk assessment scan and known vulnerabilities not identified by the risk assessment scan to form a prioritized order, wherein at least one identified vulnerability is prioritized higher than a non-identified vulnerability; and

utilizing the prioritized vulnerabilities to enhance network security;

wherein performing the risk assessment scan includes simulating security events that make up an attack and executing one or more vulnerability probes; and

wherein network communications that exploit the prioritized vulnerabilities identified by the risk assessment scan are attempted to be identified before attempting to identify network communications that exploit other known vulnerabilities not identified by the scan.

Assignments (10)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
MERGER Recorded Sep 12, 2007
From: NETWORKS ASSOCIATES TECHNOLOGY, INC.
To: MCAFEE, INC.
Reel/Frame 019820/0403 →