IP Library Granted Patent US 8,789,140
Granted Patent B2
US 8,789,140 · App. 13/312,963 · Granted Jul 22, 2014

System and method for interfacing with heterogeneous network data gathering tools

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,789,140
App. No.
13/312,963
Granted
Jul 22, 2014
Kind
B2
Abstract

A prevention-based network auditing system includes a plurality of heterogeneous information sources gathering information about the network. An audit server invokes the heterogeneous information sources via a uniform communications interface to gather information about the network, and converts the information gathered by the information sources into a normalized data format such as, for example, into XML (Extensible Markup Language). The converted information is then stored in an audit repository for security and regulatory policy assessment, network vulnerability analysis, report generation, and security improvement recommendations.

Claims (37)

1. A method, comprising:

receiving network scan results from information sources in heterogeneous formats;

converting the network scan results into structurally normalized scan results using a plurality of first tags and a second tag nested in the first tags, the first tags indicating a test, the second tag indicating a result of the test;

identifying semantically equivalent network scan results in the structurally normalized scan results; and

comparing at least a portion of the semantically equivalent network scan results with a network policy to determine a compliance with the network policy.

2. The method of claim 1 , wherein the network scan results include a list of wireless access point devices and associated parameters for accessing one or more wireless networks, and a location for each of the wireless access points is determined.

3. The method of claim 1 , further comprising

generating a remediation task for a violation of the network policy.

4. The method of claim 1 , further comprising

generating a remediation task for a violation of the network policy, wherein the remediation task identifies the violation by a severity and an address of a host associated with the violation.

5. The method of claim 1 , wherein the identifying the semantically equivalent network scan results comprises associating a symbolic reference with at least two of the information sources in a reference map.

6. The method of claim 5 , wherein the symbolic reference is mapped to corresponding test identifiers produced by the information sources.

7. Logic encoded in one or more non-transitory media that includes code for execution and when executed by one or more processors is operable to perform operations comprising:

receiving network scan results from information sources in heterogeneous formats;

converting the network scan results into structurally normalized scan results using a plurality of first tags and a second tag nested in the first tags, the first tags indicating a test, the second tag indicating a result of the test;

identifying semantically equivalent network scan results in the structurally normalized scan results; and

comparing at least a portion of the semantically equivalent network scan results with a network policy to determine a compliance with the network policy.

8. The encoded logic of claim 7 , wherein the network scan results include a list of wireless access point devices and associated parameters for accessing one or more wireless networks, and a location for each of the wireless access points is determined.

9. The encoded logic of claim 7 , wherein the operations further comprise

generating a remediation task for a violation of the network policy.

10. The encoded logic of claim 7 , wherein the operations further comprise

generating a remediation task for a violation of the network policy, wherein the remediation task identifies the violation by a severity and an address of a host associated with the violation.

11. The encoded logic of claim 7 , wherein the identifying the semantically equivalent network scan results comprises associating a symbolic reference with at least two of the information sources in a reference map.

12. The encoded logic of claim 11 , wherein the symbolic reference is mapped to corresponding test identifiers produced by the information sources.

13. A system, comprising:

one or more processors operable to execute instructions stored on a memory such that the one or more processors

receive network scan results from information sources in heterogeneous formats;

convert the network scan results into structurally normalized scan results using a plurality of first tags and a second tag nested in the first tags, the first tags indicating a test, the second tag indicating a result of the test;

identify semantically equivalent network scan results in the structurally normalized scan results; and

compare at least a portion of the semantically equivalent network scan results with a network policy to determine a compliance with the network policy.

14. The system of claim 13 , wherein the network scan results include a list of wireless access point devices and associated parameters for accessing one or more wireless networks, and a location for each of the wireless access points is determined.

15. The system of claim 13 , wherein the one or more processors are operable to generate a remediation task for a violation of the network policy.

16. The system of claim 13 , wherein the one or more processors are operable to generate a remediation task for a violation of the network policy, and the remediation task identifies the violation by a severity and an address of a host associated with the violation.

17. The system of claim 13 , wherein the one or more processors identify the semantically equivalent network scan results by associating a symbolic reference with at least two of the information sources in a reference map.

18. The method of claim 1 , wherein the information sources are associated with a plurality of scanners for which meta-information is provided, the meta-information relates to capabilities for each of the scanners and how each of the scanners maps to scanners that can perform similar testing operations, and the converting comprises utilizing a conversion table that maps fields of the heterogeneous formats into fields in the normalized scan results.

19. The encoded logic of claim 7 , wherein the information sources are associated with a plurality of scanners for which meta-information is provided, the meta-information relates to capabilities for each of the scanners and how each of the scanners maps to scanners that can perform similar testing operations, and the converting comprises utilizing a conversion table that maps fields of the heterogeneous formats into fields in the normalized scan results.

20. The system of claim 13 , wherein the information sources are associated with a plurality of scanners for which meta-information is provided, the meta-information relates to capabilities for each of the scanners and how each of the scanners maps to scanners that can perform similar testing operations, and the one or more processors are operable to utilize a conversion table that maps fields of the heterogeneous formats into fields in the normalized scan results.

Assignments (19)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 057453, FRAME 0053 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0413 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 056990, FRAME 0960 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0430 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 29, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 061007/0124 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 057315 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 11, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 060878/0126 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 056990/0960 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057453/0053 →
RELEASE OF SECURITY INTEREST Recorded Jul 26, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: MCAFEE, LLC; SKYHIGH NETWORKS, LLC
Reel/Frame 057620/0102 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →