IP Library Granted Patent US 8,914,341
Granted Patent B2
US 8,914,341 · App. 12/167,934 · Granted Dec 16, 2014

Method and apparatus for continuous compliance assessment

Inventor: Robert A. DiFalco (Portland, OR)
Assignee: Tripwire, Inc.
H04L12/2697H04L43/50
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,914,341
App. No.
12/167,934
Granted
Dec 16, 2014
Kind
B2
Abstract

In various embodiments, a target host may provide a change data to a compliance server in response to detecting a change, and the change data may include one or more rules, settings, and/or parameters. Also, in various embodiments, the compliance server may determine whether the one or more rules, settings, and/or parameters meet one or more compliance policies and generate one or more test results based at least on the results of the determining. Further, in some embodiments, the target host may detect a change to a rule, setting, and/or parameter based on a collection policy defining what change data is to be collected by the target host and provide data associated with the rule, setting, and/or parameter as change data to the compliance server.

Claims (62)

1. A method for continuous compliance assessment comprising:

receiving, by a compliance server, change data associated with a change to a target host rule detected by a collection policy that defines a scope of what change data is to be collected, and for which rules of the target host, the change data comprising:

(a) an identification of the target host,

(b) an identification of the collection policy, and

(c) element data for the change to the target host rule;

determining, by the compliance server, whether the change to the target host rule meets one or more of a plurality of compliance policies associated with the collection policy, the determining comprising:

matching the collection policy with the one or more of the plurality of compliance policies,

evaluating whether the target host specified in the change data is associated with one or more waivers and thereby determining that the target host is not associated with the one or more waivers, and

evaluating the element data against expressions of the matching one or more compliance policies, the expressions specifying requirements of the matching one or more compliance policies; and

generating, by the compliance server, one or more test results based at least on results of the determining, the one or more test results indicating whether the change to the target host rule is in compliance with the matching one or more compliance policies, and

when the change is not in compliance with the matching one or more compliance policies, generating appropriate element data for the target host rule to place the target host rule into compliance with the matching one or more compliance policies.

2. The method of claim 1 , further comprising storing, by the compliance server, the received change data in a change database.

3. The method of claim 1 , further comprising:

in response to receiving the change data, generating, by the compliance server, an event; and

performing the determining in response to the generated event.

4. The method of claim 1 , further comprising filtering, by the compliance server, the received change data and conditionally performing the determining based on a result of the filtering.

5. The method of claim 1 , wherein the generating the one or more test results comprises generating a report for at least one of the target host or an administrative user.

6. The method of claim 1 , further comprising receiving or retrieving, by the compliance server, new or updated compliance policies.

7. The method of claim 1 , further comprising repeating the receiving, determining, and generating in real time each time the target host captures an additional change to the target host rule.

8. The method of claim 1 , wherein one or more standards are defined by standards organizations that define industry standards, the matching one or more compliance policies ensuring that the target host is in compliance with the one or more standards.

9. The method of claim 8 , wherein the matching one or more compliance policies comprising matching at least two compliance policies, and wherein each of the at least two compliance policies is for a different standard.

10. The method of claim 1 , further comprising performing remedial measures to place the target host in compliance with the matching one or more compliance policies based on the one or more test results.

11. A compliance server for continuous compliance assessment comprising:

a computer processor;

a change database for storing change data associated with a change to a target host rule detected by a collection policy that defines a scope of what change data is to be collected, and for which rules of the target host, wherein the change data comprises:

(a) an identification of the target host,

(b) an identification of the collection policy, and

(c) element data for the target host configuration parameter or setting, the element data specifying requirements of the target host rule; and

logic communicatively coupled to the change database and operable by the computer processor to:

receive the change data;

store the change data in the change database;

determine which one or more of a plurality of compliance policies match the collection policy;

evaluate whether the change to the target host rule complies with the matching one or more compliance policies, the evaluating comprising:

identifying whether the target host is associated with one or more waivers specified by the matching compliance policies; and

when the target host is not exempt from the matching one or more compliance policies, evaluating the element data for compliance with the matching one or more compliance policies;

generate one or more test results based at least on results of the determining and evaluating, the one or more test results indicating whether the change to the target host rule is in compliance with the matching one or more compliance policies; and

when the change is not in compliance with the matching one or more compliance policies, generating appropriate element data for the target host rule to place the target host rule into compliance with the matching one or more compliance policies.

12. The compliance server of claim 11 , wherein the logic is further operable by the processor to filter the received change data and conditionally perform the determining based on a result of the filtering.

13. The compliance server of claim 11 , wherein the identifying whether the target host is associated with the one or more waivers specified by the matching compliance policies comprises determining whether the target host is listed in a waiver list element of the matching one or more compliance policies.

14. A non-transitory storage medium storing programming instructions configured to cause a target host to:

detect a change to a target host rule detected by a collection policy that defines a scope of what change data is to be collected, and for which rules of the target host;

provide change data to a compliance server, the change data comprising:

(a) an identification of the target host,

(b) an identification of the collection policy, and

(c) element data for the change to the target host rule; and

receive a report from the compliance server including one or more test results, the one or more test results being based at least on results of:

matching, by the compliance server, the collection policy with one or more of a plurality of compliance policies,

evaluating whether the target host specified in the change data is associated with one or more waivers and thereby determining that the target host is not associated with the one or more waivers, and

evaluating the element data against expressions specifying requirements of the matching one or more compliance policies,

the one or more test results indicating whether the change to the target host rule is in compliance with the matching one or more compliance policies, and when the change is not in compliance with the matching one or more compliance policies, generating appropriate element data for the target host rule to place the target host rule into compliance with the matching one or more compliance policies.

15. The non-transitory storage medium of claim 14 , wherein the programming instructions are further configured to cause the target host to repeat the detecting and providing each time a change to the target host rule occurs on the target host.

16. A non-transitory storage medium storing programming instructions configured to cause a compliance server to perform a method, the method comprising:

receiving change data associated with a change to a target host rule detected by a collection policy that defines a scope of what change data is to be collected and for which rules of the target host, the change data comprising:

(a) an identification of the target host,

(b) an identification of the collection policy, and

(c) element data for the change to the target host rule;

determining whether the change to the target host rule meets one or more of a plurality of compliance policies associated with the collection policy, the determining comprising:

matching the collection policy with the one or more of the plurality of compliance policies,

evaluating whether the target host specified in the change data is associated with one or more waivers and thereby determining that the target host is not associated with the one or more waivers, and

evaluating the element data against expressions of the matching one or more compliance policies, the expressions specifying requirements of the matching one or more compliance policies;

generating one or more test results based at least on results of the determining, the one or more test results indicating whether the change to the target host rule is in compliance with the matching one or more compliance policies; and

when the change is not in compliance with the matching one or more compliance policies, generating appropriate element data for the target host rule to place the target host rule into compliance with the matching one or more compliance policies.

Assignments (14)
SECURITY INTEREST Recorded Jan 6, 2026
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.
To: ACQUIOM AGENCY SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 074233/0632 →
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 60306/0365 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: TRIPWIRE, INC.
Reel/Frame 074023/0235 →
TERMINATION AND RELEASE OF FIRST LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 60306/0555 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: TRIPWIRE, INC.
Reel/Frame 074023/0320 →
EXTENDED RCF FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: TRIPWIRE, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073663/0639 →
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 60306/0649 Recorded Nov 21, 2025
From: ACQUIOM AGENCY SERVICES LLC
To: TRIPWIRE, INC.
Reel/Frame 073663/0698 →
EXTENDED FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: TRIPWIRE, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073664/0124 →
NEW MONEY FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.; VERA SECURITY, INC.
To: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 073683/0534 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 14, 2025
From: GOLUB CAPITAL MARKETS LLC (AS EXISTING AGENT)
To: ACQUIOM AGENCY SERVICES LLC (AS SUCCESSOR COLLATERAL AGENT)
Reel/Frame 072471/0665 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jun 7, 2022
From: TRIPWIRE, INC.
To: GOLUB CAPITAL MARKETS LLC, AS COLLATERAL AGENT
Reel/Frame 060306/0649 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jun 7, 2022
From: TRIPWIRE, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 060306/0365 →
RELEASE OF SECURITY INTEREST Recorded Feb 2, 2015
From: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
To: TRIPWIRE, INC.; NCIRCLE NETWORK SECURITY INC.
Reel/Frame 034874/0150 →
SECURITY AGREEMENT Recorded Apr 2, 2013
From: TRIPWIRE, INC.; NCIRCLE NETWORK SECURITY, INC.
To: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 030132/0101 →
SECURITY AGREEMENT Recorded May 23, 2011
From: TRIPWIRE, INC.
To: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 026322/0580 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 16, 2009
From: DIFALCO, ROBERT A.
To: TRIPWIRE, INC.
Reel/Frame 022557/0738 →
Continuity (1)
Related Publication 20100005107A1 · Jan 7, 2010