IP Library Granted Patent US 10,158,660
Granted Patent B1
US 10,158,660 · App. 14/165,410 · Granted Dec 18, 2018

Dynamic vulnerability correlation

Inventors: Tyler Reguly (Toronto, CA); Chris Pawlukowsky (Alpharetta, GA); Matthew Jonathan Condren (Cumming, GA)
Assignee: Tripwire, Inc.
H04L63/1433H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,158,660
App. No.
14/165,410
Filed
Jan 27, 2014
Granted
Dec 18, 2018
Kind
B1
Examiner
LE, DAVID
Art Unit
2498
USPC
726/1
Abstract

Apparatus and methods are disclosed for performing dynamic vulnerability correlation suitable for use in enterprise information technology (IT) environments, including vulnerability filtering, patch correlation, and vulnerability paring. According to one disclosed embodiment, a method of vulnerability filtering includes attempting to execute vulnerability scanning rules according to a specified order in a rule hierarchy, and depending on the type of the rule hierarchy and on whether the attempt was successful, not executing additional rules in the rule hierarchy. In another disclosed embodiment, a method of patch correlation includes executing vulnerability scanning rules based on a correlation associations including, if a particular vulnerability is detected, then not executing other correlated scanning rules for a particular software patch. In another disclosed embodiment, a method of vulnerability paring includes defining a plurality of patch milestones for a software product and scanning a target computer for vulnerabilities associated with a current installed patch.

Claims (48)

1. A method of vulnerability filtering using one or more ontologies of rules, each of the ontologies comprising at least one rule hierarchy comprising one or more vulnerability or weakness scanning rules, the at least one rule hierarchy including priorities that are assigned to at least some of the vulnerability or weakness scanning rules, the method comprising:

by a computer, attempting to execute a first one of the vulnerability or weakness scanning rules against a target remote computing device in an order based at least in part on the assigned priorities, producing at least one scan result;

based on the at least one scan result, determining that an attempt to execute the first one of the vulnerability or weakness scanning rules against the target remote computing device was unsuccessful; and

based on the determining, not executing a scanning rule in the rule hierarchy having a lower assigned priority than the first scanning rule against the target remote computing device.

2. The method of claim 1 , further comprising:

after the not executing the scanning rule, attempting to execute a second one of the vulnerability or weakness scanning rules in a different rule hierarchy than the first scanning rule against the target remote computing device.

3. The method of claim 1 , wherein the at least one rule hierarchy is marked as Restrictive, and wherein the method further comprises:

if a higher priority scanning rule in the at least one rule hierarchy executes successfully against the target remote computing device, then not executing any subsequent scanning rules in the at least one rule hierarchy against the target remote computing device.

4. The method of claim 1 , wherein the at least one rule hierarchy is marked as Inclusive, and wherein the method further comprises:

if a higher priority scanning rule in the at least one rule hierarchy does not execute successfully against the target remote computing device, then not executing any subsequent scanning rules in the at least one rule hierarchy against the target remote computing device.

5. The method of claim 1 , wherein the ontologies comprise forests of rules including a Common Vulnerabilities and Exposures (CVE) forest, a Common Weakness Enumeration (CWE) forest, and a Generic forest, each of the forests including at least one rule hierarchy comprising a tree of scanning rules enumerated as a set of branches.

6. The method of claim 1 , wherein the order of executing the vulnerability or weakness scanning rules is based at least in part on confidence levels designating the respective reliability of each of the vulnerability or weakness scanning rules.

7. The method of claim 1 , wherein the order of executing the vulnerability or weakness scanning rules is based at least in part on confidence levels that cause credentialed scans to be executed before remote scans.

8. The method of claim 1 , wherein a host agent executes the scanning rule locally on the target remote computing device.

9. The method of claim 1 , wherein the target remote computing device is remotely scanned by a Device Profiler to execute the scanning rules.

10. The method of claim 1 , wherein the scanning rules comprise vulnerability scanning rules and weakness scanning rules.

11. An apparatus for analyzing vulnerabilities in a networked environment, the system comprising:

one or more processors;

memory;

a network interface coupled to the one or more processors and configured to scan one or more computers accessible using the network interface; and

one or more non-transitory computer-readable storage media storing computer-readable instructions that, when executed by the one or more processors, cause the one or more processors to perform a method of scanning the one or more remote computers according to a scanning rule hierarchy comprising a plurality of scanning rules, the instructions comprising:

instructions to attempt to execute two or more branches of the vulnerability scanning rule hierarchy against the one or more remote computers, each of the branches comprising a portion of the vulnerability scanning rules ordered based at least in part on assigned priorities, producing at least one vulnerability scanning rule execution result,

instructions to, based on the at least one vulnerability scanning rule execution result, determine that an attempt to execute at least one vulnerability scanning rule associated with the at least one vulnerability scanning rule execution result against the one or more remote computers was unsuccessful, and

instructions to, based on the determination, not execute a respective portion of vulnerability scanning rules in one or more branches of the vulnerability scanning rule hierarchy, having a lower assigned priority than the at least one vulnerability scanning rule associated with the at least one vulnerability scanning rule execution result, against the one or more remote computers.

12. The apparatus of claim 11 , wherein the computer-readable instructions further comprise:

instructions to, after executing the instructions to not execute the vulnerability scanning rules, attempt to execute a second one of the vulnerability scanning rules in a different branch of the vulnerability scanning rule hierarchy than the two or more branches against the one or more remote computers.

13. The apparatus of claim 11 , wherein the vulnerability scanning rule hierarchy is marked as Restrictive, and wherein the computer-readable instructions further comprise:

instructions to, if an attempt to execute a higher priority vulnerability scanning rule in the vulnerability scanning rule hierarchy against the one or more remote computers is successful, then not attempt to execute any subsequent vulnerability scanning rules in the scanning rule hierarchy against the one or more remote computers.

14. The apparatus of claim 11 , wherein the vulnerability scanning rule hierarchy is marked as Inclusive, and wherein the computer-readable instructions further comprise:

if an attempt to execute a higher priority vulnerability scanning rule in the scanning rule hierarchy against the one or more remote computers is not successful, then not attempt to execute any subsequent vulnerability scanning rules in the vulnerability scanning rule hierarchy against the one or more remote computers.

15. The apparatus of claim 11 , wherein the order of executing the vulnerability scanning rules is based at least in part on confidence levels designating the respective reliability of each of the vulnerability scanning rules.

16. The apparatus of claim 11 , wherein the order of executing the vulnerability scanning rules is based at least in part on confidence levels that cause credentialed scans to be executed before remote scans.

17. One or more computer-readable storage media storing computer-readable instructions that, when executed by a computer, cause the computer to perform a method of scanning one or more target remote computers according to a rule hierarchy comprising a plurality of vulnerability or weakness scanning rules, the instructions comprising:

instructions to attempt to execute a first one of the vulnerability or weakness scanning rules to scan the one or more target remote computers using the network interface in an order based at least in part on priorities assigned according to the rule hierarchy comprising the plurality of the vulnerability or weakness scanning rules, producing at least one scan result,

instructions to, based on the at least one scan result, determine that the attempt to execute the first one of the vulnerability or weakness scanning rules was unsuccessful, and

instructions to, based on the determination, not execute a vulnerability or weakness scanning rule in the rule hierarchy having a different assigned priority than the first vulnerability or weakness scanning rule against the one or more target remote computers.

18. The computer-readable storage media of claim 17 ,

wherein the instructions further comprise, after the not executing the vulnerability or weakness scanning rule, attempting to execute a second one of the vulnerability or weakness scanning rules in a different rule hierarchy than the first vulnerability or weakness scanning rule against the one or more target remote computers.

19. The computer-readable storage media of claim 17 , wherein the rule hierarchy is marked as Restrictive, and wherein the instructions further comprise:

if a higher priority vulnerability or weakness scanning rule in the at least one rule hierarchy executes successfully against the one or more target remote computers, then not executing any subsequent vulnerability or weakness scanning rules in the rule hierarchy against the one or more target remote computers.

20. The computer-readable storage media of claim 17 , wherein the rule hierarchy is marked as Inclusive, and wherein the instructions further comprise:

if a higher priority vulnerability or weakness scanning rule in the at least one rule hierarchy does not execute successfully against the one or more target remote computers, then not executing any subsequent vulnerability or weakness scanning rules in the rule hierarchy against the one or more target remote computers.

21. The computer-readable storage media of claim 17 , wherein the ontologies comprise forests of rules including a Common Vulnerabilities and Exposures (CVE) forest, a Common Weakness Enumeration (CWE) forest, and a Generic forest, each of the forests including at least one rule hierarchy comprising a tree of scanning rules enumerated as a set of branches.

22. The computer-readable storage media of claim 17 , wherein the order of executing the scanning rules is based at least in part on confidence levels designating the respective reliability of each of the scanning rules.

23. The computer-readable storage media of claim 17 , wherein the order of executing the scanning rules is based at least in part on confidence levels that cause credentialed scans to be executed before remote scans.

24. The computer-readable storage media of claim 17 , wherein a host agent executes the vulnerability or weakness scanning rules locally on the one or more target remote computers.

25. The computer-readable storage media of claim 17 , wherein the one or more target remote computers are remotely scanned by a Device Profiler to execute the scanning rules.

26. The computer-readable storage media of claim 17 , wherein the scanning rules comprise vulnerability scanning rules and weakness scanning rules.

Assignments (11)
SECURITY INTEREST Recorded Jan 6, 2026
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.
To: ACQUIOM AGENCY SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 074233/0632 →
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 60306/0365 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: TRIPWIRE, INC.
Reel/Frame 074023/0235 →
TERMINATION AND RELEASE OF FIRST LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 60306/0555 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: TRIPWIRE, INC.
Reel/Frame 074023/0320 →
NEW MONEY FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.; VERA SECURITY, INC.
To: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 073683/0534 →
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 60306/0649 Recorded Nov 21, 2025
From: ACQUIOM AGENCY SERVICES LLC
To: TRIPWIRE, INC.
Reel/Frame 073663/0698 →
EXTENDED RCF FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: TRIPWIRE, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073663/0639 →
EXTENDED FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: TRIPWIRE, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073664/0124 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 14, 2025
From: GOLUB CAPITAL MARKETS LLC (AS EXISTING AGENT)
To: ACQUIOM AGENCY SERVICES LLC (AS SUCCESSOR COLLATERAL AGENT)
Reel/Frame 072471/0665 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jun 7, 2022
From: TRIPWIRE, INC.
To: GOLUB CAPITAL MARKETS LLC, AS COLLATERAL AGENT
Reel/Frame 060306/0649 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jun 7, 2022
From: TRIPWIRE, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 060306/0365 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 31, 2014
From: REGULY, TYLER; PAWLUKOWSKY, CHRIS; CONDREN, MATTHEW JONATHAN
To: TRIPWIRE, INC.
Reel/Frame 032103/0706 →
Continuity (2)
Provisional Application 61922679 · Dec 31, 2013
Provisional Application 61892318 · Oct 17, 2013
Cited By (4)
US 12,355,787 US 12,368,746 US 12,380,222 US 12,608,260