IP Library Granted Patent US 8,627,466
Granted Patent B2
US 8,627,466 · App. 13/245,799 · Granted Jan 7, 2014

Alert message control of security mechanisms in data processing systems

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,627,466
App. No.
13/245,799
Granted
Jan 7, 2014
Kind
B2
Abstract

An authenticated secure network communication link is established between an alert message generating computer 2 and a destination data processing system 6 . The alert message sent specifies a risk threat level and a suggested countermeasure amongst other data. The destination computer 6 automatically responds to the alert message as controlled by its local response configuration parameters to trigger security actions of one or more security mechanisms, such as malware scanners, firewall scanners, security policy managers and the like.

Claims (66)

1. A method, comprising:

establishing a secure link between a computer and a server, which communicated an alert message indicative of a security threat;

authenticating the alert message;

evaluating local response configuration parameters previously set for the computer by a user; and

executing a countermeasure action for the security threat based on the local response configuration parameters that outline which actions are to be taken based on a risk level indicator provided in the alert message; wherein:

the alert message comprises a content filter specifying a temporary countermeasure;

if the risk level is high, the temporary countermeasure is to be automatically taken until a permanent countermeasure is subsequently taken to resolve the security threat; and

the temporary countermeasure is automatically taken only if permitted by the local response configuration parameters by the user.

2. The method of claim 1 , wherein a database is accessed in order to identify an Internet address for an HTTP data transfer associated with the alert message.

3. The method of claim 1 , wherein the temporary countermeasure action includes a selected one of a group of temporary countermeasure actions, the group consisting of:

a) initiating a software update;

b) notifying an administrator;

c) blocking certain e-mails;

d) blocking Internet access for a particular port;

e) quarantining a particular file; and

f) executing malware scanning at the computer.

4. The method of claim 1 , wherein the alert message includes a selected one of a group of elements, the group consisting of:

a) a date of the alert message;

b) a time of the alert message;

c) a threat name of the security threat associated with the alert message;

d) a uniform resource locator (URL) identifying a location for information regarding the security threat;

e) data specifying a transport type for the security threat.

5. The method of claim 1 , further comprising:

monitoring a particular port for security threat data that originates from a particular source.

6. The method of claim 1 , wherein the establishing of the secure link is performed via an exchange of encrypted messages that can be signed by the computer and the server.

7. The method of claim 1 , wherein the secure link is authenticated by exchanging data associated with public and private key encryption.

8. An apparatus, comprising:

a processor; and

a memory, wherein the apparatus is configured for:

establishing a secure link between the apparatus and a server, which communicated an alert message indicative of a security threat;

authenticating the alert message;

evaluating local response configuration parameters previously set for the apparatus by a user; and

executing a countermeasure action for the security threat based on the local response configuration parameters that outline which actions are to be taken based on a risk level indicator provided in the alert message; wherein:

the alert message comprises a content filter specifying a temporary countermeasure;

if the risk level is high, the temporary countermeasure is to be automatically taken until a permanent countermeasure is subsequently taken to resolve the security threat; and

the temporary countermeasure is automatically taken only if permitted by the local response configuration parameters.

9. The apparatus of claim 8 , wherein a database is accessed in order to identify an Internet address for an HTTP data transfer associated with the alert message.

10. The apparatus of claim 8 , wherein the temporary countermeasure action includes a selected one of a group of temporary countermeasure actions, the group consisting of:

a) initiating a software update;

b) notifying an administrator;

c) blocking certain e-mails;

d) blocking Internet access for a particular port;

e) quarantining a particular file; and

f) executing malware scanning at the apparatus.

11. The apparatus of claim 8 , wherein the alert message includes a selected one of a group of elements, the group consisting of:

a) a date of the alert message;

b) a time of the alert message;

ic) a threat name of the security threat associated with the alert message;

d) a uniform resource locator (URL) identifying a location for information regarding the security threat; and

e) data specifying a transport type for the security threat.

12. The apparatus of claim 8 , further comprising: monitoring a particular port for security threat data that originates from a particular source.

13. The apparatus of claim 8 , wherein the establishing of the secure link is performed via an exchange of encrypted messages that can be signed by the apparatus and the server.

14. The apparatus of claim 8 , wherein the secure link is authenticated by exchanging data associated with public and private key encryption.

15. A computer program product including a non-transitory computer medium for performing operations, comprising:

establishing a secure link between a computer and a server, which communicated an alert message indicative of a security threat;

authenticating the alert message;

evaluating local response configuration parameters previously set for the computer by a user; and

executing a countermeasure action for the security threat based on the local response configuration parameters that outline which actions are to be taken based on a risk level indicator provided in the alert message; wherein:

the alert message comprises a content filter specifying a temporary countermeasure;

if the risk level is high, the temporary countermeasure is to be automatically taken until a permanent countermeasure is subsequently taken to resolve the security threat; and

the temporary countermeasure is automatically taken only if permitted by the local response configuration parameters.

16. The computer program product of claim 15 , the operations further comprising:

identifying an Internet address for an HTTP data transfer associated with the alert message.

17. The computer program product of claim 15 , the operations further comprising:

exchanging encrypted messages between the computer and the server.

18. The computer program product of claim 15 , wherein the secure link is authenticated by exchanging data associated with public and private key encryption.

Assignments (9)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →