×

Service detection

  • US 7,698,730 B2
  • Filed: 03/16/2004
  • Issued: 04/13/2010
  • Est. Priority Date: 03/16/2004
  • Status: Active Grant
First Claim
Patent Images

1. A method for detection of a new service involving a host in a network, the method comprises:

  • retrieving a baseline list of port and/or service protocols used by a host being tracked, the baseline list listing service and/or port protocols used by that host over a baseline period that is of a longer duration than a current period;

    retrieving a current list of service and/or port protocols for the current period used by the host being tracked;

    determining whether there is a difference in the protocols, by finding a protocol that was in the current list but was not in the baseline list; and

    if there is a difference;

    determining whether the host is providing or using the new service;

    determining if the host is sending traffic using a protocol not in the current list;

    identifying an alert rule corresponding to whether the host is providing or using the new service; and

    issuing an alert based at least on the identified alert rule and whether the host is providing or using the new service.

View all claims
  • 21 Assignments
Timeline View
Assignment View
    ×
    ×