IL219560A

System and method of intrusion detection in a network

Abstract

This record has no abstract on file.

IL219560A, drawing sheet 1
Sheet 1 of 16

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

15 claims: 3 independent, 12 dependent

  1. 1
    CLAIMS:1. A system of intrusion detection in a network comprising: a flow processing facility that is configured to detect and process intrusions in network data flowing through the facility, the facility comprising at least one network 5 processor module having at least one processor, a plurality of network ports for connecting network devices for communicating network data, and instructions to cause the at least one processor to recognize one or more data packets in the network data that contain data, including profile information, for processing by an application executing on the flow processing facility by applying a policy to the data, and directing a portion 10 of the network data to at least one flow processor module for executing the application based on the profile information and the policy;the at least one flow processor module having at least one processor and at least one memory for storing the application for execution by the at least one flow processor module processor, the at least one flow processor module including instructions to 15 receive the portion of the network data from the at least one network processor module, to process the data in the one or more data packets for detecting intrusions, thereby providing one or more data packets with processed data, and to return the one or more data packets with processed data to the at least one network processor module for facilitating prevention of a detected intrusion from being propagated to the network;and 20 at least one control processor module in communication with the at least one flow processor module and the at least one network processor module, and having at least one control processor module processor, and instructions for causing the at least one control processor module processor to manage the applications in the flow processor module memories. 25
  2. 5
    The system of claim I, further comprising a local memory device coupled to the at least one of control processor module.
  3. 10
    A method of intrusion detection in a network, comprising:providing a flow processing facility in-line in a network;configuring the flow processing facility to detect intrusions received by the flow processing facility by recognizing with a network processor module of the flow processing facility one or more data packets in a data flow that contain data, including 5 profile information, for processing by an application executing on the flow processing facility by applying a policy to the data;directing the one or more data packets associated with a data flow that includes detected intrusions from the network processor module to at least one application processor module, based on the profile information and the policy, to process the data 10 thereby providing one or more data packets with processed data;and executing the application on the at least one application processor module, thereby taking an action on the one or more data packets with processed data such that the data flow of the detected intrusion is not propagated to the network.