Nova Patents
EP1558937A2

Active network defense system and method

Abstract

This record has no abstract on file.

Term

Term ended

Projected expiry passed 7 November 2023, 2.9 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

74 claims: 8 independent, 66 dependent

  1. 1
    Claims of equivalent WO 2004045126 A2 WHAT IS CLAIMED IS:1. A network defense system, comprising: a state manager functionality connected in-line with respect to a data flow of packets, the state manager functionality operable to track sessions currently in existence on the data flow and save historical packet related data;and an algorithmic filter operable to perform a statistical analysis on the tracked sessions and historical packet related data to determine whether packets in the data flow across multiple sessions present a threat to a protected network.
  2. 14
    A method for defending a network, comprising the steps of:tracking sessions currently in existence on a data flow of packets;collecting historical packet related data with respect to those sessions;and algorithmically filtering the tracked sessions and collected historical packet related data to determine based on statistical analysis whether packets in the data flow across multiple sessions present a threat to the network.
  3. 26
    A system for defending a network, comprising:a state manager functionality connected in-line with respect to a data flow of packets, the state manager functionality operable to track information concerning multiple sessions currently in existence on the data flow;an algorithmic filter operable to perform a statistical analysis on the information to deteπnine whether packets in the data flow across multiple sessions present a threat to the network;a trigger filter also connected in-line with respect to the data flow of packets and operable to filter packets in the data flow against criteria designed for detecting threatening packets in individual sessions;and a packet handler also connected in-line with respect to the data flow of packets and operable responsive to algorithmic and trigger filter detected threats to block the threatening packets.
  4. 40
    A packet filtering system, comprising:a normahzer connected in-line with respect to a data flow of packets, the normalizer operable to examine each passing packet in the data flow and enforce on those packets conformance to certain predefined standards;and a packet handler also connected in-line with respect to the data flow of packets and operable responsive to the presence of nonconforming packets with a blocking of those packets from entry to a protected network.
  5. 50
    A method for packet filtering, comprising the steps of:normalizing packets within a data flow of packets by examining each passing packet in the data flow and enforcing on those packets conformance to certain predefined standards;and handling the passing packets in response to the presence of nonconforming packets by blocking of those packets from entering a protected network.
  6. 60
    A packet filtering system, comprising:a set of filtering criteria, the criteria including an identification of network assets that are threatened by certain suspicious traffic;a filter operable to examine suspicious packets in comparison to the set of filtering criteria, the filter identifying certain ones of the suspicious packets for further investigation;and a risk assessor operable to examine the certain ones of the suspicious packets in comparison to the identification of threatened network assets, the risk assessor issuing an alert notification in the event a protected network includes at least one of the identified network assets that are threatened by the certain ones of the suspicious packets.
  7. 64
    A packet filtering method, comprising:defining a set of filtering criteria, the criteria including an identification of network assets that are threatened by certain suspicious traffic;examining suspicious packets in comparison to the set of filtering criteria, the examination identifying certain ones of the suspicious packets for further investigation;assessing risk associated with the certain ones of the suspicious packets with respect to the identification of threatened network assets;and issuing an alert notification in the event a protected network includes at least one of the identified network assets that are threatened by the certain ones of the suspicious packets.
  8. 69
    A method for network protection, comprising the steps of:performing a deep packet inspection of each packet in a data flow at line speed to identify good packets, bad packets and suspicious packets;allowing the good packets to pass on to a protected network;blocking the bad packets from entry into the protected network;and extracting the suspicious packets from the data flow for further investigation.