发明名称 Network Security System Having a Device Profiler Communicatively Coupled to a Traffic Monitor
摘要 A system and method for providing distributed security of a network. Several device profilers are placed at different locations of a network to assess vulnerabilities from different perspectives. The device profiler identifies the hosts on the network, and characteristics such as operating system and applications running on the hosts. The device profiler traverses a vulnerability tree having nodes representative of characteristics of the hosts, each node having an associated set of potential vulnerabilities. Verification rules can verify the potential vulnerabilities. A centralized correlation server, at a centrally accessible location in the network, stores the determined vulnerabilities of the network and associates the determined vulnerabilities with attack signatures. Traffic monitors access the attack signatures and monitor network traffic for attacks against the determined vulnerabilities.
申请公布号 US2007143852(A1) 申请公布日期 2007.06.21
申请号 US20070676051 申请日期 2007.02.16
申请人 KEANINI TIMOTHY D;QUIROGA MARTIN A;BUCHANAN BRIAN W;FLOWERS JOHN S 发明人 KEANINI TIMOTHY D.;QUIROGA MARTIN A.;BUCHANAN BRIAN W.;FLOWERS JOHN S.
分类号 G06F11/00 主分类号 G06F11/00
代理机构 代理人
主权项
地址