IP Library Granted Patent US 8,700,767
Granted Patent B2
US 8,700,767 · App. 13/371,353 · Granted Apr 15, 2014

System and method for network vulnerability detection and reporting

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,700,767
App. No.
13/371,353
Granted
Apr 15, 2014
Kind
B2
Abstract

A system and method provide comprehensive and highly automated testing of vulnerabilities to intrusion on a target network, including identification of operating system, identification of target network topology and target computers, identification of open target ports, assessment of vulnerabilities on target ports, active assessment of vulnerabilities based on information acquired from target computers, quantitative assessment of target network security and vulnerability, and hierarchical graphical representation of the target network, target computers, and vulnerabilities in a test report. The system and method employ minimally obtrusive techniques to avoid interference with or damage to the target network during or after testing.

Claims (35)

1. A method comprising:

assigning, utilizing a computer, a vulnerability risk level to each of a plurality of vulnerabilities found on a set of computer devices;

assigning an exposure risk level to each exposure found in the set of computer devices; and

providing a security score for the set of computer devices that is dependent on at least the vulnerability risk levels of the vulnerabilities and the exposure risk level of the exposures found on the network;

wherein the security score is derived from a formula of form F=a-V-E, wherein F is the security score, a is a constant, V is a vulnerability loss, and E is an exposure loss and vulnerability loss V is dependent on at least two of the assigned vulnerability risk levels and exposure loss E is dependent on at least two of the assigned exposure risk levels.

2. The method of claim 1 , further comprising determining a number of computer devices in the set, wherein the security score is further dependent on the number of computer devices in the set.

3. The method of claim 1 , wherein the plurality of vulnerabilities are found on the set of computer devices through a scan of the set of computer devices, wherein the scan assesses each computer device in the set of computer devices against one or more vulnerabilities in a set of vulnerabilities including the plurality of vulnerabilities.

4. The method of claim 3 , further comprising determining attributes of each computer device in the set of computer devices, wherein each computer device in the set of computer devices is scanned for vulnerabilities in the set of vulnerabilities relating to the attributes of the respective computer device.

5. The method of claim 1 , wherein assigning a vulnerability risk level for each of the plurality of vulnerabilities includes calculating the respective vulnerability risk level for each of the plurality of computer devices.

6. The method of claim 5 , wherein vulnerability risk level of a corresponding vulnerability is calculated based at least in part on popularity of the vulnerability, ease of exploitation of the vulnerability, and level of access granted by the vulnerability.

7. The method of claim 6 , wherein the vulnerability risk level is calculated as one of at least three discrete risk levels.

8. The method of claim 1 , further comprising detecting exposures present on the set of computer devices.

9. The method of claim 1 , wherein the set of computer devices is a network of computer devices.

10. The method of claim 1 , wherein vulnerability level V is based at least in part on the number of high level vulnerabilities affecting the set of computer devices, the number of computer devices in the set vulnerable to the high level vulnerabilities, the number of medium level vulnerabilities affecting the set of computer devices, the number of computer devices in the set vulnerable to the medium level vulnerabilities, the number of low level vulnerabilities affecting the set of computer devices, and the number of computer devices in the set vulnerable to the low level vulnerabilities.

11. The method of claim 1 , wherein exposure loss E is based at least in part on the weighted sum of exposures found on computer devices in the set.

12. The method of claim 1 , wherein the security score indicates security of the set of computer devices as viewed from outside the set of computer devices.

13. The method of claim 12 , wherein each exposure is at least one of an open UDP port, an open ICMP port, and a non-essential service detected among the set of computer devices.

14. The method of claim 12 , wherein the plurality of vulnerabilities are from a set of vulnerabilities affecting the external security of the set of computer devices.

15. The method of claim 1 , wherein the security score indicates security of the set of computer devices as viewed from inside the set of computer devices.

16. The method of claim 15 , wherein each exposure is at least one of a rogue application, wireless access point, trojan horse, and backdoor detected among the set of computer devices.

17. The method of claim 15 , wherein the plurality of vulnerabilities are from a set of vulnerabilities affecting the internal security of the set of computer devices.

18. The method of claim 1 , further comprising determining whether each computer device in a plurality of computer devices is active, wherein each active computer device is assigned to the set of computer devices.

19. At least one non-transitory machine accessible storage medium having instructions stored thereon, the instructions when executed on a machine, cause the machine to:

assign a vulnerability risk level to each of a plurality of vulnerabilities found on a set of computer devices;

assign an exposure risk level to each exposure found in the set of computer devices; and

provide a security score for the set of computer devices that is dependent on at least the vulnerability risk levels of the vulnerabilities and the exposure risk level of the exposures found on the network;

wherein the security score is to be derived from a formula of form F=a-V-E, wherein F is the security score, a is a constant, V is a vulnerability loss, and E is an exposure loss and vulnerability loss V is dependent on at least two of the assigned vulnerability risk levels and exposure loss E is dependent on at least two of the assigned exposure risk levels.

20. A system comprising:

at least one processor device;

at least one memory element; and

a vulnerability scanner, adapted when executed by the at least one processor device to:

assign a vulnerability risk level to each of a plurality of vulnerabilities found on a set of computer devices;

assign an exposure risk level to each exposure found in the set of computer devices; and

provide a security score for the set of computer devices that is dependent on at least the vulnerability risk levels of the vulnerabilities and the exposure risk level of the exposures found on the network;

wherein the security score is derived from a formula of form F=a-V-E, wherein F is the security score, a is a constant, V is a vulnerability loss, and E is an exposure loss and vulnerability loss V is dependent on at least two of the assigned vulnerability risk levels and exposure loss E is dependent on at least two of the assigned exposure risk levels.

Assignments (9)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →