×

Automated change detection within a network environment

  • US 7,810,151 B1
  • Filed: 01/27/2005
  • Issued: 10/05/2010
  • Est. Priority Date: 01/27/2005
  • Status: Active Grant
First Claim
Patent Images

1. A method comprising:

  • processing, with an intrusion detection device, packet flows to identify low-level network elements associated with the packet flows, wherein the low-level network elements describe one or more network devices of a network;

    assembling application-layer communications from the packet flows with protocol-specific decoders;

    processing the application-layer communications with the protocol-specific decoders to identify application-layer elements;

    analyzing the application-layer communications to determine whether any of the packet flows represent a network attack and, for each of the packet flows, forwarding the packet flow only when the packet flow does not represent a network attack;

    generating profiling data that associates the application-layer elements of the application-layer communications with the low-level network elements of the packet flows;

    maintaining, within the intrusion detection device, a correlation database that stores the profiling data describing the packet flows within the network;

    defining a database trigger for the correlation database to detect database operations that have changed the profiling data stored within the correlation database, wherein the database trigger is defined to detect database operations that have utilized a specified combination of the low-level network elements and the application-layer elements, such that the database trigger fires when changes are made to the network devices of the network that are determined to expose the network to security risks; and

    maintaining, within the intrusion detection device, a log to record the detected database operations by updating the log when the database trigger fires to record in the log the database operation that fired the database trigger.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×