IP Library Patent Application 17111398
Patent Application
App. No. 17/111,398

IDENTIFICATION OF POTENTIAL NETWORK VULNERABILITY AND SECURITY RESPONSES IN LIGHT OF REAL-TIME NETWORK RISK ASSESSMENT

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
17/111,398
Abstract

The present disclosure relates to methods and apparatus that collect data regarding malware threats, that organizes this collected malware threat data, and that provides this data to computers or people such that damage associated with these software threats can be quantified and reduced. The present disclosure is also directed to preventing the spread of malware before that malware can damage computers or steal computer data. Methods consistent with the present disclosure may optimize tests performed at different levels of a multi-level threat detection and prevention system. As such, methods consistent with the present disclosure may collect data from various sources that may include endpoint computing devices, firewalls/gateways, or isolated (e.g. “sandbox”) computers. Once this information is collected, it may then be organized, displayed, and analyzed in ways that were not previously possible.

Claims (55)

1 . A method for characterizing the spread of malware, the method comprising:

receiving information that identifies a threat to computers at a computer network;

identifying an action that causes the identified threat to spread to other computers at the computer network;

identifying assets that could be affected by the spread of the threat to the other computers; and

sending a message to a computing device regarding the assets that could be affected by the spread of the threat, the message identifying the threat and the action that causes the threat to spread to the other computers.

2 . The method of claim 1 , further comprising:

identifying a type of damage that can be caused at the computer network by the threat;

identifying a cost to rectify a single instance of the type of damage;

estimating a total number of computers at the computer network that the threat could affect; and

estimating a total cost of rectifying the type of damage at the total number of computers, the total cost estimate identified according to a formula that includes the cost to rectify the single instance of the type of damage and the estimated total number of computers that the threat could affect.

3 . The method of claim 1 , further comprising generating a visualization that identifies a potential extent of the spread of the threat to the other computers.

4 . The method of claim 1 , further comprising:

generating a signature from data associated with the threat; and

sending the signature to one or more computing devices, wherein the one or more computing devices generate a new signature from received computer data and compare the new signature with the signature generated from the data associated with the threat.

5 . The method of claim 1 , further comprising:

receiving information that identifies a second threat; and

sending a message regarding the second threat to one or more computing devices.

6 . The method of claim 5 , further comprising identifying at least one action that causes the second threat to spread to other computing devices, wherein the message regarding the second threat identifies the at least one action that causes the second threat to spread to the other computing devices.

7 . The method of claim 1 , further comprising receiving information that identifies a plurality of other threats that are spreading to the other computers at the computer network.

8 . The method of claim 1 , wherein the threat is at least one of a computer virus, spam, or spyware.

9 . A non-transitory computer-readable storage medium having embodied thereon a program executable by a processor for implementing a method for characterizing the spread of malware, the method comprising:

receiving information that identifies a threat to computers at a computer network;

identifying an action that causes the identified threat to spread to other computers at the computer network;

identifying assets that could be affected by the spread of the threat to the other computers; and

sending a message to a computing device regarding the assets that could be affected by the spread of the threat, the message identifying the threat and the action that causes the threat to spread to the other computers.

10 . The non-transitory computer-readable storage medium of claim 9 , the program further executable to:

identify a type of damage that can be caused at the computer network by the threat;

identify a cost to rectify a single instance of the type of damage;

estimate a total number of computers at the computer network that the threat could affect; and

estimate a total cost of rectifying the type of damage at the total number of computers, the total cost estimate identified according to a formula that includes the cost to rectify the single instance of the type of damage and the estimated total number of computers that the threat could affect.

11 . The A non-transitory computer-readable storage medium of claim 9 , the program further executable to generate a visualization that identifies a potential extent of the spread of the threat to the other computers.

12 . The non-transitory computer-readable storage medium of claim 9 , the program further executable to:

generate a signature from data associated with the threat; and

send the signature to one or more computing devices, wherein the one or more computing devices generate a new signature from received computer data and compare the new signature with the signature generated from the data associated with the threat.

13 . The non-transitory computer-readable storage medium of claim 1 , the program further executable to:

receive information that identifies a second threat; and

send a message regarding the second threat to one or more computing devices.

14 . The non-transitory computer-readable storage medium of claim 13 , the program further executable to identify at least one action that causes the second threat to spread to other computing devices, wherein the message regarding the second threat identifies the at least one action that causes the second threat to spread to the other computing devices.

15 . The non-transitory computer-readable storage medium of claim 9 , the program further executable to receive information that identifies a plurality of other threats that are spreading to the other computers at the computer network.

16 . The non-transitory computer-readable storage medium of claim 9 , wherein the threat is at least one of a computer virus, spam, or spyware.

17 . A system for characterizing the spread of malware, the system comprising:

a plurality of computing devices that collect threat information that identifies a threat to devices at a computer network; and

a computer that receives the threat information from the plurality of computing devices at the computer network, wherein the computer:

identifies an action that causes the identified threat to spread to other computers,

identifies assets that could be affected by the spread of the threat to the other computers, and

sends a message to a computing device regarding the assets that could be affected by the spread of the threat, the message identifying the threat and the action that causes the threat to spread to the other computers.

18 . The system of claim 1 , wherein the computer also:

identifies a type of damage that can be caused at the computer network by the threat,

identifies a cost to rectify a single instance of the type of damage,

estimates a total number of computers at the computer network that the threat could affect; and

estimates a total cost of rectifying the type of damage at the total number of computers, the total cost estimate identified according to a formula that includes the cost to rectify the single instance of the type of damage and the estimated total number of computers that the threat could affect.

19 . The system of claim 17 , wherein the computer also generates a visualization that identifies an extent of the spread of the threat to the other computers.

20 . The system of claim 1 , wherein the computer also:

generates a signature from data associated with the threat; and

sends the signature to one or more other computing devices, wherein the one or more other computing devices generate a new signature from received computer data and compare the new signature with the signature generated from the data associated with the threat.

Assignments (2)
FIRST LIEN IP SUPPLEMENT Recorded Jun 30, 2025
From: SONICWALL INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 071758/0159 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 16, 2021
From: DUO, ZHUANGZHI; DHABLANIA, ATUL
To: SONICWALL INC.
Reel/Frame 055612/0112 →