IP Library Granted Patent US 8,176,544
Granted Patent B2
US 8,176,544 · App. 13/020,775 · Granted May 8, 2012

Network security system having a device profiler communicatively coupled to a traffic monitor

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,176,544
App. No.
13/020,775
Granted
May 8, 2012
Kind
B2
Abstract

A system and method for providing distributed security of a network. Several device profilers are placed at different locations of a network to assess vulnerabilities from different perspectives. The device profiler identifies the hosts on the network, and characteristics such as operating system and applications running on the hosts. The device profiler traverses a vulnerability tree having nodes representative of characteristics of the hosts, each node having an associated set of potential vulnerabilities. Verification rules can verify the potential vulnerabilities. A centralized correlation server, at a centrally accessible location in the network, stores the determined vulnerabilities of the network and associates the determined vulnerabilities with attack signatures. Traffic monitors access the attack signatures and monitor network traffic for attacks against the determined vulnerabilities.

Claims (29)

1. A computer-implemented system for protecting a host on a network, the system comprising:

a device profiler having a hardware Input/Output module communicatively coupling the device profiler to the network, the device profiler for identifying characteristics of the host, accessing a vulnerability tree having nodes representative of the characteristics of the host and sets of vulnerabilities associated with the nodes, and determining one or more vulnerabilities of the host that could be exploited by network traffic; and

a module for configuring a firewall to prevent the determined vulnerabilities of the host from being exploited.

2. The system of claim 1 , wherein the device profiler is configured to observe behaviors of an application executing on the host to identify the characteristics of the host.

3. The system of claim 1 , wherein the module for configuring the firewall sends a notification to the firewall in real-time responsive to detection of network traffic attempting to exploit the determined vulnerabilities of the host.

4. The system of claim 1 , wherein configuring the firewall comprises sending a notification to the firewall.

5. The system of claim 1 , wherein configuring the firewall causes the firewall to selectively restrict network traffic to the host.

6. The system of claim 1 , wherein the vulnerability tree has nodes representative of vulnerabilities of an application executing on the host.

7. A non-transitory computer-readable storage medium storing executable instructions for protecting a host on a network, the instructions comprising instructions for:

evaluating responses of the host to data packets sent over the network to determine characteristics of the host;

accessing a vulnerability tree having nodes representative of the characteristics of the host and sets of vulnerabilities associated with the nodes;

determining one or more vulnerabilities of the host described by the vulnerability tree that could be exploited by network traffic; and

configuring a firewall to prevent the determined vulnerabilities of the host from being exploited.

8. The computer-readable storage medium of claim 7 , wherein evaluating responses of the host comprises observing behaviors of an application executing on the host.

9. The computer-readable storage medium of claim 7 , wherein the firewall is configured in real-time responsive to detection of network traffic attempting to exploit the determined vulnerabilities of the host.

10. The computer-readable storage medium of claim 7 , wherein configuring the firewall comprises sending a notification to the firewall.

11. The computer-readable storage medium of claim 7 , wherein configuring the firewall causes the firewall to selectively restrict network traffic to the host.

12. The computer-readable storage medium of claim 7 , wherein the vulnerability tree has nodes representative of vulnerabilities of an application executing on the host.

13. A method for protecting a host on a network, the method comprising:

using a computer to perform steps comprising:

evaluating responses of the host to data packets sent over the network to determine characteristics of the host;

accessing a vulnerability tree having nodes representative of the characteristics of the host and sets of vulnerabilities associated with the nodes;

determining one or more vulnerabilities of the host described by the vulnerability tree that could be exploited by network traffic; and

configuring a firewall to prevent the determined vulnerabilities of the host from being exploited.

14. The method of claim 13 , wherein evaluating responses of the host comprises observing behaviors of an application executing on the host.

15. The method of claim 13 , wherein the firewall is configured in real-time responsive to detection of network traffic attempting to exploit the determined vulnerabilities of the host.

16. The method of claim 13 , wherein configuring the firewall comprises sending a notification to the firewall.

17. The method of claim 13 , wherein configuring the firewall causes the firewall to selectively restrict network traffic to the host.

18. The method of claim 13 , wherein the vulnerability tree has nodes representative of vulnerabilities of an application executing on the host.

Assignments (10)
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 60306/0365 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: TRIPWIRE, INC.
Reel/Frame 074023/0235 →
TERMINATION AND RELEASE OF FIRST LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 60306/0555 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: TRIPWIRE, INC.
Reel/Frame 074023/0320 →
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 60306/0649 Recorded Nov 21, 2025
From: ACQUIOM AGENCY SERVICES LLC
To: TRIPWIRE, INC.
Reel/Frame 073663/0698 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 14, 2025
From: GOLUB CAPITAL MARKETS LLC (AS EXISTING AGENT)
To: ACQUIOM AGENCY SERVICES LLC (AS SUCCESSOR COLLATERAL AGENT)
Reel/Frame 072471/0665 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jun 7, 2022
From: TRIPWIRE, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 060306/0365 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jun 7, 2022
From: TRIPWIRE, INC.
To: GOLUB CAPITAL MARKETS LLC, AS COLLATERAL AGENT
Reel/Frame 060306/0649 →
RELEASE OF SECURITY INTEREST Recorded Feb 2, 2015
From: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
To: TRIPWIRE, INC.; NCIRCLE NETWORK SECURITY INC.
Reel/Frame 034874/0150 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 24, 2014
From: NCIRCLE NETWORK SECURITY, INC.
To: TRIPWIRE, INC.
Reel/Frame 032124/0592 →
RELEASE OF SECURITY INTEREST Recorded Apr 3, 2013
From: COMERICA BANK
To: NCIRCLE NETWORK SECURITY, INC.
Reel/Frame 030146/0080 →
SECURITY AGREEMENT Recorded Apr 2, 2013
From: TRIPWIRE, INC.; NCIRCLE NETWORK SECURITY, INC.
To: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 030132/0101 →