发明名称 Distributed intrusion response system
摘要 A system and method to respond to intrusions detected on a network system including attached functions and a network infrastructure. The system includes means for receiving from an intrusion detection function information about intrusions, a directory service function for gathering and reporting at least the physical and logical addresses of devices of the network infrastructure associated with the detected intrusions, and a plurality of distributed enforcement devices of the network infrastructure for enforcing policies responsive to the detected intrusions. A policy decision function evaluates the reported detected intrusions and makes a determination whether one or more policy changes are required on the enforcement devices in response to a detected intrusion. A policy manager function configures the distributed enforcement devices with the responsive changed policy or policies. Policy changes rules can vary from no change to complete port blocking on one or more identified enforcement devices associated with the detected intrusion, to redirecting the associated traffic including the intrusion and these policies may be modified or removed over time as warranted by network operation.
申请公布号 US7581249(B2) 申请公布日期 2009.08.25
申请号 US20030713560 申请日期 2003.11.14
申请人 ENTERASYS NETWORKS, INC. 发明人 BUSSIERE RICHARD;TOWNSEND MARK;PETTIT STEVEN;HARRINGTON DAVID;ROESE JOHN;GRAHAM RICHARD
分类号 G06F11/00;G06F;G06F11/30;G06F21/00;H04L29/06 主分类号 G06F11/00
代理机构 代理人
主权项
地址