Network intrusion detection in a network that includes a distributed virtual switch fabric
Abstract
A network intrusion detection system (NIDS) works in conjunction with a distributed virtual switch fabric to provide enhanced network intrusion detection in a way that does not require as much human intervention, autonomically adjusts to hardware changes in the network, and responds much more quickly than known network intrusion detection systems. The NIDS accesses network information from the distributed virtual switch fabric, which gives the NIDS access to a virtual view that includes hardware information for all networking devices in the network. This allows the NIDS to automatically determine network topology, update itself as hardware in the network is added or changed, and promptly take automated service actions in response to detected network intrusions. The result is a NIDS that is easier to configure, maintain, and use, and that provides enhanced network security.
Claims
exact text as granted — not AI-modified1 . A computer-implemented method for detecting network intrusions in a networked computer system that includes a plurality of networks interconnecting a plurality of systems, the plurality of systems including a distributed virtual switch fabric that provides a virtual view of the plurality of networks and the plurality of systems, the method comprising the steps of:
querying the distributed virtual switch fabric to determine from the virtual view network topology and configuration of the networked computer system; defining a plurality of attack signatures that specify characteristics of network intrusions; defining a plurality of service actions that each may be performed automatically without input from a human system administrator when a network intrusion that matches at least one of the plurality of attack signatures is detected by the network intrusion detection system; detecting a network intrusion in the networked computer system that matches at least one of the plurality of attack signatures; and in response to detecting the network intrusion that matches the at least one of the plurality of attack signatures, autonomically performing at least one of the plurality of service actions without input from a human system administrator.
2 . The method of claim 1 wherein the plurality of service actions comprises monitoring a compromised host that originated network traffic detected as the network intrusion.
3 . The method of claim 1 wherein the plurality of service actions comprises quarantining a compromised host that originated network traffic detected as the network intrusion.
4 . The method of claim 1 wherein the plurality of service actions comprises moving to a different network a compromised host that originated network traffic detected as the network intrusion to a different network.
5 . The method of claim 1 wherein the plurality of service actions comprises shutting down a compromised host that originated network traffic detected as the network intrusion.
6 . The method of claim 1 further comprising the steps of:
detecting an addition to the plurality of systems;
querying the distributed virtual switch fabric to determine if the addition is reflected in the virtual view of the plurality of networks and the plurality of systems; and
when the addition is reflected in the virtual view, autonomically changing the network topology and configuration without input from a human system administrator.
7 . The method of claim 1 further comprising the steps of:
detecting a change to the plurality of systems;
querying the distributed virtual switch fabric to determine if the change is reflected in the virtual view of the plurality of networks and the plurality of systems; and
when the change is reflected in the virtual view, autonomically changing the network topology and configuration without input from a human system administrator.
8 . A computer-implemented method for detecting network intrusions in a networked computer system that includes a plurality of networks interconnecting a plurality of systems, the plurality of systems including a distributed virtual switch fabric that provides a virtual view of the plurality of networks and the plurality of systems, the method comprising the steps of:
(A) configuring a network intrusion detection system by performing the steps of:
querying the distributed virtual switch fabric to determine from the virtual view network topology and configuration of the networked computer system;
defining a plurality of attack signatures that specify characteristics of network intrusions;
defining a plurality of service actions that each may be performed automatically without input from a human system administrator when a network intrusion that matches at least one of the plurality of attack signatures is detected by the network intrusion detection system;
(B) running the network intrusion detection system, which performs the steps of:
monitoring network traffic in the networked computer system;
detecting a network intrusion in the networked computer system that matches at least one of the plurality of attack signatures; and
in response to detecting the network intrusion that matches the at least one of the plurality of attack signatures, when a corresponding action for the detected network intrusion is to notify a human system administrator, notifying the human system administrator of the network intrusion, and when the corresponding action for the detected network intrusion is to perform a specified service action, automatically performing the specified service action and notifying the system administrator, wherein the specified service action comprises performing at least one of the following steps:
monitoring a compromised host that originated network traffic detected as the network intrusion;
quarantining the compromised host;
moving to a different network the compromised host; and
shutting down the compromised host.Join the waitlist — get patent alerts
Track US2013219500A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.