Patents by Inventor Bradley Kenneth McFarlane

Bradley Kenneth McFarlane has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 8438643
    Abstract: Information system service-level security risk analysis systems, methods, and Graphical User Interfaces are disclosed. Assets of an information system that have relationships with a service provided by the information system are identified, and at least one security risk to the service is determined by analyzing security vulnerabilities associated with the identified assets. A consolidated representation of the service is provided, and includes an indication of the determined security risk(s) and an indication of a relationship between the service and at least one of the identified assets. The security risk indication may include indications of multiple security parameters. Security risks may be represented differently depending on whether they arise from a security vulnerability of an asset that has a relationship with the service or a security vulnerability of an asset that has a relationship with the service only through a relationship with an asset that has a relationship with the service.
    Type: Grant
    Filed: March 2, 2006
    Date of Patent: May 7, 2013
    Assignee: Alcatel Lucent
    Inventors: Douglas Wiemer, Christophe Gustave, Stanley TaiHai Chow, Bradley Kenneth McFarlane
  • Patent number: 8095984
    Abstract: Systems and methods of associating security vulnerabilities and assets, and related Graphical User Interfaces (GUIs) and data structures, are disclosed. A definition of a security vulnerability, which includes multiple asset characteristics such as an asset platform that may be exploited via the security vulnerability and an asset platform that is affected when the exploited asset platform is exploited via the security vulnerability, is compared with definitions of one or more assets of an information system. An association between the security vulnerability and an asset is made if the definition of the asset includes a first asset characteristic of the security vulnerability definition and either the definition of the asset or the definition of another asset that has a relationship with the asset includes a second asset characteristic of the security vulnerability definition. The security vulnerability definition may also identify an asset platform that protects against the vulnerability.
    Type: Grant
    Filed: March 2, 2006
    Date of Patent: January 10, 2012
    Assignee: Alcatel Lucent
    Inventors: Bradley Kenneth McFarlane, Douglas Wiemer, Kevin McNamee
  • Patent number: 8020207
    Abstract: A malware detection and response system based on traffic pattern anomalies detection is provided, whereby packets associated with a variety of protocols on each port of a network element are counted distinctly for each direction. Such packets include: ARP requests, TCP/SYN requests and acknowledgements, TCP/RST packets, DNS/NETBEUI name lookups, out-going ICMP packets, UDP packets, etc. When a packet causes an individual count or combination of counts to exceed a threshold, appropriate action is taken. The system can be incorporated into the fast path, that is, the data plane, enabling communications systems such as switches, routers, and DSLAMs to have built-in security at a very low cost.
    Type: Grant
    Filed: January 23, 2007
    Date of Patent: September 13, 2011
    Assignee: ALCATEL LUCENT
    Inventors: Stanley TaiHai Chow, Jean-Marc Robert, Kevin McNamee, Douglas Wiemer, Bradley Kenneth McFarlane
  • Publication number: 20110197278
    Abstract: A malware detection and response system based on traffic pattern anomalies detection is provided, whereby packets associated with a variety of protocols on each port of a network element are counted distinctly for each direction. Such packets include: ARP requests, TCP/SYN requests and acknowledgements, TCP/RST packets, DNS/NETBEUI name lookups, out-going ICMP packets, UDP packets, etc. When a packet causes an individual count or combination of counts to exceed a threshold, appropriate action is taken. The system can be incorporated into the fast path, that is, the data plane, enabling communications systems such as switches, routers, and DSLAMs to have built-in security at a very low cost.
    Type: Application
    Filed: January 23, 2007
    Publication date: August 11, 2011
    Applicant: ALCATEL LUCENT
    Inventors: Stanley TaiHai Chow, Jean-Marc Robert, Kevin McNamee, Douglas Wiemer, Bradley Kenneth McFarlane
  • Publication number: 20040024859
    Abstract: Methods and apparatus for network resource utilization assessment are presented. The apparatus includes an information warehousing layer for storing a coherent network model including network node generated reporting information and derived reporting information. The coherent network model is generated by a network modeler and the derived information is generated by a network engineering analyzer. The apparatus further includes a presentation layer enabling support for extensive network resource utilization assessments. An equipment trend analyzer module provides equipment utilization tracking in communications network over time. Advantages are derived from a network resource utilization assessment enabling model based network engineering analysis to attain improved network resources utilization efficiencies.
    Type: Application
    Filed: August 5, 2002
    Publication date: February 5, 2004
    Inventors: Gerald Bloch, Bradley Kenneth McFarlane, Daniel Constantin Pietraru