IP Library Granted Patent US 9,710,655
Granted Patent B2
US 9,710,655 · App. 15/298,277 · Granted Jul 18, 2017

Controlled delivery and assessing of security vulnerabilities

Inventors: Margaret M. Bennett (Markham, CA); Barbara J. Bryant (Clinton Corners, NY); William E. Spencer (Pleasant Valley, NY)
Assignee: International Business Machines Corporation
G06F21/577H04L63/083H04L63/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,710,655
App. No.
15/298,277
Granted
Jul 18, 2017
Kind
B2
Abstract

A method for providing security vulnerability information is provided. The method may include checking for the security vulnerability information product supplier servers. The method may further include sending alerts to a security vulnerability administrator associated with a client environment. Additionally, the method may include performing a security check on the security vulnerability administrator to authorize the security vulnerability administrator to receive the security vulnerability information. The method may also include authenticating customers associated with the client environment to authorize the customers to receive the security vulnerability information. The method may further include prompting the authorized security vulnerability administrator to acknowledge an information confidentiality reminder. The method may also include sending an audit record to the product supplier server. The method may further include presenting the security vulnerability information to the authorized security vulnerability administrator and the authorized customers associated with the client environment.

Claims (9)

1. A computer system for providing a plurality of security vulnerability information, the computer system comprising:

one or more processors, one or more computer-readable memories, one or more computer-readable tangible storage devices, and program instructions stored on at least one of the one or more storage devices for execution by at least one of the one or more processors via at least one of the one or more memories, wherein the computer system is capable of performing a method comprising:

checking for the plurality of security vulnerability information on at least one product supplier server, wherein the plurality of security vulnerability information comprises at least one security installation patch, and wherein the at least one security installation patch resolves at least one security integrity issue selected from a group comprising at least one of a malware, a configuration problem, a product inventory and a maintenance level;

in response to finding the plurality of security vulnerability information on the at least one product supplier server, sending at least one alert to at least one security vulnerability administrator (SVA) associated with a client environment, wherein the at least one alert is selected from a group comprising at least one of an email alert and a pop-up notification;

performing at least one security check on the at least one SVA to authorize the at least one security vulnerability administrator to receive the plurality of security vulnerability information, wherein performing the at least one security check on the at least one SVA further comprises at least one of prompting the at least one SVA to enter at least one password, and verifying a plurality of data associated with the at least one SVA via a digital certificate;

authenticating at least one customer associated with the client environment to authorize the at least one customer to receive the plurality of security vulnerability information, wherein authenticating the at least one customer associated with the client environment further comprises verifying at least one customer licensed product certificate;

prompting the authorized at least one security vulnerability administrator to acknowledge an information confidentiality reminder to receive the plurality of security vulnerability information, wherein the information confidentiality reminder comprises at least one sharing restriction notification associated with the plurality of security vulnerability information;

in response to the authorized at least one security vulnerability administrator acknowledging the information confidentiality reminder, sending an audit record to the at least one product supplier server; and

presenting the plurality of security vulnerability information to the authorized at least one security vulnerability administrator and the authorized at least one customer associated with the client environment.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 13, 2019
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: HCL TECHNOLOGIES LIMITED
Reel/Frame 050374/0781 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 20, 2016
From: BENNETT, MARGARET M.; BRYANT, BARBARA J.; SPENCER, WILLIAM E.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 040423/0957 →
Continuity (3)
Continuation 15142004 · Apr 29, 2016
Continuation 14950226 · Nov 24, 2015
Related Publication 20170147823A1 · May 25, 2017