×

System and method for risk detection and analysis in a computer network

  • US 6,952,779 B1
  • Filed: 10/01/2002
  • Issued: 10/04/2005
  • Est. Priority Date: 10/01/2002
  • Status: Expired due to Term
First Claim
Patent Images

1. A method for performing risk assessment in a computer network, the method comprising:

  • generating a network topology model for the computer network, the network topology model including a set of network nodes, a set of actual vulnerabilities associated with the network nodes, and a set of access rules associated with the network nodes;

    determining, among the set of network nodes, one or more start points, by analyzing a set of access control lists and filtering rules from one or more network devices, the set of access control lists and filtering rules collected by a network discovery agent to determine the start points, and one or more end points of one or more potential attack paths through the network topology model;

    generating an attack graph comprising a set of graph nodes wherein each graph node represents a state of a single service in the network;

    simulating one or more attacks from one or more start points to one or more end points using the attack graph; and

    storing the results of the attack simulation in a computer memory.

View all claims
  • 6 Assignments
Timeline View
Assignment View
    ×
    ×