IP Library Granted Patent US 9,544,324
Granted Patent B2
US 9,544,324 · App. 13/786,314 · Granted Jan 10, 2017

System and method for managed security assessment and mitigation

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,544,324
App. No.
13/786,314
Granted
Jan 10, 2017
Kind
B2
Abstract

In an embodiment of the invention, a system for assessing vulnerabilities includes: a security management system; a network device in a system under test (SUT), wherein the network device is privy to traffic in the SUT; and wherein the SMS is privy to traffic that is known by the network device and/or to one or more traffic observations that is known by the network device.

Claims (29)

1. A system for security management, the system comprising:

a security management system (SMS) that is outside a system under test (SUT); and

a network device in the SUT to:

transmit traffic information in the SUT to the SMS at a first time, wherein the traffic information includes a captured request, the SMS to transmit the captured request to an application program interface (API) of a server, separate from the network device, in the SUT at a second time later than the first time, and

in response to the SMS sending the captured request to the API:

capture traffic between the server and another device, separate from the server and the network device, in the system under test, the traffic sent by the server in response to the captured request received via the API, and

transmit the traffic to the SMS, the SMS to scan the traffic for vulnerabilities, wherein the SUT includes a firewall configured to filter traffic from the SMS to devices in the SUT and to block the captured request when the captured request is transmitted to the server by a device outside the SMS, the network device configured to at least one of set up tunneling for the SMS, alter communications output from the SUT, or perform a fault injection in the captured request transmitted by the SMS.

2. The system of claim 1 , wherein the SMS and the network device are communicatively coupled together.

3. The system of claim 1 , wherein the SMS is configured to request the traffic information from the network device.

4. The system of claim 1 , wherein the SMS is configured to request that the network device perform an analysis of the traffic information.

5. The system of claim 1 , wherein the network device includes an Application Delivery Controller (ADC).

6. The system of claim 1 , wherein the traffic information includes traffic flowing through the SUT.

7. The system of claim 1 , wherein the SMS is configured to select the captured request from the traffic information.

8. The system of claim 1 , wherein the SMS receives the traffic through a tunnel in the firewall.

9. A method in a network device, the method comprising:

transmitting traffic information in a system under test (SUT) to a security management system (SMS) at a first time, wherein the traffic information includes a captured request; and

in response to detecting that the SMS sends the captured request to an application program interface of a server, separate from the network device, in the SUT at a second time after the first time:

capturing traffic between the server and another device, separate from the server and the network device, in the system under test, the traffic sent by the server in response to the captured request received via the API, and

transmitting the traffic to the SMS for scanning for vulnerabilities, wherein the SUT includes a firewall configured to filter traffic from the SMS to devices in the SUT and to block the captured request when the captured request is transmitted to the server by a device outside the SMS, the network device configured to at least one of set up tunneling for the SMS, alter communications output from the SUT, or perform a fault injection in the captured request transmitted by the SMS.

10. The method of claim 9 , wherein the SMS requests the network device to perform an analysis of the traffic information.

11. The method of claim 9 , wherein the traffic information includes traffic flowing through the SUT.

12. The method of claim 9 , wherein the SMS selects the captured request from the traffic information.

13. The method of claim 9 , wherein the SMS receives the traffic through a tunnel in the firewall.

14. The method of claim 9 , wherein the SMS requests the traffic information from the network device.

15. A tangible computer readable storage disk or storage device medium comprising instructions that, when executed, cause a network device to at least:

transmit traffic information in a system under test (SUT) to a security management system (SMS) at a first time, wherein the traffic information includes a captured request; and

in response to detecting that the SMS sends the captured request to an application program interface of a server, separate from the network device, in the SUT at a second time after the first time:

capture traffic between the server and another device, separate from the server and the network device, in the system under test, the traffic sent by the server in response to the captured request received via the API, and

transmit the traffic to the SMS for scanning for vulnerabilities, wherein the SUT includes a firewall configured to filter traffic from the SMS to devices in the SUT and to block the captured request when the captured request is transmitted to the server by a device outside the SMS, the network device configured to at least one of set up tunneling for the SMS, alter communications output from the SUT, or perform a fault injection in the captured request transmitted by the SMS.

Assignments (13)
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 73649/0743 Recorded Apr 30, 2026
From: ANKURA TRUST COMPANY, LLC
To: TRUSTWAVE HOLDINGS, INC.; STROZ FRIEDBERG INC.; STROZ FRIEDBERG, LLC
Reel/Frame 075371/0363 →
SECURITY INTEREST Recorded Feb 18, 2026
From: TRUSTWAVE HOLDINGS, INC.; STROZ FRIEDBERG INC.; STROZ FRIEDBERG, LLC
To: AT&T ENTERPRISES, LLC
Reel/Frame 073824/0146 →
SECURITY INTEREST Recorded Jan 30, 2026
From: TRUSTWAVE HOLDINGS, INC.; STROZ FRIEDBERG INC.; STROZ FRIEDBERG, LLC
To: ANKURA TRUST COMPANY, LLC
Reel/Frame 073649/0743 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 071508/0540 Recorded Aug 18, 2025
From: LEVELBLUE, LLC
To: TRUSTWAVE HOLDINGS, INC.
Reel/Frame 072510/0679 →
SECURITY INTEREST Recorded Jun 24, 2025
From: TRUSTWAVE HOLDINGS, INC.
To: LEVELBLUE, LLC
Reel/Frame 071508/0540 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 070952/0452 Recorded Jun 24, 2025
From: STG V, L.P.; STG VI, L.P.
To: TRUSTWAVE HOLDINGS, INC.
Reel/Frame 071723/0263 →
SECURITY INTEREST Recorded Apr 25, 2025
From: TRUSTWAVE HOLDINGS, INC.
To: STG V, L.P.; STG VI, L.P.
Reel/Frame 070952/0452 →
SECURITY INTEREST Recorded Oct 22, 2024
From: TRUSTWAVE HOLDINGS, INC.
To: CYBEREASON INC.
Reel/Frame 068974/0691 →
SECURITY INTEREST Recorded Sep 12, 2024
From: TRUSTWAVE HOLDINGS, INC.
To: CYBEREASON INC.
Reel/Frame 068572/0937 →
SECURITY INTEREST Recorded Jan 8, 2024
From: TRUSTWAVE HOLDINGS, INC.
To: SINGTEL ENTERPRISE SECURITY (US), INC.
Reel/Frame 066050/0947 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 30, 2015
From: PARCEL, SCOTT
To: CENZIC INC.
Reel/Frame 034858/0234 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 30, 2015
From: CENZIC INC.
To: TRUSTWAVE HOLDINGS, INC.
Reel/Frame 034858/0237 →
SECURITY INTEREST Recorded Mar 17, 2014
From: CENZIC, INC.
To: WELLS FARGO CAPITAL FINANCE, LLC, AS AGENT
Reel/Frame 032450/0685 →