IP Library Granted Patent US 9,990,501
Granted Patent B2
US 9,990,501 · App. 14/748,756 · Granted Jun 5, 2018

Diagnosing and tracking product vulnerabilities for telecommunication devices via a database

Inventors: Andrew R. McGee (Toms River, NJ); Fabio Jaramillo (Bloomfield, NJ); Kirtan Shah (Newark, NJ); Keith W. Johnson (Denver, CO); Marc Verbruggen (Mortsel, BE); Donald McBride (Naperville, IL); Rao Vasireddy (Holmdel, NJ)
Assignee: Alcatel Lucent
G06F21/577G06F17/3053H04L63/1433G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,990,501
App. No.
14/748,756
Granted
Jun 5, 2018
Kind
B2
Abstract

Systems and methods for tracking telecom computing device vulnerabilities. The system includes a database storing a plurality of entries that describe security vulnerabilities, and a controller that receives input from a user selecting a class of telecommunication devices, e.g. a product line, and searches the database to identify pertinent entries describing a relevant security vulnerability for the class. The controller also identifies an authoritative entry that describes the relevant security vulnerability, validates pertinent entries within the database that conform with the authoritative entry, generates a report indicating a severity of the security vulnerability within the class based on valid entries within the database, and assesses a severity of the relevant security vulnerability for the class based on the conforming entries.

Claims (67)

1. A system comprising:

a database configured to store a plurality of entries describing security vulnerabilities that enable unauthorized control of telecommunication devices; and

a controller configured to receive input describing a class of telecommunication devices that each utilize the same software and hardware, and identifies a security vulnerability;

the controller being further configured to identify an authoritative entry in the database that describes the security vulnerability, and electronically search the database to identify entries that each describe both the security vulnerability and the class, and

for each identified entry in the database, add a tag to the entry indicating a conflict on the condition that information in the entry directly contradicts information in the authoritative entry,

wherein the authoritative entry and the identified entries exist within the same database;

wherein:

the entries include results of tests performed upon the class for detecting the security vulnerability, and

the controller is configured to selectively invalidate entries in the database that conflict with the results.

2. The system of claim 1 , wherein:

the database is configured to store multiple types of entries that each include different categories of information, and

the controller is configured to selectively invalidate the entries in the database based on a ranking assigned to each type of entry.

3. The system of claim 1 , wherein:

the database stores at least one software development update, the at least one software development update indicating a patch for the class to address security vulnerabilities, and

the controller is configured to report information related to the at least one software development update in a security vulnerability report.

4. The system of claim 1 , wherein:

each entry in the database includes multiple fields for storing data related to a security vulnerability, and

the controller is configured to perform semantic analysis of the multiple fields to identify entries describing both the security vulnerability and the class.

5. The system of claim 1 , wherein:

the controller is configured to identify entries describing the security vulnerability by detecting entries that include a Common Vulnerabilities and Exposures (CVE) Identifier (ID) field, and by selecting entries for which the CVE ID field matches a CVE ID for the security vulnerability.

6. The system of claim 1 , wherein:

the controller is configured to identify entries describing the security vulnerability by searching the database for entries that match at least one keyword associated with the security vulnerability.

7. The system of claim 1 , wherein:

each of the security vulnerabilities enables exploitation of a defect on a telecommunication device to gain unauthorized access to the telecommunication device, to effect denials of service at the telecommunication device, to access information on the device without authorization, or to steal service provided by the telecommunication device.

8. A method comprising:

receiving input describing a class of telecommunication devices that each utilize the same software and hardware:

identifying a database storing a plurality of entries describing security vulnerabilities that enable unauthorized control of telecommunication devices;

identifying a security vulnerability:

identifying an authoritative entry in the database that describes the security vulnerability; and

electronically searching the database to identify entries that each describe both the security vulnerability and the class, and

for each identified entry in the database, adding a tag to the entry indicating a conflict on the condition that information in the entry directly contradicts information in the authoritative entry,

wherein the authoritative entry and the identified entries exist within the same database;

wherein:

the entries include results of tests performed upon the class for detecting the security vulnerability, and

the method further comprises selectively invalidating entries in the database that conflict with the results.

9. The method of claim 8 , wherein:

the database stores multiple types of entries that each include different categories of information, and the method further comprises:

selectively invalidating the entries in the database based on a ranking assigned to each type of entry.

10. The method of claim 8 , wherein:

the entries include at least one software development update, the at least one software development update indicating a patch for the class to address security vulnerabilities, and the method further comprises:

reporting information related to the at least one software development update in a security vulnerability report.

11. The method of claim 8 , wherein:

each of the entries in the database includes multiple fields for storing data related to a security vulnerability, and the method further comprises:

performing semantic analysis upon the fields of the multiple fields to identify entries describing the security vulnerability for the class.

12. The method of claim 8 , further comprising:

identifying entries describing the security vulnerability for the class by detecting entries that include a Common Vulnerabilities and Exposures (CVE) Identifier (ID) field; and

selecting entries for which the CVE ID field matches a CVE ID for the security vulnerability.

13. The method of claim 8 , wherein:

the entries include results of tests performed upon the class for detecting the security vulnerability, and the results of the test indicate a presence and a severity of a security vulnerability with respect to the class.

14. The method of claim 8 , wherein:

each of the security vulnerabilities enables exploitation of a defect on a telecommunication device to gain unauthorized access to the telecommunication device, to effect denials of service at the telecommunication device, access information on the device without authorization, or to steal service provided by the telecommunication device.

15. A non-transitory computer readable medium embodying programmed instructions which, when executed by a processor, are operable for directing the processor to perform a method comprising:

receiving input describing a class of telecommunication devices that each utilize the same software and hardware:

identifying a database storing a plurality of entries describing security vulnerabilities that enable unauthorized control of telecommunication devices;

identifying a security vulnerability:

identifying an authoritative entry in the database that describes the security vulnerability; and

electronically searching the database to identify entries that each describe both the security vulnerability and the class, and

for each identified entry in the database, adding a tag to the entry indicating a conflict on the condition that information in the entry directly contradicts information in the authoritative entry,

wherein the authoritative entry and the identified entries exist within the same database;

wherein:

the entries include results of tests performed upon the class for detecting the security vulnerability, and

the method further comprises selectively invalidating entries in the database that conflict with the results.

16. The medium of claim 15 , wherein the method further comprises:

selectively invalidating the entries in the database based on a ranking assigned to each type of entry.

17. The medium of claim 15 , wherein:

the database stores multiple types of entries that each include different categories of information, and the method further comprises:

selectively invalidating the entries in the database based on a ranking assigned to each type of entry.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 21, 2016
From: ALCATEL-LUCENT USA INC.
To: ALCATEL LUCENT
Reel/Frame 039212/0856 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 24, 2015
From: MCGEE, ANDREW R; JARAMILLO, FABIO; SHAH, KIRTAN; JOHNSON, KEITH W; MCBRIDE, DONALD; VASIREDDY, RAO; VERBRUGGEN, MARC
To: ALCATEL-LUCENT USA INC.
Reel/Frame 035962/0800 →
Continuity (1)
Related Publication 20160378993A1 · Dec 29, 2016