发明授权
- 专利标题: System and method of managing network security risks
- 专利标题(中): 管理网络安全风险的系统和方法
-
申请号: US10813917申请日: 2004-03-31
-
公开(公告)号: US08201257B1公开(公告)日: 2012-06-12
- 发明人: Steven G. Andres , David M. Cole , Thomas Gregory Cummings , Roberto Ramon Garcia , Brian Michael Kenyon , George R. Kurtz , Stuart Cartier McClure , Christopher William Moore , Michael J. O'Dea , Ken D. Saruwatari
- 申请人: Steven G. Andres , David M. Cole , Thomas Gregory Cummings , Roberto Ramon Garcia , Brian Michael Kenyon , George R. Kurtz , Stuart Cartier McClure , Christopher William Moore , Michael J. O'Dea , Ken D. Saruwatari
- 申请人地址: US CA Santa Clara
- 专利权人: McAfee, Inc.
- 当前专利权人: McAfee, Inc.
- 当前专利权人地址: US CA Santa Clara
- 代理机构: Patent Capital Group
- 主分类号: G06F21/00
- IPC分类号: G06F21/00
摘要:
A security risk management system comprises a vulnerability database, an asset database, a local threat intelligence database and a threat correlation module. The vulnerability database comprises data about security vulnerabilities of assets on a network gathered using active or passive vulnerability assessment techniques. The asset database comprises data concerning attributes of each asset. The threat correlation module receives threat intelligence alerts that identify attributes and vulnerabilities associated with security threats that affect classes of assets. The threat correlation module compares asset attributes and vulnerabilities with threat attributes and vulnerabilities and displays a list of assets that are affected by a particular threat. The list can be sorted according to a calculated risk score, allowing an administrator to prioritize preventive action and respond first to threats that affect higher risk assets. The security risk management system provides tools for performing preventive action and for tracking the success of preventive action.
信息查询