US2013219500A1PendingUtilityA1

Network intrusion detection in a network that includes a distributed virtual switch fabric

Assignee: IBMPriority: Feb 20, 2012Filed: Nov 27, 2012Published: Aug 22, 2013
Est. expiryFeb 20, 2032(~5.6 yrs left)· nominal 20-yr term from priority
G06F 21/50H04L 49/70H04L 63/1416
48
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A network intrusion detection system (NIDS) works in conjunction with a distributed virtual switch fabric to provide enhanced network intrusion detection in a way that does not require as much human intervention, autonomically adjusts to hardware changes in the network, and responds much more quickly than known network intrusion detection systems. The NIDS accesses network information from the distributed virtual switch fabric, which gives the NIDS access to a virtual view that includes hardware information for all networking devices in the network. This allows the NIDS to automatically determine network topology, update itself as hardware in the network is added or changed, and promptly take automated service actions in response to detected network intrusions. The result is a NIDS that is easier to configure, maintain, and use, and that provides enhanced network security.

Claims

exact text as granted — not AI-modified
1 . A computer-implemented method for detecting network intrusions in a networked computer system that includes a plurality of networks interconnecting a plurality of systems, the plurality of systems including a distributed virtual switch fabric that provides a virtual view of the plurality of networks and the plurality of systems, the method comprising the steps of:
 querying the distributed virtual switch fabric to determine from the virtual view network topology and configuration of the networked computer system;   defining a plurality of attack signatures that specify characteristics of network intrusions;   defining a plurality of service actions that each may be performed automatically without input from a human system administrator when a network intrusion that matches at least one of the plurality of attack signatures is detected by the network intrusion detection system;   detecting a network intrusion in the networked computer system that matches at least one of the plurality of attack signatures; and   in response to detecting the network intrusion that matches the at least one of the plurality of attack signatures, autonomically performing at least one of the plurality of service actions without input from a human system administrator.   
     
     
         2 . The method of  claim 1  wherein the plurality of service actions comprises monitoring a compromised host that originated network traffic detected as the network intrusion. 
     
     
         3 . The method of  claim 1  wherein the plurality of service actions comprises quarantining a compromised host that originated network traffic detected as the network intrusion. 
     
     
         4 . The method of  claim 1  wherein the plurality of service actions comprises moving to a different network a compromised host that originated network traffic detected as the network intrusion to a different network. 
     
     
         5 . The method of  claim 1  wherein the plurality of service actions comprises shutting down a compromised host that originated network traffic detected as the network intrusion. 
     
     
         6 . The method of  claim 1  further comprising the steps of:
 detecting an addition to the plurality of systems; 
 querying the distributed virtual switch fabric to determine if the addition is reflected in the virtual view of the plurality of networks and the plurality of systems; and 
 when the addition is reflected in the virtual view, autonomically changing the network topology and configuration without input from a human system administrator. 
 
     
     
         7 . The method of  claim 1  further comprising the steps of:
 detecting a change to the plurality of systems; 
 querying the distributed virtual switch fabric to determine if the change is reflected in the virtual view of the plurality of networks and the plurality of systems; and 
 when the change is reflected in the virtual view, autonomically changing the network topology and configuration without input from a human system administrator. 
 
     
     
         8 . A computer-implemented method for detecting network intrusions in a networked computer system that includes a plurality of networks interconnecting a plurality of systems, the plurality of systems including a distributed virtual switch fabric that provides a virtual view of the plurality of networks and the plurality of systems, the method comprising the steps of:
 (A) configuring a network intrusion detection system by performing the steps of:
 querying the distributed virtual switch fabric to determine from the virtual view network topology and configuration of the networked computer system; 
 defining a plurality of attack signatures that specify characteristics of network intrusions; 
 defining a plurality of service actions that each may be performed automatically without input from a human system administrator when a network intrusion that matches at least one of the plurality of attack signatures is detected by the network intrusion detection system; 
   (B) running the network intrusion detection system, which performs the steps of:
 monitoring network traffic in the networked computer system; 
 detecting a network intrusion in the networked computer system that matches at least one of the plurality of attack signatures; and 
 in response to detecting the network intrusion that matches the at least one of the plurality of attack signatures, when a corresponding action for the detected network intrusion is to notify a human system administrator, notifying the human system administrator of the network intrusion, and when the corresponding action for the detected network intrusion is to perform a specified service action, automatically performing the specified service action and notifying the system administrator, wherein the specified service action comprises performing at least one of the following steps:
 monitoring a compromised host that originated network traffic detected as the network intrusion; 
 quarantining the compromised host; 
 moving to a different network the compromised host; and 
 shutting down the compromised host.

Join the waitlist — get patent alerts

Track US2013219500A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.