IP Library Granted Patent US 8,289,882
Granted Patent B2
US 8,289,882 · App. 12/688,400 · Granted Oct 16, 2012

Systems and methods for modifying network map attributes

Assignee: Sourcefire, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,289,882
App. No.
12/688,400
Granted
Oct 16, 2012
Kind
B2
Abstract

The disclosed systems and methods provide a user interface for modifying host configuration data that has been automatically and passively determined and for adding or modifying other parameters associated with a host. A host data table can store various parameters descriptive of a host including the applicability of specific vulnerabilities. If it is determined that one or more hosts should not be identified as associated with a specific vulnerability, a graphical user interface can be used to modify the vulnerability parameter.

Claims (35)

1. A method for assigning a vulnerability parameter to a device on a network, comprising:

passively determining, responsive to a passively read packet, a vulnerability parameter for an operating system or service;

storing, responsive to the vulnerability parameter being passively determined, the vulnerability parameter in a host map associated with a network device;

modifying the vulnerability parameter which was passively determined; and

storing the modified vulnerability parameter in the host map, wherein the vulnerability parameter is invalid or valid,

when the vulnerability is invalid and a pre-defined change in the operating system or service occurs on the network device, a new vulnerability lookup is performed for the changed operating system or service and the vulnerability parameter is remapped from invalid to valid based on the new vulnerability lookup for the changed operating system or service,

wherein the vulnerability parameter is associated with a universal unique identifier to distinguish between locally and remotely generated vulnerability parameters and is synchronized to a high availability peer, the vulnerability parameter being propagated from the host map to the high availability peer,

when the vulnerability parameter is modified at the high availability peer, the modified vulnerability parameter is propagated from the high availability peer back to the host map.

2. The method of claim 1 , wherein a graphical user interface is provided through an application program interface.

3. The method of claim 1 , wherein a graphical user interface provides a function for setting the vulnerability parameter for a plurality of selected hosts or services.

4. The method of claim 1 , wherein a graphical user interface provides a function for deleting a host from a network map.

5. A method for assigning a vulnerability parameter to a device on a network, comprising:

passively determining, responsive to a passively read packet, a vulnerability parameter for an operating system or service, wherein the vulnerability parameter is associated with a universal unique identifier to distinguish between locally and remotely generated vulnerability parameters;

storing, responsive to the vulnerability parameter being passively determined, the vulnerability parameter in a host map associated with a network device;

modifying the vulnerability parameter which was passively determined; and

storing the modified vulnerability parameter in the host map, wherein

the vulnerability parameter is invalid or valid,

when the vulnerability is invalid and a pre-defined change in the operating system or service occurs on the network device, a new vulnerability lookup is performed for the changed operating system or service and the vulnerability parameter is remapped from invalid to valid based on the new vulnerability lookup for the changed operating system or service,

wherein the vulnerability parameter is propagated from the host map to the high availability peer,

when the vulnerability parameter is modified at the high availability peer, the modified vulnerability parameter is propagated from the high availability peer back to the host map.

6. The method of claim 5 , wherein a graphical user interface is provided through an application program interface.

7. The method of claim 5 , wherein a graphical user interface provides a function for setting the vulnerability parameter for a plurality of selected hosts or services.

8. The method of claim 5 , wherein a graphical user interface provides a function for deleting a host from a network map.

9. A method for assigning a vulnerability parameter to a device on a network, comprising:

passively determining, responsive to a passively read packet, a vulnerability parameter for an operating system or service;

storing, responsive to the vulnerability parameter being passively determined, the vulnerability parameter in a host map associated with a network device;

modifying the vulnerability parameter which was passively determined; and

storing the modified vulnerability parameter in the host map, wherein

the vulnerability parameter is invalid or valid,

when the vulnerability is invalid and a pre-defined change in the operating system or service occurs on the network device, a new vulnerability lookup is performed for the changed operating system or service and the vulnerability parameter is remapped from invalid to valid based on the new vulnerability lookup for the changed operating system or service,

wherein the vulnerability parameter is associated with a universal unique identifier to distinguish between locally and remotely generated vulnerability parameters and is synchronized to a peer, the vulnerability parameter being propagated from the host map to the peer,

when the vulnerability parameter is modified at the peer, the modified vulnerability parameter is propagated from the peer back to the host map.

10. The method of claim 9 , wherein a graphical user interface is provided through an application program interface.

11. The method of claim 9 , wherein a graphical user interface provides a function for setting the vulnerability parameter for a plurality of selected hosts or services.

12. The method of claim 9 , wherein a graphical user interface provides a function for deleting a host from a network map.

Assignments (2)
CHANGE OF NAME Recorded Mar 24, 2014
From: SOURCEFIRE, INC.
To: SOURCEFIRE LLC
Reel/Frame 032513/0481 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 24, 2014
From: SOURCEFIRE LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 032513/0513 →
Continuity (2)
Continuation 11272034 · Nov 14, 2005
Related Publication 20100205675A1 · Aug 12, 2010