Patent · US Active

System and method for identifying system vulnerabilities

US11095675B1 · kind B1 · utility

0Cited by
2References
16Claims
0Family size

Assignee

Inventors

Key dates

Filing dateMar 27, 2019
Grant dateAug 17, 2021
Priority date
Expiry dateMar 27, 2039

Classification

  • Technology area (CPC G)Physics
  • CPC primaryG06F21/577
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

The invention relates to detecting vulnerabilities in technology infrastructure environments. Data describing vulnerabilities detected in a technological environment of an enterprise is obtained. The vulnerability data is combined with data relating to servers, applications associated with the servers, and business functions associated with the applications, within the technological environment of the enterprise in order to create enriched data. The enriched data is enhanced using one or more of the following proceses: deduplicating records in the enriched data; modifying of a severity assigned to vulnerabilities based on one or more enterprise-infrastructure factors; archiving and purging of records included in the enriched data; consolidating IP addresses associated with the vulnerabilities; excepting records in the enriched data for vulnerabilities undergoing active remediation; and validating the enriched data. After the enriched data is enhanced, it may be sorted in accordance with one or more filters. The sorted data may then be displayed for further analysis.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.