IP Library Patent Application 13103307
Patent Application
App. No. 13/103,307

SYSTEMS AND METHODS FOR PERFORMING RISK ANALYSIS

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
13/103,307
Abstract

A method for analyzing a network element may include assigning values to each of a plurality of vulnerabilities. The method may also include identifying a vulnerability associated with the network element and generating a risk indicator for the network element based on the assigned value associated with the identified vulnerability.

Claims (64)

1 . A computer-implemented method, comprising:

assigning values to each of a plurality of security-related vulnerabilities, each of the values being based on at least one of a function or location of a network element;

monitoring a first one of a plurality of network elements;

identifying at least one security-related vulnerability associated with the first network element; and

generating a risk indicator for the first network element based on an assigned value associated with the identified at least one security-related vulnerability.

2 . The computer-implemented method of claim 1 , wherein the monitoring comprises:

scanning the first network element to identify security-related vulnerabilities, the security-related vulnerabilities representing potential points of attack.

3 . The computer-implemented method of claim 2 , wherein the identifying at least one security-related vulnerability comprises:

identifying a plurality of security-related vulnerabilities, and wherein generating a risk indicator for the first network element comprises:

performing a mathematical operation on values associated with each of the plurality of identified security-related vulnerabilities associated with the first network element.

4 . The computer-implemented method of claim 1 , further comprising:

displaying the risk indicator at a user device.

5 . The computer-implemented method of claim 1 , wherein the identifying at least one security-related vulnerability comprises at least one of:

identifying at least one open port associated with the first network element,

determining that the first network element does not include a firewall or an intrusion detection system,

determining that the first network element interfaces with a non-secured device, or

identifying that the first network element is under an attack.

6 . The computer-implemented method of claim 1 , further comprising:

identifying a plurality of open ports on the plurality of network elements, wherein the assigning values comprises:

assigning values to each identified open port based on a level of vulnerability associated with the corresponding network element on which the open port exists.

7 . The computer-implemented method of claim 1 , further comprising:

monitoring the plurality of network elements;

generating a risk indicator for each of the network elements, the risk indicator representing a relative risk level associated with the corresponding network element; and

providing the risk indicator for each of the network elements to a user device for display.

8 . The computer-implemented method of claim 7 , further comprising:

prioritizing risk associated with the plurality of network elements based on the risk indicators.

9 . The computer-implemented method of claim 1 , further comprising:

determining whether action is required with respect to the first network element based on the risk indicator; and

automatically performing a remedial action with respect to the first network element, in response to determining that action is required.

10 . The computer-implemented method of claim 9 , further comprising:

generating, after performing the remedial action, a second risk indicator for the first network element; and

determining, based on the second risk indicator, whether a security-related compliance has been achieved with respect to the first network element.

11 . The computer-implemented method of claim 9 , wherein the automatically performing a remedial action comprises:

quarantining or preventing access to the first network element.

12 . The computer-implemented method of claim 1 , wherein the risk indicator comprises a numerical score.

13 . The computer-implemented method of claim 1 , wherein the generating a risk indicator comprises:

determining whether an exception to a security rule exists with respect to the identified at least one security-related vulnerability; and

adjusting the risk indicator for the first network element in response to determining that an exception to a security rule exists with respect to the identified at least one security-related vulnerability.

14 . A system, comprising:

a memory configured to:

store values associated with a plurality of security-related vulnerabilities, and

store information representing exceptions to security rules; and

a processing device configured to:

receive information corresponding to at least one identified security-related vulnerability associated with a first network device,

access the memory to determine a value associated with each of the at least one identified security-related vulnerability associated with the first network device,

access the memory to determine whether an exception to a security rule exists with respect to any of the at least one identified security-related vulnerability associated with the first network device, and

generate a risk indicator for the first network device based on the value associated with each of the at least one identified security-related vulnerability and whether an exception to a security rule exists with respect to any of the at least one identified security-related vulnerability.

15 . The system of claim 14 , wherein the processing device is further configured to:

forward the risk indicator to a user device for display.

16 . The system of claim 14 , wherein the processing device is further configured to:

provide an interface to a user device, the interface including options associated with monitoring a plurality of network devices,

receive an input from the user device,

identify a second network device in response to the input,

generate a risk indicator associated with the second network device, and

provide the risk indicator for the second network device to the user device.

17 . The system of claim 14 , wherein the values stored in the memory are based on at least one of a function or location associated with a network device.

18 . The system of claim 14 , wherein the processing device is further configured to:

scan the first network device to identify whether any open ports exist on the first network device.

19 . The system of claim 14 , wherein the processing logic is further configured to:

determine whether action is required with respect to the first network device based on the risk indicator; and

automatically perform a remedial action with respect to the first network device, in response to determining that action is required.

20 . The system of claim 14 , wherein the processing logic is further configured to at least one of:

transmit a message to a party responsible for monitoring the first network device, in response to determining that action is required, or

store information associated with the remedial action.

Assignments (5)
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 032734 FRAME: 0502. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: VERIZON BUSINESS GLOBAL LLC
To: VERIZON PATENT AND LICENSING INC.
Reel/Frame 044626/0088 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 22, 2014
From: VERIZON BUSINESS GLOBAL LLC
To: VERIZON PATENT AND LICENSING INC.
Reel/Frame 032734/0502 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 9, 2011
From: FUDGE, ROBERT T.
To: MCI, INC.
Reel/Frame 026245/0015 →
MERGER Recorded May 9, 2011
From: MCI, INC.
To: MCI, LLC
Reel/Frame 026245/0035 →
CHANGE OF NAME Recorded May 9, 2011
From: MCI, LLC
To: VERIZON BUSINESS GLOBAL LLC
Reel/Frame 026247/0001 →