United States Patent
US Patent 7356585: Vertically extensible intrusion detection system…
US 7356585 · granted 2008-04-08

Abstract
A method for vertically extensible intrusion detection for an enterprise comprises receiving a first packet flow from a first node, the first packet flow comprising at least a portion of packet headers received at the first node during a first timeframe and receiving a second packet flow, the second packet flow comprising at least a portion of packet headers received at the second node during a second timeframe. The first and second packet flow are processed to detect an attack on the enterprise system. In response to the attack, an alert message is communicated to a master server, a response message is received from the master server, the response message comprising a signature to impede the attack, and the response message is automatically communicated to the first node and the second node.
| Patent Number | 7356585 |
|---|---|
| Title | Vertically extensible intrusion detection system and method |
| Filed | 2003-04-04 |
| Granted | 2008-04-08 |
| Inventor(s) | Michael C., Rixon; Matthew C., Brooks; Randall S., Rockwood; Troy Dean |
| Assignee | Raytheon Company |
| CPC Classification | G06F 15/16, G06F 15/173 |
| Number of Claims | 203 |
Abstract
A method for vertically extensible intrusion detection for an enterprise comprises receiving a first packet flow from a first node, the first packet flow comprising at least a portion of packet headers received at the first node during a first timeframe and receiving a second packet flow, the second packet flow comprising at least a portion of packet headers received at the second node during a second timeframe. The first and second packet flow are processed to detect an attack on the enterprise system. In response to the attack, an alert message is communicated to a master server, a response message is received from the master server, the response message comprising a signature to impede the attack, and the response message is automatically communicated to the first node and the second node.
Claim 1
Software encoded in one or more computer-readable storage media and when executed operable to: receive a first packet flow from a first node, the first packet flowcomprising at least a portion of packet headers received at the first node during a first timeframe; receive a second packet flow from a second node, the second packet flow comprising at least a portion of packet headers received at the second nodeduring a second timeframe; process the first and second packet flows to detect an attack; associate the first packet flow with the second packet flow to create a third packet flow, the third packet flow comprising the first and second packet flows; associate an alert message with the third packet flow; in response to the attack: communicate the alert message to a master server, wherein the operability of the software to communicate the alert message to the master server comprises the softwarebeing operable to communicate the third packet flow and the associated alert message to the master server; receive a response message from the master server; automatically communicate the response message to the first node; automatically communicatethe response message to the second node; wh
Claims
203 totalSoftware encoded in one or more computer-readable storage media and when executed operable to: receive a first packet flow from a first node, the first packet flowcomprising at least a portion of packet headers received at the first node during a first timeframe; receive a second packet flow from a second node, the second packet flow comprising at least a portion of packet headers received at the second nodeduring a second timeframe; process the first and second packet flows to detect an attack; associate the first packet flow with the second packet flow to create a third packet flow, the third packet flow comprising the first and second packet flows; associate an alert message with the third packet flow; in response to the attack: communicate the alert message to a master server, wherein the operability of the software to communicate the alert message to the master server comprises the softwarebeing operable to communicate the third packet flow and the associated alert message to the master server; receive a response message from the master server; automatically communicate the response message to the first node; automatically communicatethe response message to the second node; wh