×

System and method for a distributed application of a network security system (SDI-SCAM)

  • US 8,925,095 B2
  • Filed: 12/03/2012
  • Issued: 12/30/2014
  • Est. Priority Date: 12/24/2002
  • Status: Expired due to Fees
First Claim
Patent Images

1. A system that detects the state of a computer network, comprising:

  • a plurality of processing devices, each of said processing devices having a distributed agent adapted to;

    passively collect, monitor, and aggregate data representative of states of respective nodes within said computer network,analyze collected data to develop models representative of states of said computer network in a normal state and said computer network in an abnormal state as a result of intrusions, infections, scams, code emulating code or humans, and/or other suspicious activities in said computer network,compare collected data to said state models to determine whether said computer network is in said normal state or said abnormal state at different times and to dynamically update said state models based on said collected data,perform a pattern analysis on the collected data to identify patterns in the collected data representative of suspicious activities and/or normal activities, andcompare the results of the pattern analysis of data collected by an agent to the results of pattern analysis of data collected by other agents to identify similar patterns of suspicious activity and/or normal activity in different portions of the computer network.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×