×

Synchronizing network security devices within a network security system

  • US 7,565,696 B1
  • Filed: 12/10/2003
  • Issued: 07/21/2009
  • Est. Priority Date: 12/10/2003
  • Status: Active Grant
First Claim
Patent Images

1. A network security system comprising:

  • a first distributed software agent comprising a processor configured to collect a first stream of alerts from a first network security device having a first clock, each alert in the first stream representing an event detected by the first network security device and including a time of detection by the first network security device according to the first clock;

    a second distributed software agent comprising a processor configured to collect a second stream of alerts from a second network security device having a second clock, each alert in the second stream representing an event detected by the second network security device and including a time of detection by the second network security device according to the second clock; and

    a manager module in communication with the distributed software agents, the manager module comprising a processor configured to;

    receive the first and second stream of alerts;

    identify a first alert in the first stream and a second alert in the second stream,wherein the first alert includes an Internet Protocol (IP) address, andwherein the second alert includes the IP address;

    determine, based on the first alert and the second alert, whether the first clockand the second clock are synchronized; and

    when the first clock and the second clock are not synchronized;

    synchronize the first clock and the second clock;

    modify at least one of a timestamp within the first alert and a timestamp within the second alert; and

    after having modified at least one of the timestamp within the first alert and the timestamp within the second alert, determine whether the first alert and the second alert satisfy a condition of a rule, wherein the rule determines whether a security incident has occurred.

View all claims
  • 11 Assignments
Timeline View
Assignment View
    ×
    ×