Patents by Inventor Luis Filipe Pereira Valente

Luis Filipe Pereira Valente has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 8584195
    Abstract: User names and user groups serve as the basis of a formal policy in a network. A passive monitor examines network traffic in near real time and indicates: which network traffic is flowing on the network as before; which users or user groups were logged into workstations initiating this network traffic; and which of this traffic conforms to the formal policy definition. In one embodiment of the invention, users and user groups are determined by querying Microsoft® Active Directory and Microsoft® Windows servers, to determine who is logged onto the Microsoft® network. Other sources of identity information are also possible.
    Type: Grant
    Filed: September 12, 2007
    Date of Patent: November 12, 2013
    Assignee: McAfee, Inc
    Inventors: Kieran Gerard Sherlock, Geoffrey Howard Cooper, John Richard Guzik, Derek Patton Pearcy, Luis Filipe Pereira Valente
  • Publication number: 20100067390
    Abstract: A system and method of discovering network entities. Network traffic is monitored, wherein monitoring includes finding network entities in the network traffic. If the network entities are network assets, the system determines if the network entities are critical network assets. If the network entities are network users, the system classifies the network users automatically into user groups. The network traffic is then displayed as a function of the critical network assets and the user groups.
    Type: Application
    Filed: May 21, 2009
    Publication date: March 18, 2010
    Inventors: Luis Filipe Pereira Valente, Derek Patton Pearcy, Geoffrey Howard Cooper, Kieran Gerard Sherlock
  • Patent number: 7478422
    Abstract: The invention is a declarative language system and comprises a language as a tool for expressing network security policy in a formalized way. It allows the specification of security policy across a wide variety of networking layers and protocols. Using the language, a security administrator assigns a disposition to each and every network event that can occur in a data communications network. The event's disposition determines whether the event is allowed (i.e. conforms to the specified policy) or disallowed and what action, if any, should be taken by a system monitor in response to that event. Possible actions include, for example, logging the information into a database, notifying a human operator, and disrupting the offending network traffic.
    Type: Grant
    Filed: June 15, 2004
    Date of Patent: January 13, 2009
    Assignee: Securify, Inc.
    Inventors: Luis Filipe Pereira Valente, Geoffrey Howard Cooper, Robert Allen Shaw, Kieran Gerard Sherlock
  • Patent number: 7451488
    Abstract: A system and method for a vulnerability assessment mechanism that serves to actively scan for vulnerabilities on a continuous basis and interpret the resulting traffic in context of policy is provided. Vulnerability information is presented within an enterprise manager system enabling the user to access vulnerability information, recommended remediation procedures, and associated network traffic. A studio mechanism is used to add scanners to the appropriate policies and control the scope and distribution of scans within the target network.
    Type: Grant
    Filed: April 29, 2004
    Date of Patent: November 11, 2008
    Assignee: Securify, Inc.
    Inventors: Geoffrey Cooper, Luis Filipe Pereira Valente, Derek P. Pearcy, Harry Alexander Richardson
  • Publication number: 20080109870
    Abstract: User names and user groups serve as the basis of a formal policy in a network. A passive monitor examines network traffic in near real time and indicates: which network traffic is flowing on the network as before; which users or user groups were logged into workstations initiating this network traffic; and which of this traffic conforms to the formal policy definition. In one embodiment of the invention, users and user groups are determined by querying Microsoft® Active Directory and Microsoft® Windows servers, to determine who is logged onto the Microsoft® network. Other sources of identity information are also possible.
    Type: Application
    Filed: September 12, 2007
    Publication date: May 8, 2008
    Inventors: Kieran Gerard Sherlock, Geoffrey Howard Cooper, John Richard Guzik, Derek Patton Pearcy, Luis Filipe Pereira Valente
  • Patent number: 7272646
    Abstract: A method and apparatus for a network monitor internals mechanism that serves to translate packet data into multiple concurrent streams of network event data is provided. The data translation is accomplished by interpreting both sides of each protocol transaction.
    Type: Grant
    Filed: June 14, 2001
    Date of Patent: September 18, 2007
    Assignee: Securify, Inc.
    Inventors: Geoffrey Cooper, Robert Allen Shaw, Luis Filipe Pereira Valente, Kieran Gerard Sherlock
  • Publication number: 20040250112
    Abstract: The invention is a declarative language system and comprises a language as a tool for expressing network security policy in a formalized way. It allows the specification of security policy across a wide variety of networking layers and protocols. Using the language, a security administrator assigns a disposition to each and every network event that can occur in a data communications network. The event's disposition determines whether the event is allowed (i.e. conforms to the specified policy) or disallowed and what action, if any, should be taken by a system monitor in response to that event. Possible actions include, for example, logging the information into a database, notifying a human operator, and disrupting the offending network traffic.
    Type: Application
    Filed: June 15, 2004
    Publication date: December 9, 2004
    Inventors: Luis Filipe Pereira Valente, Geoffrey Howard Cooper, Robert Allen Shaw, Kieran Gerard Sherlock
  • Patent number: 6779120
    Abstract: The invention is a declarative language system and comprises a language as a tool for expressing network security policy in a formalized way. It allows the specification of security policy across a wide variety of networking layers and protocols. Using the language, a security administrator assigns a disposition to each and every network event that can occur in a data communications network. The event's disposition determines whether the event is allowed (i.e. conforms to the specified policy) or disallowed and what action, if any, should be taken by a system monitor in response to that event. Possible actions include, for example, logging the information into a database, notifying a human operator, and disrupting the offending network traffic.
    Type: Grant
    Filed: January 7, 2000
    Date of Patent: August 17, 2004
    Assignee: Securify, Inc.
    Inventors: Luis Filipe Pereira Valente, Geoffrey Howard Cooper, Robert Allen Shaw, Kieran Gerard Sherlock
  • Publication number: 20040103315
    Abstract: A method and apparatus for allowing a technique for continuously assessing the security of a network to be applicable to network assessment, by capturing and classifying large volumes of network traffic based on a formal policy, and applying such to both long-term and short-term network assessment.
    Type: Application
    Filed: July 18, 2003
    Publication date: May 27, 2004
    Inventors: Geoffrey Cooper, Robert Allen Shaw, Luis Filipe Pereira Valente, Kieran Gerard Sherlock
  • Publication number: 20040039942
    Abstract: A method and apparatus for generating an initial policy specification file is provided. A level of abstraction over a policy language is used, simplifying creating the file based on gross character characteristics of a network at the IP level, such as policy domains, communities of hosts, subnets, and firewalls.
    Type: Application
    Filed: June 5, 2003
    Publication date: February 26, 2004
    Inventors: Geoffrey Cooper, Robert Allen Shaw, Luis Filipe Pereira Valente, Kieran Gerard Sherlock
  • Publication number: 20040030796
    Abstract: A method and apparatus for a network monitor internals mechanism that serves to translate packet data into multiple concurrent streams of network event data is provided. The data translation is accomplished by interpreting both sides of each protocol transaction.
    Type: Application
    Filed: June 10, 2003
    Publication date: February 12, 2004
    Inventors: Geoffrey Cooper, Robert Allen Shaw, Luis Filipe Pereira Valente, Kieran Gerard Sherlock