Method, system and computer software product for responding to a computer intrusion
Abstract
A method and system for managing an intrusion on a computer by graphically representing an intrusion pattern of a known past intrusion, and then comparing the intrusion pattern of the known intrusion with a current intrusion. The intrusion pattern may either be based on intrusion events, which are the effects of the intrusion or activities that provide a signature of the type of intrusion, or the intrusion pattern may be based on hardware topology that is affected by the intrusion. The intrusion pattern is graphically displayed with scripted responses, which in a preferred embodiment are presented in pop-up windows associated with each node in the intrusion pattern. Alternatively, the response to the intrusion may be automatic, based on a pre-determined percentage of common features in the intrusion pattern of the known past intrusion and the current intrusion.

Term
Term ended
Expired 28 November 2023, 2.8 years ago.
- Priority
- Filed
- Granted
- Expired
- Today
10 claims: 3 independent, 7 dependent
- 1A method for managing an intrusion on a computer, the method comprising:graphically representing an intrusion pattern of a known intrusion, the graphical representation including a scripted response at a node in an intrusion path (200);matching a current intrusion of the computer to the graphical representation of the known intrusion according to at least one common feature in the intrusion path of the known intrusion and the current intrusion;and responsive to the matching of the known intrusion and the current intrusion, initiating the scripted response, which is capable of responding to the current intrusion.
- 6A system for managing an intrusion on a computer, the system comprising:means for graphically representing an intrusion pattern of a known intrusion, the graphical representation including a scripted response at a node in an intrusion path (200);means for matching a current intrusion of the computer to the intrusion pattern of the known intrusion according to at least one common feature in the intrusion path of the known intrusion and the current intrusion;and means for initiating a scripted response for the current intrusion according to the matching of the known intrusion and the current intrusion.
- 10A computer usable medium for managing an intrusion on a computer, the computer usable medium comprising:computer program code for graphically representing an intrusion pattern of a known intrusion, the graphical representation including a scripted response at a node in an intrusion path (200);computer program code for matching a current intrusion of the computer to the intrusion pattern of the known intrusion according to at least one common feature in the intrusion,path of the known intrusion and the current intrusion;and computer program code for initiating a scripted response for the current intrusion according to the matching of the known intrusion and the current intrusion.
Independent claims3
33 paragraphs in 3 sections, as filed
Field of the Invention
The present invention relates in general to the field of data processing, and, in particular, to an improved data processing system and method for responding to a malicious intrusion using a graphical representation of the intrusion's effect.
Background of the Invention
Most modern enterprise networks include means for access by remote users, typically via the Internet. This access is designed to afford authorized users interaction with the network for purposes such as e-commerce, sharing content, and other electronic activities. Because these networks are designed to be easily accessible to authorized users, they are also prone to access by unauthorized users, specifically those with malicious intent for accessing the network. This malice is presenting in the form of an "intrusion" by the user. An intrusion is defined as a malicious electronic access of the network or a computer in the network. Examples of intrusions include viruses, unauthorized data mining (sometimes called "hacking of files"), and distributed denial of service (DDOS) attacks, in which a computer system is overloaded by the intrusion such that real work can no longer be performed.
An intrusion event is defined as the result (effect) of an intrusion. Examples of an intrusion event are data files being corrupted or illegally copied, system/computer crashes and system/computer slow-downs.
Countering intrusions is typically the job of a security administrator, an information technology specialist who monitors, with the aid of risk management software, a computer system for intrusions. While there are many known methods for detecting an intrusion and the intrusion event, managing responses to the intrusion is extremely complicated. That is, while detection of an event is well known and may be automatic, management and response actions are typically taken manually. Because of the complex nature of an intrusion, it is difficult for the security administrator to evaluate what type of intrusion is occurring, and how to respond appropriately.
The document "Intrusion detection using autonomous agents" by Eugene H. Spafford and Diego Zamboni interpretes the term "intrusion detection", derives desirable characteristics of an intrusion detection system, provides a comparison between various existing distributed and centralized system implementations and suggests to integrate autonomous software agents for data collection and analysis. With regard to user interfaces, it mentions a graphical user interface (GUI) for interactive access and a command line based interface in scripts for maintenance automation.
Thus, there is a need for a method and system to assist the security administrator in responding to detected intrusions, preferably in an manner that is automatic or semi-automatic.
SUMMARY OF THE INVENTION
The present invention is directed to a method and system for managing an intrusion on a computer by graphically representing an intrusion pattern of a known past intrusion, and then comparing the intrusion pattern of a current intrusion with the past intrusion. If the known and current intrusions have some or all common results (intrusion events or commonly affected hardware), then a security administrator can execute scripted responses to heal damage caused by the current intrusion, or at least prevent the current intrusion from causing any further damage.
The intrusion pattern may either be based on intrusion events, which are the effects of the intrusion or activities that provide a signature of the type of intrusion, or the intrusion pattern may be based on hardware topology that is affected by the intrusion.
The intrusion pattern is graphically displayed to the security administrator, who can respond by executing scripted responses, which in a preferred embodiment are presented in pop-up windows associated with each node in the intrusion pattern. Alternatively, the response to the intrusion may be automatic, based on a pre-determined percentage of common features in the intrusion pattern of the known past intrusion and the current intrusion.
The above, as well as additional objectives, features, and advantages of the present invention will become apparent in the following detailed written description.
BRIEF DESCRIPTION OF THE DRAWINGS
Preferred embodiments of the present invention will now be described in detail by way of example only with reference to the following drawings: <ul id="ul0001" list-style="none"><li><b>Figure 1</b> depicts a block diagram of a data processing system in a preferred embodiment of the present invention;</li><li><b>Figure 2a</b> illustrates an intrusion pattern based on intrusion events of a many different intrusions, including a known past intrusion in a preferred embodiment of the present invention;</li><li><b>Figure 2b</b> depicts an intrusion pattern based on intrusion events of an unknown current intrusion that matches an intrusion pattern of a known past intrusion in a preferred embodiment of the present invention;</li><li><b>Figure 3</b> is a flow chart of a preferred embodiment of the present invention for automatically running scripted responses for an unknown current intrusion in a preferred embodiment of the present invention;</li><li><b>Figure 4a</b> illustrates an intrusion pattern based on affected hardware topology of a many different intrusions, including a known past intrusion in a preferred embodiment of the present invention; and</li><li><b>Figure 4b</b> depicts an intrusion pattern based on affected hardware topology of an unknown current intrusion that matches an intrusion pattern of a known past intrusion in a preferred embodiment of the present invention.</li></ul>
DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
With reference now to the figures, and in particular with reference to <b>Figure 1,</b> a data processing system <b>100,</b> capable of communication with a network (not shown), is depicted in accordance with a preferred embodiment of the present invention. Data processing system <b>100</b> may be, for example, one of the models of personal computers or servers available from International Business Machines Corporation of Armonk, New York. Data processing system <b>100</b> may include only a single processor or may be a multiprocessor (MP) system including a plurality of processors. A single processor system is shown in the example depicted. A second processor (not shown) may be added to the system depicted, either with a separate L2 cache or sharing L2 cache <b>108</b> with processor <b>102.</b> Processor <b>102</b> may be a superscalar reduced instruction set computing (RISC) processor including separate Level One (L1) instruction and data caches <b>104</b> and <b>106</b> within the processor.
Processor <b>102</b> is connected to Level Two (L2) cache <b>108.</b> L2 cache <b>108</b> is connected to system bus <b>110</b> for data processing system <b>100.</b> System memory <b>112</b> is also connected to system bus <b>112,</b> as is Input/Output (I/O) bus bridge <b>114.</b> I/O bus bridge <b>112</b> couples I/O bus <b>118</b> to system bus <b>110,</b> relaying and/or transforming data transactions from one bus to the other. Other devices may also be connected to system bus <b>110,</b> such as memory-mapped graphics adapter <b>116,</b> which provides user interface information to a display <b>124.</b>
I/O bus bridge <b>114</b> is connected to I/O bus <b>118,</b> which may be connected to a variety of other devices such as an input device <b>126,</b> which may be a conventional mouse, a trackball, a keyboard, or the like, and a non-volatile storage <b>122,</b> such as a hard drive, a compact disk read-only memory (CD-ROM) drive, a digital video disk (DVD) drive, or similar like storage devices.
Also connected to I/O bus <b>118</b> is a networks adapter <b>120,</b> which provides a logical interface with a network, which may be a local area network (LAN), wide area network (WAN), the Internet or other network that affords communication with other computers in the network with data processing system <b>100.</b>
The exemplary embodiment shown in <b>Figure 1</b> is provided solely for the purpose of explaining a preferred embodiment of the present invention, and those skilled in the art will recognize that numerous variations are possible, both in form and function. For instance, data processing system 100 may include a sound card and audio speakers, other I/O devices and communication ports, and numerous other components.
With reference now to <b>Figure 2a,</b> illustrated are possible intrusion events caused by many different intrusions. The intrusion events are defined as effects or activities initiated by the intrusion. While depicted in a tree manner, these intrusion events are best understood by realizing that the intrusion events illustrated are interrelated. For example, consider an intrusion path <b>200,</b> which depicts intrusion events (shown in heavy circles) caused by an Intrusion A. Intrusion A, which for exemplary purposes may be a virus such as "Code Red," is an intrusion that affects multiple hosts <b>202</b> in creating a distributed denial of service <b>204</b> in a host computer <b>206.</b> Intrusion A is shown as being detected by a Snort <b>208,</b> which is an exemplary intrusion detection system, capable of performing real-time traffic analysis and packet logging on IP networks. Snort <b>208</b> can perform protocol analysis, content searching/matching and can be used to detect a variety of attacks and probes, such as buffer overflows, stealth port scans, common gateway interface (CGI) attacks, server message block (SMB) probes, operating system (OS) fingerprinting attempts, and the like.
Intrusion A may also trigger a response from an intrusion detection system (IDS) <b>210,</b> which inspects all inbound and outbound network activity and identifies suspicious patterns that may indicate a network or system attack from someone attempting to break into or compromise the system. IDS <b>210</b> detected a network event <b>212,</b> which in the present example is Intrusion A, which is a type of intrusion event <b>214</b> identified by and affecting the entire system.
Note that Intrusion A also affects other parts of the computer system, as illustrated by intrusion path <b>200.</b> That is, Intrusion A also creates a host event <b>216,</b> which at system level <b>218</b> affects both a memory event <b>220</b> as well as a permission event <b>222.</b> Further, Intrusion A creates a perimeter event <b>224,</b> which is detected by firewall <b>226</b> as being both a scanning event <b>228</b> and also having a bad packet <b>230</b> of data. The bad packet <b>230</b> is a transmission control protocol (TCP) malformed protocol packet <b>232,</b> as depicted.
Thus, the pattern shown by intrusion path <b>200</b> having darkened heavy borders is a unique signature intrusion pattern for Intrusion A. Referring now to <b>Figure 2b,</b> there is depicted an intrusion path <b>201</b> based on intrusion events of an unknown current intrusion. The cause of the current intrusion is initially unknown. However, since the intrusion pattern is identical to that of Intrusion A of <b>Figure 2a,</b> the security administrator of the computer network or computer that has been intruded upon can recognize that the current intrusion is the same as, or at least acts in the same manner as, Intrusion A.
In a preferred embodiment of the present invention, associated with each node is a scripted response, such as scripted response <b>204a</b> associated with denial of service event <b>204.</b> The scripted response is a pre-scripted code for handling the intrusion event. For example, scripted response <b>204a</b> may be a program designed to isolate the intrusion that is overwhelming the computer system, and then disabling the intrusion. The scripted responses are depicted associated with each event describing node, and are preferably in an active window, such as a pop-up window, that initiates the scripted response simply by clicking on the active window with a mouse or similar pointing device. While scripted responses are depicted as single items, in an alternate preferred embodiment, a list of multiple suggested scripted responses are depicted and active in one or all of the nodes in the intrusion path <b>201.</b> The multiple scripted responses are preferably depicted with rankings, with one of the scripted responses having a highest ranking based on historical success using the scripted response, the criticality of the intrusion, or other factors determined by the security administrator when developing a risk manager program for evaluating intrusions. For example, a risk manager program may determine that any intrusion that attacks mission critical data must be ensured of isolation, even if the isolation takes down non-affected parts of the computer system. In such a case, the highest suggested response would be to take down many areas of the computer system, and would be recommended as the highest suggested response.
Note that intrusion paths need not be identical to provide the security administrator information on how to respond to the intrusion. That is, if the known and unknown intrusions have a certain number of commonalities in their intrusion paths, the security administrator may initiate a response that will cure most, if not all, of the detrimental effects of the current unknown intrusion.
In one embodiment of the present invention, each scripted response is manually selected by the security administrator for each node in the intrusion path <b>201.</b> Alternatively, a setting may be selected to automatically initiate a highest suggested response for all nodes in response to an intrusion, as described in the flow chart of <b>Figure 3.</b> As described in block <b>302,</b> a current intrusion is detected, preferably by a risk manager capable of detecting an intrusion according to characteristics of the intrusion. Such characteristics may include known packets of mischievous header information or other data received, actions taken by software or hardware in the computer system characteristic of an intrusion, such as scanning all computers in a network for Internet protocol (IP) address, sudden computer performance degradation or CPU usage, and like events or conditions. The intrusion events of the current intrusion are compared with those of a known intrusion, as described in block <b>304.</b> A determination is made, as illustrated at query block <b>306,</b> as to whether a pre-determined percentage of common event nodes are found in both the unknown current intrusion and the known historical intrusion. That is, the intrusion pathways of the known and current intrusions are compared. If the known past and unknown current intrusions have a significant number of common event nodes, then scripted responses for all nodes are automatically run, as described for block <b>310.</b> If there are not enough common event nodes between the known and unknown intrusions, then the security administrator is prompted to manually select a scripted response for each event node.
The determination to automatically run all scripted responses can also be determined by a risk management program on the computer system that classifies intrusions to determine whether an automatic response should be activated. For example, if the risk management program determines that the current intrusion is of a known classification type, or is or a known severity that could cause the entire system to crash, an automatic scripted response may be initiated. In a preferred embodiment, the severity of the intrusion is matched with a severity of the results of a scripted response. That is, a severe intrusion is matched to a scripted response that may have a severe impact on the system, such as preemptively bringing down a part of the system, but the severe impact may be justified due to the severe nature of the intrusion and the potential harm the intrusion may cause.
Similarly, if the risk management program has been designed to understand that the expected response time for the security administrator to respond is likely to be so long that significant damage is done to the system before the security administrator responds, an automatic scripted response may be initiated. Likewise, if a particular intrusion path has historically resulted in execution of specific scripted responses a significant number of times (or only once), then the risk management program can automatically initiate execution of the scripted responses based on this history.
In addition to common event patterns, as illustrated in <b>Figures 2a</b> and <b>2b,</b> intrusions also have signatures regarding what hardware in a hardware topology is affected. With reference now to <b>Figure 4a,</b> there is depicted hardware that may be affected by an intrusion. An intrusion path <b>400,</b> identified in the figure by bold bordered boxes, identified hardware topology of a computer system that is affected by Intrusion A, described above in <b>Figure 2a.</b> Thus, Intrusion A causes an anomaly in an enterprises computer system's intranet <b>402,</b> which is affected by a local area network (LAN) A <b>404</b> in intranet <b>402.</b> Within LAN A <b>404</b> are affected servers <b>406,</b> personal computers (PC's) <b>408</b> and intrusion detection system (IDS) hardware <b>410.</b> Within servers <b>406</b> is an affected web server <b>416,</b> whose portal B <b>418</b> is also affected by Intrusion A. Similarly, all PC's running Windows® based operating systems are affected and shown as Windows® based <b>414</b> PC's. Likewise, IDS hardware <b>410</b> running Snort enabled hardware <b>412</b> registers an event that Intrusion A has been detected. Thus, the hardware shows a signature intrusion pattern in a manner analogous to that of the intrusion event intrusion pattern described above with <b>Figures 2a</b> and <b>2b.</b>
With reference now to <b>Figure 4b,</b> the hardware topology intrusion path <b>401</b> depicts that pattern caused by Intrusion A. When a current unknown intrusion occurs having a same or similar pattern as shown by hardware topology intrusion path <b>401,</b> the security administrator responds in a manner similar to that described for the intrusion event intrusion pattern above. Thus, each event node in the hardware topology intrusion path <b>401</b> includes an associated active window containing scripted response(s), which are analogous to those described above in describing <b>Figures 2a</b> and <b>2b.</b> As with scripted responses for intrusion events, the scripted responses described in the hardware topology intrusion path <b>401</b> may be singular, as depicted, or may be a list of suggested scripted responses, which list is preferably scored such that a highest scripted response is advocated. The scripted responses may be initiated manually or automatically in a manner analogous to that described above for intrusion event intrusion paths.
As with the graphical display of intrusion events described and depicted above with <b>Figure 2a</b> and <b>2b,</b> intrusion paths of known and unknown intrusions need not be identical to provide the security administrator information on how to respond to the intrusion. That is, if the known and unknown intrusions have a certain number of commonalities in their intrusion paths, the security administrator may initiate a response that will cure most, if not all, of the detrimental effects of the current unknown intrusion.
The scripted response to the intrusion may be initiated by the security administrator either locally or remotely, in response to a notification. For example, the security administrator may receive a notification on a cellular phone or personal digital assistant (PDA) informing her of the intrusion event. The security administrator may then activate some or all of the scripted responses electronically by clicking an interactive window in the PDA, such that the input is recognized by a risk management program for the computer system to initiate the requested scripted response(s).
The preferred embodiment described above presents a method and means for creating and graphically representing an intrusion pattern of a known intrusion for comparison to an current intrusion, which may be known or unknown by the risk management program of the computer system. After the current intrusion is identified according to its signature intrusion path which is graphically represented, scripted responses are initiated to respond to and control the intrusion. The scripted responses may be based on historical data for the known intrusion. The known and current intrusions may be the same or different, and suggested scripted responses are graphically suggested in association with some or all of the event or hardware nodes in the intrusion path affected by the current intrusion. The scripted response may be a single choice for each event/hardware node in the intrusion path, or may be chosen from a list of ranked suggested scripted responses.
Programs defining functions of the preferred embodiment can be delivered to a data storage system or computer system via a variety of signal-bearing media, which include, without limitation, non-writable storage media (e.g. CD-ROM), writable storage media (e.g. a floppy diskette, hard disk drive, read/write CD-ROM, optical media), and communication media, such as computer and telephone networks including Ethernet. Such signal-bearing media, when carrying or encoding computer readable instructions that direct method functions of the present invention, represent alternative embodiments of the present invention.
Contents3
6 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6
Every citation, both waysCites: the store holds 2 of 3
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US7941854B2 | Cited by | United States of America | Applicant |
| FR3104776A1 | Cited by | France | Applicant |
| WO0223808A | Cites | World Intellectual Property Organization (WIPO) | – |
| US5684957A | Cites | United States of America | – |
| SPAFFORD E H ET AL: "Intrusion detection using autonomous agents" COMPUTER NETWORKS, ELSEVIER SCIENCE PUBLISHERS B.V., AMSTERDAM, NL, vol. 34, no. 4, October 2000 (2000-10), pages 547-570, XP004304737 ISSN: 1389-1286 | Non-patent | – | – |
| DEBAR H ET AL: "Towards a taxonomy of intrusion-detection systems" COMPUTER NETWORKS, ELSEVIER SCIENCE PUBLISHERS B.V., AMSTERDAM, NL, vol. 31, no. 8, 23 April 1999 (1999-04-23), pages 805-822, XP004304519 ISSN: 1389-1286 | Non-patent | – | – |
20 members in 10 offices
Priority claims9
| Document | Office | Kind | Date |
|---|---|---|---|
| 313732 | United States of America | – | |
| 31373202 | United States of America | A | |
| 31373202 | United States of America | A | |
| 0305219 | United Kingdom | W | |
| 0305219 | United Kingdom | W | |
| 313732 | – | – | – |
| GB2003005219 | – | – | – |
| US20020313732 | – | – | – |
| WO2003GB05219 | – | – | – |
Members20
| Document | Office | Kind | |
|---|---|---|---|
| US2004111637A1 | United States of America | A1 | |
| WO2004051441A2 | World Intellectual Property Organization (WIPO) | A2 | |
| AU2003285563A1 | Australia | A1 | |
| AU2003285563A8 | Australia | A8 | |
| WO2004051441A3 | World Intellectual Property Organization (WIPO) | A3 | |
| TW200424845A | Taiwan Province of China | A | |
| TWI234707B | Taiwan Province of China | B | |
| KR20050086445A | Republic of Korea | A | |
| EP1567926A2 | European Patent Office (EPO) | A2 | |
| CN1695365A | China | A | |
| JP2006509283A | Japan | A | |
| EP1567926B1This record | European Patent Office (EPO) | B1 | |
| AT341024T | Austria | T | |
| ATE341024T1 | Austria | T1 | |
| DE60308722D1 | Germany | D1 | |
| KR100734732B1 | Republic of Korea | B1 | |
| DE60308722T2 | Germany | T2 | |
| JP4283228B2 | Japan | B2 | |
| CN100518174C | China | C | |
| US7941854B2 | United States of America | B2 |
55 legal events, as 6 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Patent expired after termination of 20 yearsExpiredPE20 | PE20 | GB | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Application deemed withdrawn, or ip right lapsed, due to non-payment of renewal feeWithdrawnR119 | R119 | DE | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Notification of lapseLapsedST | ST | FR | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Register noted 'licences of right' (sect. 46/1977)746 | 746 | GB | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| No opposition filedOpposition26N | 26N | EP | |
| No opposition filed within time limitOppositionORIGINAL CODE: 0009261PLBE | PLBE | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: NO OPPOSITION FILED WITHIN TIME LIMITSTAA | STAA | EP | |
| Patent ceasedCeasedPL | PL | CH | |
| Fr: translation filedET | ET | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Nl: lapsed or annulled due to failure to fulfill the requirements of art. 29p and 29m of the patents actLapsedNLV1 | NLV1 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Corresponds to:REF | REF | EP | |
| European patents granted designating irelandGrantedFG4D | FG4D | IE | |
| European patent takes effect as a national patent in ch/liEP | EP | CH | |
| New agentNV | NV | CH | |
| Designated contracting statesAK | AK | EP | |
| European patent grantedGrantedFG4D | FG4D | GB | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| (expected) grantORIGINAL CODE: 0009210GRAA | GRAA | EP | |
| Grant fee paidORIGINAL CODE: EPIDOSNIGR3GRAS | GRAS | EP | |
| Despatch of communication of intention to grant a patentORIGINAL CODE: EPIDOSNIGR1GRAP | GRAP | EP | |
| Request for extension of the european patent (deleted)DAX | DAX | EP | |
| Request for examination filed17P | 17P | EP | |
| Designated contracting statesAK | AK | EP | |
| Request for extension of the european patentAX | AX | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP |
Numbers
- Publication
- 1567926
- Publication, DOCDB
- 1567926
- Publication, EPODOC
- EP1567926
- Application
- 3778561
- Application, DOCDB
- 03778561
- Application, EPODOC
- EP20030778561
Titles3
- German
- VERFAHREN, VORRICHTUNG UND COMPUTERSOFTWARE-PRODUKT ZUR REAKTION AUF COMPUTEREINBRÜCHE
- English
- METHOD, SYSTEM AND COMPUTER SOFTWARE PRODUCT FOR RESPONDING TO A COMPUTER INTRUSION
- French
- PROCEDE ET SYSTEME PERMETTANT DE REPONDRE A UNE INTRUSION SUR ORDINATEUR
Classification
- CPC, 8
- G06F21/316
- H04L63/1408
- G06F21/552
- G06F21/554
- G06F21/566
- G06F2221/2101
- H04L63/1458
- G06F21/556
- IPC, 8
- G06F1 00
- G06F9 30
- G06F11 30
- G06F11 36
- G06F15 00
- G06F21 00
- H04L12 24
- H04L29 06
Designated states1
- Contracting states, 1
- Türkiye