US2003229703A1PendingUtilityA1

Method and apparatus for identifying intrusions into a network data processing system

Assignee: IBMPriority: Jun 6, 2002Filed: Jun 6, 2002Published: Dec 11, 2003
Est. expiryJun 6, 2022(expired)· nominal 20-yr term from priority
H04L 63/1416H04L 2463/146
42
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method, apparatus, and computer instructions for handling intrusions. A tracer packet is sent back to an intruder causing the intrusion in response to receiving notification of an intrusion from a particular node in a network data processing system. Nodes in the network data processing system are notified of the tracer packet. Identification of the node is stored for use in tracing a route of the tracer packet through the data processing system in response to receiving a message from a node indicating receipt of the tracer packet.

Claims

exact text as granted — not AI-modified
What is claimed is:  
     
         1 . A method in a data processing system for handling intrusions, the method comprising: 
 responsive to receiving notification of an intrusion from a particular node in a network data processing system, sending a tracer packet back to an intruder causing the intrusion;    notifying nodes in the network data processing system of the tracer packet; and    responsive to receiving a message from a node indicating receipt of the tracer packet, storing identification of the node for use in tracing a route of the tracer packet through the data processing system.    
     
     
         2 . The method of  claim 1  further comprising: 
 determining whether the intruder is a node within the network data processing system using the route; and  
 responsive to the intruder being a node within the network data processing system, revoking access by the intruder to other nodes within the network data processing system.  
 
     
     
         3 . The method of  claim 2  further comprising: 
 responsive to the intruder being a node outside of the network data processing system, identifying an entry node serving as an entry point into the network data processing system; and  
 preventing access to the entry node.  
 
     
     
         4 . The method of  claim 1 , wherein the network data processing system is a grid.  
     
     
         5 . A method in a data processing system for handling an intrusion, wherein the data processing system is located within a network data processing system, the method comprising: 
 detecting an intrusion by a attacking node, wherein a connection is established with the attacking node;    responsive to detecting the intrusion, sending a notification of the intrusion to a security node in the network data processing system;    ceasing communication with the attacking node; and    maintaining the connection with the attacking node.    
     
     
         6 . The method of  claim 5 , wherein the network data processing system is a grid.  
     
     
         7 . The method of  claim 5 , wherein the attacking node is a node within the network data processing system.  
     
     
         8 . The method of  claim 5 , wherein the attacking node is a node outside of the network data processing system.  
     
     
         9 . A network data processing system comprising: 
 a network;    a security node connected to the network; and    a plurality of nodes connected to the network, wherein a victim node within the plurality of nodes sends an intrusion alert to the security node in response to detecting an attack in which the intrusion alert includes information about the intrusion, the security node sends a tracer packet onto the network and notifies the plurality of nodes of the tracer pack when an intrusion alert is received, each of the plurality of nodes looks for the tracer packet and sends a message to the security node when the tracer packet in which the message indicates reception of the tracer node, and the security node stores information about nodes within the plurality of nodes receiving the tracer packet for use in identifying a route of the tracer packet in the network data processing system.    
     
     
         10 . A data processing system for handling intrusions, the data processing system comprising: 
 a bus system;    a communications unit connected to the bus system;    a memory connected to the bus system, wherein the memory includes a set of instructions; and    a processing unit connected to the bus system, wherein the processing unit executes the set of instructions to send a tracer packet back to an intruder causing the intrusion in response to receiving notification of an intrusion from a particular node in a network data processing system; notify nodes in the network data processing system of the tracer packet; and store identification of the node for use in tracing a route of the tracer packet through the data processing system in response to receiving a message from a node indicating receipt of the tracer packet.    
     
     
         11 . A data processing system for handling an intrusion, the data processing system comprising: 
 a bus system;    a communications unit connected to the bus system;    a memory connected to the bus system, wherein the memory includes a set of instructions; and    a processing unit connected to the bus system, wherein the processing unit executes the set of instructions to detect an intrusion by a attacking node in which a connection is established with the attacking node; send a notification of the intrusion to a security node in the network data processing system in response to detecting the intrusion; cease communication with the attacking node; and maintain the connection with the attacking node.    
     
     
         12 . A data processing system for handling intrusions, the data processing system comprising: 
 sending means, responsive to receiving notification of an intrusion from a particular node in a network data processing system, for sending a tracer packet back to an intruder causing the intrusion;    notifying means for notifying nodes in the network data processing system of the tracer packet; and    storing means, responsive to receiving a message from a node indicating receipt of the tracer packet, for storing identification of the node for use in tracing a route of the tracer packet through the data processing system.    
     
     
         13 . The data processing system of  claim 12  further comprising: 
 determining means for determining whether the intruder is a node within the network data processing system using the route; and  
 revoking means, responsive to the intruder being a node within the network data processing system, for revoking access by the intruder to other nodes within the network data processing system.  
 
     
     
         14 . The data processing system of  claim 13  further comprising: 
 identifying means, responsive to the intruder being a node outside of the network data processing system, for identifying an entry node serving as an entry point into the network data processing system; and  
 preventing means for preventing access to the entry node.  
 
     
     
         15 . The data processing system of  claim 12 , wherein the network data processing system is a grid.  
     
     
         16 . A data processing system for handling an intrusion, wherein the data processing system is located within a network data processing system, the data processing system comprising: 
 detecting means for detecting an intrusion by a attacking node, wherein a connection is established with the attacking node;    sending means, responsive to detecting the intrusion, for sending a notification of the intrusion to a security node in the network data processing system;    ceasing means for ceasing communication with the attacking node; and    maintaining means for maintaining the connection with the attacking node.    
     
     
         17 . The data processing system of  claim 16 , wherein the network data processing system is a grid.  
     
     
         18 . The data processing system of  claim 16 , wherein the attacking node is a node within the network data processing system.  
     
     
         19 . The data processing system of  claim 16 , wherein the attacking node is a node outside of the network data processing system.  
     
     
         20 . A computer program product in a computer readable medium for handling intrusions, the computer program product comprising: 
 first instructions, responsive to receiving notification of an intrusion from a particular node in a network data processing system, for sending a tracer packet back to an intruder causing the intrusion;    second instructions for notifying nodes in the network data processing system of the tracer packet; and    third instructions, responsive to receiving a message from a node indicating receipt of the tracer packet, for storing identification of the node for use in tracing a route of the tracer packet through the data processing system.    
     
     
         21 . A computer program product in a computer readable medium for handling an intrusion in a data processing system located within a network data processing system, the computer program product comprising: 
 first instructions for detecting an intrusion by a attacking node, wherein a connection is established with the attacking node;    second instructions, responsive to detecting the intrusion, for sending a notification of the intrusion to a security node in the network data processing system;    third instructions for ceasing communication with the attacking node; and    fourth instructions for maintaining the connection with the attacking node.

Join the waitlist — get patent alerts

Track US2003229703A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.