首页> 外国专利> Method and apparatus for reducing security risk in a networked computer system architecture

Method and apparatus for reducing security risk in a networked computer system architecture

机译:用于降低网络计算机系统架构中的安全风险的方法和装置

摘要

An apparatus and associated method are provided for reducing a security risk in a networked computer system architecture. The method comprises receiving at a security computer external vulnerability data from an external source regarding vulnerabilities associated with an attack vector for configuration item (CI) data related to a (CI) device, of the networked computer system. The security computer accesses a configuration management database (CMDB) and the CI data related to the physical device is read. Trust zone data associated with the CI device is determined utilizing the CMDB, and the security computer performs a vulnerability calculation for the CI device utilizing the external vulnerability data and associated trust zone data. This is also done for a second CI device. The vulnerability calculations for both are compared and this comparison serves as a basis for prioritizing an action to be taken on the CI device or associated other network components.
机译:提供了一种用于降低网络计算机系统架构中的安全风险的装置和相关方法。该方法包括在来自关于与网络计算机系统的配置项(CI)数据相关联的关于与配置项(CI)数据相关联的漏洞相关联的外部源处的安全计算机外部漏洞数据接收。安全计算机访问配置管理数据库(CMDB),读取与物理设备相关的CI数据。利用CMDB确定与CI设备相关联的信任区域数据,并且安全计算机利用外部漏洞数据和相关的信任区域数据对CI设备执行漏洞计算。这也用于第二个CI设备。比较两个漏洞计算,并且该比较是优先考虑在CI设备或相关的其他网络组件上采取的动作的基础。

著录项

  • 公开/公告号US10938850B2

    专利类型

  • 公开/公告日2021-03-02

    原文格式PDF

  • 申请/专利权人 SERVICENOW INC.;

    申请/专利号US201916596478

  • 申请日2019-10-08

  • 分类号H04L9;H04L29/06;G06F21/57;

  • 国家 US

  • 入库时间 2022-08-24 17:25:50

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号