Integrated network intrusion detection
Abstract
Intrusion preludes may be detected (including detection using fabricated responses to blocked network requests), and particular sources of network communications may be singled out for greater scrutiny, by performing intrusion analysis on packets blocked by a firewall. An integrated intrusion detection system uses an end-node firewall that is dynamically controlled using invoked-application information and a network policy. The system may use various alert levels to trigger heightened monitoring states, alerts sent to a security operation center, and/or logging of network activity for later forensic analysis. The system may monitor network traffic to block traffic that violates the network policy, monitor blocked traffic to detect an intrusion prelude, and monitor traffic from a potential intruder when an intrusion prelude is detected. The system also may track behavior of applications using the network policy to identify abnormal application behavior, and monitor traffic from an abnormally behaving application to identify an intrusion.
Claims
exact text as granted — not AI-modified1 . (canceled)
2 . A machine-implemented method comprising:
receiving requests for network communication services from an invoked application; selectively designating each of the received requests as authorized or unauthorized based on a network policy; and monitoring network communications, for the invoked application, based on the designating of the requests.
3 . The method of claim 2 , wherein selectively designating each of the received requests comprises selectively designating each of the received requests as authorized or unauthorized based on an application-specific network policy corresponding to the invoked application.
4 . The method of claim 3 , wherein monitoring the network communications comprises monitoring outbound network communications.
5 . The method of claim 2 , further comprising increasing a monitoring level for the invoked application when the invoked application behaves abnormally.
6 . The method of claim 5 , wherein increasing the monitoring level for the invoked application comprises adding the invoked application to a watch list to initiate monitoring of network communications both to and from the application, including searching packets for application-specific intrusion signatures.
7 . The method of claim 2 , wherein monitoring of the network communications for the invoked application comprises monitoring in an intrusion detection system component invoked with the invoked application.
8 . The method of claim 7 , wherein the intrusion detection system component and the invoked application run within a single execution context.
9 . A machine-readable medium embodying machine instructions for causing one or more machines to perform operations comprising:
receiving requests for network communication services from an invoked application; selectively designating each of the received requests as authorized or unauthorized based on a network policy; and monitoring network communications, for the invoked application, based on the designating of the requests.
10 . The machine-readable medium of claim 9 , wherein selectively designating each of the received requests comprises selectively designating each of the received requests as authorized or unauthorized based on an application-specific network policy corresponding to the invoked application.
11 . The machine-readable medium of claim 10 , wherein monitoring the network communications comprises monitoring outbound network communications.
12 . The machine-readable medium of claim 9 , the operations further comprising increasing a monitoring level for the invoked application when the invoked application behaves abnormally.
13 . The machine-readable medium of claim 12 , wherein increasing the monitoring level for the invoked application comprises adding the invoked application to a watch list to initiate monitoring of network communications both to and from the application, including searching packets for application-specific intrusion signatures.
14 . The machine-readable medium of claim 9 , wherein monitoring of the network communications for the invoked application comprises monitoring in an intrusion detection system component invoked with the invoked application.
15 . The machine-readable medium of claim 14 , wherein the intrusion detection system component and the invoked application run within a single execution context.
16 . A system comprising:
a processor; a communication interface coupled with the processor; and a machine-readable medium operatively coupled with the processor and embodying machine instructions for causing the processor to perform operations comprising: receiving requests for network communication services from an invoked application; selectively designating each of the received requests as authorized or unauthorized based on a network policy; and monitoring network communications, for the invoked application, based on the designating of the requests.
17 . The system of claim 16 , wherein selectively designating each of the received requests comprises selectively designating each of the received requests as authorized or unauthorized based on an application-specific network policy corresponding to the invoked application.
18 . The system of claim 17 , wherein monitoring the network communications comprises monitoring outbound network communications.
19 . The system of claim 16 , the operations further comprising increasing a monitoring level for the invoked application when the invoked application behaves abnormally.
20 . The system of claim 19 , wherein increasing the monitoring level for the invoked application comprises adding the invoked application to a watch list to initiate monitoring of network communications both to and from the application, including searching packets for application-specific intrusion signatures.
21 . The system of claim 16 , wherein monitoring of the network communications for the invoked application comprises monitoring in an intrusion detection system component invoked with the invoked application.
22 . The system of claim 21 , wherein the intrusion detection system component and the invoked application run within a single execution context.Join the waitlist — get patent alerts
Track US2007209070A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.