IP Library Granted Patent US 8,261,347
Granted Patent B2
US 8,261,347 · App. 12/204,573 · Granted Sep 4, 2012

Security system for a computer network having a security subsystem and a master system which monitors the integrity of a security subsystem

Assignee: Solutionary, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,261,347
App. No.
12/204,573
Granted
Sep 4, 2012
Kind
B2
Abstract

A security system for a computer network that has a plurality of devices connected thereto comprises a security subsystem, a master system and a secure link. The security subsystem is connected to at least some of the devices in the network. The security subsystem is configured to monitor activities of the at least some devices on the network and detect attacks on the at least some devices. The master system monitors the integrity of the security subsystem and registers information pertaining to attacks detected by the security subsystem. The secure link is connected between the security subsystem and the master system. The master system monitors the integrity of the security subsystem and receives the information pertaining to the attacks through the secure link.

Claims (20)

1. A security system for a computer network, the network having a plurality of devices connected thereto, at least some of the devices having security-related functions, the security system comprising:

(a) a security subsystem implemented on a first computer, the security subsystem being associated with at least some of the devices in the network which tests the integrity of the security-related functions;

(b) a master system implemented on a second computer which is different from the first computer, the master system monitoring the integrity of the security subsystem and receiving and storing results of the integrity testing of the devices having security-related functions; and

(c) a secure link connected between the security subsystem and the master system, the master system monitoring the integrity of the security subsystem and receiving the results of the integrity testing of the devices having security-related functions through the secure link.

2. The system of claim 1 wherein the secure link is defined by a virtual private network (VPN) tunnel.

3. The system of claim 1 wherein at least one of the devices having security-related functions is a firewall.

4. The system of claim 1 wherein at least one of the devices having security-related functions is a network intrusion detection system.

5. A security system for a computer network, the computer network having a plurality of devices connected thereto, the security system comprising:

(a) a security subsystem implemented on a first computer, the security subsystem being connected to at least some of the devices in the computer network, the security subsystem configured to monitor activities of the at least some devices on the computer network and detect attacks on the at least some devices, wherein the security system is on a first network;

(b) a master system implemented on a second computer which is different from the first computer, the master system monitoring the integrity of the security subsystem and registering information pertaining to attacks detected by the security subsystem, wherein the master system is on a second network that is different from the first network; and

(c) a first secure link connected between the security subsystem and the master system, the master system monitoring the integrity of the security subsystem and receiving the information pertaining to the attacks through the first secure link.

6. The system of claim 1 wherein the master system has no connection to the network other than via the secure link.

7. The system of claim 5 wherein the master system has no connection to the network other than via the first secure link.

8. The system of claim 5 wherein the master system does not take direction from the security subsystem.

9. The system of claim 5 further comprising:

(d) a second secure link connected between the master system and the network which enables data communication from the master system to the network for issuing instructions to the network devices.

10. The system of claim 5 wherein the master system is hierarchically independent from the security subsystem.

11. The system of claim 5 wherein the security subsystem is hierarchically subordinate to the master system.

12. The system of claim 5 wherein the first secure link is defined by a virtual private network (VPN) tunnel.

13. The system of claim 5 wherein the master system further comprises a pseudo-attack generator which generates attacks on the network, the security subsystem detecting such attacks when functioning properly, the master system comparing the pseudo-attacks made on the network to the attacks actually detected by the security subsystem, the master system thereby determining whether the integrity of the subsystem has been compromised.

Assignments (1)
MERGER AND CHANGE OF NAME Recorded Sep 22, 2016
From: SOLUTIONARY, INC; NTT SECURITY (US) INC.
To: NTT SECURITY (US) INC.
Reel/Frame 039835/0477 →
Continuity (3)
Continuation 11647660 · Dec 29, 2006
Continuation 09770525 · Jan 25, 2001
Related Publication 20080320586A1 · Dec 25, 2008