IP Library Granted Patent US 8,881,272
Granted Patent B2
US 8,881,272 · App. 12/726,492 · Granted Nov 4, 2014

System and method for selecting and applying filters for intrusion protection system within a vulnerability management system

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,881,272
App. No.
12/726,492
Granted
Nov 4, 2014
Kind
B2
Abstract

A system for controlling selection of filters for protecting against vulnerabilities of a computer network includes a vulnerability management system analyzes the computer network and determines network vulnerabilities for the computer network. The vulnerability management system is configured to receive real-time data on a status of filters protecting against vulnerabilities of the computer network. A database contains a pre-generated mapping of network vulnerabilities to filters for protecting against the network vulnerabilities. The vulnerability management system enables user control of filters for protecting against vulnerabilities of the computer network based upon the determined network vulnerabilities of the computer network, the pre-generated mapping of network vulnerabilities to the filters for protecting against the network vulnerabilities and the real-time data on the status of the filters.

Claims (35)

1. A system for controlling selection of filters for protecting against vulnerabilities of a computer network, comprising:

a vulnerability management system adapted to analyze the computer network and to determine network vulnerabilities for the computer network, wherein the vulnerability management system is configured to receive real-time data on a status of filters protecting against vulnerabilities of the computer network, wherein a filter comprises program code adapted to be implemented within an intrusion protection system to identify and prevent a particular type of attack from penetrating the computer network, the intrusion protection system being distinct from the vulnerability management system; and

a database that contains a pre-generated mapping of network vulnerabilities to filters for protecting against the network vulnerabilities;

the vulnerability management system outputting one or more recommended actions for selection of filters for the intrusion protection system based upon the determined network vulnerabilities of the computer network, the pre-generated mapping of network vulnerabilities to the filters for protecting against the network vulnerabilities, and the real-time data on the status of the filters.

2. The system of claim 1 , wherein the vulnerability management system generates one or more reports relating to the status of filters associated with the determined network vulnerabilities responsive to the determined network vulnerabilities, the database of mapped vulnerabilities to filters, and the real-time data on the status of the filters.

3. The system of claim 2 , wherein the one or more reports include a mitigated risk report listing each of the determined network vulnerabilities that is protected from by an enabled filter responsive to the determined network vulnerabilities, the database of mapped vulnerabilities to filters, and the real-time data on the status of the filters.

4. The system of claim 2 , wherein the one or more reports include an active risk report listing each of the determined network vulnerabilities that are at least partially unprotected from by one of the filters, further wherein the active risk report associates with each of the determined network vulnerabilities at least one filter that can protect from the determined network vulnerabilities and whether the at least one filter is enabled or disabled responsive to the determined network vulnerabilities, the database of mapped vulnerabilities to filters, and the real-time data on the status of the filters.

5. The system of claim 2 , wherein the one or more reports include a list of determined network vulnerabilities that do not have an associated filter to protect from the vulnerability responsive to the determined network vulnerabilities, the database of mapped vulnerabilities to filters, and the real-time data on the status of the filters.

6. The system of claim 2 , wherein the one or more reports include a mitigated risk report listing each of the determined network vulnerabilities that is protected from by an enabled filter responsive to the determined network vulnerabilities, the database of mapped vulnerabilities to filters, and the real-time data on the status of the filters and further wherein the determined network vulnerabilities in the mitigated risk report can be exempted from future mitigated risk reports.

7. The system of claim 1 , wherein the vulnerability management system further includes an interface to a security management system controlling the filters of the intrusion protection system, the interface enabling provision of commands to the security management system relating the control of the filters for protecting against vulnerabilities of the computer network.

8. The system of claim 1 , wherein the vulnerability management system further includes:

at least one scanning server for scanning for the network vulnerabilities within the computer network; and

a vulnerability management server for receiving the determined network vulnerabilities from the scanning server and controlling the filters for protecting against the vulnerabilities of the computer network based upon the determined network vulnerabilities of the computer network, the database of mapped vulnerabilities to filters, and the real-time data on the status of the filters.

9. The system of claim 1 , wherein the real-time data on the status of filters protecting against vulnerabilities of the computer network are provided from an intrusion protection system.

10. A method for controlling selection of filters for protecting against vulnerabilities of a computer network, comprising:

storing in a database a plurality of mapped network vulnerabilities of the computer network to filters for protecting against the network vulnerabilities, wherein a filter comprises program code adapted to be implemented within an intrusion protection system to identify and prevent a particular type of attack from penetrating the computer network;

determining network vulnerabilities for the computer network within a vulnerability management system executing in a computing entity having a hardware element;

receiving real-time data on a status of available filters protecting against vulnerabilities of the computer network at the vulnerability management system; and

outputting one or more recommended actions for selection of filters for the intrusion protection system to protect against vulnerabilities of the computer network based upon the determined network vulnerabilities of the computer network, the mapped network vulnerabilities to the filters for protecting against the network vulnerabilities, and the real-time data on the status of the filters from the vulnerability management system.

11. The method of claim 10 further including the step of generating one or more reports relating to the status of the filters associated with the determined network vulnerabilities responsive to the determined network vulnerabilities, the mapped network vulnerabilities to filters, and the real-time data on the status of the filters.

12. The method of claim 11 , wherein the step of generating reports further includes the step of generating a mitigated risk report listing each of the determined network vulnerabilities that is protected from by an enabled filter responsive to the determined network vulnerabilities, the mapped network vulnerabilities to filters, and the real-time data on the status of the filters.

13. The method of claim 11 , wherein the step of generating reports further includes the step of generating an active risk report listing each of the determined network vulnerabilities that are at least partially unprotected from by one of the filters, the active risk report associating with each of the determined network vulnerabilities at least one filter that can protect from the determined network vulnerabilities and whether the at least one filter is enabled or disabled responsive to the determined network vulnerabilities, the mapped network vulnerabilities to filters, and the real-time data on the status of the filters.

14. The method of claim 11 , wherein the step of generating reports further includes the step of generating a list of determined network vulnerabilities that do not have an associated filter to protect from the vulnerability responsive to the determined network vulnerabilities, the mapped network vulnerabilities to filters, and the real-time data on the status of the filters.

15. The method of claim 11 , wherein the steps of generating reports further includes:

generating a mitigated risk report listing each of the determined network vulnerabilities that is protected from by an enabled filter in the intrusion protection system;

selecting determined network vulnerabilities to be filtered out from future mitigated risk reports; and

exempting the selected vulnerabilities from the future mitigated risk reports.

16. The method of claim 10 , wherein the step of controlling further comprises:

transmitting commands controlling the filters to a security management system from the vulnerability management system; and

controlling the filters of at least one intrusion protection system for protecting against vulnerabilities of the computer network responsive to the commands to the security management system.

17. The method of claim 10 , wherein the step of determining further comprises:

scanning for the network vulnerabilities within the computer network using a scanning server;

receiving the determined network vulnerabilities at a control server from the scanning server; and

controlling the filters for protecting against the vulnerabilities of the computer network based upon the determined network vulnerabilities of the computer network, the mapped network vulnerabilities to filters, and the real-time data on the status of the filters.

18. The method of claim 10 , wherein the step of receiving further includes receiving the real-time data on the status of filters protecting against vulnerabilities of the computer network from an intrusion protection system.

Assignments (17)
SECURITY INTEREST Recorded Apr 9, 2026
From: CYBEREASON INC.; ALERT LOGIC, LLC
To: ANKURA TRUST COMPANY, LLC
Reel/Frame 075375/0297 →
SECURITY INTEREST Recorded Apr 7, 2026
From: CYBEREASON INC.; ALERT LOGIC, LLC
To: AT&T ENTERPRISES, LLC
Reel/Frame 075377/0304 →
RELEASE OF SECURITY INTEREST Recorded Jan 27, 2026
From: ARES CAPITAL CORPORATION
To: ALERT LOGIC LLC
Reel/Frame 073599/0576 →
RELEASE OF SECURITY INTEREST Recorded Jan 27, 2026
From: JEFFERIES FINANCE LLC
To: ALERT LOGIC LLC
Reel/Frame 073599/0498 →
SECURITY INTEREST Recorded Jan 6, 2026
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.
To: ACQUIOM AGENCY SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 074233/0632 →
TERMINATION AND RELEASE OF FIRST LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 60306/0555 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: TRIPWIRE, INC.
Reel/Frame 074023/0320 →
EXTENDED RCF FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: ALERT LOGIC, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073663/0001 →
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 60306/0758 Recorded Nov 21, 2025
From: ACQUIOM AGENCY SERVICES LLC
To: ALERT LOGIC, INC.
Reel/Frame 073664/0050 →
EXTENDED FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: ALERT LOGIC, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073663/0757 →
NEW MONEY FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.; VERA SECURITY, INC.
To: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 073683/0534 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 14, 2025
From: GOLUB CAPITAL MARKETS LLC (AS EXISTING AGENT)
To: ACQUIOM AGENCY SERVICES LLC (AS SUCCESSOR COLLATERAL AGENT)
Reel/Frame 072471/0665 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jun 7, 2022
From: ALERT LOGIC, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 060306/0555 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jun 7, 2022
From: ALERT LOGIC, INC.
To: GOLUB CAPITAL MARKETS LLC, AS COLLATERAL AGENT
Reel/Frame 060306/0758 →
RELEASE OF SECURITY INTEREST Recorded Mar 24, 2022
From: PACIFIC WESTERN BANK
To: ALERT LOGIC, INC.
Reel/Frame 059498/0361 →
SECURITY INTEREST Recorded Mar 20, 2020
From: ALERT LOGIC, INC.
To: PACIFIC WESTERN BANK
Reel/Frame 052203/0073 →
MERGER Recorded Jul 10, 2019
From: ACHILLES GUARD, INC. (D/B/A CRITICAL WATCH)
To: ALERT LOGIC, INC.
Reel/Frame 049717/0788 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 18, 2010
From: BUNKER, EVA; BUNKER, NELSON; MITCHELL, KEVIN; HARRIS, DAVID
To: ACHILLES GUARD, INC. D/B/A CRITICAL WATCH
Reel/Frame 024099/0588 →