US2012096539A1PendingUtilityA1

Wireless intrusion prevention system and method

Assignee: HU GUONINGPriority: Nov 27, 2006Filed: Dec 23, 2011Published: Apr 19, 2012
Est. expiryNov 27, 2026(~0.3 yrs left)· nominal 20-yr term from priority
H04W 12/125H04W 12/128G06F 21/552Y02D30/70H04L 63/1416G06F 21/74G06F 2221/2105G06F 21/566H04L 63/0218
46
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A wireless intrusion prevention system and method to prevent, detect, and stop malware attacks is presented. The wireless intrusion prevention system monitors network communications for events characteristic of a malware attack, correlates a plurality of events to detect a malware attack, and performs mitigating actions to stop the malware attack.

Claims

exact text as granted — not AI-modified
1 . A network device, comprising:
 a network interface configured to receive an indication from a mobile device that the mobile device has detected malicious network activity originating from a source Internet protocol (IP) address, wherein the mobile device is separate from the network device; and   a mitigation agent configured to detect packets originating from the source IP address and to drop packets originating from the source IP address.   
     
     
         2 . The network device of  claim 1 , wherein the mitigation agent is further configured to instruct one or more additional mitigation agents of one or more additional network devices, separate from the network device and the mobile device, to drop packets originating from the source IP address, in response to the indication from the mobile device. 
     
     
         3 . A system comprising:
 a network device comprising a mitigation agent configured to trigger a mitigating action in response to detected malicious events; and   a mobile device, separate from the network device, the mobile device comprising a detection agent configured to detect a malicious event from network traffic received by the mobile device, to determine a source Internet protocol (IP) address for the malicious event, and to provide an indication of the source IP address to the mitigation agent of the network device,   wherein the mitigation agent is configured to drop packets originating from the source IP address and to instruct one or more additional mitigation agents of one or more additional network devices, separate from the network device and the mobile device, to drop packets originating from the source IP address, in response to the indication from the mobile device.   
     
     
         4 . The system of  claim 3 , further comprising a security center device, wherein the mitigation agent is configured to send an indication of the source IP address to the security center device, and wherein the security center device is configured to send an indication of the source IP address to a plurality of network devices to cause the plurality of network devices to drop packets originating from the source IP address. 
     
     
         5 . A method comprising:
 receiving, by a network device, an indication from a mobile device that the mobile device has detected malicious network activity originating from a source Internet protocol (IP) address, wherein the mobile device is separate from the network device;   detecting packets originating from the source IP address; and   dropping the detected packets originating from the source IP address.   
     
     
         6 . The method of  claim 5 , further comprising instructing one or more additional network devices, separate from the network device and the mobile device, to drop packets originating from the source IP address, in response to the indication from the mobile device. 
     
     
         7 . A non-transitory computer-readable storage medium comprising instructions that, when executed, cause a processor of a network device to:
 receive an indication from a mobile device that the mobile device has detected malicious network activity originating from a source Internet protocol (IP) address, wherein the mobile device is separate from the network device;   detect packets originating from the source IP address; and   drop the detected packets originating from the source IP address.   
     
     
         8 . The computer-readable storage medium of  claim 7 , further comprising instructions that cause the processor to instruct one or more additional network devices, separate from the network device and the mobile device, to drop packets originating from the source IP address, in response to the indication from the mobile device.

Join the waitlist — get patent alerts

Track US2012096539A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.