US2014317752A1PendingUtilityA1
Computer network security platform
Est. expiryNov 16, 2029(~3.2 yrs left)· nominal 20-yr term from priority
Inventors:John Maguire
H04L 63/1433G06F 21/552H04L 9/32
48
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
A computer system for managing security information for an organization includes a scanner execution module configured to automatically execute at least two scanners in a predetermined interval to analyze potential vulnerabilities of a computer environment. A vulnerability is acquired from the at least two scanners and stored in a data store. A user associated with the analyzed computer environment is determined based on the vulnerability stored in the data store, the user is notified of the vulnerability.
Claims
exact text as granted — not AI-modified1 .- 20 . (canceled)
21 . A computer system for managing security information for an organization, comprising:
one or more memories storing instructions; and one or more processors configured to execute the instructions to:
receive scan data from at least two scanners;
correlate the scan data to determine one or more vulnerabilities;
receive an input indicating that a vulnerability from the one or more vulnerabilities is an excluded vulnerability, the excluded vulnerability being excluded from a report based on a risk rating of the vulnerability; and
generate a report that includes the one or more vulnerabilities but not the excluded vulnerability.
22 . The computer system of claim 21 , wherein the one or more processors are further configured to execute the instructions to:
generate a user interface that displays vulnerability data.
23 . The computer system of claim 22 , wherein the one or more processors are further configured to execute the instructions to:
receive an input through the user interface from a user, the input specifying one or more preferences of the user that are remembered between sessions.
24 . The computer system of claim 22 , wherein the one or more processors are further configured to execute the instructions to:
enable a user to exclude, override, or accept a risk associated with one of the one or more vulnerabilities through the user interface.
25 . The computer system of claim 22 , wherein the one or more processors are further configured to execute the instructions to:
enable a user to exclude, through the user interface, one of the one or more vulnerabilities from display or inclusion in the report permanently.
26 . The computer system of claim 22 , wherein the one or more processors are further configured to execute the instructions to:
enable a user to exclude, through the user interface, one of the one or more vulnerabilities from display or inclusion in the report for a time period.
27 . The computer system of claim 22 , wherein the one or more processors are further configured to execute the instructions to:
enable a user to adjust the risk rating of one of the one or more vulnerabilities through the user interface.
28 . A computer-implemented method for managing computer security, the method comprising the following operations performed by at least one processor:
receiving scan data from at least two scanners; correlating the scan data to determine one or more vulnerabilities; receiving an input indicating that a vulnerability from the one or more vulnerabilities is an excluded vulnerability, the excluded vulnerability being excluded from a report based on a risk rating of the vulnerability; and generating a report that includes the one or more vulnerabilities but not the excluded vulnerability.
29 . The computer-implemented method of claim 28 , further comprising:
generating a user interface that displays vulnerability data.
30 . The computer-implemented method of claim 29 , further comprising:
receive an input through the user interface from a user, the input specifying one or more preferences of the user that are remembered between sessions.
31 . The computer-implemented method of claim 29 , further comprising:
enabling a user to exclude, override, or accept a risk associated with one of the one or more vulnerabilities through the user interface.
32 . The computer-implemented method of claim 29 , further comprising:
enabling a user to exclude, through the user interface, one of the one or more vulnerabilities from display or inclusion in the report permanently.
33 . The computer-implemented method of claim 29 , further comprising:
enabling a user to exclude, through the user interface, one of the one or more vulnerabilities from display or inclusion in the report for a time period.
34 . The computer-implemented method of claim 29 , further comprising:
enabling a user to adjust the risk rating of one of the one or more vulnerabilities through the user interface.
35 . A nontransitory computer readable medium encoded with instructions that, when executed by at least one processor, cause the at least one processor to perform a method for managing security information for an organization, the method comprising:
receiving scan data from at least two scanners; correlating the scan data to determine one or more vulnerabilities; receiving an input indicating that a vulnerability from the one or more vulnerabilities is an excluded vulnerability, the excluded vulnerability being excluded from a report based on a risk rating of the vulnerability; and generating a report that includes the one or more vulnerabilities but not the excluded vulnerability.
36 . The nontransitory computer readable medium of claim 35 , the method further comprising:
generating a user interface that displays vulnerability data.
37 . The nontransitory computer readable medium of claim 36 , the method further comprising:
receive an input through the user interface from a user, the input specifying one or more preferences of the user that are remembered between sessions.
38 . The nontransitory computer readable medium of claim 36 , the method further comprising:
enabling a user to exclude, override, or accept a risk associated with one of the one or more vulnerabilities through the user interface.
39 . The nontransitory computer readable medium of claim 36 , the method further comprising:
enabling a user to exclude, through the user interface, one of the one or more vulnerabilities from display or inclusion in the report permanently.
40 . The nontransitory computer readable medium of claim 36 , further comprising:
enabling a user to exclude, through the user interface, one of the one or more vulnerabilities from display or inclusion in the report for a time period.Join the waitlist — get patent alerts
Track US2014317752A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.