Network intrusion detection with distributed correlation
US8516576B2 · kind B2 · utility
Assignee
Inventors
Key dates
| Filing date | Jan 13, 2010 |
| Grant date | Aug 20, 2013 |
| Priority date | — |
| Expiry date | Jan 13, 2032 |
Classification
- Technology area (CPC H)Electricity
- CPC primaryH04L63/205
- WIPO fieldDigital communication
- WIPO sectorElectrical engineering
Abstract
A network security system employing multiple levels of processing to identify security threats. Multiple host machines may each contain an agent that detects possibilities of security threats based on raw data sensed locally at that host. The hosts may share information obtained from local analysis and each host may use information generated at one or more other hosts, in combination with information generated locally, to identify a security concern, indicating with greater certainty that a security threat exists. Based on security concerns generated by multiple hosts, a security threat may be indicated and protective action may be taken.
Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.