×

Systems and methods for correlating and distributing intrusion alert information among collaborating computer systems

  • US 7,779,463 B2
  • Filed: 06/09/2004
  • Issued: 08/17/2010
  • Est. Priority Date: 05/11/2004
  • Status: Active Grant
First Claim
Patent Images

1. A method of detecting a threat to a computer system in a plurality of collaborating computer systems, the method comprising:

  • grouping a first computer system, a collaborating second computer system and other collaborating systems into groups so that each collaborating system in a group occupies a position in that group;

    receiving, at the first computer system, a first one-way data structure from the collaborating second computer system, the first one-way data structure representing first data relating to a first intrusion attempt detected by an intrusion detection system of the collaborating second computer system such that the first data is hidden in the first one-way data structure, the receiving comprising periodically exchanging one-way data structures between the first computer system and the collaborating second computer system when in the same position in the different groups;

    detecting, using an intrusion detection system of the first computer system, a second intrusion attempt;

    storing second data relating to the second intrusion attempt in a second one-way data structure of the first computer system such that the second data is hidden in the second one-way data structure;

    determining whether the second intrusion attempt correlates with the first intrusion attempt by comparing the first data structure and the second data structure;

    indicating that a threat is present if the second intrusion attempt is determined to correlate with the data received from the collaborating second computer system relating to the first intrusion attempt;

    rotating the position occupied by each member of at least one of the groups according to a schedule; and

    changing the schedule,wherein the first one-way data structure is a bloom filter.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×