Method and Apparatus for Detecting a Change in Security Status of a Target
A method and apparatus for detecting a change in security status of a target are provided. The method comprises receiving at a server from a target, a notification, the notification providing notice of detection, immediately upon occurrence or at a predefined time interval, of an event on the target. The event on the target comprises a detected change in status of at least one of a network interface from active to inactive or from inactive to active, a client network service from start to stop or from stop to start, a server network service from start to stop or from stop to start, or a port from open to close or from close to open. The method determines, at the server, in response to the notification, that the security status of the target is vulnerable.
1 . A computer implemented method for detecting a change in security status of a target, the method comprising:
receiving at a server from a target, a notification, the notification providing notice of detection, immediately upon occurrence or at a predefined time interval, of an event on the target, the event on the target comprising a detected change in status of at least one of:
a network interface from active to inactive or from inactive to active,
a client network service from start to stop or from stop to start,
a server network service from start to stop or from stop to start, or
a port from open to close or from close to open;
determining, at the server, in response to the notification, that the security status of the target is vulnerable.
2 . A computer implemented method for detecting a change in security status of a target, the method comprising:
detecting, immediately upon occurrence or at a predefined time interval, an event on a target, the event on the target comprising a detected change in status of at least one of:
a network interface from active to inactive or from inactive to active,
a client network service from start to stop or from stop to start,
a server network service from start to stop or from stop to start, or
a port from open to close or from close to open;
sending, from the target to a server, a notification of the detection of the event, the notification is configured for determining that the security status of the target is vulnerable.
3 . A computer implemented method for detecting a change in security status of a target, the method comprising:
detecting, immediately upon occurrence or at a predefined time interval, an event on a target, the event on the target comprising a detected change in status of at least one of:
a network interface from active to inactive or from inactive to active,
a client network service from start to stop or from stop to start,
a server network service from start to stop or from stop to start, or
a port from open to close or from close to open;
sending, from the target to a server, a notification of the detection of the event;
determining, at the server, in response to the notification, that the security status of the target is vulnerable.