×

Distributed intrusion response system

  • US 7,581,249 B2
  • Filed: 11/14/2003
  • Issued: 08/25/2009
  • Est. Priority Date: 11/14/2003
  • Status: Active Grant
First Claim
Patent Images

1. A method of responding to the detection of an intrusion on a network system that provides network services, the network system including one or more attached functions and a plurality of interconnection devices, the method comprising the steps of:

  • a. providing means for one or more attached functions to connect to one or more of a plurality of interconnection devices of the network system;

    b. acquiring information about the attached functions seeking access to the network services;

    c. determining whether one or more stored policies exist for the attached functions;

    d. allowing at least one of the one or more attached functions to access a selectable portion of the network services based on a policy established in one or more of the interconnection devices;

    e. monitoring the network system for intrusions;

    f. excluding from at least one of the plurality of interconnection devices a policy enforcement module for effecting its own signal transfer policy changes;

    g. including in at least one of the plurality of interconnection devices the capability for such interconnection device to change directly its own signal transfer policies;

    h. upon detection of one or more intrusions of the network,i. determining a physical address or a logical address for each attached function associated with the source of the intrusion; and

    ii. identifying one or more interconnection devices having a policy enforcement module and used by the identified attached function or functions to gain access to the network services;

    i. selectively changing one or more signal transfer policies of one or more of the plurality of interconnection devices in response to the one or more detected intrusions; and

    j. saving changed policies for the one or more attached functions.

View all claims
  • 13 Assignments
Timeline View
Assignment View
    ×
    ×