IP Library Patent Application 14265287
Patent Application
App. No. 14/265,287

SECURITY CONTROLS

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
14/265,287
Abstract

A network of computers has a network management system which stores metadata comprising at least the identities of software present on computers of the network. A computer of the network runs a monitoring program which accesses the metadata stored in the network management system to provide a measure of the extent to which one or more of a plurality of security controls are implemented in the network. The security controls are the application of Operating System patches, the application of third party software patches, allowing only applications on a list of approved software to run, and limiting administrator privileges. The measure comprises risk ratings dependent on the extents to which the controls are implemented.

Claims (39)

1 . A method of monitoring a network of computers, the network having a network management system which stores metadata and other data relating to software run on computers of the network, the method comprising:

running on a computer of the network a monitoring program which accesses the metadata and other data stored in the network management system to provide a measure of the extent to which one or more of a plurality of security controls are implemented in the network, wherein the security controls include:

application of Operating System patches;

application of third party software patches;

allowing only applications on a list of approved software to run; and

limiting administrator privileges; and

wherein the measure comprises risk ratings dependent on the extents to which the controls are implemented.

2 . The method of claim 1 , wherein a user of the monitoring program indicates whether or not the security control relating to allowing only software on a list of approved software to run is implemented and applying a risk rating dependent on whether or not that security control is not implemented.

3 . The method of claim 1 , wherein if the security control relating to allowing only applications on a list of approved software to run is not implemented, the program analyses a plurality of risk criteria relating to items of software running on the network and applies risk ratings dependent on those criteria.

4 . The method of claim 3 , wherein for an item of software running on the network, the criteria include whether the item of software has one or more of a compile time populated producer name, product name, version name and date, and a risk rating is applied to the item of software accordingly.

5 . The method of claim 4 , wherein criteria include whether the software has a software identification code associated with an installation system.

6 . The method of claim 4 , wherein criteria include whether the software has a security certificate.

7 . The method of claim 4 , wherein the risk determination program calculates a risk metric dependent on the risk criteria.

8 . The method of claim 7 , wherein the risk metric is a weighted sum of confidence values associated with the respective criteria.

9 . The method of claim 4 , wherein a risk rating is applied to the network dependent on the proportion of all software items on the network are deemed safe according to the risk ratings of the individual items of software.

10 . The method of claim 3 , wherein criteria include the identity of where the software runs from.

11 . The method of claim 3 , wherein the criteria include whether metadata of software running on the network correlates with metadata in the network management system.

12 . The method of claim 1 , wherein a measure of the extent to which the application of software patches is determined according to one or more of a measure of the number of updates applied to software through the network management system;

a measure of the total number of software items installed with the most recent versions; and

a measure of the number of software items updated to the most recent versions.

13 . The method of claim 1 , wherein a measure of the extent to which the application of operating system patches is determined according to one or more of

a measure of the number of security and critical operating system updates applied across the network;

a measure of the number of all operating system updates applied across the network; and

a measure of the number of operating system updates applied across the network within a preset time of the updates being available.

14 . The method of claim 1 , wherein a measure of the extent to which the limitation of administrator privileges is determined according to the percentage of all users having local administrative rights.

15 . The method of claim 14 wherein that percentage is compared to a preset number representing good practice.

16 . The method of claim 1 , further comprising providing a measure of the extent to which one or more of a plurality of security controls are implemented in another network, wherein the security controls are application of Operating System patches;

application of third party software patches;

allowing only applications on a list of approved software to run; and

limiting administrator privileges; and

the measure comprises risk ratings dependent on the extents to which the controls are implemented; and

comparing the risk ratings of the first-mentioned network with risk ratings of the another network.

17 . A non-transitory computer-readable medium comprising computer-executable instructions which, when executed by a processor, cause a computing device to perform a method for monitoring on a network of computers the network having a network management system which stores metadata and other data relating to software present on computers of the network, the method comprising:

accessing the metadata and other data stored in the network management system to provide a measure of the extent to which one or more of a plurality of security controls are implemented in the network, wherein the security controls include:

application of Operating System patches;

application of third party software patches;

allowing only applications on a list of approved software to run; and

limiting administrator privileges; and

wherein the measure comprises risk ratings dependent on the extents to which the controls are implemented.

Assignments (5)
RELEASE BY DECLARATION RECORDED AT REEL 041984, FRAME 0904 Recorded Jan 21, 2025
From: SILICON VALLEY BANK
To: IE LIMITED
Reel/Frame 069986/0908 →
SECURITY INTEREST Recorded Apr 12, 2017
From: 1E LIMITED
To: SILICON VALLEY BANK
Reel/Frame 041984/0904 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 28, 2014
From: VAIDYA, RIPAL; AL-HASSANI, OSAMA
To: 1E LIMITED
Reel/Frame 034054/0941 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 28, 2014
From: THRELKELD, RICHARD
To: 1E INC.
Reel/Frame 034055/0136 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 28, 2014
From: 1E INC.
To: 1E LIMITED
Reel/Frame 034055/0160 →