US2007209070A1PendingUtilityA1

Integrated network intrusion detection

Assignee: INTEL CORPPriority: Feb 1, 2002Filed: Feb 5, 2007Published: Sep 6, 2007
Est. expiryFeb 1, 2022(expired)· nominal 20-yr term from priority
Inventors:Satyendra Yadav
H04L 63/1408H04L 63/1425H04L 63/145H04L 63/0218H04L 63/0227H04L 63/20H04L 63/02H04L 63/1441H04L 63/1416
53
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Intrusion preludes may be detected (including detection using fabricated responses to blocked network requests), and particular sources of network communications may be singled out for greater scrutiny, by performing intrusion analysis on packets blocked by a firewall. An integrated intrusion detection system uses an end-node firewall that is dynamically controlled using invoked-application information and a network policy. The system may use various alert levels to trigger heightened monitoring states, alerts sent to a security operation center, and/or logging of network activity for later forensic analysis. The system may monitor network traffic to block traffic that violates the network policy, monitor blocked traffic to detect an intrusion prelude, and monitor traffic from a potential intruder when an intrusion prelude is detected. The system also may track behavior of applications using the network policy to identify abnormal application behavior, and monitor traffic from an abnormally behaving application to identify an intrusion.

Claims

exact text as granted — not AI-modified
1 . (canceled)  
   
   
       2 . A machine-implemented method comprising: 
 receiving requests for network communication services from an invoked application;    selectively designating each of the received requests as authorized or unauthorized based on a network policy; and monitoring network communications, for the invoked application, based on the designating of the requests.    
   
   
       3 . The method of  claim 2 , wherein selectively designating each of the received requests comprises selectively designating each of the received requests as authorized or unauthorized based on an application-specific network policy corresponding to the invoked application.  
   
   
       4 . The method of  claim 3 , wherein monitoring the network communications comprises monitoring outbound network communications.  
   
   
       5 . The method of  claim 2 , further comprising increasing a monitoring level for the invoked application when the invoked application behaves abnormally.  
   
   
       6 . The method of  claim 5 , wherein increasing the monitoring level for the invoked application comprises adding the invoked application to a watch list to initiate monitoring of network communications both to and from the application, including searching packets for application-specific intrusion signatures.  
   
   
       7 . The method of  claim 2 , wherein monitoring of the network communications for the invoked application comprises monitoring in an intrusion detection system component invoked with the invoked application.  
   
   
       8 . The method of  claim 7 , wherein the intrusion detection system component and the invoked application run within a single execution context.  
   
   
       9 . A machine-readable medium embodying machine instructions for causing one or more machines to perform operations comprising: 
 receiving requests for network communication services from an invoked application;    selectively designating each of the received requests as authorized or unauthorized based on a network policy; and    monitoring network communications, for the invoked application, based on the designating of the requests.    
   
   
       10 . The machine-readable medium of  claim 9 , wherein selectively designating each of the received requests comprises selectively designating each of the received requests as authorized or unauthorized based on an application-specific network policy corresponding to the invoked application.  
   
   
       11 . The machine-readable medium of  claim 10 , wherein monitoring the network communications comprises monitoring outbound network communications.  
   
   
       12 . The machine-readable medium of  claim 9 , the operations further comprising increasing a monitoring level for the invoked application when the invoked application behaves abnormally.  
   
   
       13 . The machine-readable medium of  claim 12 , wherein increasing the monitoring level for the invoked application comprises adding the invoked application to a watch list to initiate monitoring of network communications both to and from the application, including searching packets for application-specific intrusion signatures.  
   
   
       14 . The machine-readable medium of  claim 9 , wherein monitoring of the network communications for the invoked application comprises monitoring in an intrusion detection system component invoked with the invoked application.  
   
   
       15 . The machine-readable medium of  claim 14 , wherein the intrusion detection system component and the invoked application run within a single execution context.  
   
   
       16 . A system comprising: 
 a processor;    a communication interface coupled with the processor; and    a machine-readable medium operatively coupled with the processor and embodying machine instructions for causing the processor to perform operations comprising:    receiving requests for network communication services from an invoked application;    selectively designating each of the received requests as authorized or unauthorized based on a network policy; and    monitoring network communications, for the invoked application, based on the designating of the requests.    
   
   
       17 . The system of  claim 16 , wherein selectively designating each of the received requests comprises selectively designating each of the received requests as authorized or unauthorized based on an application-specific network policy corresponding to the invoked application.  
   
   
       18 . The system of  claim 17 , wherein monitoring the network communications comprises monitoring outbound network communications.  
   
   
       19 . The system of  claim 16 , the operations further comprising increasing a monitoring level for the invoked application when the invoked application behaves abnormally.  
   
   
       20 . The system of  claim 19 , wherein increasing the monitoring level for the invoked application comprises adding the invoked application to a watch list to initiate monitoring of network communications both to and from the application, including searching packets for application-specific intrusion signatures.  
   
   
       21 . The system of  claim 16 , wherein monitoring of the network communications for the invoked application comprises monitoring in an intrusion detection system component invoked with the invoked application.  
   
   
       22 . The system of  claim 21 , wherein the intrusion detection system component and the invoked application run within a single execution context.

Join the waitlist — get patent alerts

Track US2007209070A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.