Systems and methods for reconnaissance of computer environments can include performing, by one or more processors, a hierarchical process to discover information of a computer environment. The one or more processors can discover a plurality of assets and a plurality of features of the computer environment, responsive to performing the hierarchical process. The one or more processors can generate, using the plurality of assets and the plurality of features of the computer environment, a representation of an architecture of the computer environment. The one or more processors can generate, based at least on the representation of the architecture of the computer environment, one or more attack vectors of the computer environment.
G06F 21/57 - Certification ou préservation de plates-formes informatiques fiables, p. ex. démarrages ou arrêts sécurisés, suivis de version, contrôles de logiciel système, mises à jour sécurisées ou évaluation de vulnérabilité
Systems and methods for managing asset risk in computer environment can include receiving, by one or more processors, data indicative of attributes of an asset of the computer environment. The one or more processors can determine a risk context based on the data indicative of the attributes of the asset. The one or more processors can update a risk score of the asset based at least on the risk context. The one or more processors can adjust, responsive to the risk score of the asset, a configuration parameter of at least one of the asset or another asset to mitigate a security risk associated with the asset.
Systems and methods for determining subsystems of a computer environment that are in a mutual independence state can include a computing device obtaining information indicative of a group of assets of a subsystem of a computer environment. For each asset of the group of assets, the computing device can identify one or more first assets on which the asset depends and one or more second assets that depend on the asset, and determine whether the one or more first assets and the one or more second assets belong to the group of assets. The computing device can determine that the subsystem is in a mutual independence state upon determining, for each asset of the group of assets, that the first and second assets belong to the group of assets. The computing device can update a data record to indicate the determined state of subsystem of the computer environment.
Systems and methods for identifying and managing solution stacks integrated within a computer environment include one or more computing devices receiving information identifying one or more first assets as belonging to a solution stack integrated within a computer environment. The computing devices can iteratively identify additional assets of the computer environment related to, but not part of, the assets already identified as belonging to the solution stack, and determine, based on a comparison of attributes of the additional assets to attributes of the assets already identified as belonging to the solution stack, whether any of the additional assets belongs to the solution stack. The one or more computing devices can repeat these steps until no additional is identified as belonging to the solution stack. The computing devices can generate a current state of the solution stack defining at least a complete set of assets forming the solution stack.
G06F 9/455 - ÉmulationInterprétationSimulation de logiciel, p. ex. virtualisation ou émulation des moteurs d’exécution d’applications ou de systèmes d’exploitation
G06F 11/34 - Enregistrement ou évaluation statistique de l'activité du calculateur, p. ex. des interruptions ou des opérations d'entrée–sortie
5.
SYSTEMS AND METHODS FOR DATA ABSTRACTION FOR TRANSMISSION CROSS-REFERENCE TO RELATED APPLICATIONS
Systems and methods for data abstraction can include a data abstraction system assigning to each data item of a plurality of data items a corresponding arbitrary identifier, and maintaining a mapping between each data item of the plurality of data items and the corresponding arbitrary identifier. The data abstraction system can determine information associated with a first data item of the plurality of data items for transmission to a computing device. The data abstraction system can identify, using the mapping, a first arbitrary identifier assigned to the first data item, and transmit the information with the first arbitrary identifier to the computing device.
Systems and methods for data abstraction can include a data abstraction system assigning to each data item of a plurality of data items a corresponding arbitrary identifier, and maintaining a mapping between each data item of the plurality of data items and the corresponding arbitrary identifier. The data abstraction system can determine information associated with a first data item of the plurality of data items for transmission to a computing device. The data abstraction system can identify, using the mapping, a first arbitrary identifier assigned to the first data item, and transmit the information with the first arbitrary identifier to the computing device.
Systems and methods for data access management can include one or more processors determining settings defining a workspace of a user responsive to a request to establish a session with the workspace, and identifying a set of data items of the workspace using the settings and one or more control access permissions of the user. The one or more processors can generate a database of the workspace using copies of the set of data items, and providing the user access to the database. The one or more processors may delete the database upon detecting closing of the workspace
Systems and methods for session-based collaboration can include a collaboration system detecting initiation of a session by a first user to share content of a workspace with a second user. The collaboration system can identify, based at least on the initiation of the session, settings defining the workspace, and generate a database of the specific to the second user using the settings and one or more access control permissions of the second user. The database can include copies of data items of the workspace to which the second user has permission to access. The collaboration system can provide the second user access to the database during the session. The collaboration system may delete the database upon detecting ending of the session.
Systems and methods for data access management can include one or more processors determining settings defining a workspace of a user responsive to a request to establish a session with the workspace, and identifying a set of data items of the workspace using the settings and one or more control access permissions of the user. The one or more processors can generate a database of the workspace using copies of the set of data items, and providing the user access to the database. The one or more processors may delete the database upon detecting closing of the workspace
Systems and methods for session-based collaboration can include a collaboration system detecting initiation of a session by a first user to share content of a workspace with a second user. The collaboration system can identify, based at least on the initiation of the session, settings defining the workspace, and generate a database of the specific to the second user using the settings and one or more access control permissions of the second user. The database can include copies of data items of the workspace to which the second user has permission to access. The collaboration system can provide the second user access to the database during the session. The collaboration system may delete the database upon detecting ending of the session.
Systems and methods for reconnaissance of computer environments can include performing, by one or more processors, a hierarchical process to discover information of a computer environment. The one or more processors can discover a plurality of assets and a plurality of features of the computer environment, responsive to performing the hierarchical process. The one or more processors can generate, using the plurality of assets and the plurality of features of the computer environment, a representation of an architecture of the computer environment. The one or more processors can generate, based at least on the representation of the architecture of the computer environment, one or more attack vectors of the computer environment.
G06F 21/57 - Certification ou préservation de plates-formes informatiques fiables, p. ex. démarrages ou arrêts sécurisés, suivis de version, contrôles de logiciel système, mises à jour sécurisées ou évaluation de vulnérabilité
G06F 21/56 - Détection ou gestion de programmes malveillants, p. ex. dispositions anti-virus
Systems and methods for asset fingerprinting can include probing, by one or more processors, each of a plurality of assets associated with a computer environment, and receiving, responsive to the probe, parameters for the plurality of assets. The one or more processors can cluster, using the parameters, each of the plurality of assets into respective cluster of a plurality of clusters of assets. The one or more processors can determine a profile of a cluster of the plurality of clusters. The profile can define one or more common features of assets of the cluster. The one or more processors can assign the profile of the cluster an unidentified asset of the cluster.
Systems and methods for threat response in computer environments can include detecting, by one or more processors, using performance data of a computer environment, an event that occurred and that is indicative of abnormal performance of the computer environment. The one or more processors can identify, among a plurality of assets of the computer environment, a subset of assets associated with the event, and determine from a predefined set of resolutions a plurality of resolutions executable to address a cause of the event. The one or more processors can execute, for each resolution of the plurality of resolutions, a trained model to simulate the resolution for the subset of assets, and select, based at least on results of simulation of each resolution, a resolution among the plurality of resolutions to be implemented.
Systems and methods for reconnaissance of computer environments can include performing, by one or more processors, a hierarchical process to discover information of a computer environment. The one or more processors can discover a plurality of assets and a plurality of features of the computer environment, responsive to performing the hierarchical process. The one or more processors can generate, using the plurality of assets and the plurality of features of the computer environment, a representation of an architecture of the computer environment. The one or more processors can generate, based at least on the representation of the architecture of the computer environment, one or more attack vectors of the computer environment.
G06F 21/57 - Certification ou préservation de plates-formes informatiques fiables, p. ex. démarrages ou arrêts sécurisés, suivis de version, contrôles de logiciel système, mises à jour sécurisées ou évaluation de vulnérabilité
15.
SYSTEMS AND METHODS FOR MONITORING RISK SCORES BASED ON DYNAMIC ASSET CONTEXT
Systems and methods for managing asset risk in computer environment can include receiving, by one or more processors, data indicative of attributes of an asset of the computer environment. The one or more processors can determine a risk context based on the data indicative of the attributes of the asset. The one or more processors can update a risk score of the asset based at least on the risk context. The one or more processors can adjust, responsive to the risk score of the asset, a configuration parameter of at least one of the asset or another asset to mitigate a security risk associated with the asset.
G06F 21/57 - Certification ou préservation de plates-formes informatiques fiables, p. ex. démarrages ou arrêts sécurisés, suivis de version, contrôles de logiciel système, mises à jour sécurisées ou évaluation de vulnérabilité
16.
SYSTEMS AND METHODS FOR ASSET FINGERPRINTING CROSS REFERENCE TO RELATED APPLICATIONS
Systems and methods for asset fingerprinting can include probing, by one or more processors, each of a plurality of assets associated with a computer environment, and receiving, responsive to the probe, parameters for the plurality of assets. The one or more processors can cluster, using the parameters, each of the plurality of assets into respective cluster of a plurality of clusters of assets. The one or more processors can determine a profile of a cluster of the plurality of clusters. The profile can define one or more common features of assets of the cluster. The one or more processors can assign the profile of the cluster an unidentified asset of the cluster.
Systems and methods for managing asset risk in computer environment can include receiving, by one or more processors, data indicative of attributes of an asset of the computer environment. The one or more processors can determine a risk context based on the data indicative of the attributes of the asset. The one or more processors can update a risk score of the asset based at least on the risk context. The one or more processors can adjust, responsive to the risk score of the asset, a configuration parameter of at least one of the asset or another asset to mitigate a security risk associated with the asset.
Systems and methods for threat response in computer environments can include detecting, by one or more processors, a threat to the computer environment, and identifying a subset of assets of the plurality of assets associated with the threat. The one or more processors can determine from a predefined set of resolutions a plurality of resolutions executable to resolve the threat for the subset of assets. The one or more processors can execute, for each resolution of the plurality of resolutions, a trained model to simulate the resolution for the subset of assets. The one or more processors can select, based at least on results of execution of each resolution, a resolution among the plurality of resolutions to be implemented.
Systems and methods for threat response in computer environments can include detecting, by one or more processors, a threat to the computer environment, and identifying a subset of assets of the plurality of assets associated with the threat. The one or more processors can determine from a predefined set of resolutions a plurality of resolutions executable to resolve the threat for the subset of assets. The one or more processors can execute, for each resolution of the plurality of resolutions, a trained model to simulate the resolution for the subset of assets. The one or more processors can select, based at least on results of execution of each resolution, a resolution among the plurality of resolutions to be implemented.
H04L 41/28 - Restriction de l’accès aux systèmes ou aux fonctions de gestion de réseau, p. ex. en utilisant la fonction d’autorisation pour accéder à la configuration du réseau
20.
SYSTEM AND METHOD FOR ASSESSING OPERATIONAL STATES OF A COMPUTER ENVIRONMENT
Systems and methods for threat response in computer environments can include detecting, by one or more processors, using performance data of a computer environment, an event that occurred and that is indicative of abnormal performance of the computer environment. The one or more processors can identify, among a plurality of assets of the computer environment, a subset of assets associated with the event, and determine from a predefined set of resolutions a plurality of resolutions executable to address a cause of the event. The one or more processors can execute, for each resolution of the plurality of resolutions, a trained model to simulate the resolution for the subset of assets, and select, based at least on results of simulation of each resolution, a resolution among the plurality of resolutions to be implemented.
Systems and methods for determining subsystems of a computer environment that are in a mutual independence state can include a computing device obtaining information indicative of a group of assets of a subsystem of a computer environment. For each asset of the group of assets, the computing device can identify one or more first assets on which the asset depends and one or more second assets that depend on the asset, and determine whether the one or more first assets and the one or more second assets belong to the group of assets. The computing device can determine that the subsystem is in a mutual independence state upon determining, for each asset of the group of assets, that the first and second assets belong to the group of assets. The computing device can update a data record to indicate the determined state of subsystem of the computer environment.
Systems and methods for generating and rendering dynamic 3D representations of subsystems of a computer ecosystem can include a computing device receiving data indicative of importance parameters of a subset of assets of a plurality of assets of a computer environment. Each asset of the subset of assets can be associated with a respective importance parameter. The computing device can determine, for each asset of the subset of assets, a respective visual depth using the respective importance parameter of the asset. The computing device can construct a visual representation of a 3D model of the subset of assets. Each asset can be depicted according to the respective visual depth in the visual representation of the 3D model. The computing device can include causing display of the visual representation of the 3D model on a display device.
Systems and methods for segmenting computer environment data can include a computer system obtaining data of a computer environment including a plurality of assets. The computer system can filter, using the data and one or more first criteria, the plurality of assets to identify a set of filtered assets. The computer system can determine, using the data, a state of each asset of the set of filtered assets, and identify one or more asset clusters within the set of filtered assets, using one or more slicing criteria. Each asset cluster can include assets of the set of filtered assets identified based on corresponding values of the one or more slicing criteria. The computer system can generate a visual representation of an asset cluster of the one or more asset clusters, and assign the visual representation to a user account or a computing device associated with a user profile.
Systems and methods for segmenting computer environment data can include a computer system obtaining data of a computer environment including a plurality of assets. The computer system can filter, using the data and one or more first criteria, the plurality of assets to identify a set of filtered assets. The computer system can determine, using the data, a state of each asset of the set of filtered assets, and identify one or more asset clusters within the set of filtered assets, using one or more slicing criteria. Each asset cluster can include assets of the set of filtered assets identified based on corresponding values of the one or more slicing criteria. The computer system can generate a visual representation of an asset cluster of the one or more asset clusters, and assign the visual representation to a user account or a computing device associated with a user profile.
Systems and methods for determining subsystems of a computer environment that are in a mutual independence state can include a computing device obtaining information indicative of a group of assets of a subsystem of a computer environment. For each asset of the group of assets, the computing device can identify one or more first assets on which the asset depends and one or more second assets that depend on the asset, and determine whether the one or more first assets and the one or more second assets belong to the group of assets. The computing device can determine that the subsystem is in a mutual independence state upon determining, for each asset of the group of assets, that the first and second assets belong to the group of assets. The computing device can update a data record to indicate the determined state of subsystem of the computer environment.
G06F 21/55 - Détection d’intrusion locale ou mise en œuvre de contre-mesures
H04L 12/24 - Dispositions pour la maintenance ou la gestion
H04L 29/06 - Commande de la communication; Traitement de la communication caractérisés par un protocole
G06F 21/57 - Certification ou préservation de plates-formes informatiques fiables, p. ex. démarrages ou arrêts sécurisés, suivis de version, contrôles de logiciel système, mises à jour sécurisées ou évaluation de vulnérabilité
26.
SYSTEMS AND METHODS FOR GENERATING DYNAMIC 3D MODELS OF COMPUTER SYSTEMS
Systems and methods for generating and rendering dynamic 3D representations of subsystems of a computer ecosystem can include a computing device receiving data indicative of importance parameters of a subset of assets of a plurality of assets of a computer environment. Each asset of the subset of assets can be associated with a respective importance parameter. The computing device can determine, for each asset of the subset of assets, a respective visual depth using the respective importance parameter of the asset. The computing device can construct a visual representation of a three-dimensional (3D) model of the subset of assets. Each asset can be depicted according to the respective visual depth in the visual representation of the 3D model. The computing device can include causing display of the visual representation of the 3D model on a display device.
Systems and methods for identifying and managing solution stacks integrated within a computer environment include one or more computing devices receiving information identifying one or more first assets as belonging to a solution stack integrated within a computer environment. The computing devices can iteratively identify additional assets of the computer environment related to, but not part of, the assets already identified as belonging to the solution stack, and determine, based on a comparison of attributes of the additional assets to attributes of the assets already identified as belonging to the solution stack, whether any of the additional assets belongs to the solution stack. The one or more computing devices can repeat these steps until no additional is identified as belonging to the solution stack. The computing devices can generate a current state of the solution stack defining at least a complete set of assets forming the solution stack.
G06F 9/50 - Allocation de ressources, p. ex. de l'unité centrale de traitement [UCT]
G06F 21/57 - Certification ou préservation de plates-formes informatiques fiables, p. ex. démarrages ou arrêts sécurisés, suivis de version, contrôles de logiciel système, mises à jour sécurisées ou évaluation de vulnérabilité
28.
Systems and methods for computer environment situational awareness
Systems and methods for monitoring states of operation of a computer environment can include one or more computer servers identifying a target asset of the computer environment and establishing a communication link with a computing device associated with the target asset. The one or more computer servers can determine a first set of parameters for profiling the target asset, transmit a first query for the first set of parameters to the computing device via the communication link, and receive one or more first parameter values corresponding to the first set of parameters responsive to the query. The one or more computer servers can compare the one or more first parameter values to one or more first criteria or threshold values, an determine a state of operation of the target asset based on the comparison. The state of operation can be indicative of an abnormal behavior associated with the target asset.
G06F 16/951 - IndexationTechniques d’exploration du Web
H04L 43/0817 - Surveillance ou test en fonction de métriques spécifiques, p. ex. la qualité du service [QoS], la consommation d’énergie ou les paramètres environnementaux en vérifiant la disponibilité en vérifiant le fonctionnement
G06F 21/55 - Détection d’intrusion locale ou mise en œuvre de contre-mesures
H04L 41/0853 - Récupération de la configuration du réseauSuivi de l’historique de configuration du réseau en recueillant activement des informations de configuration ou en sauvegardant les informations de configuration
G06F 21/57 - Certification ou préservation de plates-formes informatiques fiables, p. ex. démarrages ou arrêts sécurisés, suivis de version, contrôles de logiciel système, mises à jour sécurisées ou évaluation de vulnérabilité
29.
Systems and methods for multi-tier cache visual system and visual modes
Systems and methods for displaying computer environment monitoring data can include a multi-tier cache memory associated with a processor of a first device. The multi-tier cache memory can include a first cache layer, and a second cache layer having a higher data access rate than the first cache layer. The first device can receive, from a second device, a data block including monitoring data selected based on user profile information associated with a user of the first device. The first device can store the data block in the first cache layer, and generate a first data sub-block using data from the data block having a higher priority for display as compared to other data of the data block. The first device can store the first data sub-block in the second cache layer, and provide the first data sub-block for display on a display device from the second cache layer.
H04L 29/06 - Commande de la communication; Traitement de la communication caractérisés par un protocole
G06F 12/0868 - Transfert de données entre une mémoire cache et d'autres sous-systèmes, p. ex. des dispositifs de stockage ou des systèmes hôtes
G06F 21/57 - Certification ou préservation de plates-formes informatiques fiables, p. ex. démarrages ou arrêts sécurisés, suivis de version, contrôles de logiciel système, mises à jour sécurisées ou évaluation de vulnérabilité
G06F 7/24 - Tri, c.-à-d. extraction de données d'un ou de plusieurs supports, nouveau rangement des données dans un ordre de succession numérique ou autre, et réinscription des données triées sur le support original ou sur un support différent ou sur une série de supports
G06F 12/0811 - Systèmes de mémoire cache multi-utilisateurs, multiprocesseurs ou multitraitement avec hiérarchies de mémoires cache multi-niveaux
G06F 12/0813 - Systèmes de mémoire cache multi-utilisateurs, multiprocesseurs ou multitraitement avec configuration en réseau ou matrice
30.
Methods and systems for ranking, filtering and patching detected vulnerabilities in a networked system
Systems and methods for determining priority levels to process vulnerabilities associated with a networked computer system can include a data collection engine receiving a plurality of specification profiles, each defining one or more specification variables of the networked computer system or a respective asset. The data collection engine can receive, from a vulnerability scanner, vulnerability data indicative of a vulnerability associated with the networked computer system. A profiling engine can interrogate a computing device of the networked computer system, and receive one or more respective profiling parameters from that computing device. A ranking engine can compute a priority ranking value of the computing device based on the profile specification variables, the vulnerability data and the profiling parameters. The priority ranking value associated with the computing device can be indicative of a priority level, compared to other computing devices of the computer network, for patching a vulnerability affecting that computing device.
H04L 29/06 - Commande de la communication; Traitement de la communication caractérisés par un protocole
G06F 7/24 - Tri, c.-à-d. extraction de données d'un ou de plusieurs supports, nouveau rangement des données dans un ordre de succession numérique ou autre, et réinscription des données triées sur le support original ou sur un support différent ou sur une série de supports
31.
Systems and methods for computer environment situational awareness
Systems and methods for monitoring states of operation of a computer environment can include one or more computer servers identifying a target asset of the computer environment and establishing a communication link with a computing device associated with the target asset. The one or more computer servers can determine a first set of parameters for profiling the target asset, transmit a first query for the first set of parameters to the computing device via the communication link, and receive one or more first parameter values corresponding to the first set of parameters responsive to the query. The one or more computer servers can compare the one or more first parameter values to one or more first criteria or threshold values, an determine a state of operation of the target asset based on the comparison. The state of operation can be indicative of an abnormal behavior associated with the target asset.
G06F 21/55 - Détection d’intrusion locale ou mise en œuvre de contre-mesures
H04L 12/24 - Dispositions pour la maintenance ou la gestion
G06F 21/57 - Certification ou préservation de plates-formes informatiques fiables, p. ex. démarrages ou arrêts sécurisés, suivis de version, contrôles de logiciel système, mises à jour sécurisées ou évaluation de vulnérabilité
32.
Methods and systems for ranking, filtering and patching detected vulnerabilities in a networked system
Systems and methods for determining priority levels to process vulnerabilities associated with a networked computer system can include a data collection engine receiving a plurality of specification profiles, each defining one or more specification variables of the networked computer system or a respective asset. The data collection engine can receive, from a vulnerability scanner, vulnerability data indicative of a vulnerability associated with the networked computer system. A profiling engine can interrogate a computing device of the networked computer system, and receive one or more respective profiling parameters from that computing device. A ranking engine can compute a priority ranking value of the computing device based on the profile specification variables, the vulnerability data and the profiling parameters. The priority ranking value associated with the computing device can be indicative of a priority level, compared to other computing devices of the computer network, for patching a vulnerability affecting that computing device.
H04L 29/06 - Commande de la communication; Traitement de la communication caractérisés par un protocole
G06F 7/24 - Tri, c.-à-d. extraction de données d'un ou de plusieurs supports, nouveau rangement des données dans un ordre de succession numérique ou autre, et réinscription des données triées sur le support original ou sur un support différent ou sur une série de supports
33.
Methods and systems for ranking, filtering and patching detected vulnerabilities in a networked system
Systems and methods for determining priority levels to process vulnerabilities associated with a networked computer system can include a data collection engine receiving a plurality of specification profiles, each defining one or more specification variables of the networked computer system or a respective asset. The data collection engine can receive, from a vulnerability scanner, vulnerability data indicative of a vulnerability associated with the networked computer system. A profiling engine can interrogate a computing device of the networked computer system, and receive one or more respective profiling parameters from that computing device. A ranking engine can compute a priority ranking value of the computing device based on the profile specification variables, the vulnerability data and the profiling parameters. The priority ranking value associated with the computing device can be indicative of a priority level, compared to other computing devices of the computer network, for patching a vulnerability affecting that computing device.
H04L 29/06 - Commande de la communication; Traitement de la communication caractérisés par un protocole
G06F 7/24 - Tri, c.-à-d. extraction de données d'un ou de plusieurs supports, nouveau rangement des données dans un ordre de succession numérique ou autre, et réinscription des données triées sur le support original ou sur un support différent ou sur une série de supports
34.
Systems and methods for multi-tier cache visual system and visual modes
Systems and methods for displaying computer environment monitoring data can include a multi-tier cache memory associated with a processor of a first device. The multi-tier cache memory can include a first cache layer, and a second cache layer having a higher data access rate than the first cache layer. The first device can receive, from a second device, a data block including monitoring data selected based on user profile information associated with a user of the first device. The first device can store the data block in the first cache layer, and generate a first data sub-block using data from the data block having a higher priority for display as compared to other data of the data block. The first device can store the first data sub-block in the second cache layer, and provide the first data sub-block for display on a display device from the second cache layer.
H04L 29/06 - Commande de la communication; Traitement de la communication caractérisés par un protocole
G06F 7/24 - Tri, c.-à-d. extraction de données d'un ou de plusieurs supports, nouveau rangement des données dans un ordre de succession numérique ou autre, et réinscription des données triées sur le support original ou sur un support différent ou sur une série de supports
G06F 12/0811 - Systèmes de mémoire cache multi-utilisateurs, multiprocesseurs ou multitraitement avec hiérarchies de mémoires cache multi-niveaux
G06F 12/0813 - Systèmes de mémoire cache multi-utilisateurs, multiprocesseurs ou multitraitement avec configuration en réseau ou matrice
G06F 21/57 - Certification ou préservation de plates-formes informatiques fiables, p. ex. démarrages ou arrêts sécurisés, suivis de version, contrôles de logiciel système, mises à jour sécurisées ou évaluation de vulnérabilité
G06F 12/0868 - Transfert de données entre une mémoire cache et d'autres sous-systèmes, p. ex. des dispositifs de stockage ou des systèmes hôtes
35.
Systems and methods for computer environment situational awareness
Systems and methods for monitoring states of operation of a computer environment can include one or more computer servers identifying a target asset of the computer environment and establishing a communication link with a computing device associated with the target asset. The one or more computer servers can determine a first set of parameters for profiling the target asset, transmit a first query for the first set of parameters to the computing device via the communication link, and receive one or more first parameter values corresponding to the first set of parameters responsive to the query. The one or more computer servers can compare the one or more first parameter values to one or more first criteria or threshold values, an determine a state of operation of the target asset based on the comparison. The state of operation can be indicative of an abnormal behavior associated with the target asset.
Systems and methods for determining priority levels to process vulnerabilities associated with a networked computer system can include a data collection engine receiving a plurality of specification profiles, each defining one or more specification variables of the networked computer system or a respective asset. The data collection engine can receive, from a vulnerability scanner, vulnerability data indicative of a vulnerability associated with the networked computer system. A profiling engine can interrogate a computing device of the networked computer system, and receive one or more respective profiling parameters from that computing device. A ranking engine can compute a priority ranking value of the computing device based on the profile specification variables, the vulnerability data and the profiling parameters. The priority ranking value associated with the computing device can be indicative of a priority level, compared to other computing devices of the computer network, for patching a vulnerability affecting that computing device.
Systems and methods for displaying computer environment monitoring data can include a multi-tier cache memory associated with a processor of a first device. The multi-tier cache memory can include a first cache layer, and a second cache layer having a higher data access rate than the first cache layer. The first device can receive, from a second device, a data block including monitoring data selected based on user profile information associated with a user of the first device. The first device can store the data block in the first cache layer, and generate a first data sub-block using data from the data block having a higher priority for display as compared to other data of the data block. The first device can store the first data sub-block in the second cache layer, and provide the first data sub-block for display on a display device from the second cache layer.
G06F 21/57 - Certification ou préservation de plates-formes informatiques fiables, p. ex. démarrages ou arrêts sécurisés, suivis de version, contrôles de logiciel système, mises à jour sécurisées ou évaluation de vulnérabilité
G06F 12/0811 - Systèmes de mémoire cache multi-utilisateurs, multiprocesseurs ou multitraitement avec hiérarchies de mémoires cache multi-niveaux
H04L 29/06 - Commande de la communication; Traitement de la communication caractérisés par un protocole
38.
SYSTEM AND METHOD FOR COMPUTER ENVIRONMENT SITUATIONAL AWARENESS
Systems and methods for monitoring states of operation of a computer environment can include one or more computer servers identifying a target asset of the computer environment and establishing a communication link with a computing device associated with the target asset. The one or more computer servers can determine a first set of parameters for profiling the target asset, transmit a first query for the first set of parameters to the computing device via the communication link, and receive one or more first parameter values corresponding to the first set of parameters responsive to the query. The one or more computer servers can compare the one or more first parameter values to one or more first criteria or threshold values, an determine a state of operation of the target asset based on the comparison. The state of operation can be indicative of an abnormal behavior associated with the target asset.