EP1559008A1

Method for risk detection and analysis in a computer network

Abstract

A method, system and computer program product for evaluating an IDP entity, the method includes evaluating an effect of at least one IDP rule applied by the IDP entity on legitimate traffic, based upon a network model; evaluating an effect of at least one IDP rule applied by the IDP entity based upon a network model and an attack model; determining an effectiveness of the IDP entity in response to the evaluated effects.

Term

Term ended

Projected expiry passed 26 September 2023, 3 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

28 claims: 5 independent, 23 dependent

  1. 1
    Claims of equivalent WO 2004031953 A1 WHAT IS CLAIMED IS:1. A computerized method for determining actual vulnerability information associated with at least one network node in a computer network, the method comprising: obtaining raw vulnerability information associated with the at least one network node;obtaining network information relating to the computer network;utilizing the raw vulnerability information and the network information, determining the actual vulnerability information associated with the at least one network node;and, storing the actual vulnerability information.
  2. 17
    A system for determining actual vulnerability information associated with at least one network node of a computer network, the system comprising:one or more databases, the one or more databases comprising raw vulnerability information associated with the at least one network node, and the one or more databases comprising network information associated with the computer network;and, a computer, connectable to the one or more databases;wherein the computer is programmed to, utilizing the raw vulnerability information and the network information as input, generate output comprising the actual vulnerability information associated with the at least one network node.
  3. 22
    The system of claiml7, wherein the network information is filtered network information.
  4. 24
    A computer usable medium storing program code which, when executed on a computerized device, causes the computerized device to execute a computerized method for determining actual vulnerability information associated with at least one network node in a computer network, the method comprising:obtaining raw vulnerability information associated with the at least one network node;obtaining network information relating to the computer network;utilizing the raw vulnerability information and the network information, determining actual vulnerability information associated with the at least one network node;and, storing the actual vulnerability information.
  5. 25
    A computerized method for determining actual vulnerability information associated a computer network, the method comprising:obtaining a first set of information associated with the network by utilizing at least one vulnerability information discovery agent;obtaining a second set of information associated with the network utilizing at least one network information discovery agent;utilizing the first set of information and the second set of information, determining the actual vulnerability information associated with the network;and, storing the actual vulnerability information.