Nova Patents
EP1558937B1

Active network defense system and method

Abstract

This record has no abstract on file.

EP1558937B1, drawing sheet 1
Sheet 1 of 2

Term

Term ended

Expired 7 November 2023, 2.9 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

6 claims: 3 independent, 3 dependent

  1. 1
    A network defense system, comprising:a state manager functionality (20) connected in-line with respect to a data flow (14) of packets, the state manager functionality being operable to track a plurality of sessions currently in existence on the data flow and to save historical packet related data;an algorithmic filter (28) operable to perform a statistical analysis on the tracked sessions and historical packet related data to determine whether packets in the data flow across multiple session present a threat to a protected network by determining whether packets in the data flow across multiple sessions are suspicious;a packet handler (70) also connected in-line with respect to the data flow (14) of packets and operable, in response to the presence of a threat, to block threatening packets;and a trigger filter (50) also connected in-line with respect to the data flow of packets and operable in response to the algorithmic filter's suspicion determination, to filter the suspicious packets in the data flow against criteria designed for detecting threatening packets across multiple sessions, the trigger filter (50) being further operable to filter packets in the data flow against criteria designed for detecting threatening packets in individual sessions, the trigger filter (50) being still further operable to determine whether packets in the data flow in individual sessions are suspicious;characterised in that the packet handler (70) is further operable to extract the suspicious packets from the data flow for further examination;and in that the system further comprises a threat verifier (100) adapted to receive the extracted packets from the packet handler (70) and to implement a filtering operation thereon with criteria that are more comprehensive than the criteria used by the in-line trigger filter (50) for the purpose of resolving whether the suspicious extracted packets are threatening.
  2. 5
    A system according to any foregoing claim, further including a flow controller (80) also connected in-line with respect to the data flow of packets and operable to regulate a rate of the passage of packets along the data flow and through the network defense system to the protected network.
  3. 6
    A system according to any foregoing claim, wherein the state manager functionality (20) is implemented in hardware;and the algorithmic filter (28) is implemented in software.