IP Library Granted Patent US 7,779,468
Granted Patent B1
US 7,779,468 · App. 11/855,949 · Granted Aug 17, 2010

Intrusion detection and vulnerability assessment system, method and computer program product

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,779,468
App. No.
11/855,949
Granted
Aug 17, 2010
Kind
B1
Abstract

A system and associated method/computer program product are provided including an intrusion detection tool for determining whether network communications violate at least one of a plurality of policies. Such policies are defined to detect potential attacks in the network communications. Further included is a vulnerability assessment scanning tool coupled to the intrusion detection tool. The vulnerability assessment scanning tool is adapted for performing a vulnerability assessment scan for identifying vulnerabilities.

Claims (31)

1. A method for scanning a source of suspicious network communications, comprising:

monitoring network communications for violations of policies;

determining whether the network communications violate at least one of the policies;

identifying a source of the network communications that violate at least one of the policies;

automatically scanning the source of the network communications upon it being determined that the network communications violate at least one of the policies, utilizing a processor, wherein the scan includes a risk assessment scan for identifying vulnerabilities at the source; and

executing a remedying event based on the risk assessment scan, wherein the remedying event includes extracting harmful information from infected network communications.

2. The method as recited in claim 1 , and further comprising determining whether the network communications exploit at least one of a plurality of known vulnerabilities.

3. The method as recited in claim 2 , and further comprising executing the remedying event if it is determined that the network communications exploit at least one of the known vulnerabilities.

4. The method as recited in claim 1 , wherein the policies are user-defined.

5. The method as recited in claim 1 , wherein the policies are defined to detect potential attacks in the network communications.

6. The method as recited in claim 1 , and further comprising updating a database of known vulnerabilities based on the risk assessment scan.

7. The method as recited in claim 6 , wherein the database of known vulnerabilities is utilized for determining whether the network communications exploit at least one of a plurality of the known vulnerabilities, and executing the remedying event if it is determined that the network communications exploit at least one of the known vulnerabilities.

8. The method as recited in claim 1 , wherein the monitoring, the determining, and the identifying are executed utilizing an intrusion detection tool.

9. The method as recited in claim 1 , wherein the automatic scanning is executed utilizing a risk assessment scanning tool.

10. The method as recited in claim 1 , wherein the monitoring, the determining, the identifying, and the automatic scanning are executed utilizing a single module.

11. A computer program product embodied on a non-transitory computer readable medium for scanning a source of suspicious network communications, comprising:

computer code for monitoring network communications for violations of policies;

computer code for determining whether the network communications violate at least one of the policies;

computer code for identifying a source of the network communications that violate at least one of the policies;

computer code for automatically scanning the source of the network communications upon it being determined that the network communications violate at least one of the policies, wherein the scan includes a risk assessment scan for identifying vulnerabilities at the source; and

computer code for executing a remedying event based on the risk assessment scan, wherein the remedying event includes extracting harmful information from infected network communications.

12. The computer program product as recited in claim 11 , and further comprising computer code for determining whether the network communications exploit at least one of a plurality of known vulnerabilities.

13. The computer program product as recited in claim 12 , and further comprising computer code for executing the remedying event if it is determined that the network communications exploit at least one of the known vulnerabilities.

14. The computer program product as recited in claim 11 , wherein the policies are user-defined.

15. The computer program product as recited in claim 11 , wherein the policies are defined to detect potential attacks in the network communications.

16. A system, comprising:

an intrusion detection tool for determining whether network communications violate at least one of a plurality of policies; and

risk assessment scanning tool coupled to the intrusion detection tool, the risk assessment scanning tool adapted for scanning a source of the network communications that violate the at least one policy in response to a command from the intrusion detection tool, wherein the scan includes a risk assessment scan for identifying vulnerabilities at the source; and

wherein the system is operable such that a remedying event is executed based on the risk assessment scan, the remedying event including extracting harmful information from infected network communications;

wherein the intrusion detection tool and the risk assessment scanning tool are embodied on a non-transitory computer readable medium.

17. The method as recited in claim 1 , wherein the remedying event includes quarantining the infected network communications.

Assignments (8)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →