IP Library Granted Patent US 11,722,514
Granted Patent B1
US 11,722,514 · App. 17/396,467 · Granted Aug 8, 2023

Dynamic vulnerability correlation

Inventors: Tyler Reguly (Toronto, CA); Chris Pawlukowsky (Alpharetta, GA); Matthew Jonathan Condren (Cumming, GA)
Assignee: TRIPWIRE, INC.
H04L63/1433H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,722,514
App. No.
17/396,467
Filed
Aug 6, 2021
Granted
Aug 8, 2023
Kind
B1
Art Unit
2498
USPC
726/1
Abstract

Apparatus and methods are disclosed for performing dynamic vulnerability correlation suitable for use in enterprise information technology (IT) environments, including vulnerability filtering, patch correlation, and vulnerability paring. According to one disclosed embodiment, a method of vulnerability filtering includes attempting to execute vulnerability scanning rules according to a specified order in a rule hierarchy, and depending on the type of the rule hierarchy and on whether the attempt was successful, not executing additional rules in the rule hierarchy. In another disclosed embodiment, a method of patch correlation includes executing vulnerability scanning rules based on a correlation associations including, if a particular vulnerability is detected, then not executing other correlated scanning rules for a particular software patch. In another disclosed embodiment, a method of vulnerability paring includes defining a plurality of patch milestones for a software product and scanning a target computer for vulnerabilities associated with a current installed patch.

Claims (35)

1. A method of vulnerability paring for scanning a target computer, the method comprising:

receiving a plurality of ordered patch milestones, each of the patch milestones designating a set of one or more vulnerability scanning rules having an associated scanning order;

based on a current patch level for the target computer, selecting a set of one or more of but not all of the patch milestones, wherein at least some of the patch milestones are not selected based on the ordering of the patch milestones and the current patch level, wherein the ordering of the patch milestones defines whether an install date of a first patch milestone of the plurality of ordered patch milestones precedes or supercedes an install date a second patch milestone of the plurality of ordered patch milestones; and

evaluating the selected set of patch milestones, the evaluating comprising executing at least one of the vulnerability scanning rules associated with the selected set of patch milestones.

2. The method of claim 1 , wherein the evaluating comprises executing the vulnerability scanning rules associated with the selected set of patch milestones according to a specified order.

3. The method of claim 1 , wherein at least one of the selected set of patch milestones references one or more ordered subsets of patch milestones, the method further comprising:

selecting at least one of the subsets of patch milestones based on the order of the subset of patch milestones and a current patch level of the target computer; and

evaluating the selected at least one of the subset of patch milestones, the evaluating comprising executing a vulnerability scanning rule associated with the selected at least one of the subsets of patch milestones.

4. The method of claim 1 , further comprising reporting vulnerabilities for the target computer grouped at least in part on a per-patch milestone basis.

5. The method of claim 1 , wherein the scanning is performed by a Device Profiler remote from the target computer.

6. The method of claim 1 , wherein the scanning is performed by an agent executing on the target computer.

7. The method of claim 1 , further comprising identifying a platform associated with the target computer and, based on the identifying, only executing scanning rules that are relevant to the target computer.

8. The method of claim 1 , further comprising correcting a vulnerability identified on the target computer by executing at least one of the vulnerability scanning rules.

9. The method of claim 1 , further comprising storing, in a computer-readable storage device, an indication of a vulnerability identified on the target computer by executing at least one of the vulnerability scanning rules.

10. One or more non-transitory computer-readable storage media storing computer-readable instructions that when executed by a computer, cause the computer to perform a method, the instructions comprising:

instructions that cause the computer to receive a plurality of ordered patch milestones, each of the patch milestones designating a set of one or more vulnerability scanning rules having an associated scanning order;

instructions that cause the computer to, based on a current patch level for a target computer, select a set of one or more of but not all of the patch milestones, wherein at least some of the patch milestones are not selected based on the ordering of the patch milestones and the current patch level, wherein the ordering of the patch milestones defines whether an install date of a first patch milestone of the plurality of ordered patch milestones precedes or supercedes an install date a second patch milestone of the plurality of ordered patch milestones; and

instructions that cause the computer to evaluate the selected set of patch milestones, the evaluating comprising executing at least one of the vulnerability scanning rules associated with the selected set of patch milestones.

11. The non-transitory computer-readable storage media of claim 10 , wherein the evaluating comprises executing the vulnerability scanning rules associated with the selected set of patch milestones according to a specified order.

12. The non-transitory computer-readable storage media of claim 10 , wherein at least one of the selected set of patch milestones references one or more ordered subsets of patch milestones, the method further comprising:

selecting at least one of the subsets of patch milestones based on the order of the subset of patch milestones and a current patch level of the target machine; and

evaluating the selected at least one of the subset of patch milestones, the evaluating comprising executing a vulnerability scanning rule associated with the selected at least one of the subsets of patch milestones.

13. The non-transitory computer-readable storage media of claim 10 , further comprising reporting vulnerabilities for the target computer grouped at least in part on a per-patch milestone basis.

14. The non-transitory computer-readable storage media of claim 10 , wherein the scanning is performed by a Device Profiler remote from the target computer.

15. The non-transitory computer-readable storage media of claim 10 , wherein the scanning is performed by an agent executing on the target computer.

16. A computer comprising:

one or more processors;

memory;

a network interface coupled to the processors and configured to scan or more target computers accessible using the network interface; and

a computer-readable storage media storing computer-readable instructions that when executed by the one or more processors, cause the one or more processors to perform a method, the instructions comprising:

instructions that cause the computer to receive a plurality of ordered patch milestones, each of the patch milestones designating a set of one or more vulnerability scanning rules having an associated scanning order;

instructions that cause the computer to, based on a current patch level for a target computer, select a set of one or more of but not all of the patch milestones, wherein at least some of the patch milestones are not selected based on the ordering of the patch milestones and the current patch level, wherein the ordering of the patch milestones defines whether an install date of a first patch milestone of the plurality of ordered patch milestones precedes or supercedes an install date a second patch milestone of the plurality of ordered patch milestones; and

instructions that cause the computer to evaluate the selected set of patch milestones, the evaluating comprising executing at least one of the vulnerability scanning rules associated with the selected set of patch milestones.

17. The computer of claim 16 , wherein selecting the set of one or more of but not all of the patch milestones does not select at least some of the patch milestones based on the ordering of the patch milestones and the current patch level of the target computer.

18. The computer of claim 16 , wherein evaluating the selected set of patch milestones executes at least one of a plurality of vulnerability scanning rules associated with the selected set of patch milestones.

Assignments (11)
SECURITY INTEREST Recorded Jan 6, 2026
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.
To: ACQUIOM AGENCY SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 074233/0632 →
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 60306/0365 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: TRIPWIRE, INC.
Reel/Frame 074023/0235 →
TERMINATION AND RELEASE OF FIRST LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 60306/0555 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: TRIPWIRE, INC.
Reel/Frame 074023/0320 →
NEW MONEY FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.; VERA SECURITY, INC.
To: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 073683/0534 →
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 60306/0649 Recorded Nov 21, 2025
From: ACQUIOM AGENCY SERVICES LLC
To: TRIPWIRE, INC.
Reel/Frame 073663/0698 →
EXTENDED RCF FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: TRIPWIRE, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073663/0639 →
EXTENDED FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: TRIPWIRE, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073664/0124 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 14, 2025
From: GOLUB CAPITAL MARKETS LLC (AS EXISTING AGENT)
To: ACQUIOM AGENCY SERVICES LLC (AS SUCCESSOR COLLATERAL AGENT)
Reel/Frame 072471/0665 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jun 7, 2022
From: TRIPWIRE, INC.
To: GOLUB CAPITAL MARKETS LLC, AS COLLATERAL AGENT
Reel/Frame 060306/0649 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jun 7, 2022
From: TRIPWIRE, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 060306/0365 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 6, 2021
From: REGULY, TYLER; PAWLUKOWSKY, CHRIS; CONDREN, MATTHEW JONATHAN
To: TRIPWIRE, INC.
Reel/Frame 058309/0614 →
Continuity (4)
Continuation 16170962 · Oct 25, 2018
Division 14165410 · Jan 27, 2014
Provisional Application 61922679 · Dec 31, 2013
Provisional Application 61892318 · Oct 17, 2013