U.S. patents available from 1976 to present.
U.S. patent applications available from 2005 to present.

Icon_funbox Did You Know...

...that the video game, Pong, was invented by a guy who graduated at the bottom of his engineering class? Nolan Bushnell spent more time running the games at a local amusement park than he did on his studies at the University of Utah. His dreams of working for Disney's amusement empire were dashed when the company wouldn't hire him. Taking a boring job, Nolan daydreamed about electronic versions of popular games. He invented Pong, the first video game, and went on to found Atari Co.

Newsletter  PatentStorm News

Make the Most of Our Site

See this month's Top Inventors and Most Cited Patents.

Stay on top of the latest innovations by subscribing to an RSS feed.

Registered users: Manage your profile.

 

Class 726/25 - Vulnerability assessment


Subclass of Class 726 - Information security
Definition: Subject matter wherein monitoring or scanning of software
No. of patents: 410
Last issue date: 05/29/2012


1                      
NumberTitleIssue Date
8191149System and method for predicting cyber threat
Provided are a system and method for predicting a cyber threat. The system and method collect various variables and synthetically predict the frequency, dangerousness, possibility, and time of the occurrence of a cyber threat including hacking, a worm/virus, a Denia...
05/29/2012
8185956Real-time website safety reputation system
A mechanism is provided for determining a safety reputation for a network site in a manner that provides both wide coverage of potentially malicious sites as well as improves the freshness of information from which the safety reputation is derived. Community-based i...
05/22/2012
8181252Intrusion event correlation system
Disclosed is a system for correlating intrusion events using attack graph distances. The system includes an attack graph generator, an exploit distance calculator, an intrusion detector, an event report/exploit associator, an event graph creator, an event graph dist...
05/15/2012
8181254Setting default security features for use with web applications and extensions
According to one general aspect, a computer-implemented method for implementing default security features for web applications and browser extensions includes receiving a request to include a web application or a web browser extension in a digital marketplace. A det...
05/15/2012
8181253System and method for reducing security risk in computer network
Disclosed are systems, methods and computer program products for reducing security risk in a computer network. The system includes an administration server that collects system usage, user profile and security incidents information from a plurality of computers in t...
05/15/2012
8176560Evaluation of tamper resistant software system implementations
According to one embodiment of the present invention, a method for evaluating a software system includes defining a rating of the tamper resistance of a software system and breaking down the rating into a plurality of metrics relevant to the tamper resistance of the...
05/08/2012
8176561Assessing network security risk using best practices
A method and appertaining system for implementing the method are provided that utilize predefined Best Practice Templates that are rules/criteria for assessing the security of a particular network and devices on the network. A value is determined for each object and...
05/08/2012
8171555Determining technology-appropriate remediation for vulnerability
A machine-actionable memory comprises one or more machine-actionable records arranged according to a data structure. Such a data structure may include links that respectively map between: a RID field, the contents of which denote an identification (ID) of a remediat...
05/01/2012
8166552Adaptive configuration management system
An automated configuration management system (ACMS) oversees resources of a virtualized ecosystem by establishing a baseline configuration (including, e.g., security controls) for the resources; and, repeatedly, monitoring and collecting data from the resources, ana...
04/24/2012
8166551Automated security manager
Systems, methods, media, and other embodiments associated with automated security management are described. One example system embodiment includes logic to collect, organize, and maintain data concerning electronic information resources, data concerning security cri...
04/24/2012
8161558Network management and administration
Method and arrangements are provided for use in managing a network having one more user computing entities and one or more administrative computing entities. One method includes monitoring network traffic from a user computing entity; detecting a client request sent...
04/17/2012
8161559Methods, computer networks and computer program products for reducing the vulnerability of user devices
Methods, computer networks, and computer program products that reduce the vulnerability of network user devices to security threats include scanning a user device connected to a network to determine whether the user device contains a particular version of an applica...
04/17/2012
8161560Extensible framework for system security state reporting and remediation
A security health reporting system provides an application program interface (API) for use by independent software vendors (ISVs) to extend the security health reporting capabilities of the security health reporting system. An ISV security solution can register with...
04/17/2012
8156559Systematic approach to uncover GUI logic flaws
To achieve end-to-end security, traditional machine-to-machine security measures are insufficient if the integrity of the graphical user interface (GUI) is compromised. GUI logic flaws are a category of software vulnerabilities that result from logic flaws in GUI im...
04/10/2012
8156558Mechanism for evaluating security risks
Described is a mechanism for collectively evaluating security risks associated with loading an application. A hosting environment associated with loading the application invokes a trust manager to evaluate the security risks. The trust manager invokes a plurality of...
04/10/2012
8150779Validating the detection of spam based entities in social networking contexts
A validation system validates the detection of spam based entities in social networking contexts. Suspected spam based social networking entities are detected in a social networking site. A virtual social networking group is created that emulates a plurality of user...
04/03/2012
8141158Measuring coverage of application inputs for advanced web application security testing
A computer implemented method, a data processing system, and a computer usable recordable-type medium having a computer usable program code monitor a black box web application security scan. A black box scan of a web application is initiated. The black box scan send...
03/20/2012
8136164Manual operations in an enterprise security assessment sharing system
An enterprise-wide sharing arrangement uses a semantic abstraction, called a security assessment, to share security-related information between different security products, called endpoints. A security assessment is defined as a tentative assignment by an endpoint o...
03/13/2012
8136163Method, apparatus and program storage device for providing automated tracking of security vulnerabilities
A method, apparatus and program storage device for providing automated tracking of security vulnerabilities is disclosed. Security problems are reported, aged and tracked. A time to fix the vulnerability identified by the vulnerability assessment of the system is ba...
03/13/2012
8132259System and method for security planning with soft security constraints
A method for security planning with soft security constraints, include: receiving security-related requirements of a workflow to be developed using system inputs and processing components; and generating at least one proposed workflow according to the security-relat...
03/06/2012
8132260Methods and apparatus for prioritization of remediation techniques for network security risks
A method for a computer system includes receiving a topology of a network including a server location and a threat server at a threat server location, determining a vulnerability security risk for the server location, determining remediation actions including a firs...
03/06/2012
8127359Systems and methods for real-time network-based vulnerability assessment
A system for real-time vulnerability assessment of a host/device, said system comprising an agent running on the host/device. The agent includes a a first data structure for storing the status of interfaces and ports on the interfaces of the host/device. An n execut...
02/28/2012
8127360Method and apparatus for detecting leakage of sensitive information
A method and apparatus for preventing leakage of sensitive information from a computer is described. The method includes identifying data entered into the computer system as sensitive data, tainting the sensitive data with at least one taint bit to form a tainted da...
02/28/2012
8122510Method for analyzing and managing unstructured data
A system and method for managing unstructured data that includes identifying at least one unstructured data environment with unstructured data, identifying mitigating controls in each of the unstructured data environments, the mitigating controls reducing a security...
02/21/2012
8117660Secure control flows by monitoring control transfers
A cross-module detection system and method for detecting and monitoring control flow transfers between software modules in a computer system. The system and method detect and monitor control flows entering and exiting the software modules. For a particular module, a...
02/14/2012
8108933System and method for attack and malware prevention
The present invention is a system and method for detecting and preventing attacks and malware on mobile devices such as a cell phones, smartphones or PDAs, which are significantly limited in power consumption, computational power, and memory. The invention enables m...
01/31/2012
8108932Calculating a password strength score based upon character proximity and relative position upon an input device
A solution for computing password strength based upon layout positions of input mechanisms of an input device that entered a password. A password including an ordered sequence of at least two characters can be identified. A position of each of the characters of the ...
01/31/2012
8099786Embedded mechanism for platform vulnerability assessment
Embodiments of the present invention provide an embedded mechanism for platform vulnerability assessment. In various embodiments, a management component of a managed platform may scan at least one host component of the managed platform for vulnerability of the at le...
01/17/2012
8099787Knowledge-based and collaborative system for security assessment of web applications
A standardized system for assessing the security of web based applications which has a component for collecting information regarding threat and vulnerabilities to web applications is described. The system includes a component for organizing the information regardin...
01/17/2012
8095984Systems and methods of associating security vulnerabilities and assets
Systems and methods of associating security vulnerabilities and assets, and related Graphical User Interfaces (GUIs) and data structures, are disclosed. A definition of a security vulnerability, which includes multiple asset characteristics such as an asset platform...
01/10/2012
8095982Analyzing the security of communication protocols and channels for a pass-through device
A security analyzer includes a single software application that both sends test messages to a device under analysis (DUA) and receives response messages generated by the DUA in response to the test messages. In this way, synchronization of which response messages co...
01/10/2012
8095983Platform for analyzing the security of communication protocols and channels
A security analyzer tests the security of a device by attacking the device and observing the device's response. Attacking the device includes sending one or more messages to the device. A message can be generated by the security analyzer or generated independently o...
01/10/2012
8087088Using fuzzy classification models to perform matching operations in a web application security scanner
A system provides for fuzzy classification in comparisons of scanner responses. A web application test suite performs tests against a web application by sending client requests from a testing computer to the server running the web application and checking how the we...
12/27/2011
8087087Management of computer security events across distributed systems
A computer receives a system event initiated by an initiating client associated with a user. The system event comprises a plurality of data elements associated with respective ones of a plurality of system event attributes. It is determined that the system event fai...
12/27/2011
8074282System, method, and computer program product for conveying a status of a plurality of security applications
A system, method and computer program product are provided for displaying a status of a security application. A status of at least one security application is initially identified. An index is calculated that is representative of a degree of risk associated with the...
12/06/2011
8060936Security status and information display system
The present invention provides a system and method for reporting security information relating to a mobile device. The invention enables a security assessment to be displayed in various formats on the mobile device display or on a client computer. A security compone...
11/15/2011
8056137Communication terminal device and computer device
A communication terminal device includes a wireless communication unit, an integrity measurement request unit, a cryptographic processing unit, a pointing unit. The integrity measurement request unit generates a command to request another computer device to measure ...
11/08/2011
8051486Indicating SQL injection attack vulnerability with a stored value
A web application receives a user input with a SQL injection attack string that references a function. The application generates a corresponding statement based on the user input string, which the application sends to a database server. Upon receiving the statement,...
11/01/2011
8046836Method for device quarantine and quarantine network system
A network quarantine management system eliminates registration or updating work of a quarantine-exempted device and prevents a fraudulent device from abusing authorized network information registered as a quarantine-exempted device and from impersonation. Whe...
10/25/2011
8046835Distributed computer network security activity model SDI-SCAM
A distributed multi-agent system and method is implemented and employed across at least one intranet for purposes of real time collection, monitoring, aggregation, analysis and modeling of system and network operations, communications, internal and external accesses...
10/25/2011
1                      
 
Sign InRegister
Username  
Password   
forgot password?