×

On-box active reconnaissance

  • US 7,934,257 B1
  • Filed: 01/07/2005
  • Issued: 04/26/2011
  • Est. Priority Date: 01/07/2005
  • Status: Active Grant
First Claim
Patent Images

1. A computer-implemented method of monitoring events in a network, comprising:

  • monitoring activities received over the network associated with a node located remotely over the network;

    collecting event information associated with the monitored activities and based on a set of collection rules, the collection rules specifying a set of patterns associated with a triggering event and a timeout window for collection of the event information, the event information being stored in a database;

    determining whether a portion of the collected event information stored in the database complies or potentially complies with one of the set of patterns and is considered a supporting event of the triggering event;

    selecting event information as supporting events from the collected event information stored in the database based on the determination, and if none of the collected event information is found to be a supporting event, establishing a temporary rule to forward any future supporting events that comply with or potentially comply with one of the set of patterns; and

    sending the selected event information and future supporting events to a manager associated with the node and other nodes over the network;

    wherein the temporary rule is automatically removed when the timeout window has elapsed.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×