Patent · US Active

Inline intrusion detection using a single physical port

US7555774B2 · kind B2 · utility

3Cited by
33References
17Claims
0Family size

Assignee

Inventors

Key dates

Filing dateAug 2, 2004
Grant dateJun 30, 2009
Priority date
Expiry dateOct 7, 2026

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L63/1416
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

In accordance with one embodiment of the present invention, a method for inline intrusion detection includes receiving a packet at a physical interface of an intrusion detection system. The packet is tagged with a first VLAN identifier associated with an external network. The network further includes buffering the packet at the physical interface, communicating a copy of the packet to a processor, and analyzing the copy of the packet at the processor to determine whether the packet includes an attack signature. The method also includes communicating a reply message from the processor to the interface indicating whether the packet includes an attack signature. If the packet does not contain an attack signature the buffered copy of the packet is re-tagged with a second VLAN identifier associated with a protected network and re-tagged packet is communicated to the protected network.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.