Active intrusion resistant environment of layered object and compartment keys (airelock)
First Claim
1. A security device for installation at a node of a digital network, said security device comprising:
- a security engine for providing user transparent communications to another node of said digital network;
at least two locking devices, wherein each locking device is coupled to the other locking devices and the security engine, and each locking device is configured to communicate with the other locking devices and with the security engine; and
a programmed data processor including a memory to store data corresponding to said user communications and to store an embedded security policy manager and a manager object and at least one managed object, wherein the managed object is configured to detect communications at a first node having a characteristic which differs from a normal usage characteristic and to send an alarm through the manager object to said security engine for communication to a managed object of a second node, the managed object corresponding to said first node, as said user transparent communications and for responding to user transparent communications from said second node of said digital network and controlling of routing of communications in said digital network wherein said first node and said second node are hierarchically arranged locally in said digital network and arranged to provide redundant connections between nodes at different hierarchical levels.
1 Assignment
0 Petitions
Accused Products
Abstract
A high level of security and fault tolerance is provided in a digital network by use of highly secure infrastructure of user transparent signalling for communicating detection of signals at a network node having characteristics of a potential attack to another node and controlling communications at routers at the node from another node in response to the user transparent signals. A processor is connected to the routers and the network through an encryption engine and includes a manager object to issue control commands to nodes of a locally lower hierarchy tier and managed objects to detect potential attacks and exercise control over the routers responsive to signals from a node of a locally higher hierarchy tier. Identifications are provided for communications between nodes regardless of whether or not a corresponding user is identified and communications are logged. Thus any network session comprises one or more secure sessions in a plurality of security domains and any fault or potential attack can be compartmentalized to a node or sector of the network and isolated while normal communications are continued over redundant network links.
-
Citations
15 Claims
-
1. A security device for installation at a node of a digital network, said security device comprising:
-
a security engine for providing user transparent communications to another node of said digital network; at least two locking devices, wherein each locking device is coupled to the other locking devices and the security engine, and each locking device is configured to communicate with the other locking devices and with the security engine; and a programmed data processor including a memory to store data corresponding to said user communications and to store an embedded security policy manager and a manager object and at least one managed object, wherein the managed object is configured to detect communications at a first node having a characteristic which differs from a normal usage characteristic and to send an alarm through the manager object to said security engine for communication to a managed object of a second node, the managed object corresponding to said first node, as said user transparent communications and for responding to user transparent communications from said second node of said digital network and controlling of routing of communications in said digital network wherein said first node and said second node are hierarchically arranged locally in said digital network and arranged to provide redundant connections between nodes at different hierarchical levels.
-
-
2. A digital network for active intrusion resistance, said digital network comprising:
-
a plurality of nodes arranged in a tiered hierarchy, each node including at least two locking devices; a security policy manager device for detecting network communications or activity having a characteristic different from a normal usage characteristic and providing a signal to other network nodes; and a communication module responsive to a user transparent signal from another node for controlling said at least two locking devices to isolate a node by selecting from among redundant communication paths in said digital network to maintain network communications between nodes that are not to be isolated and restricting communications with a node to be isolated, whereby the digital network actively resists intrusion by isolating one or more nodes that are determined to have become untrusted. - View Dependent Claims (3, 4, 5, 6, 7, 8, 9, 10)
-
-
11. A method of actively resisting intrusion in a digital network using extensions to an object request broker, said method comprising:
-
providing object request broker software; extending the object request broker software to include encryption, intrusion detection, and security policy management and enforcement; generating a manager object on one or more nodes and at least one managed object on each node; detecting, with a managed object, a communication having a characteristic differing from a normal usage characteristic at a first node of said digital network, said communication received from a second node of said digital network; communicating a user transparent signal from a managed object of the first node to a managed object of a third digital network node responsive to said detection; and controlling communications, through coordinated managed and manager objects, at said first node and said third node to restrict communications from said second node with a user transparent signal. - View Dependent Claims (12, 13, 14, 15)
-
Specification