U.S. patents available from 1976 to present.
U.S. patent applications available from 2005 to present.

System and method for risk detection and analysis in a computer network

Patent 6952779 Issued on October 4, 2005. Estimated Expiration Date: Icon_subject October 1, 2022. Estimated Expiration Date is calculated based on simple USPTO term provisions. It does not account for terminal disclaimers, term adjustments, failure to pay maintenance fees, or other factors which might affect the term of a patent.

Patent References

Method and apparatus for improved monitoring and detection of improper device operation
Patent #: 4773028
Issued on: 09/20/1988
Inventor: Tallman

Distributed security auditing subsystem for an operating system
Patent #: 5032979
Issued on: 07/16/1991
Inventor: Hecht, et al.

Pattern-oriented intrusion-detection system and method
Patent #: 5278901
Issued on: 01/11/1994
Inventor: Shieh, et al.

Knowledge representation for expert system
Patent #: 5295230
Issued on: 03/15/1994
Inventor: Kung

System and method for controlling the use of a computer
Patent #: 5361359
Issued on: 11/01/1994
Inventor: Tajalli, et al.

Method and arrangement for monitoring computer manipulations
Patent #: 5475625
Issued on: 12/12/1995
Inventor: Glaschick

Automated penetration analysis system and method
Patent #: 5485409
Issued on: 01/16/1996
Inventor: Gupta, et al.

Method and system for detecting intrusion into and misuse of a data processing system
Patent #: 5557742
Issued on: 09/17/1996
Inventor: Smaha, et al.

Facility for detecting intruders and suspect callers in a computer installation and a security system including such a facility
Patent #: 5621889
Issued on: 04/15/1997
Inventor: Lermuzeaux, et al.

Method and apparatus for automated network-wide surveillance and security breach intervention
Patent #: 5796942
Issued on: 08/18/1998
Inventor: Esbensen

More ...

Inventors

Application

No. 10262648 filed on 10/01/2002

US Classes:

714/37Analysis (e.g., of output, state, or design)

Examiners

Primary: Morse, Gregory
Assistant: Nalven, Andrew

Attorney, Agent or Firm

International Class

H04L009/00

Abstract

The present invention provides systems and methods for risk detection and analysis in a computer network. Computerized, automated systems and methods can be provided. Raw vulnerability information and network information can be utilized in determining actual vulnerability information associated with network nodes. Methods are provided in which computer networks are modeled, and the models utilized in performing attack simulations and determining risks associated with vulnerabilities. Risks can be evaluated and prioritized, and fix information can be provided.

Other References

  • Swiler, Laura Painton, et al.; “A Graph-Based Network-Vulnerability Analysis System”, Sandia Report, Jan. 1998, pp. 1-21.
  • Phillips, Cynthia, et al.; “A Preliminary Classification Scheme for Information System Threats, Attacks, and Defenses; A Cause and Effect Model; and Some Analysis Based on that Model”, Sandia National Laboratories, Sep., 1998, pp. 1-78.
  • http://www-2.cs.cmu.edu/afs/cs.cmu.edu/project/venari/www/usenix96-kindred-wing.html, Kindred, Darrell, et al.; “Fast, Automatic Checking of Security Protocols”, pp. 1-19.
  • Wing, Jeannette M., et al.; “Survivability Analysis of Networked Systems”, Computer Science Dept., Carnegie Mellon Univ., Pittsburgh, PA; Information and Communications Univ., Taejon, Korea, May, 14, 2001, pp. 1-31.
  • Wyss, Gregory D., et al.; “Information Systems Vulnerability: A Systems Analysis Perspective”, Sandia National Laboratories, pp. 1-14.
  • http://www.math.uiuc.edu/Hilda/htmlcalenders/Apr2400/jhaapr24-00.html, Jha, Somesh; “Survivability Analysis of Software Specifications”, Department of Mathmatics, University of Illinois at Urbana-Champaign, Abstract.
  • Oleg Sheyner, et al.; “Toward Compositional Analysis of Security Protocols Using Theorem Proving”, School of Computer Science, CarnegieMellon Univ., Jan. 2000, pp. 1-28.
  • Jha, Somesh, et al.; “Minimization and Reliability Analyses of Attack Graphs”, School of Computer Science, Carnegie Mellon University, pp. 1-30.
  • Deswarte, Yves, et al.; “Experimental Validation of a Security Metrics”, LAAS-CNRS, pp. 1-6.
  • Mummidi, Sailaja, et al.; “Information Management System Vulnerability Analysis Study”, New Mexico Tech., Nov. 8, 2001, pp. 1-16.
  • http://www/naseo.org/committees/energy data/energy assurance/, pp. 1-2.
  • Hutchinson, Bob, et al.; “Lessons Learned Through Sandia's Cyber Assessment Program”, Sandi National Laboratories, pp. 1-17.
  • http://www.comp.nus.edu.sg/apsec2000/indexright.html, Wing, Jeannete M.; “Survivability Analysis of Networked Systems”, Carnegie Mellon University, Abstract; van Lamsweerde, Axel; “Building Formal Models for Software Requirements”, Universite Catholique de Louvain, Abstract.
PatentsPlus Images
Enhanced PDF formats
loading...
PatentsPlus: add to cart
PatentsPlus: add to cartSearch-enhanced full patent PDF image
$9.95more info
PatentsPlus: add to cart
PatentsPlus: add to cartIntelligent turbocharged patent PDFs with marked up images
$16.95more info
 
Sign InRegister
Username  
Password   
forgot password?