EP1817685A2

Intrusion detection in a data center environment

Abstract

This record has no abstract on file.

Term

Term ended

Projected expiry passed 11 October 2025, 1 year ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

20 claims: 3 independent, 17 dependent

  1. 1
    Claims of equivalent WO 2006049814 A2 What Is Claimed Is:1. In a network environment having a plurality of traffic sources, a system for monitoring traffic on at least a portion of said plurality of traffic sources comprising: means for copying traffic from each of said plurality of traffic sources;a plurality of intrusion detection systems, at least one of which is associated with each of said plurality of traffic sources;and means for redirecting the copied traffic from each of said plurality of traffic sources to said associated one of said plurality of intrusion detection systems.
  2. 12
    In a network having at least three subnets, a system for selectively monitoring traffic on each of said subnets comprising:a plurality of intrusion detection systems;a switch adapted to identify traffic to be copied;a VLAN adapted to receive said copied traffic;and a switch associated with said VLAN adapted for performing a hierarchal determination the traffic source and the traffic type and for selectively sending said traffic to a selected one of said intrusion detection systems based on the traffic source and the traffic type.
  3. 16
    In a network having at least three subnets, a method for selectively monitoring traffic on each of said selective comprising:configuring a first switch for copying traffic from each of said subnets;sending a copy of said copied traffic to a virtual local area network;determining the source and destination of said traffic;determining traffic type (layer 4 protocol and layer 4 port);based on said determining steps, filtering said traffic to remove safe traffic;and redirecting the filtered traffic to an intrusion detection system.