US2005193429A1PendingUtilityA1

Integrated data traffic monitoring system

Assignee: BARRIER GROUPPriority: Jan 23, 2004Filed: Jan 24, 2005Published: Sep 1, 2005
Est. expiryJan 23, 2024(expired)· nominal 20-yr term from priority
H04L 63/0281H04L 63/1458H04L 51/212H04L 63/1408H04L 63/1466H04L 63/145H04L 63/0209H04L 63/0236H04L 63/0245H04L 41/16H04L 63/1475H04L 63/0254H04L 63/0263H04L 63/1425H04L 63/1441H04L 63/1416G06F 21/552H04L 63/02
38
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

The present invention includes an integrated data traffic monitoring system monitoring data traffic received from a communication network and destined for a protected network. The monitoring system includes a security appliance and one or more security and monitoring technologies such as hardware and open source and proprietary software products. The security appliance and the security and monitoring technologies may be implemented as separate and distinct modules or combined into a single security appliance. The security and monitoring technologies monitor network data traffic on, or directed to, the protected network. The monitoring system collects data from each of the technologies into an event database and, based on the data, automatically generates rules directing one or more of the technologies to prevent subsequent communications traffic from specific sources from entering the protected network.

Claims

exact text as granted — not AI-modified
1 . A method of automatically generating rules for an intrusion detection module comprising: 
 analyzing a data packet received from a communication network by the intrusion detection module using a set of rules, the data packet containing a source IP address;    in response to the packet failing the analyzing operation, 
 searching an event database for events associated with the source IP address of the packet,  
 if the event database contains an event record associated with the source IP address of the packet, 
 generating a new rule to block subsequent packets from the source IP address of the packet for a predetermined period of time; and  
 adding the new rule to the set of rules used by the intrusion detection module.  
 
   
   
   
       2 . The method of  claim 1 , wherein the event database is maintained by an integrated security system separate from the intrusion detection module.  
   
   
       3 . The method of  claim 1  further comprising: 
 generating, by the intrusion detection module, event data based on the data packet, the event data including the IP address of the packet, and    transmitting the event data to the integrated security system.    
   
   
       4 . The method of  claim 1  further comprising: 
 storing at least some of the event data in a new event record in the event database.    
   
   
       5 . The method of  claim 1 , wherein at least some event records in the event database are based on event data received from the intrusion detection module.  
   
   
       6 . The method of  claim 1 , wherein the event record associated with the source IP address of the packet was created from event data received from a firewall module.  
   
   
       7 . The method of  claim 1 , wherein the event record associated with the source IP address of the packet was created from event data received from a virus detection module.  
   
   
       8 . The method of  claim 1 , wherein the event record associated with the source IP address of the packet was created from event data received from a VPN authentication module.  
   
   
       9 . The method of  claim 1 , the event record associated with the source IP address of the packet was created from event data received from a monitor module other than the intrusion detection module.  
   
   
       10 . A method of screening packets received from a communication network comprising: 
 receiving a packet associated with one of an e-mail message, a VPN connection, and a web page response, the packet having a source;    performing an intrusion detection analysis on the packet using a set of intrusion detection rules;    if the packet passes the intrusion detection analysis, performing a firewall analysis on the packet using a set of firewall rules;    if the packet passes the firewall analysis, determining if the packet is associated with an e-mail message, a VPN connection or a web page response;    if the packet is associated with an e-mail message, performing a virus analysis on the packet using a set of virus definitions;    if the packet is associated with a VPN connection, performing an authentication analysis on the packet using a set of authentication criteria; and    if the packet fails any of the intrusion detection analysis, the firewall analysis, the virus analysis, or the authentication analysis, automatically generating a new intrusion detection rule to delete any subsequent packets received from the same source as the packet.    
   
   
       11 . The method of  claim 10 , further comprising: 
 if the packet fails any of the intrusion detection analysis, the firewall analysis, the virus analysis, or the authentication analysis, deleting the packet.    
   
   
       12 . The method of  claim 10 , wherein automatically generating a new intrusion detection rule comprises: 
 generating event data based on the packet; and    storing at least some of the event data in a new event record associated with the packet in an event database having a plurality of event records associated with previously received packets.    
   
   
       13 . The method of  claim 10 , wherein automatically generating a new intrusion detection rule further comprises: 
 automatically generating a new intrusion detection rule if one or more of the plurality of event records are associated with previously received packets from the source.    
   
   
       14 . The method of  claim 12 , wherein the event data comprises a priority associated with the packet and automatically generating further comprises: 
 assigning an initial priority to the event data; and    automatically increasing a priority associated with the packet if one or more of the plurality of event records are associated with previously received packets from the source and the priority is less than a highest priority.    
   
   
       15 . The method of  claim 14 , further comprising: 
 storing the priority assigned to the event data with the event data.    
   
   
       16 . A computing system for receiving communication packets from a communication network and transmitting the communication packets to a protected network, the computing system comprising: 
 an intrusion detection module that compares a communication packet to a set of rules and, based on the comparison, either transmits the communication packet to a firewall or deletes the communication packet and transmits event data based on the deleted communication packet to an event database;    an event database that stores an event record based on the event data received from the intrusion detection module and maintains a plurality of event records based on previously received event data; and    an integrated security system that analyzes the event data and the plurality of event records and, based on the results of the analysis, automatically generates at least one rule to the intrusion detection module.

Join the waitlist — get patent alerts

Track US2005193429A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.