×

System and method for network vulnerability detection and reporting

  • US 7,257,630 B2
  • Filed: 03/10/2003
  • Issued: 08/14/2007
  • Est. Priority Date: 01/15/2002
  • Status: Active Grant
First Claim
Patent Images

1. A method of objectively assessing the security of a networks, said method comprising:

  • assigning a vulnerability risk level to each of a plurality of vulnerabilities found on the network;

    assigning a vulnerability risk level to each of a plurality of nodes on the network based on vulnerabilities found on each of the plurality of nodes;

    assigning an exposure risk level to each exposure found on the network;

    providing a security score that is dependent on at least the vulnerability risk levels of the vulnerabilities, the vulnerability risk levels of the nodes, and a number of nodes on the network;

    wherein the security score is derived from a formula of form F=a−

    V−

    E, wherein F is the security score, a is a constant, V is a vulnerability loss, and E is an exposure loss.

View all claims
  • 13 Assignments
Timeline View
Assignment View
    ×
    ×