IP Library Granted Patent US 8,789,190
Granted Patent B2
US 8,789,190 · App. 13/336,891 · Granted Jul 22, 2014

System and method for scanning for computer vulnerabilities in a network environment

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,789,190
App. No.
13/336,891
Granted
Jul 22, 2014
Kind
B2
Abstract

A method in one embodiment includes identifying a set of known vulnerabilities and a set of new vulnerabilities in an asset, selecting one or more scripts that include checks for vulnerabilities in a union of the set of known vulnerabilities and the set of new vulnerabilities, and using the selected scripts to scan the asset. Known vulnerabilities and new vulnerabilities may be identified by accessing results of previous scans on the asset. The method may also include identifying a plurality of assets to scan in a network, identifying a plurality of sets of known vulnerabilities and a plurality of sets of new vulnerabilities in substantially all assets in the plurality of assets, and inserting checks for vulnerabilities included in a union of the plurality of sets of known vulnerabilities and the plurality of sets of new vulnerabilities into the selected scripts.

Claims (48)

1. A method comprising:

identifying, using at least one data processing apparatus, a plurality of assets to scan in a network;

identifying, using at least one data processing apparatus, a plurality of sets of known vulnerabilities in the plurality of assets, wherein identifying the plurality of sets of known vulnerabilities comprises identifying, for two or more of the plurality of assets, a respective set of known vulnerabilities previously detected as being present on the asset;

identifying, using at least one data processing apparatus, a plurality of sets of new vulnerabilities in the plurality of assets, wherein identifying the plurality of sets of new vulnerabilities comprises identifying, for two or more of the plurality of assets, a respective set of new vulnerabilities for which the asset has not yet been scanned;

selecting, using at least one data processing apparatus, a set of scripts comprising checks for particular vulnerabilities included in a union of the plurality of sets of known vulnerabilities and the plurality of sets of new vulnerabilities; and

using the selected scripts to scan the plurality of assets for vulnerabilities.

2. The method of claim 1 , wherein vulnerabilities that have been previously tested and known not to exist in the asset are not included in the selected scripts.

3. The method of claim 1 , wherein identifying the set of known vulnerabilities comprises:

accessing results of previous scans on the asset, wherein the results indicate the known vulnerabilities.

4. The method of claim 1 , wherein identifying the set of new vulnerabilities comprises:

accessing results of previous scans on the asset, wherein the results indicate a set of scanned vulnerabilities; and

determining vulnerabilities included in a universal set of vulnerabilities in a computer system that are not in the set of scanned vulnerabilities.

5. The method of claim 1 , further comprising:

storing results of the scan in a results database.

6. The method of claim 1 , further comprising: using the selected scripts to scan substantially all assets in the plurality of assets.

7. The method of claim 1 , wherein the plurality of assets is identified by a range of Internet Protocol (IP) addresses.

8. The method of claim 1 , wherein each vulnerability comprises a respective asset attribute that potentially enables at least one of a security breach and a policy violation.

9. An apparatus comprising:

a memory element configured to store data; and

a processor operable to execute instructions associated with the data, wherein the apparatus is configured for:

identifying a plurality of assets to scan in a network;

identifying a plurality of sets of known vulnerabilities in the plurality of assets, wherein identifying the plurality of sets of known vulnerabilities comprises identifying, for two or more of the plurality of assets, a respective set of known vulnerabilities previously detected as being present on the asset;

identifying a plurality of sets of new vulnerabilities in the plurality of assets, wherein identifying the plurality of sets of new vulnerabilities comprises identifying, for two or more of the plurality of assets, a respective set of new vulnerabilities for which the asset has not yet been scanned;

selecting a set of scripts comprising checks for particular vulnerabilities included in a union of the plurality of sets of known vulnerabilities and the plurality of sets of new vulnerabilities; and

using the selected scripts to scan the plurality of assets.

10. The apparatus of claim 9 , wherein identifying the set of known vulnerabilities comprises:

accessing results of previous scans on the asset, wherein the results indicate the known vulnerabilities.

11. The apparatus of claim 9 , wherein identifying the set of new vulnerabilities comprises:

accessing results of previous scans on the asset, wherein the results indicate a set of scanned vulnerabilities; and

determining vulnerabilities included in a universal set of vulnerabilities in a computer system that are not in the set of scanned vulnerabilities.

12. The apparatus of claim 9 , wherein the apparatus is further configured for:

storing results of the scan in a results database.

13. The apparatus of claim 9 , further comprising: using the selected scripts to scan substantially all assets in the plurality of assets.

14. At least one non-transitory, machine accessible storage medium having instructions stored thereon, the instructions when executed on a machine, cause the machine to:

identify a plurality of assets to scan in a network;

identify a plurality of sets of known vulnerabilities in the plurality of assets, wherein the instructions when executed, cause the machine to identify, for two or more of the plurality of assets, a respective set of known vulnerabilities previously detected as being present on an asset;

identify a plurality of sets of new vulnerabilities in the plurality of assets, wherein the instructions when executed, cause the machine to identify, for two or more of the plurality of assets, a respective set of new vulnerabilities for which the asset has not yet been scanned;

select a set of scripts comprising checks for vulnerabilities included in a union of the plurality of sets of known vulnerabilities and the plurality of sets of new vulnerabilities; and

use the selected scripts to scan the plurality of assets.

15. The storage medium of claim 14 , wherein identifying the set of known vulnerabilities comprises:

accessing results of previous scans on the asset, wherein the results indicate the known vulnerabilities.

16. The storage medium of claim 14 , wherein identifying the set of new vulnerabilities comprises:

accessing results of previous scans on the asset, wherein the results indicate a set of scanned vulnerabilities; and

determining vulnerabilities included in a universal set of vulnerabilities in a computer system that are not in the set of scanned vulnerabilities.

17. The storage medium of claim 14 , wherein the instructions, when executed, further cause the machine to:

store results of the scan in a results database.

18. The storage medium of claim 14 , wherein the instructions, when executed, further cause the machine to:

use the selected scripts to scan substantially all assets in the plurality of assets.

Assignments (9)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →